DPDP for Auto Dealers: Customer Data, Finance and Insurance Leads

How DPDP applies to auto dealerships handling customer, finance and MISP insurance lead data, with vendor and consent considerations.

ComplianceCheck Team·Published 5 June 2026

Auto dealerships sit at an unusual intersection of DPDP compliance: they collect customer data for vehicle sales, share it with finance partners for loans, and share it again with insurers under MISP arrangements. Each handoff needs its own basis.

Key facts at a glance

  • DPDP applies to any business processing personal data digitally in India, including auto dealerships, regardless of whether they are also regulated by IRDAI or lenders.
  • A Motor Insurance Service Provider (MISP) is a dealer appointed by an insurer or intermediary to distribute and service motor insurance under IRDAI guidelines.
  • MISPs must retain records for at least 7 years from policy issuance or termination of appointment, whichever is later, a requirement that overrides DPDP's shorter default retention principle for that data.
  • A dealer can be sponsored by one or more insurers, or by one insurance intermediary, not both at once, under IRDAI's MISP rules.
  • Full substantive DPDP obligations, including notice and consent, become enforceable 13 May 2027, with no stated grace period.
  • Penalties for inadequate security safeguards under DPDP can reach up to Rs 250 crore per instance.

Three separate data-sharing events, three separate bases

A typical car purchase at a dealership involves personal data moving through at least three distinct relationships: the dealership itself, a finance partner if the customer takes a loan, and an insurer or intermediary if the dealership acts as a MISP for insurance. DPDP expects each of these sharing events to rest on its own clear purpose and, generally, the customer's informed consent, rather than treating "the customer's data" as one undifferentiated pool the dealership can pass around freely.

Vehicle sale and service data

Name, contact details, address, and vehicle details collected at the point of sale or during service visits are the dealership's own core customer data, used to complete the transaction and provide after-sales service.

Finance and loan referrals

When a customer opts for dealer-facilitated financing, their personal and financial details are shared with a bank or NBFC. This is a distinct purpose from the vehicle sale itself and should be clearly disclosed to the customer as such.

MISP insurance data

As a MISP, a dealer collects customer and vehicle information to facilitate a motor insurance policy on behalf of an appointed insurer or intermediary. This data flow is governed both by IRDAI's MISP guidelines and by DPDP, since it involves processing personal data.

MISP-specific obligations to keep in view

IRDAI's MISP guidelines require dealers to follow a prescribed code of conduct and to retain records for at least 7 years from policy issuance or termination of appointment, whichever is later. This retention period is longer than DPDP's general "erase once purpose is served" default, and because it comes from a sector-specific regulation, it takes precedence for that specific category of data. Dealers should keep their insurance-related records on this 7-year schedule while applying DPDP's purpose-based principle to other, non-insurance customer data they hold.

Dealers should also confirm their sponsorship structure is compliant: appointment by one or more insurers, or by one insurance intermediary, but not a mix of both at the same time.

Mapping data flows and retention by category

Data flowShared withGoverning retention logic
Vehicle sale and service historyHeld internally by the dealershipDPDP purpose-based principle
Loan/finance applicationBank or NBFC finance partnerFinance partner's own regulatory retention rules
MISP insurance policy dataSponsoring insurer or intermediaryMinimum 7 years from policy issuance or appointment termination, per IRDAI MISP guidelines
Marketing and service remindersUsed internally, sometimes via CRM vendorDPDP purpose-based principle, tied to consent for marketing use

Practical steps for dealerships

Map exactly which customer data moves to finance partners and which moves to insurers under the MISP arrangement, and make sure consent or notice language at the point of sale reflects both flows clearly rather than a single generic disclosure. Review contracts with finance partners, insurers, and any CRM or lead-management vendor for security and data-handling commitments. Keep insurance-related records on the 7-year MISP retention schedule, distinct from other customer data that may be erased sooner under DPDP's general principle.

If you are not sure where your dealership stands on DPDP compliance across sales, finance and MISP data flows, ComplianceCheck's DPDP assessment gives you a clear picture in a few minutes.

Sources

  • Ministry of Electronics and Information Technology - meity.gov.in
  • Data Protection Board of India (as constituted under DPDP) - meity.gov.in
  • Insurance Regulatory and Development Authority of India (IRDAI) - irdai.gov.in

This guide is general information, not legal advice. Requirements vary by state, sector and headcount - confirm specifics with a compliance professional or the relevant authority.

Frequently Asked Questions

Does DPDP apply to auto dealerships and not just banks or tech companies?
Yes. Any business that processes personal data digitally in India, including auto dealerships handling customer, finance and insurance data, falls within the scope of the Digital Personal Data Protection Act 2023.
Can a dealer share customer data with a bank for a car loan without consent?
Sharing customer data with a finance partner for a loan application generally requires the customer's consent for that specific purpose, since DPDP expects data sharing to stay within the scope the customer was informed of.
What is a Motor Insurance Service Provider (MISP) and how does it relate to DPDP?
A MISP is an auto dealer appointed by an insurer or intermediary under IRDAI guidelines to distribute and service motor insurance for vehicles it sells; because this role involves collecting and sharing customer data with insurers, it is also a DPDP-relevant data processing activity.
How long must a MISP retain customer records, and does that align with DPDP?
MISPs must retain records for at least 7 years from policy issuance or termination of appointment, whichever is later, under IRDAI's MISP guidelines; this sector-specific requirement takes precedence over DPDP's shorter default purpose-based retention principle.
When do DPDP's notice and consent obligations become enforceable for dealerships?
Full substantive DPDP obligations, including notice and consent requirements, become enforceable on 13 May 2027, with no stated grace period after that date.
Can a dealer be sponsored by both an insurer and an insurance intermediary at the same time for MISP purposes?
No. Under IRDAI's MISP guidelines, a dealer can be sponsored by one or more insurers, or by one insurance intermediary, but not both at once.

Check your status

DPDP Gap Assessment

A 45-question gap assessment for the Digital Personal Data Protection (DPDP) Act 2023, scoring data-protection maturity across 6 phases.

Start free assessment →From ₹2,499 · no subscription
Share:LinkedInXWhatsApp