Risk Insider: Chris Mandel

Data Protection in the EU: GDPR’s New Level of Accountability and Exposure

By: | July 30, 2018 • 3 min read
Chris Mandel is SVP, strategic solutions for Sedgwick and Director of the Sedgwick Institute. He is a long-term risk management leader and a former president of RIMS. He can be reached at [email protected]

The General Data Protection Regulation (GDPR) may be one of the biggest changes implemented by the European Union with the intent to provide individuals more control over their personal information.

Advertisement




GDPR, now in full effect as of May 25, 2018, gives the European Commission Office authority to impose heavy fines on all organizations that fail to follow the new guidelines.

Insurance companies and many players in the industry, through the ordinary course of business, collect large amounts of personal data and regularly process this data through the many and varied transactions completed daily. This new law applies to insurance companies around the world that do business in the EU.

All companies processing personal data of European citizens must comply. Therefore, insurance companies must ensure their operations align with GDPR requirements. There are three major issues risk managers and insurance industry professionals must be ready to comply with: receiving accurate consent, ensuring third-party compliance and avoiding completely automated decision making.

A greater weight is now being placed on receiving consent, with violations subject to the higher tier of fines. Consent is considered to be a statement or clear affirmative action giving a company permission to gather and use individuals’ personal data.

Consent must be well informed, given freely by the subject and made easily able to be withdrawn. Third-party users must be specifically named in the consent request and documentation about what, when and how an individual has consented must be maintained and available to EU enforcement authorities upon request.

Historically, ensuring the security of personal data has been the responsibility of the entity controlling the data. Under GDRP however, the burden is divided between the data processor and data controller.

For internet and mobile applications, it is no longer acceptable to obtain consent using pre-ticked check-boxes; the subject must take an affirmative action to be counted as consent.

In addition to individuals having the right to have their data erased, insurance companies must be careful not to retain data longer than necessary for the purpose of which it was collected. Nevertheless, there are exceptions to this rule, such as the allowance that data may be kept indefinitely if it is anonymized or kept for historical research or statistical purposes.

Historically, ensuring the security of personal data has been the responsibility of the entity controlling the data. Under GDRP however, the burden is divided between the data processor and data controller.

A controlling entity can be a natural or legal person, public authority or agency that determines the purpose and means of personal information being collected.

This differs from the data processor who holds and handles data for any purpose. With most insurance providers being data controllers, they must ensure all third parties who process data on their behalf are GDRP compliant.

Another major issue the insurance industry must be wary of is profiling. Profiling can be a part of automated processing of data to evaluate and predict certain characteristics, interests, behaviors or habits of individuals.

GDPR has strict requirements regarding decisions made entirely automatically without any human intervention. Examples of profiling used by insurance professionals include setting premiums, investigating fraud and planning marketing campaigns.

Advertisement




However, automated individual decision making can only be carried out if necessary for the performance of a contract or based on an individual’s explicit consent.

GDPR also grants individuals the right to request human intervention and challenge decisions made about them. Consequently, insurance companies must regularly check to ensure their systems are operating as intended.

Companies affected by this new law will want to take notice of the substantial fines for non-compliance. The maximum penalty is €20 million (about $23 million in U.S. dollars) or 4 percent of a company’s worldwide annual revenue, whichever is higher.

The core of the more critical aspects to understand include the requirements for ensuring personal data held is accurate, necessary to retain and that consent has been granted.

Finally, risk managers will want to ensure that their company’s contracts with data processors and data controllers account for relevant GDPR requirements in order to effectively manage this broadened regulatory exposure to data privacy and protection.

More from Risk & Insurance

More from Risk & Insurance

High Net Worth

High Net Worth Clients Live in CAT Zones. Here’s What Their Resiliency Plan Should Include

Having a resiliency plan and practicing it can make all the difference in a disaster.
By: | September 14, 2018 • 7 min read

Packed with state-of-the-art electronics, priceless collections and high-end furnishings, and situated in scenic, often remote locations, the dwellings of high net worth individuals and families pose particular challenges when it comes to disaster resiliency. But help is on the way.

Advertisement




Armed with loss data, innovative new programs, technological advances, and a growing army of niche service-providers aimed at addressing an astonishingly diverse set of risks, insurers are increasingly determined to not just insure against their high net worth clients’ losses, but to prevent them.

Insurers have long been proactive in risk mitigation, but increasingly, after the recent surge in wildfire and storm losses, insureds are now, too.

“Before, insurance was considered the only step in risk management. Now, our client families realize it is one of the many imperative steps in an effective risk management strategy,” said Laura Sherman, founding partner at Baldwin Krystyn Sherman Partners.

And especially in the high net worth space, preventing that loss is vastly preferable to a payout, for insurers and insureds alike.

“If insurers can preserve even one house that’s 10 or 20 or 40 million dollars … whatever they have spent in a year is money well spent. Plus they’ve saved this important asset for the client,” said Bruce Gendelman, chairman and founder Bruce Gendelman Insurance Services.

High Net Worth Vulnerabilities

Laura Sherman, founding partner, Baldwin Krystyn Sherman Partners

As the number and size of luxury homes built in vulnerable areas has increased, so has the frequency and magnitude of extreme weather events, including hurricanes, harsh cold and winter storms, and wildfires.

“There is a growing desire to inhabit this riskier terrain,” said Jason Metzger, SVP Risk Management, PURE group of insurance companies. “In the western states alone, a little over a million homes are highly vulnerable to wildfires because of their proximity to forests that are fuller of fuel than they have been in years past.”

Such homes are often filled with expensive artwork and collections, from fine wine to rare books to couture to automobiles, each presenting unique challenges. The homes themselves present other vulnerabilities.

“Larger, more sophisticated homes are bristling with more technology than ever,” said Stephen Poux, SVP and head of Risk Management Services and Loss Prevention for AIG’s Private Client Group.

“A lightning strike can trash every electronic in the home.”

Niche Service Providers

A variety of niche service providers are stepping forward to help.

Secure facilities provide hurricane-proof, wildfire-proof off-site storage for artwork, antiques, and all manner of collectibles for seasonal or rotating storage, as well as ahead of impending disasters.

Other companies help manage such collections — a substantial challenge anytime, but especially during a crisis.

“Knowing where it is, is a huge part of mitigating the risk,” said Eric Kahan, founder of Collector Systems, a cloud-based collection management company that allows collectors to monitor their collections during loans to museums, transit between homes, or evacuation to secure storage.

“Before, insurance was considered the only step in risk management. Now, our client families realize it is one of the many imperative steps in an effective risk management strategy.” — Laura Sherman, founding partner, Baldwin Krystyn Sherman Partners

Insurers also employ specialists in-house. AIG employs four art curators who advise clients on how to protect and preserve their art collections.

Perhaps the best known and most striking example of this kind of direct insurer involvement are the fire teams insurers retain or employ to monitor fires and even spray retardant or water on threatened properties.

High-Level Service for High Net Worth

All high net worth carriers have programs that leverage expertise, loss data, and relationships with vendors to help clients avoid and recover from losses, employing the highest levels of customer service to accomplish this as unobtrusively as possible.

“What allows you to do your job best is when you develop that relationship with a client, where it’s the same people that are interacting with them on every front for their risk management,” said Steve Bitterman, chief risk services officer for Vault Insurance.

Site visits are an essential first step, allowing insurers to assess risks, make recommendations to reduce them, and establish plans in the event of a disaster.

“When you’re in a catastrophic situation, it’s high stress, time is of the essence, and people forget things,” said Sherman. “Having a written plan in place is paramount to success.”

Advertisement




Another important component is knowing who will execute that plan in homes that are often unoccupied.

Domestic staff may lack the knowledge or authority to protect the homeowner’s assets, and during a disaster may be distracted dealing with threats to their own homes and families. Adequate planning includes ensuring that whoever is responsible has the training and authority to execute the plan.

Evaluating New Technology

Insurers use technologies like GPS and satellite imagery to determine which homes are directly threatened by storms or wildfires. They also assess and vet technologies that can be implemented by homeowners, from impact glass to alarm and monitoring systems, to more obscure but potentially more important options.

AIG’s Poux recommends two types of vents that mitigate important, and unexpected risks.

“There’s a fantastic technology called Smart Vent, which allows water to flow in and out of the foundation,” Poux said. “… The weight of water outside a foundation can push a foundation wall in. If you equalize that water inside and out at the same level, you negate that.”

Another wildfire risk — embers getting sucked into the attic — is, according to Poux, “typically the greatest cause of the destruction of homes.” But, he said, “Special ember-resisting venting, like Brandguard Vents, can remove that exposure altogether.”

Building Smart

Many disaster resiliency technologies can be applied at any time, but often the cost is fractional if implemented during initial construction. AIG’s Smart Build is a free program for new or remodeled homes that evolved out of AIG’s construction insurance programs.

Previously available only to homes valued at $5 million and up, Smart Build recently expanded to include homes of $1 million and up. Roughly 100 homes are enrolled, with an average value of $13 million.

“In the high net worth space, sometimes it takes longer potentially to recover, simply because there are limited contractors available to do specialty work.” — Curt Goetsch, head of underwriting, Private Client Group, Ironshore

“We know what goes wrong in high net worth homes,” said Poux, citing AIG’s decades of loss data.

“We’re incenting our client and by proxy their builder, their architects and their broker, to give us a seat at the design table. … That enables us to help tweak the architectural plans in ways that are very easy to do with a pencil, as opposed to after a home is built.”

Poux cites a remote ranch property in Texas.

Curt Goetsch, head of underwriting, Private Client Group, Ironshore

“The client was rebuilding a home but also installing new roads and grading and driveways. … The property was very far from the fire department and there wasn’t any available water on the property.”

Poux’s team was able to recommend underground water storage tanks, something that would have been prohibitively expensive after construction.

“But if the ground is open and you’ve got heavy equipment, it’s a relatively minor additional expense.”

Homes that graduate from the Smart Build program may be eligible for preferred pricing due to their added resilience, Poux said.

Recovery from Loss

A major component of disaster resiliency is still recovery from loss, and preparation is key to the prompt service expected by homeowners paying six- or seven-figure premiums.

Before Irma, PURE sent contact information for pre-assigned claim adjusters to insureds in the storm’s direct path.

“In the high net worth space, sometimes it takes longer potentially to recover, simply because there are limited contractors available to do specialty work,” said Curt Goetsch, head of underwriting for Ironshore’s Private Client Group.

Advertisement




“If you’ve got custom construction or imported materials in your house, you’re not going to go down the street and just find somebody that can do that kind of work, or has those materials in stock.”

In the wake of disaster, even basic services can be scarce.

“Our claims and risk management departments have to work together in advance of the storm,” said Bitterman, “to have contractors and restoration companies and tarp and board services that are going to respond to our company’s clients, that will commit resources to us.”

And while local agents’ connections can be invaluable, Goetsch sees insurers taking more of that responsibility from the agent, to at least get the claim started.

“When there is a disaster, the agency’s staff may have to deal with personal losses,” Goetsch said. &

Jon McGoran is a novelist and magazine editor based outside of Philadelphia. He can be reached at [email protected]