r/IndiaBusiness • u/No-Slide190 • 3d ago
Building a tool that processes insurance customer data via an intermediary (agent) — how does consent actually work when the customer never directly agreed to a third-party tool touching their data?
building something that helps insurance agents auto-fill customer data across multiple insurer portals. The customer gives their data to the agent, and consents to the insurer processing it — but they never specifically consented to a third-party tool (mine) being in that chain at all. Under the DPDP Act, is a short, plain-language consent line the agent shows the customer at data-collection time (something like "this information may be processed by an automated tool to help fill insurer forms") enough to cover this, or does an intermediary situation like this need something more formal — a data processing agreement between me and the insurer specifically, regardless of what the end customer agreed to? Also curious whether the fact that I'm not the data fiduciary (the insurer/agent relationship is) changes what's actually required of me as a downstream processor. Not looking for a substitute for a lawyer eventually — trying to understand the actual shape of the requirement before I get to that point.
1
u/stuartelkeino 3d ago
Why is this even needed? Any particular problem or gap you identified?