We are a data controller, and our data protection officer is James Clist
We act as your agent and will collect data, including personal information and risk details, solely to enable us to obtain and provide insurance quotations, arrange and administer your insurance. Under the General Data Protection Regulation (GDPR), the lawful bases we rely on for processing this information are contractual obligation, and for our legitimate business interests as an insurance broker. We will be unable to offer any quotation or insurance if you refuse to provide certain personal data, including health, financial and criminal records data which is collected under the lawful basis of public interest, where these would affect the provision of cover and/or performance of insurance contracts.
For the purposes specified within this privacy statement, we collect and process the following information:
We regard the lawful and correct handling of personal information by the firm as an essential element in achieving fair treatment of customers and to maintaining confidence between those with whom we deal and ourselves. We therefore need to ensure that our organisation treats personal information lawfully and correctly. To this end, we fully endorse and adhere to the Principles of data protection, as set out in the Data Protection Act and General Data Protection Regulations.
In this respect, personal information:
Therefore, the firm will, through appropriate management and strict application of criteria and controls:
Your information will be held securely by us and shared with insurers, which could include reputable providers outside the EU, to enable them to provide accurate terms and they will also obtain data about you and your insurance history from various insurance anti-fraud databases, such as the Claims and Underwriting Exchange (CUE) as well as publicly available websites and credit referencing agencies.
We willnot give anyone else any personal information except on your instructions or authority, or where we are required to do so by law, or our regulatory requirements. Information about you and your insurances will be securely stored on our secure servers while you are a client and for a minimum of three years, and in certain circumstances up to six years, after expiry of your policies. We will then dispose your information by deleting or anonymising your data.
Under the Data Protection Act, the rights of data subjects include the following:
Data Subject Right to Rectification
If a data subject contacts the firm advising that the information held about them is inaccurate or incomplete, the firm must refrain from processing (ie. using, but not storing) the data, until it has been verified or rectified. The business encourages customers to check and correct data as disclosure is an essential element in ensuring any policy provided by the company will protect the customer.
Full notes of any allegedly incorrect information will be kept on the customer record and, although there is a 30 day period in which to rectify information once notified under the DPA, in practice this must be carried out as soon as possible and confirmed to the customer in writing (email or letter) along with the impact on their insurance of any such change.
Data Subject Right to Erasure (Right to be Forgotten)
The right to erasure is extremely limited where the data subject is a customer of the business due to the legal obligation on the firm to retain customer data for a minimum period of 3 years under FSMA and the firm’s legitimate business purposes for retention to 6 years from lapsing. Once the firm has no lawful basis for holding data it must be deleted and our policy below indicates the relevant periods for which we will hold data.
Data subjects do, however, have the right to erasure where data is being held on the basis of consent (such as previous quotations or for marketing purposes) or their data has been processed unlawfully (such as where data has been obtained/ purchased from a third party that did not have the right to pass on that data)
Any request for erasure will be passed to the company’s data protection officer for review and appropriate action.
Data Subject Right to Restrict Processing
Individuals have the right to request that we restrict the processing (but NOT holding) of their personal data where:
Any request for restriction of processing must be noted on the file and passed to the company’s data protection officer for review and appropriate action.
Data Subject Right to Object to Processing
Again, this is a limited right which only applies in specific circumstances. Primarily in the case of Insurance Intermediaries it will be a specific right to opt-out of marketing communications.
Where a customer opts not to receive marketing communications, or, as a consumer, has not opted-in this will be noted on the client record and details will be removed from any marketing lists (Zywave, Brief Your Market etc). (Confirmation should be sent to the marketing manager or data protection officer).
In other cases of objection, where the firm has a lawful basis for continued processing, this will be referred to the data protection officer to evaluate whether the firm’s legitimate grounds should override the data subject’s objection.
Data Subject Right to Portability of Data
The right to data portability gives individuals the right to receive personal data they have provided to us in a structured, commonly used and machine-readable format. It also gives them the right to request that we transmit this data directly to another controller, however it is important to understand that the right to data portability only applies to personal data.
The right applies where the lawful basis for processing is consent or for the performance of a contract, the latter of which would apply to most of our data for individuals.
Any request for data portability will be noted on the file and passed to the company’s data protection officer for review and appropriate action.
You are NOT required to pay any charge for exercising your rights. If you make a request, we have one month to respond to you.
Please write to our data protection officer at james@eig.ltd, +44 7740 552007 and/or Fursdon, Clapperbrook Lane, Exeter, EX2 8TE if you wish to exercise your rights or have a complaint about our use of your data.