Leaders Insights
Leaders Insights

Stay at the top of your field, a little every day.

DomainsMarketingDataFinanceAI
ResourcesLearnTestToolsBlogGlossary
© 2026 Leaders Insights — All rights reserved.
Tracks/Data in insurance/Governance, privacy and checks/Running a data privacy audit before a market conduct exam
4/4+150 XP

Governance, privacy and checks

10Privacy rules that shape how insurers can use customer data+15011Consent and data-sharing chains across brokers, reinsurers and vendors+15012Setting up a data governance council that regulators trust+15013Running a data privacy audit before a market conduct exam+150

Running a data privacy audit before a market conduct exam

# Running a data privacy audit before a market conduct exam

A regional insurer's marketing team pulled a "customers likely to lapse" list from the claims database, cross-referenced it with credit score data bought from a third-party broker, and sent a retention offer email. Nobody flagged it. Six months later, a market conduct examiner asked a simple question: "Show me your authorization for using claims data in a marketing campaign." Nobody could. That single gap triggered a multi-line data-use review that took four months and cost more in legal hours than the retention campaign ever generated in saved premium.

Market conduct exams (state or national reviews of how insurers treat policyholders, covering claims handling, underwriting, and sales practices) increasingly include a data trail. Examiners don't just ask "did you treat the customer fairly." They ask "where did this data point come from, who approved its use, and can you prove it."

This lesson builds the checklist to run before they do.

Why data privacy sits inside market conduct now

Market conduct exams historically focused on claims timelines and complaint handling. That's changed. Regulators like the NAIC (National Association of Insurance Commissioners, which coordinates model laws across US states) have pushed the Insurance Data Security Model Law, adopted in some form by over 20 US states as of 2024 (estimate, check current NAIC adoption tracker), requiring insurers to run information security programs and report breaches.

In Europe, the GDPR (General Data Protection Regulation) governs any insurer processing EU residents' data, with fines up to 4% of global annual turnover for serious violations. The UK runs a parallel regime enforced by the ICO (Information Commissioner's Office) and the

FCA
(Financial Conduct Authority), which explicitly examines data use in its conduct reviews.

The common thread: examiners now sample data flows, not just outcomes. They want to see a system where every use of personal data traces back to a lawful basis and a documented purpose.

The four systems examiners probe

1. Policy administration systems

This is the system of record for policyholder details: name, address, health disclosures, beneficiaries, payment data.

Checks to run:

  • Purpose mapping: for every data field collected at quote or bind, is there a documented reason tied to underwriting, pricing, or servicing?
  • Retention limits: are records purged or archived per your retention schedule, or sitting indefinitely "just in case"? GDPR's storage limitation principle and many US state laws expect defined retention periods.
  • Access logs: who inside the company can query full policyholder records, and is access role-based rather than open to all staff?

2. Claims systems

Claims data is the richest and most sensitive pool: medical records, accident details, financial hardship indicators, sometimes criminal history in fraud investigations.

Checks to run:

  • Segregation of claims data from other business lines: can an auto claims adjuster see a policyholder's separate life insurance claim? If yes, is that access justified?
  • Third-party data sharing: claims often flow to reinsurers, medical review vendors, or fraud databases like the US NICB (National Insurance Crime Bureau). Is there a data processing agreement for each recipient?
  • Special category data handling: under GDPR, health and biometric data are "special category" and need explicit consent or another narrow legal basis, not just general policy terms.

3. Marketing systems

This is where the opening example lives, and where examiners increasingly dig, because marketing teams often pull from claims and policy data without re-checking consent scope.

Checks to run:

  • Consent trail: does the marketing database record what the customer actually agreed to, and when? A 2019 opt-in doesn't cover a 2026 use case if practices changed.
  • Cross-system data blending: did marketing combine claims history, credit data, or telematics (usage-based driving data) into a single profile without a fresh legal basis?
  • Opt-out mechanics: can a customer actually stop marketing use, and is that opt-out propagated across all systems within a reasonable window (commonly 30 days is cited as a workable benchmark, though exact requirements vary by law)?

4. Vendor and third-party datathird-party dataData purchased from external aggregators, collected from audiences you don't own. It is bought or licensed rather than gathered through your own direct relationships.View full definition → flows

Insurers rarely hold data alone. Telematics providers, claims adjusters, credit bureaus, and cloud hosts all touch policyholder data.

Checks to run:

  • Data processing agreements (DPAs) in place for every vendor touching personal data, specifying purpose and deletion obligations.
  • Sub-processor visibility: does your telematics vendor use a fourth party for data analytics, and do you know about it?
  • Cross-border transfer mechanisms: if data moves from the EU to a US-based cloud provider, is there a valid transfer mechanism such as Standard Contractual Clauses?

A simple audit scoring approach

Before the exam, score each system on a basic 1 to 4 scale across four dimensions: purpose documentation, consent validity, access control, retention compliance. This isn't a regulatory requirement, it's a practical triage tool.

System            Purpose  Consent  Access  Retention  Avg
Policy Admin         3        4       2         3      3.0
Claims                4        3       3         4      3.5
Marketing             2        1       3         2      2.0
Vendor/Telematics     2        2       2         1      1.75

Marketing and vendor flows score lowest here, which matches the real-world pattern: most enforcement actions and exam findings cluster in exactly these two areas because they involve repurposed data and external parties. Prioritize remediation there first.

What "good" looks like: a data use register

The single most useful artifact to bring to an exam is a data use register: a live document listing every data source, its purpose, its legal basis, who has access, and its retention period. Examiners consistently ask for something like this, and insurers without one scramble to reconstruct it under time pressure.

A minimal template:

| Data element | Source system | Purpose | Legal basis | Retention | Owner |

|---|---|---|---|---|---|

| Telematics driving score | Mobile app vendor | Usage-based pricing | Contractual necessity | 7 years post-policy | Underwriting |

| Claims medical records | Claims system | Claims adjudication | Explicit consent | Per state schedule | Claims ops |

For a practical primer on data mapping obligations under GDPR, the ICO's guide to documentation is a solid free reference, and it's directly transferable to US market conduct prep even though it's UK-specific.

Knowledge check

1. Why did the retention email scenario in the lesson trigger a serious market conduct problem, even though the campaign itself may have been well-intentioned?

2. How has the focus of market conduct exams shifted according to the lesson, and what does that shift require insurers to do differently?

3. An insurer wants to use claims history data to build a targeted underwriting model. Based on the lesson's framing, what is the key question a pre-exam data privacy audit should answer first?

MULTIPLE CHOICE

4. Select ALL correct answers about why data privacy has become embedded in market conduct exams rather than treated as a separate compliance silo.

Select all the correct answers.

MULTIPLE CHOICE

5. Select ALL correct answers about what an examiner is likely trying to determine when asking 'where did this data point come from, who approved its use, and can you prove it?'

Select all the correct answers.

Running the audit: a practical sequence

1. Inventory first: list every system holding personal data before assessing controls. You cannot audit what you haven't mapped.

2. Interview data owners, not just IT: the claims manager knows how data actually moves better than a systems diagram does.

3. Sample real records: pull 20 to 30 policyholder files and trace each through the systems. Does the marketing record match what the customer actually consented to at bind?

4. Test the opt-out: submit a real (internal) test opt-out request and time how long it takes to propagate across claims, marketing, and vendor extracts.

5. Document gaps with remediation dates: examiners respond far better to "here's the gap and our fix-by date" than silence.

🎬 [VIDEO: "GDPR for Insurance: Data Mapping Basics" - youtube.com - search for insurance-focused GDPR data mapping explainers from compliance training channels, useful for visualizing how data flows across policy, claims, and marketing systems]

Key Takeaways

  • Market conduct exams now routinely trace data use, not just customer outcomes: be ready to show purpose, consent, and access trails for every data field.
  • The four systems to audit first are policy admin, claims, marketing, and vendor/third-party flows, in roughly that order of increasing risk exposure.
  • Marketing and vendor data flows are the most common weak points because they involve repurposed or externally sourced data without fresh legal basis.
  • Build and maintain a data use register before an exam is announced; reconstructing one under deadline pressure is far costlier.
  • Real enforcement regimes to know by name: NAIC's Insurance Data Security Model Law (US state level), GDPR (EU), and the ICO/FCA combination (UK), each with different but overlapping expectations on consent, retention, and breach reporting.

Previous

Setting up a data governance council that regulators trust