Regulation

General Data Protection Regulation (GDPR)

Expert-reviewed Updated: 2026-08-31 Expert-reviewed: 2026-09-04 (Guido Hesse, Hesse Group Holding AG) Version 0.1.0

The GDPR is the directly applicable EU-wide regulation protecting personal data, of particular importance to insurers given their extensive processing of sensitive health and risk data.

Concept

The General Data Protection Regulation (GDPR) is a regulation that has applied directly in all EU member states since 2018, establishing uniform rules for the processing of personal data of natural persons and granting them extensive rights, such as to access, rectification, and erasure of their data.

Relevance for Insurers

In the course of underwriting, policy administration, and claims handling, insurers regularly process particularly sensitive personal data, in particular health data, which under the GDPR is classified as a special category of personal data subject to an elevated level of protection and may only be processed under narrow statutory conditions.

Key Requirements

Key GDPR requirements particularly relevant to insurers include the principles of data minimization and purpose limitation, the obligation to appoint a data protection officer where sensitive data is processed extensively, the obligation to notify the supervisory authority of data breaches within 72 hours, and stringent fines of up to 4% of worldwide annual turnover for violations.

Legal basis

  • EU: Regulation (EU) 2016/679 (General Data Protection Regulation)