Skip to content
Topic Contested in court

Insurance

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing by insurance companies

496 linked items 5 Laws22 Case Law23 Guidance394 Enforcement22 News

Overview

16 sources · Jul 15, 2026

Legal Framework

Insurance companies operate at the intersection of several data protection regimes. Under the GDPR, insurers processing personal data must establish a valid legal basis under Article 6(1), and where special categories of data are involved—particularly health data in claims assessment—Article 9 applies. Recital 52 permits derogations from the prohibition on processing special categories of data when Union or Member State law provides suitable safeguards, particularly in fields such as social protection and health security. This is the primary gateway enabling insurers to process health-related information for coverage and claims decisions.

The AI Act adds a further layer. Recital 96 designates insurance entities as deployers of certain high-risk AI systems who must conduct a fundamental rights impact assessment before deployment. Insurers using automated systems for risk assessment, pricing, or claims triage fall squarely within this scope.

Where insurers share data with public authorities—such as health insurance funds or tax authorities—the transfer must be expressly authorized by law, and the data subject must have been informed of the recipients, as required under Articles 13 and 14 GDPR.

Key Developments

The CJEU's ruling in Bara (C-201/14, 1 October 2015) established a critical principle: national law authorizing data transfers between public bodies does not automatically satisfy the controller's information obligations. The Romanian government argued that Article 315 of Law No 95/2006 required tax authorities to transfer income data to health insurance funds. The Court rejected this, clarifying that the relevant provision did not actually encompass income data, and more fundamentally, that the existence of a legal basis for transfer cannot substitute for the Article 13/14 obligation to inform data subjects about recipients. Insurers receiving data from public sources must independently verify the scope of the authorizing law and ensure transparency.

The Columbus line of cases before Dutch courts addresses insurer claims registers (EVR). The Rechtbank Den Haag (C/09/608204 / HA RK 21-96) confirmed that registration in incident registers requires a sufficient factual basis—specifically, evidence that the claimant made intentionally false statements about the extent of damage. The court also clarified that Article 35 UAVG (Dutch GDPR Implementation Act) procedures are limited to granting or denying requests under Articles 15–22 GDPR; claims for immaterial damages or payout obligations are inadmissible in that procedural track.

The Dutch DPA's guidance on health insurance declaration data (Toets Regeling declaratiegegevens ziektekostenverzekeraars) and the EDPB's Guidelines 01/2022 on data subject access rights further define the boundaries: victims retain the freedom to withhold specific medical information from insurers, and the Medical Paragraph of the GBL code of conduct limits what medical information insurers may require.

Practical Guidance

  • Verify the scope of statutory data-sharing mandates before processing. Bara makes clear that a national law referencing transfers to insurers does not automatically cover all data categories transferred. Confirm that the specific data fields match what the authorizing provision actually permits.

  • Conduct a fundamental rights impact assessment before deploying AI systems for underwriting, pricing, or claims assessment, as required by Recital 96 of the AI Act. Document the assessment prior to operational use.

  • Ensure claims register entries rest on demonstrable evidence of intentional misrepresentation. The Columbus standard requires that insurers can substantiate that a claimant deliberately provided false information about damage scope before registering them in incident or fraud databases.

  • Respect data subjects' freedom to withhold medical information beyond what is strictly necessary for claims handling. Limit medical data collection to the indicative guidelines in the GBL code, calibrated to expected claim duration.

  • Separate GDPR procedural requests from damages claims. Article 35 UAVG proceedings address access, rectification, and erasure requests only; pursue compensation through the appropriate civil procedural track.

Everything on this topic, by type links go to the exact provision / paragraph / section
Laws 5
Art. 31(9) Notified bodies shall take out appropriate liability insurance for their conformity assessment activities, unless liability is assumed by the Member S… AI Act rec 54 Recital 54 — public interest health data processing safeguards GDPR Apr 2016 rec 96 Recital 96 — fundamental rights impact assessment deployers AI Act Jun 2024 rec 52 Recital 52 — public interest special data processing exceptions GDPR Apr 2016 rec 58 Recital 58 — AI essential public services access AI Act Jun 2024 rec 158 Recital 158 — financial services authorities for AI oversight AI Act Jun 2024
Case Law 22
¶2 The request has been made in proceedings between ZQ and his employer, the Medizinischer Dienst der Krankenversicherung Nordrhein (medical service of t… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal ¶3 Recitals 4 to 8, 10, 35, 51 to 53, 75 and 146 of the GDPR are worded as follows: ‘(4) The processing of personal data should be designed to serve mank… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal ¶17 Under Paragraph 275(1) of the Sozialgesetzbuch, Fünftes Buch (Book V of the Social Code), in the version applicable to the dispute in the main proceed… Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal ¶19 MDK Nordrhein is a body governed by public law which, as a medical service for health insurance funds, has the statutory task, inter alia, of drawing … Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal 667/21 Judgment of the Court (Third Chamber) of 21 December 2023.#ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 6(1) – Conditions for lawful processing – Article 9(1) to (3) – Processing of special categories of data – Data concerning heal Court of Justice of the European Union Dec 2023 65/23 Judgment of the Court (Eighth Chamber) of 19 December 2024.#MK v K GmbH.#Request for a preliminary ruling from the Bundesarbeitsgericht.#Reference for a preliminary ruling – Protection of natural persons with regard to the processing of personal data – Regulation (EU) 2016/679 – Article 88(1) and (2) – Processing in the context of employment – Employees’ personal data – More specific rules provided for by a Member State pursuant to that Article 88 – Obligation to comply with Article 5, Article 6 Court of Justice of the European Union Dec 2024 Supreme Administrative Court NSS - 1 As 183/2023-62 Supreme Administrative Court Aug 2026 German Supreme Court German Supreme Court: No GDPR basis for debt transmission to credit agency; €500 damages German Supreme Court May 2026 191/15 Judgment of the Court (Third Chamber) of 28 July 2016.#Verein für Konsumenteninformation v Amazon EU Sàrl.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling — Judicial cooperation in civil matters — Regulations (EC) No 864/2007 and (EC) No 593/2008 — Consumer protection — Directive 93/13/EEC — Data protection — Directive 95/46/EC — Online sales contracts concluded with consumers resident in other Member States — Unfair terms — General terms and co Court of Justice of the European Union Jul 2016 Federal Administrative Court BVwG - W252 2247042-1 Federal Administrative Court Jan 2024 807/21 Deutsche Wohnen SE v Staatsanwaltschaft Berlin CJEU Dec 2023 498/16 Judgment of the Court (Third Chamber) of 25 January 2018.#Maximilian Schrems v Facebook Ireland Limited.#Request for a preliminary ruling from the Oberster Gerichtshof.#Reference for a preliminary ruling — Area of freedom, security and justice — Regulation (EC) No 44/2001 — Articles 15 and 16 — Jurisdiction in respect of consumer contracts — Definition of ‘consumer’ — Assignment between consumers of claims against the same trader or professional.#Case C-498/16. Court of Justice of the European Union Jan 2018 GDPRhub CJEU - C-667/21 - Krankenversicherung Nordrhein GDPRhub Dec 2023 13/16 Judgment of the Court (Second Chamber) of 4 May 2017.#Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v Rīgas pašvaldības SIA "Rīgas satiksme".#Request for a preliminary ruling from the Augstākās tiesas Administratīvo lietu departaments.#Reference for a preliminary ruling — Directive 95/46/EC — Article 7(f) — Personal data — Conditions for the lawful processing of personal data — Concept of ‘necessity for the realisation of the legitimate interests of a third party’ — Reques Court of Justice of the European Union May 2017 CJEU SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”) CJEU Oct 2015 CJEU SMARANDA BARA ET AL. V. PRESEDINTELE CASEI NATIONALE DE ASIGURARI DE SANATATE (CNAS) ET AL., 1.10.2015 (“BARA”) CJEU Oct 2015 601/21 Meta Platforms and Others v Bundeskartellamt CJEU Jul 2023 Regional Administrative Court Bratislava X - BA-6S/221/2019 Regional Administrative Court Bratislava Jun 2025 VG Ansbach VG Ansbach - 14 K 19.01274 VG Ansbach Sep 2021 Regional Court in Warsaw SO Warszawa - III C 904/23 Regional Court in Warsaw Feb 2026 Social Court Nuremberg SG Nürnberg - S 5 SF 65/24 DS Social Court Nuremberg Jun 2026 National Court Spanish court reviews DPA decision on KFC Spain website privacy information and DPO National Court Jul 2026 Rb. Noord-Holland Rb. Noord-Holland - AWB-20 2618 Rb. Noord-Holland Oct 2020 Supreme Court of the Netherlands PHR - 22/01253 Supreme Court of the Netherlands Aug 2022 Show 2 more →
Guidance 23
guidelines on the concepts of controller and processor in the gdpr Guidelines 07/2020 on the concepts of controller and processor in the GDPR EDPB Jul 2021 012020 on processing personal data in the context of connected Guidelines 01/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Mar 2021 guidelines on processing personal data in the context of connected vehicles and mobility rel Guidelines 1/2020 on processing personal data in the context of connected vehicles and mobility related applications EDPB Jan 2020 guidelines on data protection by design and by default Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 EDPB Oct 2020 guidelines on data subject rights right of access Guidelines 01/2022 on data subject rights - Right of access EDPB Apr 2023 42018 on the accreditation of certification bodies under article 43 Guidelines 4/2018 on the accreditation of certification bodies under Article 43 of the General Data Protection Regulation (2016/679) EDPB Dec 2018 guidelines on certification and identifying certification criteria Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation EDPB Jun 2019 guidelines for identifying a controller or processors lead supervisory authority Guidelines 8/2022 on identifying a controller or processor's lead supervisory authority EDPB Apr 2023 guidelines on codes of conduct as tools for transfers Guidelines 04/2021 on Codes of Conduct as tools for transfers EDPB Feb 2022 112019 on the draft list of the competent supervisory Opinion 11/2019 on the draft list of the competent supervisory authority of the Czech Republic regarding the processing operations exempt from the requirement of a data protection impact assessment (Article 35(5) GDPR) EDPB Jul 2019 62024 on the draft list of the latvian sa on pro Opinion 6/2024 on the draft list of the Latvian SA on pro-cessing operations exempt from the data protection impact assessment requirement (Art. 35.5 GDPR) EDPB Apr 2024 opinion 202507 epo adequacydecision Opinion 07/2025 regarding the European Commission Draft Implementing Decision pursuant to Regulation (EU) 2016/679 on the adequate protection of personal data by the European Patent Organisation EDPB May 2025 92020 on the draft decision of the irish supervisory Opinion 9/2020 on the draft decision of the Irish Supervisory Authority regarding the Processor Binding Corporate Rules of Reinsurance Group of America EDPB Apr 2020 82020 on the draft decision of the irish supervisory Opinion 8/2020 on the draft decision of the Irish Supervisory Authority regarding the Controller Binding Corporate Rules of Reinsurance Group of America EDPB Apr 2020 opinion 202515 dbo certificationcriteria Opinion 15/2025 on the draft decision of the Austrian Supervisory Authority (AT SA) regarding the certification criteria of BDO Consulting GmbH EDPB Jul 2025 112022 on the draft decision of the competent Opinion 11/2022 on the draft decision of the competent supervisory authority of Poland regarding the approval of the requirements for accreditation of a certification body pursuant to Article 43.3 (GDPR) EDPB Jul 2022 372023 on the draft decision of the competent Opinion 37/2023 on the draft decision of the competent supervisory authority of Luxemburg regarding the approval of the requirements for accreditation of a certification body pursuant to Art. 43.3 EDPB Dec 2023 222022 on the draft decision of the liechtenstein Opinion 22/2022 on the draft decision of the Liechtenstein Supervisory Authority regarding the Controller Binding Corporate Rules of Hilti Group EDPB Sep 2022 on stakeholder event on anonymisation and Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 EDPB Feb 2026 us data privacy framework faq for european businesses EU-US Data Privacy Framework FAQ for European businesses EDPB Jul 2024 Show 3 more →
Enforcement 394
AEPD (Spain) AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data AEPD (Spain) Jul 2026 AEPD (Spain) AEPD investigates University of Navarra over student COVID-19 vaccination status requests AEPD (Spain) Jul 2026 Italian Data Protection Authority (Garante) Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Apr 2026 Belgian Data Protection Authority (APD) Isabel SA: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) May 2026 Italian Data Protection Authority (Garante) Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) Mar 2026 Italian Data Protection Authority (Garante) Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) Apr 2026 Data Protection Authority of Ireland Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland May 2026 Croatian Data Protection Authority (azop) Bank: Non-compliance with general data processing principles Croatian Data Protection Authority (azop) Dec 2025 Slovak Data Protection Office Social Insurance Agency: Insufficient technical and organisational measures to ensure information security Slovak Data Protection Office Dec 2025 Belgian Data Protection Authority (APD) Law Firm: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) May 2026 Spanish Data Protection Authority (aepd) Debt collecting agancy (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) Dec 2025 Autoriteit Persoonsgegevens Experian Nederland B.V.: Insufficient legal basis for data processing Autoriteit Persoonsgegevens Oct 2025 French Data Protection Authority (CNIL) AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing French Data Protection Authority (CNIL) Nov 2025 Czech DPA (UOOU) UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing Czech DPA (UOOU) Dec 2025 DSB (Austria) DSB Austria: No fine imposed on COVID mask shop for cookie consent failure DSB (Austria) Jan 2026 Italian Data Protection Authority (Garante) Comune di Nave: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Dec 2025 Spanish Data Protection Authority (aepd) KVIKU SPAIN, S.L.: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) Jan 2026 Polish National Personal Data Protection Office (UODO) ING Bank Śląski: Insufficient legal basis for data processing Polish National Personal Data Protection Office (UODO) Aug 2025 Italian Data Protection Authority (Garante) Bressanelli Galli Gelpi Porta & C. S.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) Feb 2026 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) May 2026 Show 374 more →
News 22
European Data Protection Board The Italian SA fined Poste Vita for data breach European Data Protection Board Jun 2026 Electronic Frontier Foundation Most Smart Watches, Rings, and Bands Lack Basic Transparency Reports and Key Privacy Features Electronic Frontier Foundation Jul 2026 noyb - European Center for Digital Rights Over 40,000 CRIF queries: Klarna, banks and telecoms entangled in CRIF network noyb - European Center for Digital Rights Sep 2025 GDPRhub KHO - KHO:2025:86 GDPRhub Jan 2026 EU News Kort: EU News Jan 2026 EU News In short: EU News Jan 2026 EU News In brief: EU News Jan 2026 Hogan Lovells UK data protection reform: How the UK's GDPR may change Hogan Lovells Sep 2022 The Markup Who Is Collecting Data from Your Car?Who Is Collecting Data from Your Car? The Markup Jul 2022 Kluwer Law Big Data Analytics, Insurtech and Consumer Contracts: A European Appraisal Kluwer Law Oct 2022 Hogan Lovells Hervorming van de privacywetgeving in het Verenigd Koninkrijk: Hoe de GDPR van het VK mogelijk zal veranderen. Hogan Lovells Sep 2022 NL Kluwer Law Big Data-analyse, technologie in de verzekeringssector en consumentencontracten: een Europees overzicht. Kluwer Law Oct 2022 NL Kromann Reumert DeFine is a calculator for GDPR fines based on method of the EDPB Kromann Reumert Feb 2022 Datatilsynet De Deense beschermingsautoriteit (SA) heeft verklaard dat het gebruik van Google Analytics onrechtmatig is zonder aanvullende maatregelen. Datatilsynet Sep 2022 NL Datatilsynet Danish SA Declares Use of Google Analytics Unlawful Without Supplementary Measures Datatilsynet Sep 2022 White Label Consultancy Data Protection Officer or Chief Privacy Officer?The rise of the Data Protection Officer White Label Consultancy Jan 2022 Hunton Andrews Kurth Irish Data Protection Commissioner Fines Instagram EUR 405M for Children Privacy Violations Hunton Andrews Kurth Sep 2022 Hunton Andrews Kurth De CNIL stelt een boete van 60 miljoen euro voor aan een Frans bedrijf dat zich bezighoudt met advertentietechnologie, vanwege het niet naleven van de AVG (Algemene Verordening Gegevensbescherming). Hunton Andrews Kurth Aug 2022 NL Hunton Andrews Kurth De Ierse autoriteit voor gegevensbescherming heeft Instagram een boete van 405 miljoen euro opgelegd vanwege schendingen van de privacy van kinderen. Hunton Andrews Kurth Sep 2022 NL Hunton Andrews Kurth CNIL Proposes 60 Million Euros Fine Against French AdTech Company For Non-Compliance with GDPR Hunton Andrews Kurth Aug 2022 Show 2 more →
Literature 30
Journal Scientific and Applied Research HOW GDPR TREATS AUTOMATED DECISION-MAKING Journal Scientific and Applied Research Nov 2025 European Journal of Privacy Law & Technologies Dalla guida assistita alle driverless cars: rischio tecnologico e responsabilità civile European Journal of Privacy Law & Technologies Jan 2026 Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza The data subject’s right to access to information under GDPR and the right of the data controller to protect its know-how Przegląd Prawniczy Uniwersytetu im. Adam Mickiewicza Dec 2023 European Data Protection Law Review Collective Damages for GDPR Breaches: A Feasible solution for the GDPR Enforcement Deficit? European Data Protection Law Review Jan 2022 Frontiers in Genetics Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40 Frontiers in Genetics Nov 2021 European Data Protection Law Review GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Romania: Overview of the GDPR Implementation European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Poland: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Austria: A Brief Overview Concerning the Implementation of the GDPR European Data Protection Law Review Jan 2017 Innovative STEM Education GDPR - General Data Protection Regulation on Sites Requiring Accessibility Innovative STEM Education Jun 2021 European Data Protection Law Review GDPR Implementation Series ∙ Malta: An Overview of the GDPR Implementation European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Slovenia: Introduction to the Most Recent Public Draft of the GDPR Implementing Law European Data Protection Law Review Jan 2020 European Data Protection Law Review GDPR Implementation Series ∙ Cyprus: A Look into the Law for the Effective Application of the GDPR European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Portugal: A Brief Overview of the GDPR Implementation European Data Protection Law Review Jan 2019 European Data Protection Law Review GDPR Implementation Series ∙ Netherlands: The GDPR Implementation Act European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Ireland: A Brief Overview of the Implementation of the GDPR European Data Protection Law Review Jan 2018 European Data Protection Law Review GDPR Implementation Series ∙ Luxembourg: Reshaping the National Context to Adjust to the GDPR European Data Protection Law Review Jan 2017 European Data Protection Law Review GDPR Implementation Series ∙ Germany: Starting Implementation of the GDPR - Brief Overview of the Government Bill for a New Federal Data Protection Act European Data Protection Law Review Jan 2017 ORBELIANI LAW REVIEW Criminal Offence and Health Condition Information as Special Categories of Data, and the Legal Aspects of Processing in Labor Relations under GDPR and Georgian Law ORBELIANI LAW REVIEW Mar 2025 European Data Protection Law Review GDPR Implementation Series ∙ Latvia: The Implementation of the GDPR in a New Legislative Framework European Data Protection Law Review Jan 2020 Show 10 more →