ModelIC · Life insurance
Chapter 5

Legislation and customer protection

Life insurers need to consider the legislation applying in each jurisdiction in which they operate. This affects the terms of the contracts they sell, the way they assess risks, and how they collect and use policyholders’ information. The exact requirements vary by jurisdiction; the examples below illustrate the issues an insurer needs to consider.

On this page

Fair contracts and consumer protection

Many countries have specific legislation to protect consumers regarding what is fair in contracts for goods and services. A life insurer will need to carefully consider any such legislation to ensure that the contracts sold are compliant.

Features that would generally be expected of a fair contract include:

  • Terms drafted so that customers can easily understand them.
  • No unfair penalties. For example, cancellation charges may be limited to losses reasonably incurred by the business.
  • Clearly defined cancellation rights.
  • Clearly defined and explained charges.
  • A clear definition of how the contract may be changed or varied.
  • A clear explanation of how the premium for a policy may be varied.

The exact features which make a contract fair or unfair will vary by jurisdiction. A common concern is whether a term causes a significant imbalance in the parties’ rights and obligations to the detriment of the consumer. A term may be so weighted in favour of a company that it tips the rights and obligations in the company’s favour, rather than reflecting fair and open dealing.

Potentially unfair terms include those allowing the company to change the characteristics of the service after the customer has been bound by the contract, or giving the company discretion over the price without appropriate protection for the customer. Requiring a customer to pay disproportionate charges when ending a contract, to pay for services which have not been used, or preventing cancellation in any circumstances may also raise concerns.

In some jurisdictions, ombudsman services have been set up to resolve disputes between customers and financial services companies. For example, a customer may believe a contract term is unfair while the insurer disagrees. Normally, the customer first makes a complaint to the company and can then escalate it to the ombudsman if they do not feel the complaint has been dealt with satisfactorily.

Equality and discrimination

Direct and indirect discrimination

In many jurisdictions, anti-discrimination laws specify characteristics which cannot be used as a reason to discriminate, directly or indirectly, in the provision of goods and services. A life insurer may therefore be restricted in how it uses particular characteristics when deciding whether to offer insurance and on what terms.

Depending on the jurisdiction and the context, protected characteristics may include age, disability, sex, gender reassignment, marriage or civil partnership, pregnancy and maternity, race, religion or belief, and sexual orientation. The characteristics protected, the activities covered and the exceptions are not identical in every jurisdiction.

Direct discrimination means treating someone less favourably because of a protected characteristic. Indirect discrimination can occur when a policy which applies in the same way to everyone particularly disadvantages people who share a protected characteristic.

For example, only selling an annuity product to individuals who are 175 cm or taller could disadvantage women, who are on average shorter than men, even though the height requirement is expressed in the same terms for everyone.

Some forms of differential treatment may be lawful where the relevant legislation allows justification or provides a specific exception. This should not be taken to mean that any form of discrimination can be justified simply by showing a commercial benefit.

Age, disability and insurance in the UK

The Equality Act 2010 provides a framework for protection against discrimination in Great Britain. Its application to insurance includes specific exceptions.

Age can still be used in insurance risk assessment. Where a financial services provider relies on the age exception and carries out a risk assessment involving age, that assessment must use relevant information from a source on which it is reasonable to rely. This is more precise than treating every difference in premiums by age as unlawful. Government guidance on age discrimination and financial services

A person is generally regarded as disabled under the Act if they have a physical or mental impairment which has a substantial and long-term adverse effect on their ability to carry out normal day-to-day activities. These might include eating, washing or going shopping.

The insurance exception relating to disability permits differences in treatment where the decision is based on information relevant to the assessment of the risk, from a source on which it is reasonable to rely, and the action is reasonable having regard to that information and other relevant factors. An insurer therefore needs a defensible basis for declining cover or imposing special terms. Equality Act 2010, Schedule 3, paragraph 21

Sex-based pricing and the EU Gender Directive

The EU Gender Directive was aimed at implementing equal treatment between men and women in access to and supply of goods and services. Initially, an exception allowed differences in insurance premiums and benefits where specified conditions were met, including the use of supporting actuarial and statistical data.

Following the Court of Justice of the European Union’s decision, that exception ceased to apply to new contracts from 21 December 2012. Insurers could no longer use sex to produce differences in individuals’ premiums and benefits for those contracts. European Commission explanation of the unisex pricing rules

The inability to differentiate between men and women when setting premium rates has significant implications for insurance pricing. This is particularly relevant to annuities and protection products where there are material observed differences in mortality or morbidity experience.

Rather than simply averaging premium rates, an insurer needs to consider the risk that the mix of business differs from the mix assumed in pricing. Contingency loadings may be needed for this uncertainty. Insurers also need to consider whether other rating factors could result in unlawful indirect discrimination.

The implementation of unisex pricing also raised questions about single-sex products, the collection of information for assessing the expected mix of business, reserving assumptions and the pricing of reinsurance. These are distinct questions from whether an individual customer’s premium or benefit may differ because of their sex.

Personal data and the insurer

Life insurers accumulate large volumes of personal data on policyholders, often including demographic, financial, health, employment and lifestyle information. Such data enables insurers to assess and appropriately price the risks they take on when an insurance policy is sold, and to assess claims arising under the policy.

Personal data is information about an individual from which they may be identified, either directly or in combination with other available information. It may include names, addresses, personal email addresses, occupations, dates of birth, health information, race or ethnicity, and criminal records.

Some information attracts additional legal protection. Under the UK General Data Protection Regulation, health information and racial or ethnic origin are examples of special category data. Criminal offence data is subject to separate rules. The insurer needs an appropriate lawful basis for processing personal data and, where applicable, an additional condition for processing special category data. Information Commissioner’s Office guidance

Data protection requirements affect how insurers collect, store, manage and use information. Non-compliance can lead to fines and reputational damage. Actuaries need to be aware of the requirements relevant to their work, particularly where health information is involved.

Different jurisdictions, different regimes

Different territories have different approaches to regulating the collection, transmission and use of data. An insurer operating across territories may need to comply with more than one regime.

The European Union’s General Data Protection Regulation became applicable in 2018. It can also apply to organisations outside the European Union where the relevant processing concerns offering goods or services to people in the Union, or monitoring their behaviour there. Its scope is therefore not determined solely by where a business is registered. General Data Protection Regulation, Article 3

Following the UK’s withdrawal from the European Union, the UK has its own data protection regime, including the UK General Data Protection Regulation and the Data Protection Act 2018, as amended.

In the United States, the Health Insurance Portability and Accountability Act sets requirements for covered health plans, certain healthcare providers and other specified entities. It does not automatically apply to a life insurer merely because it holds medical information. Other privacy laws may apply, and healthcare providers may be restricted in how they disclose information to the insurer. US Department of Health and Human Services guidance

State laws may also be relevant. For example, the California Consumer Privacy Act protects specified privacy rights, but its scope depends on eligibility criteria and exemptions. It should not be assumed to apply in the same way to every insurer or every item of data. California Attorney General’s guidance

Collecting and using data

An insurer will wish to collect sufficient data to assess risks and adjudicate claims, but must ensure that the data is collected accurately and in a way that allows the assessment to be performed cost effectively.

During underwriting, information may be collected from the individual’s application form, their doctor or a medical specialist appointed by the insurer if additional tests are needed to make a decision.

Data protection legislation will often require personal data to be collected and processed fairly, lawfully and transparently. The insurer needs a valid lawful basis and must be clear about the purpose for which the information is being collected. The data should be limited to what is needed for that purpose, rather than collected simply because it might be useful in future.

These requirements generally concern personal data, rather than purely corporate information such as a company’s financial results. Corporate records may nevertheless contain personal data about identifiable individuals.

Consent and other lawful bases

In some circumstances, an insurer needs the individual’s consent to collect or use their personal data. Where consent is relied on, the insurer needs to be clear about the purposes covered and the limitations on its use.

Consent is not the only possible lawful basis. The appropriate basis depends on the processing and the applicable legislation; sensitive categories of information may require additional conditions to be met. Obtaining information from a new source does not, by itself, make a proposed use of that information lawful. Information Commissioner’s Office guidance on lawful bases

Transmission and retention

Data transmission is also covered by data protection legislation. For example, European data protection rules place conditions on transfers of personal data outside the relevant protected area. Other jurisdictions may impose additional procedures or restrictions on transfers across their borders.

There may also be rules surrounding how long an insurer can retain an individual’s data. A retention period should reflect the purpose for which the data is held and any applicable legal obligations. It is not necessarily identical to the term of the policy.

Insurers need robust data governance processes to ensure that collection, processing, transfer and retention meet the relevant requirements.

Keeping data secure

Once an insurer has collected personal data, it needs to store it safely and securely. Appropriate controls are also needed when receiving or transferring information.

The detailed and often sensitive nature of insurers’ data, together with increasingly digital operations, creates a risk that information could be lost, corrupted or stolen. The volume and nature of the information potentially make insurers attractive targets for cyber criminals.

The costs of a cyber attack include more than the costs associated with the lost or corrupted data itself. An insurer may also suffer reputational damage and business interruption.

Appropriate security and controls are therefore needed to protect against hackers and other unauthorised access. A robust cybersecurity strategy should have clear governance and accountability, including processes for detecting, reporting and responding to cyber risks. Building and maintaining these capabilities can be costly.

Regulators may require insurers to report breaches of relevant data legislation. Breaches can also result in sanctions or restrictions on business activities.

Who holds the information?

The increasingly complex landscape of personal data creates challenges for consumers, insurers and regulators. Information about a policyholder may be collected or handled by several parties, including:

  • The insurer.
  • Employers.
  • Doctors and medical specialists.
  • Financial intermediaries.
  • Third-party information services.
  • Data analytics organisations.

For example, a third-party service may provide a central source of underwriting information for insurers. The roles, responsibilities and limits of each party need to be clearly defined and explained to the policyholder.

Clarity is also needed about who controls the information, who has access to it, and who may receive it. An insurer should understand any restrictions on sharing personal information and the purposes for which another party may use it.

Data science: opportunities and responsibilities

Increasing volumes of data and the use of data science create challenges for life insurers and their regulators. Compliance with data protection requirements is particularly important, and regulatory approaches may differ between jurisdictions.

Data quality

Data science techniques can identify issues in data, but ensuring quality becomes more difficult as the size and complexity of the data grows. Information is increasingly collected from a variety of sources and will not always be perfect. Where data is incorrect, incomplete or biased, conclusions about trends or associations may be invalid.

Ethical use and access to insurance

As insurers are able to see risks in finer detail, cross-subsidies between policyholders could decline. Less healthy individuals may then be unable to find life insurance at an affordable cost.

Ethical considerations are also relevant to privacy, fairness and bias in the use of artificial intelligence and large datasets. Companies need to take steps to minimise the potential for unfairness and bias in decision-making.

Consumer trust

Unethical use of data, or the perception of unethical use, could significantly weaken consumer trust in an insurer and in the wider industry. Public perception continues to develop: practices considered acceptable at one point may not be considered acceptable in future.

New sources of information

Insurers need to establish whether they can lawfully acquire data from new sources, such as social media, and use it for underwriting or marketing. Where consent is required, it must cover the intended use.

New data sources and techniques can also create ethical challenges. For example, an insurer may use third-party data in a risk assessment without being able to understand an opaque algorithm’s decisions. The difficulty of explaining an outcome does not remove the need to consider whether it is fair.

Monetising data

Access to large volumes of data is potentially valuable, and an insurer may be able to obtain additional revenues or other economic benefits from it. Care is required to do this ethically and legally.

Monetising data does not simply mean selling it to third parties. It refers more broadly to using data to obtain a quantifiable economic benefit. For example, it may inform decisions about cross-selling or the development of new product features.

Customer needs

Insurers need to consider whether applications of data science in product design, pricing and other activities put consumers’ needs first and are in the public interest. Failure to do so could lead to regulatory intervention to address conflicts of interest or improve customer outcomes.