# Running a data privacy audit before a market conduct exam
A regional insurer's marketing team pulled a "customers likely to lapse" list from the claims database, cross-referenced it with credit score data bought from a third-party broker, and sent a retention offer email. Nobody flagged it. Six months later, a market conduct examiner asked a simple question: "Show me your authorization for using claims data in a marketing campaign." Nobody could. That single gap triggered a multi-line data-use review that took four months and cost more in legal hours than the retention campaign ever generated in saved premium.
Market conduct exams (state or national reviews of how insurers treat policyholders, covering claims handling, underwriting, and sales practices) increasingly include a data trail. Examiners don't just ask "did you treat the customer fairly." They ask "where did this data point come from, who approved its use, and can you prove it."
This lesson builds the checklist to run before they do.
Market conduct exams historically focused on claims timelines and complaint handling. That's changed. Regulators like the NAIC (National Association of Insurance Commissioners, which coordinates model laws across US states) have pushed the Insurance Data Security Model Law, adopted in some form by over 20 US states as of 2024 (estimate, check current NAIC adoption tracker), requiring insurers to run information security programs and report breaches.
In Europe, the GDPR (General Data Protection Regulation) governs any insurer processing EU residents' data, with fines up to 4% of global annual turnover for serious violations. The UK runs a parallel regime enforced by the ICO (Information Commissioner's Office) and the
The common thread: examiners now sample data flows, not just outcomes. They want to see a system where every use of personal data traces back to a lawful basis and a documented purpose.
This is the system of record for policyholder details: name, address, health disclosures, beneficiaries, payment data.
Checks to run:
Claims data is the richest and most sensitive pool: medical records, accident details, financial hardship indicators, sometimes criminal history in fraud investigations.
Checks to run:
This is where the opening example lives, and where examiners increasingly dig, because marketing teams often pull from claims and policy data without re-checking consent scope.
Checks to run:
Insurers rarely hold data alone. Telematics providers, claims adjusters, credit bureaus, and cloud hosts all touch policyholder data.
Checks to run:
Before the exam, score each system on a basic 1 to 4 scale across four dimensions: purpose documentation, consent validity, access control, retention compliance. This isn't a regulatory requirement, it's a practical triage tool.
System Purpose Consent Access Retention Avg
Policy Admin 3 4 2 3 3.0
Claims 4 3 3 4 3.5
Marketing 2 1 3 2 2.0
Vendor/Telematics 2 2 2 1 1.75Marketing and vendor flows score lowest here, which matches the real-world pattern: most enforcement actions and exam findings cluster in exactly these two areas because they involve repurposed data and external parties. Prioritize remediation there first.
The single most useful artifact to bring to an exam is a data use register: a live document listing every data source, its purpose, its legal basis, who has access, and its retention period. Examiners consistently ask for something like this, and insurers without one scramble to reconstruct it under time pressure.
A minimal template:
| Data element | Source system | Purpose | Legal basis | Retention | Owner |
|---|---|---|---|---|---|
| Telematics driving score | Mobile app vendor | Usage-based pricing | Contractual necessity | 7 years post-policy | Underwriting |
| Claims medical records | Claims system | Claims adjudication | Explicit consent | Per state schedule | Claims ops |
For a practical primer on data mapping obligations under GDPR, the ICO's guide to documentation is a solid free reference, and it's directly transferable to US market conduct prep even though it's UK-specific.
Knowledge check
1. Why did the retention email scenario in the lesson trigger a serious market conduct problem, even though the campaign itself may have been well-intentioned?
2. How has the focus of market conduct exams shifted according to the lesson, and what does that shift require insurers to do differently?
3. An insurer wants to use claims history data to build a targeted underwriting model. Based on the lesson's framing, what is the key question a pre-exam data privacy audit should answer first?
4. Select ALL correct answers about why data privacy has become embedded in market conduct exams rather than treated as a separate compliance silo.
Select all the correct answers.
5. Select ALL correct answers about what an examiner is likely trying to determine when asking 'where did this data point come from, who approved its use, and can you prove it?'
Select all the correct answers.
1. Inventory first: list every system holding personal data before assessing controls. You cannot audit what you haven't mapped.
2. Interview data owners, not just IT: the claims manager knows how data actually moves better than a systems diagram does.
3. Sample real records: pull 20 to 30 policyholder files and trace each through the systems. Does the marketing record match what the customer actually consented to at bind?
4. Test the opt-out: submit a real (internal) test opt-out request and time how long it takes to propagate across claims, marketing, and vendor extracts.
5. Document gaps with remediation dates: examiners respond far better to "here's the gap and our fix-by date" than silence.
🎬 [VIDEO: "GDPR for Insurance: Data Mapping Basics" - youtube.com - search for insurance-focused GDPR data mapping explainers from compliance training channels, useful for visualizing how data flows across policy, claims, and marketing systems]