# What does GDPR mean for insurers?-Magazine
Author:  Pal Sinha, Barnali 
Author URL: https://financedigest.com/author/pal-sinha-barnali
Published: 2017-06-13
Category: INSURANCE
Category URL: https://financedigest.com/category/insurance
Meta Title: GDPR Impact on Insurers: Key Issues and Solutions
Meta Description: Learn from a Data Quality and Governance Manager about the upcoming EU GDPR changes and how to ensure compliance for your business. Don&#039;t get left behind!
URL: https://financedigest.com/what-does-gdpr-mean-for-insurers-magazinehtml

![undefined](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/extending-hand-to-shakemjd-1736843763124-compressed.jpg)

By **Andrew Bridges,** Data Quality and Governance Manager at REaD Group

![Andrew Bridges](https://prod.superblogcdn.com/site_cuid_cm5qst7v3003gwirgwqtxn8i8/images/andrew-bridges-read-group-p-227x300-1736843763016-compressed.jpg)

Andrew Bridges

It’s not often that data protection specialists make the headlines, but with the imminent arrival of the new EU General Data Protection Regulation (GDPR),the spotlight is shining brightly on the data industry. A great deal of my time is now taken up with helping our clients ensure that they can continue to do business post GDPR implementation onMay 25th 2018.

**What is GDPR?**

By way of background, for the last four years each EU member has been adding their ten-penneth to a new data protection act. The [aim is to unify Europe in data protection terms](https://www.financedigest.com/ab-inbev-aims-for-core-profit-growth-of-4-to-8-over-medium-term.html "AB InBev aims for core profit growth of 4% to 8% over medium term") and ensure that both the data of EU citizens is protected and that their choices are more respected.

Inevitably, any legislative change can be difficult to absorb, but the truth is that the [current Data](https://www.financedigest.com/shock-data-logger-market-2021-outlook-current-and-future-industry-landscape-analysis-2029.html "Shock Data Logger Market 2021 Outlook, Current and Future Industry Landscape Analysis 2029") Protection Act is out of date. It has scant regard for [digital communications in terms of the rich media](https://www.financedigest.com/smart-becomes-the-first-ssp-to-collaborate-with-white-bullet-to-safeguard-quality-in-the-digital-media-landscape.html "Smart becomes the first SSP to collaborate with White Bullet to safeguard quality in the digital media landscape") and information that is collected in today’s information age and is essentially not fit for purpose.

Add to this the need for organisations to be fundamentally more consumer-centric in their approach;in GDPR we have resulted in a more than passable piece of legislation that should deliver on the objectives of a more positively disposed consumer.  The days of purloining data and hoodwinking consumers are over – this just won’t cut the mustard anymore.  Successful organisations of the [future will be those that have genuinely open and transparent relationships with the both their customers and prospects](https://www.financedigest.com/interesterified-cbe-market-growth-future-prospects-and-competitive-analysis-2022-to-2032.html "Interesterified CBE Market Growth, Future Prospects And Competitive Analysis 2022 to 2032").

**What are the biggest issues that might affect [insurers](https://www.financedigest.com/different-countries-different-insurance-cultures-how-insurers-can-adapt-their-products.html "insurers")?**

- Consent

Consent is essentially the permission given by an individual to allow the processing of their personal data, and is subject to strict conditions under the new GDPR.

Firstly and perhaps most importantly, there is no threat to renewal programmes for insurers.  Following a great deal of discussion about how long consent should last, the general consensus is six months.  It might have been argued that [insurers would need](https://www.financedigest.com/insurance-that-every-individual-needs.html "Insurance that every individual needs…") to acquire a mid-term consent in order to undertake an annual renewal. However, it is clear that providing that an [insurer is undertaking that which is ‘relevant’ to the original purpose and what the consumer](https://www.financedigest.com/uk-consumers-conflicted-when-purchasing-insurance.html "UK Consumers Conflicted when Purchasing Insurance") would reasonably expect , then no further consent would be required.

It is worth noting that it would be advisable to still seek to obtain consent from an individual at the commencement of the policy in a [bid to be transparent](https://www.financedigest.com/spains-king-felipe-reveals-2-6-million-euros-in-wealth-in-bid-to-make-royal-house-more-transparent.html "Spain’s King Felipe reveals 2.6 million euros in wealth in bid to make Royal House more transparent") and avoid any surprises. After all, why hide? Loyalty and relationships with the consumer need to be built on a foundation of trust. If insurers would like to contact previous customers a year after their policy has expired, they will need to renew consent to [avoid accusations of storing irrelevant data](https://www.financedigest.com/the-race-to-avoid-data-dinosaur-extinction.html "THE RACE TO AVOID DATA DINOSAUR EXTINCTION") for longer than is necessary.

- Profiling

Processing is defined by GDPR as any form of automated processing intended to evaluate certain personal aspects of an individual.As so much of underwriting is now dependent on [analysis and profiling](https://www.financedigest.com/automotive-chrome-trim-products-market-industry-analysis-and-detailed-profiles-of-top-industry-players.html "Automotive Chrome Trim Products Market: Industry Analysis and Detailed Profiles of top Industry Players"), insurers will need to be extremely careful not to overstep what is a very narrow path within GDPR.

The regulation is very clearly [concerned with organisations creating models which corral groups](https://www.financedigest.com/tesco-reported-to-competition-watchdog-by-consumer-group-over-pricing-concerns.html "Tesco reported to competition watchdog by consumer group over pricing concerns") of citizens under one presumption. Under GDPR, insurers will need specific consent from citizens in order to profile them or use their data in the creation of a segment. This needs to be translated to [consumers in an unambiguous way](https://www.financedigest.com/the-future-of-retail-and-the-ways-that-retail-has-changed-for-consumers-during-the-pandemic.html "The future of retail and the ways that retail has changed for consumers during the pandemic"), to ensure people understand the benefits of this more tailored approach to their communications.

One of the biggest [challenges will involve clarifying the difference between data](https://www.financedigest.com/financial-services-and-data-how-do-we-meet-the-challenge.html "Financial services and data – how do we meet the challenge?") which can be consensually profiled and analysed, and data which cannot.In the GDPR these differences are explained as ‘profiling with legal or similarly significant effects’ and ‘other profiling without such effects’, which includes most profiling for direct marketing purposes. Anyone who blurs this subtle distinction risks facing serious consequences.

- Data portability

[Data portability is a concept to protect individuals from having their data stored in “silos” or “walled](https://www.financedigest.com/wall-street-pushes-stocks-oil-higher-on-promising-data.html "Wall Street pushes stocks, oil higher on promising data") gardens” that are incompatible with one another.In a [world where our governments feel that consumers](https://www.financedigest.com/world-at-rising-risk-of-recession-as-inflation-hits-consumers.html "World at rising risk of recession as inflation hits consumers") should be able to switch service provider at the touch of a button, the issue of data portability is heavily enshrined in the regulation. A consumer should not in any way be disadvantaged and should have immediate access to all data which is stored on them, and this be passed on without delay to competitors.Again, this will require some work for many insurers who for many [years will have built systems](https://www.financedigest.com/automotive-48v-system-market-sales-revenue-to-substantially-surge-in-the-next-ten-years.html "Automotive 48V System Market Sales Revenue to Substantially Surge in the Next Ten Years") and processes that actually deliver the opposite.

- Right to erasure

You will no doubt have read about the ‘right to be forgotten’, now called the ‘right to erasure’. This is driven by the issue of relevance. Gone are the days of just sitting on piles and piles of data waiting for that illusive rainy day. If companies are holding data which has no specific purpose then it must be deleted. This will have a significant [impact on the majority of insurers](https://www.financedigest.com/zurich-insurance-h1-operating-profit-leaps-60-as-covid-impact-wanes.html "Zurich Insurance H1 operating profit leaps 60% as COVID impact wanes"), who conduct a large mount of their analysis on lapsed and historical data. In principle, citizens should be able to transact with an organisation and when they move to an alternative provider, the old organisation should have no record of that interaction on file. This therefore prevents companies storing information on customers who should not be contacted.We [expect to hear](https://www.financedigest.com/italian-hearing-aid-maker-amplifon-expects-higher-2023-earnings.html "Italian hearing aid maker Amplifon expects higher 2023 earnings") more about this closer to GDPR implementation.

**So what happens if you get it wrong?**

Well firstly, this is an EU [regulation and as such there is a ‘one-stop shop’ for enforcement](https://www.financedigest.com/uk-regulators-head-of-enforcement-to-step-down-in-2023.html "UK regulator’s head of enforcement to step down in 2023"). Whilst the individual member state privacy tsars will oversee compliance and police the regulation, enforcement will be carried out by Brussels. This could have something to do with the potential enormity of the fines.  A serious [data breach](https://www.financedigest.com/when-not-if-why-a-data-breach-response-plan-is-more-important-now-than-ever.html "When not if: why a data breach response plan is more important now than ever") caused by anything less than best endeavors is likely to set you back 4% of global turnover.Think Sony or Yahoo – ouch!

The foregoing warnings aside, it is difficult to criticise this new regulation. It undoubtedly recognises the need to interact with customers on a more individualistic basis and aims to provide more clarity to [consumers around what is going to happen to the data they share](https://www.financedigest.com/ups-shares-fall-as-consumer-caution-dims-e-commerce-outlook.html "UPS shares fall as consumer caution dims e-commerce outlook"). It also [sets out to engender more trust](https://www.financedigest.com/markets-slammed-with-noise-investors-trust-tone-to-set-the-record-straight.html "Markets Slammed With Noise, Investors Trust Tone to Set the Record Straight") between individuals and organisations.

The world is a different place today and if we want loyalty, commitment and support from our customers then we had better make absolutely sure that they trust us, and of course trust starts with doing precisely what you said you would do.  Trust is experiential;it is pointless to make bold claims of ‘I want you to trust me’ (more often than not this delivers the opposite reaction). Trust is earned and indeed takes time to acquire.

Implementing GDPR will be difficult and regrettably there is no quick fix.  Many of the practices that have been the fulcrum of marketing will have to go, or at the very least change. Insurers will have a lot less data to play with, and consequently should be working on consent today.  Every piece of [communication to a consumer should provide insurers with the opportunity](https://www.financedigest.com/military-communications-market-worldwide-growth-trendsleading-segments-and-opportunities-to-2028.html "Military Communications Market Worldwide Growth, Trends,leading Segments And Opportunities to 2028") to become GDPR compliant, now.  The work that I am doing with many companies is all about continuing to [market ourselves whilst being compliant with this new regulation](https://www.financedigest.com/the-crop-growth-regulators-market-to-have-a-technological-escalation-in-its-armor.html "The Crop Growth Regulators Market To Have A Technological Escalation In Its Armor"). It is possible, but takes time. The time between now and May 25th 2018 will go by in a flash, so organisations cannot start soon enough.

Pain? Certainly. Radical overhaul of your data and [marketing strategy](https://www.financedigest.com/automotive-balance-shaft-market-competitor-analysis-winning-strategies-and-growth-drivers-2025.html "Automotive Balance Shaft Market Competitor Analysis, Winning Strategies and Growth Drivers 2025")? Absolutely.  But, this will result in a consumer that is more trusting, more engaged and more positively disposed. I’m not sure there is any price too large for that.

```
“Original publication in Finance Digest Issue 1 https://www.financedigest.com/finance-digest-print-magazine/”
```


---
This blog is powered by Superblog. Visit https://superblog.ai to know more.
---

