Unipol · Companies & groups · IT
Šaltinis: Europos Komisijos skelbiami susitikimai, sutapatinti pagal skaidrumo registro numerį. n = 14 susitikimų; x — metai pagal susitikimo datą, y — susitikimų skaičius.
EU COMMISSION’S REPORT ON THE GENERAL DATA PROTECTION REGULATION (GDPR) UNIPOL GROUP’S POSITION (February 2024) Preliminary remarks The Unipol Group (hereinafter “Unipol”) welcomes the opportunity to provide input to the European Commission for the next evaluation of the Regulation (EU) 2016/679 (hereinafter, "GDPR") foreseen in 2024. As a preliminary remark, Unipol aims to uphold the GDPR as an important standard for privacy protection. GDPR delivered a fundamental change in how data controllers and data processors handle personal data and at the same time gave natural persons expansive rights as to how their data are collected, used and stored, increasing control over their personal information.
…rights as to how their data are collected, used and stored, increasing control over their personal information. Going forward, while Europe’s competitiveness will increasingly depend on the ability of companies to analyse and leverage data, and several new laws – such as the Data Act and the AI Act – become fully applicable, GDPR will continue to represent one of the most important regulatory framework. For this reason, we think that it is of utmost importance to discuss and analyse the impact consequences of GDPR and possible ways to improve it. From a market perspective, any relevant regulations should be clear, applicable and proportionate, and encourage a level playing field for competition. The financial sector, particularly the insurance industry, stands as one of the most data-intensive fields globally.
The financial sector, particularly the insurance industry, stands as one of the most data-intensive fields globally. Insurance companies collect and store an extensive array of personal and financial information about their clients. This data is crucial for underwriting risks, setting policy prices, and processing claims. Consequently, to safeguard customer data effectively and ensure compliance with GDPR requirements, insurance companies have dedicated significant resources to the implementation of GDPR processes. However, the past five years have shown that data protection in Europe is a dynamic area and that the inherent complexity of such a high-level and horizontal regulation has sometimes triggered unintended consequences in specific sectors.
…of such a high-level and horizontal regulation has sometimes triggered unintended consequences in specific sectors. Therefore, in its evaluation the Commission should carefully review the extent to which the application of the GDPR is indirectly hampering the use of certain technologies and – in the interests of technological neutrality – deliver solutions for how innovation can truly thrive. Our data economy must be able to provide protection for our citizens while still permitting businesses to realise the full potential for making great technological forward leaps. As the digital landscape evolves, so too should the regulatory framework guiding it, ensuring it remains adaptable and responsive to the needs of all stakeholders involved. This includes fostering an environment where startups and established companies alike can innovate responsibly, without being unduly constrained by Ref.
…startups and established companies alike can innovate responsibly, without being unduly constrained by Ref. Ares(2024)975779 - 08/02/2024 compliance burdens that may stifle growth or deter the adoption of new technologies. Such an environment would not only support economic growth and competitiveness but also enhance consumer trust and security in the digital age. The Commission's role in facilitating dialogue between technology leaders, policymakers, and consumer advocates is crucial in shaping policies that are both forward-thinking and grounded in the reality of technological capabilities and societal expectations. Considering the above, Unipol call on the European Commission to address the following issues when evaluating the GDPR: I.
…the above, Unipol call on the European Commission to address the following issues when evaluating the GDPR: I. The need to add a specific legal basis at EU level for the processing of special categories of data (hereinafter, “Special Data”, as identified by Article 9 of the GDPR) for the conclusion and performance of insurance contracts. II. The impact of the GDPR on AI and more broadly on innovation. I. The need of a legal basis for health data processing for the performance of a contract Unipol recognizes that the intent of Article 9 of the GDPR was to grant data subjects with greater protection in relation to their Special Data, by listing the possible legal basis for the relevant data processing and by enabling data subjects to autonomously manage their Special Data on the basis of their consent.
…data processing and by enabling data subjects to autonomously manage their Special Data on the basis of their consent. However, with specific respect to the (re)insurance sector, we would like to point out that this approach creates a potential conflict between the requirement of consent, on the one hand, and contract law principles, on the other, according to which both parties are generally obliged to fulfill their respective duties in the form and time agreed. Indeed, to perform (re)insurance contracts, (re)insurance companies acting as data controllers have to balance the need for consent to process health data during the claim settlement procedure with the general principle of fulfilling contractual obligations, which require the company to settle the claim. Thus doing, data controllers may incur a number of operational problems and compliance issues.
…to settle the claim. Thus doing, data controllers may incur a number of operational problems and compliance issues. Article 9(2)(a) GDPR: assessing the genuine and free choice to give consent in the (re)insurance sector GDPR prohibits Special Data processing unless the data controller can rely on one of the exemptions listed under Article 9(2). However, unlike Article 6 of the GDPR, the conditions under Article 9 do not include the case for which the processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
…data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. As a direct consequence, considering that none of the legal basis listed in Article 9(2) from (b) to (j) can legitimate Special Data processing for (re)insurance companies, for a data processing to be lawful, (re)insurance companies acting as data controllers need to rely on another legal basis. According to the current formulation of Article 9(2) of the GDPR, consent seems to represent the only lawful basis for Special Data processing that is carried out by a (re)insurance company.
…seems to represent the only lawful basis for Special Data processing that is carried out by a (re)insurance company. 3 Such an approach is endorsed by the European Data Protection Board (“EDPB”) in its “Guidelines 05/2020 on consent under Regulation 2016/679”, which explicitly states that: "Data controllers and Member States dealing with this situation should consider the specific exceptions in Article 9(2)(b) to (j). Should none of the exceptions (b) to (j) apply, obtaining explicit consent in accordance with the conditions for valid consent in the GDPR remains the only possible lawful exception for processing such data”.
…with the conditions for valid consent in the GDPR remains the only possible lawful exception for processing such data”. Given the above, Special Data processing for a performance of a contract in the insurance sector is at odds with GDPR consent requirements as outlined below: − consent is “[…] any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she signifies, by a statement or by a clear affirmative action, his or her agreement to the processing of personal data relating to him or her” (Article 4 (11) GDPR); − “[...] consent should not be considered freely given if the data subject does not have a genuine or free choice or is unable to refuse or withdraw consent without detriment” (Recital 42); − "in assessing whether consent is freely given, the utmost account shall be taken of the fact that, inter alia, the performance of a…
…the processing of personal data which is not necessary for the performance of that contract” (Article 7 (4)). In the (re)insurance sector, at the same time, the processing of Special Data relating to the policyholders is essential in certain (re)insurance contracts and/or in specific phases of the contractual relationship to provide insurance-related services. For instance, in line with the applicable insurance regulatory framework, insurance companies may require individuals to complete a medical history questionnaire before concluding a health insurance contract as well as before underwriting life insurance policies. Additionally, in the framework of a personal injury insurance claim process, insurance companies may need to process Special Data, namely health data, to determine the amount of compensation policyholders are entitled to.
33 → 12