Changes in regulations concerning the insurance industry

12 June 2019

In order to adapt the regulations for various sectors, the legislator adopted the Act amending certain acts in connection with ensuring the application of the Regulation of the European Parliament and of the Council (EU) 2016/679 of April 27, 2016 (GDPR). The purpose of this legal act is to align the regulations governing various industries, including the insurance sector, with the provisions set forth in the GDPR.

Profiling

According to the provisions of the GDPR, for an organization to make decisions based solely on automated processing (including profiling), one of three grounds must exist, namely:

  • such processing is necessary for the conclusion or performance of a contract,
  • such processing is permitted by law,
  • such processing is based on the explicit consent of the data subject.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE
It is well known that insurance companies often utilize various forms of profiling and automated processing of personal data, among others, to assess insurance risk. The legislator, recognizing the specificity of the insurance sector, introduced provisions regarding this issue into the Insurance and Reinsurance Activity Act.

Firstly, in Article 41(1b) of the Insurance and Reinsurance Activity Act, the legislator specified a closed list of categories of personal data based on which automated processing may occur. Secondly, in Article 41(1a) of the Insurance and Reinsurance Activity Act, the legislator indicated the purposes of such processing along with a division into categories covering the following individuals:

  • insured persons – processing for the purpose of assessing insurance risk,
  • insured persons, policyholders, and beneficiaries of insurance contracts – processing for the purpose of performing insurance activities (in the form of determining the causes and circumstances of random events, as well as determining the amount of damages and the extent of compensation and other benefits due to beneficiaries of insurance contracts or insurance guarantee contracts).

Processing of Health Data

According to the provisions of the GDPR, as a general rule, sensitive data may be processed based on consent obtained from the data subject, or if another basis specified in Article 9(2) of the GDPR applies. However, the provision in Article 9(4) of the GDPR granted European legislators the right to introduce national regulations defining the conditions for processing data related to, among others, health. Our national legislator has exercised this right by introducing Article 41(1) of the Act on Insurance and Reinsurance Activities – the basis for insurance companies to process health-related data. The legislator precisely indicates under what circumstances this data may be processed.

This concerns data related to the health of insured individuals or beneficiaries under insurance contracts, contained in the insurance agreement or statements made prior to its conclusion. Such data may be processed based on the commented provision for the purpose of assessing insurance risk or executing the insurance contract, to the extent necessary given its purpose and type of insurance.

End of written consent requirement

Under the previously applicable legal framework, consent for the processing of, among other things, health-related data had to be expressed in writing to be valid. Since the EU legislator has waived such a requirement, consent for the processing of personal data may be granted in any form (e.g., email, online form, by phone, etc.). This change had to be reflected in the provisions of Articles 38 and 39 of the Act on Insurance and Reinsurance Activities.

It is therefore no longer necessary for the insured individual or the person on whose behalf the insurance contract is to be concluded to provide written consent for insurance companies to obtain information about their health status from entities performing medical activities. The same applies to obtaining information from the National Health Fund (NFZ) by healthcare providers who have provided healthcare services, as well as consent for transferring personal data to another insurance company.

GDPR. Support is useful!

Determination of data retention

The legislator has decided on the possibility of using personal data of insured individuals, insurers, or other parties entitled under insurance contracts after the termination of the insurance contract. Such personal data may be processed after the termination of the insurance contract for a period of up to 12 years as statistical data, collected for the purpose of determining insurance premiums, reinsurance premiums, and technical insurance reserves for solvency purposes and technical insurance reserves for accounting purposes.

Data Processing in the Context of Counteracting Insurance Crimes

The legislator added to the Insurance and Reinsurance Activity Act a provision regarding the right of insurance companies to process personal data in cases of justified suspicion of a crime to the detriment of the insurance company, for the purpose and to the extent necessary to prevent such crime (Article 35a). This change was necessary as insurance companies must process personal data to address insurance crimes.

Unfortunately, not all requests from the insurance sector submitted during the consultation phase of the amendment to certain acts related to ensuring the application of the GDPR were ultimately fulfilled. Hence, it seems crucial for the insurance industry to efficiently create and adopt a code of conduct that would address issues overlooked or omitted by the legislator.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.