Insurance
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing by insurance companies
Overview
16 sources · Jul 15, 2026Legal Framework
Insurance companies operate at the intersection of several data protection regimes. Under the GDPR, insurers processing personal data must establish a valid legal basis under Article 6(1), and where special categories of data are involved—particularly health data in claims assessment—Article 9 applies. Recital 52 permits derogations from the prohibition on processing special categories of data when Union or Member State law provides suitable safeguards, particularly in fields such as social protection and health security. This is the primary gateway enabling insurers to process health-related information for coverage and claims decisions.
The AI Act adds a further layer. Recital 96 designates insurance entities as deployers of certain high-risk AI systems who must conduct a fundamental rights impact assessment before deployment. Insurers using automated systems for risk assessment, pricing, or claims triage fall squarely within this scope.
Where insurers share data with public authorities—such as health insurance funds or tax authorities—the transfer must be expressly authorized by law, and the data subject must have been informed of the recipients, as required under Articles 13 and 14 GDPR.
Key Developments
The CJEU's ruling in Bara (C-201/14, 1 October 2015) established a critical principle: national law authorizing data transfers between public bodies does not automatically satisfy the controller's information obligations. The Romanian government argued that Article 315 of Law No 95/2006 required tax authorities to transfer income data to health insurance funds. The Court rejected this, clarifying that the relevant provision did not actually encompass income data, and more fundamentally, that the existence of a legal basis for transfer cannot substitute for the Article 13/14 obligation to inform data subjects about recipients. Insurers receiving data from public sources must independently verify the scope of the authorizing law and ensure transparency.
The Columbus line of cases before Dutch courts addresses insurer claims registers (EVR). The Rechtbank Den Haag (C/09/608204 / HA RK 21-96) confirmed that registration in incident registers requires a sufficient factual basis—specifically, evidence that the claimant made intentionally false statements about the extent of damage. The court also clarified that Article 35 UAVG (Dutch GDPR Implementation Act) procedures are limited to granting or denying requests under Articles 15–22 GDPR; claims for immaterial damages or payout obligations are inadmissible in that procedural track.
The Dutch DPA's guidance on health insurance declaration data (Toets Regeling declaratiegegevens ziektekostenverzekeraars) and the EDPB's Guidelines 01/2022 on data subject access rights further define the boundaries: victims retain the freedom to withhold specific medical information from insurers, and the Medical Paragraph of the GBL code of conduct limits what medical information insurers may require.
Practical Guidance
Verify the scope of statutory data-sharing mandates before processing. Bara makes clear that a national law referencing transfers to insurers does not automatically cover all data categories transferred. Confirm that the specific data fields match what the authorizing provision actually permits.
Conduct a fundamental rights impact assessment before deploying AI systems for underwriting, pricing, or claims assessment, as required by Recital 96 of the AI Act. Document the assessment prior to operational use.
Ensure claims register entries rest on demonstrable evidence of intentional misrepresentation. The Columbus standard requires that insurers can substantiate that a claimant deliberately provided false information about damage scope before registering them in incident or fraud databases.
Respect data subjects' freedom to withhold medical information beyond what is strictly necessary for claims handling. Limit medical data collection to the indicative guidelines in the GBL code, calibrated to expected claim duration.
Separate GDPR procedural requests from damages claims. Article 35 UAVG proceedings address access, rectification, and erasure requests only; pursue compensation through the appropriate civil procedural track.