PPLI Privacy: Who Can Access an Insurer’s Policy File?
An insurer can share parts of a PPLI file with people who need them to underwrite, administer, reinsure or supervise the policy. That does not give every employee, custodian or investment manager permission to read the insured person's medical records. Ask which legal entities receive each category of information, why they receive it, where they process it and how access is controlled. Your rights depend on the applicable law and whose personal data you are requesting.
By PPLI.com. Legal sources checked September 15, 2026.
Map the information, the recipient and the purpose
A policy file is a collection of records: identity documents, financial information, medical underwriting, ownership instructions, investment records and claims correspondence. Treating it as one unrestricted bundle conceals the most useful privacy question: which recipient needs which part?
Use the following as a due-diligence worksheet. It describes functions to investigate, not verified access rights at a particular insurer.
| Function | Information to ask about | Access boundary to verify |
|---|---|---|
| New business and compliance | Identity, ownership, source of funds and application records | Which staff can retrieve full documents and which see only verification results? |
| Medical underwriting and medical advisers | Health history, examination results and attending physician statements | Which medical records are collected, under what authority and with what retention period? |
| Reinsurer | Information needed to assess and administer the ceded risk | Is identified health information transmitted, to whom, and for which underwriting or claims function? |
| Policy administrator and intermediaries | Policy servicing, premiums, contact details and instructions | Which parts of the application remain accessible after issue? |
| Custodian and investment manager | Account, investment and required customer-diligence records | What information is needed for their own role? Do not assume that this includes medical underwriting. |
| Auditor and supervisor | Records within the applicable audit or supervisory remit | What legal powers, purpose limits and confidentiality duties govern access? |
| Technology providers | Hosted records, backups and support access | Can support staff read the contents? Who controls keys, permissions, logs and onward access? |
| Trustee and external counsel | Information required for ownership, administration or legal advice | Who is the client or data subject, and what authority permits sharing another person's information? |
The insurer's privacy notice and written response should identify the actual arrangement. A family-selected manager still needs platform approval and documented responsibilities. See adding an investment manager to an insurer's platform.
U.S. insurance privacy combines several legal frameworks
HIPAA does not automatically protect the life insurer's copy
HHS identifies life insurers among the organizations generally outside HIPAA's Privacy and Security Rules. A physician may need a valid HIPAA authorization before releasing records for life underwriting. That authorization does not turn the recipient life insurer into a HIPAA-covered health plan. HHS guidance.
A company conducting both covered and noncovered activities needs a more precise organizational analysis. Where it properly operates as a hybrid entity, the designated health care components and required safeguards matter. Coverage does not divide automatically just because products have different labels. 45 CFR 164.105.
Consumer reports have their own access and accuracy rules
The Fair Credit Reporting Act permits specified insurance-underwriting uses of consumer reports. Medical information attracts additional conditions under Section 1681b(g), including affirmative consumer consent for the insurance-transaction report under paragraph (g)(1)(A), subject to the statutory provisions. An underwriting purpose alone does not authorize every disclosure of medical data. 15 USC 1681b.
MIB, Inc. supplies medical specialty information used in individual insurance underwriting, with consumer authorization. If MIB has a file about you, you can request one free report every 12 months. The CFPB states that reporting companies required to provide an annual free report must provide it within 15 days of the request. You can dispute inaccurate or incomplete information. This report is distinct from the insurer's entire underwriting file. CFPB's MIB directory entry.
State insurance privacy rules determine additional rights
The Gramm-Leach-Bliley Act establishes protections for nonpublic personal information, with state insurance authorities assigned enforcement for insurance activities. Review the applicable state implementation and insurer notice. A privacy opt-out is not a universal veto over servicing, legally required or otherwise excepted disclosures. 15 USC 6801, 6802 and 6805.
NAIC Model 670 is a model, not a nationwide statute. Its text provides, among other things:
- Notices of information practices and specified authorization contents.
- A maximum 30-month authorization for collecting information for a life, health or disability application, reinstatement or benefit-change request. Claims authorizations follow different provisions.
- A 30-business-day response framework for qualifying access requests and requests to correct, amend or delete recorded information.
- A 21-business-day response to a timely request for specified adverse-underwriting information. The request generally must arrive within 90 business days of the adverse-decision notice under the model.
Check the enacted state text, exceptions and actual request dates before applying those periods. The NAIC's 2026 working-group mandate includes revising privacy models; a draft is not enacted state law. Model 670, Sections 4, 6, 8, 9 and 10; Privacy Protections Working Group.
European protection depends on the processing role and lawful basis
Determine GDPR scope under Article 3. Processing linked to an EU establishment can fall within the regulation even when the server is elsewhere. Specified services offered to people in the EU and monitoring of their behavior can also bring a non-EU organization within scope. A server address alone does not settle the question. GDPR.
Separate the controller, processor and employee
A controller determines why and how personal data are processed. A processor acts on the controller's behalf. An employee working under the controller's authority is not automatically a separate processor.
Article 28 governs processor arrangements, including documented instructions, confidentiality, assistance, audit rights and authorized subprocessors. Specific or general written authorization can cover subprocessors; general authorization requires notice of intended changes and an opportunity to object. Article 29 and Article 32(4) address people working under authority. Articles 5, 25 and 32 add minimization, accountability and security obligations.
Ask the insurer to explain the role assigned to each entity for each activity. An administrator can perform one activity on instructions and another for its own legal purposes. A contract heading alone cannot decide the role. The EDPB's controller and processor guidance sets out the functional analysis.
Health data needs an additional legal condition
Health information requires an Article 6 lawful basis and an applicable Article 9 exception. Explicit consent under Article 9(2)(a) and necessary legal-claims processing under Article 9(2)(f) are possible routes, subject to their conditions. They are not the only routes available in every jurisdiction.
Luxembourg's insurance-sector law expressly uses Article 9(2)(g), substantial public interest, for defined insurance and reinsurance processing. Article 181-3 excludes genetic data from that route and imposes specific safeguards. The United Kingdom separately has a conditional insurance provision in Schedule 1, paragraph 20 of its Data Protection Act 2018. Neither provision creates a global authorization. Luxembourg Article 181-3; UK insurance condition.
Article 9(2)(h) covers specified health, occupational and care-related purposes with the safeguards in Article 9(3). Engaging a doctor does not by itself make ordinary commercial life underwriting eligible. Ask for the actual purpose and national-law basis, rather than accepting a reference to medical secrecy as the complete explanation.
Reinsurance does not authorize unrestricted medical-file sharing
The reinsurance arrangement must identify the information needed, the parties' processing roles, the health-data condition and any international-transfer mechanism. An independent reinsurer making its own risk decisions may be a separate controller. That does not make every reinsurer a controller for every service or remove the cedent's duties.
There are also insurance-specific disclosure provisions. Luxembourg Article 300(5), for example, permits specified disclosure to reinsurers and co-insurers where detailed knowledge of individual files is needed to assess the risk and perform their commitments. Article 181-3 expressly addresses insurance and reinsurance health-data processing. These provisions still require a facts-based legal analysis; they do not establish that every reinsurer receives the entire medical file.
Request recipient identities and access information with the right limits
GDPR access rights belong to the natural person whose information is processed. Policy ownership by a company or trustee does not automatically give that owner access to the insured person's medical records. A representative should establish authority to act for that person.
| Request | What the right can establish | Important limit |
|---|---|---|
| Which entities received my data? | Actual recipient identities where identifiable, as explained in C-154/21 | Categories can suffice where identification is impossible or the request is demonstrably manifestly unfounded or excessive. |
| When and why was my data consulted? | Dates and purposes of consultation, as explained in C-579/21 | This does not automatically include every employee's name. |
| Where did the information come from? | Available source information for data not collected from you | The right concerns available information and your own personal data. |
| Was a decision automated? | Relevant information about automated decision-making covered by Article 15(1)(h), including meaningful information about the logic | The provision refers to decisions within Article 22(1) and (4), not every internal software calculation. |
| Can I receive a copy? | A copy of the personal data undergoing processing | Other people's rights and applicable restrictions still matter; this is not automatic access to every unredacted corporate document. |
In C-154/21, Österreichische Post, the Court of Justice explained the recipient-identity obligation. In C-579/21, Pankki S, it distinguished consultation dates and purposes from employee identities. Employee identity can be relevant where essential to exercising the person's rights, with employees' rights and freedoms also considered.
Article 12 generally requires action without undue delay and within one month. An extension of two further months can apply because of complexity or the number of requests, with reasons communicated within the first month. Identity verification, justified restrictions and manifestly unfounded or excessive requests require their own analysis. Ordinary access is free; reasonable fees can apply to additional copies or qualifying excessive requests.
A useful request identifies the person, policy reference and relevant period, then asks for data categories, sources, recipients, retention criteria, consultation information and transfer safeguards. Use the controller's secure channel. A policyholder's own access request is a different legal process from disclosure in litigation or divorce.
Check every international transfer and its onward recipients
For transfers governed by GDPR Chapter V, identify the exporter, importer, destination, processing roles and applicable mechanism. Adequacy and contractual safeguards address the transfer. They do not dispense with a lawful processing purpose or health-data condition.
The 2021 standard contractual clauses have four modules: controller to controller, controller to processor, processor to processor and processor to controller. Module 1 may fit a controller-to-controller reinsurance transfer where the clauses' scope and other conditions are met. A non-adequate destination alone does not determine the module. Assess the destination's law and practices, necessary supplementary measures and onward transfers. European Commission SCC guidance.
| Destination or development | Position checked September 15, 2026 | Case-file check |
|---|---|---|
| Switzerland | Listed by the Commission as adequate; included in its January 2024 review of earlier decisions | Confirm that the actual transfer falls within the relevant decision. |
| United Kingdom | GDPR adequacy renewed in December 2025; the renewal records validity to December 27, 2031 | Check the decision's current scope and status when transferring. |
| United States | Adequacy covers participating commercial organizations under the EU-US Data Privacy Framework | Verify the recipient's participation and the data covered. U.S. location alone is insufficient. |
Sources: Commission adequacy register and Decision 2025/2574.
The challenge to the U.S. decision in T-553/23 was dismissed on September 3, 2025; an appeal was filed on October 31, 2025 as C-703/25 P. Treat a filed appeal separately from an order suspending or annulling a decision. Official appeal notice.
On July 31, 2026, the EDPB asked the Commission to assess the implications of the U.S. Supreme Court's Trump v. Slaughter ruling for the framework. The letter is a request for assessment, not a suspension. The operational check remains the current decision and the recipient's eligibility. EDPB letter.
Luxembourg has separate rules for secrecy, outsourcing and health data
Professional secrecy has defined exceptions
Article 300 of the insurance-sector law imposes secrecy duties on specified persons and refers breaches to Penal Code Article 458. It also contains exceptions for legally authorized disclosure, contract performance, fraud prevention, supervision, outsourcing and qualifying reinsurance disclosures. Its scope contains exclusions, including for reinsurance undertakings subject to the stated exception. Ask which provision applies to each recipient.
Older policies have a specific registered-letter process
Article 181-2 applies to life contracts in Annex II classes I, III or VI taken out before April 6, 2024. It concerns requests under Article 300(2bis), second subparagraph. The sequence matters:
- After three months without a response to the request, the insurer confirms it by a first registered letter to the last known address.
- If the policyholder has not responded within three months of receiving the first registered letter, the insurer sends a second registered letter. The second cannot be sent earlier than three months after the first was sent. It must explain the request, the consequences of silence and the right to object. The insurer must make additional enquiries about the address.
- Acceptance is presumed after three months from posting the second letter if the policyholder remains silent.
This is a defined outsourcing-acceptance procedure. Receipt of two unspecified letters is insufficient evidence that it has been completed. It is not blanket explicit consent under GDPR for all health-data processing.
Health-data safeguards deserve a separate review
Article 181-3, introduced by the law of February 6, 2025, provides the conditional substantial-public-interest route described above. Its safeguards include a data protection officer, impact assessment, functional separation, encryption, restricted access, logs, staff awareness, independent review, sectoral codes and an internal policy.
The provision permits documented, justified exclusions for certain listed measures. It does not permit derogation from its requirements for encryption in transit and key management, access restrictions, specified logs, staff awareness and an internal policy. Ask which measures apply and how any permitted exclusion was justified.
Separately, Article 80 retains the domestic record-keeping rule with a defined derogation for digital storage and processing by a qualifying critical ICT provider in Luxembourg or another Member State under European supervision. It is not an unrestricted permission to host records anywhere. CAA consolidated law, Articles 80, 181-2, 181-3 and 300.
DORA adds operational requirements for entities within its scope
The Digital Operational Resilience Act has applied since January 17, 2025. Insurance and reinsurance undertakings and intermediaries appear in its scope, but Article 2 also has exclusions. These include specified small insurance undertakings and intermediaries that are micro, small or medium-sized enterprises.
Article 28(3) requires in-scope financial entities to maintain a register of contractual arrangements for third-party ICT services. That is not a log of every person who opened a policy file, and the provision gives the competent authority access rather than creating a policyholder right to the whole register. Ask for a case-relevant explanation of hosting, support access and subcontractors.
Register templates are prescribed by Regulation 2024/2956. EIOPA's earlier cloud-outsourcing guidelines ended application on January 17, 2025. Sources: DORA, register templates and EIOPA's historical-guideline notice.
Review Swiss insurance privacy under the applicable Swiss provisions
A Swiss insurer's location does not establish that banking secrecy governs its policy files. The Federal Act on Data Protection, contractual duties and applicable insurance rules need their own analysis. The revised data-protection act took effect on September 1, 2023. Its sensitive-data definition includes health and the private sphere; its access framework appears in Articles 25 to 27. Federal Act on Data Protection.
Article 62 addresses intentional disclosure of secret personal data learned through professional activity, including the specified assistance and training situations. On complaint, the maximum fine is CHF 250,000. Article 64 provides corporate-liability rules, including a subsidiary procedure where the contemplated fine is no more than CHF 50,000 and identifying the individual would require disproportionate measures.
These are criminal provisions. They do not cap all civil liability or make negligent processing harmless. The Swiss regulator explains that civil claims can involve different conditions and greater amounts. FDPIC explanation of criminal liability.
Separate breach reporting, individual notification and penalties
Under GDPR, the controller's regulator-notification duty and the affected person's notification right have different thresholds:
| Communication | Trigger and timing | Qualification |
|---|---|---|
| Processor to controller | Without undue delay after awareness of a personal-data breach | The processor must enable the controller's response. |
| Controller to supervisory authority | Without undue delay and, where feasible, within 72 hours of awareness | Not required if the breach is unlikely to risk individuals' rights and freedoms. Later notification requires reasons. |
| Controller to affected person | Without undue delay when high risk is likely | Article 34 contains conditions concerning effective protective measures, subsequent risk mitigation and disproportionate individual contact. The last requires effective public or similar communication. |
Encryption must actually protect the affected data to support that exception. A general statement that an insurer uses encryption does not establish the result. The regulator may require notification. A decision not to notify individuals can be lawful, but the absence of a message alone proves neither compliance nor wrongdoing. Other applicable jurisdictions can impose separate duties.
Article 83 sets maximum administrative-fine tiers. Specified obligations under Articles 25 to 39 fall within the EUR 10 million or, for an undertaking, 2% of worldwide annual turnover tier, whichever is higher. Specified principles, rights and transfer violations fall within EUR 20 million or 4%. Actual penalties depend on the infringement and statutory factors. A security failure can implicate more than one provision; the tiers are not a ranking of insurers or a promise of compensation. GDPR Articles 33, 34 and 83.
Build a privacy review file before sending sensitive records
- Name the parties. Record the issuer, administrator, intermediaries, known reinsurers and the controller's privacy contact.
- Split the records. List identity, financial, medical, investment and claims information separately. Match each proposed recipient to a purpose.
- Record the authority. Retain the privacy notice, relevant authorization, health-data basis and explanation of any statutory disclosure.
- Map the transfers. Record hosting and support locations, recipient roles, transfer mechanisms and onward recipients. Request the relevant SCC information where those clauses apply.
- Test the response. Submit a clear access request through the proper channel and record receipt, any justified extension and the response. Distinguish missing answers from lawful restrictions.
- Resolve discrepancies. Compare the response with the notice and application. Ask the responsible privacy team to explain mismatches and correct inaccurate personal data.
For example, suppose an illustrative access map lists an administrator and reinsurer, while the notice describes only service providers. The follow-up is to identify the entities, data categories and purposes, then determine whether the response satisfies the applicable rights. The mismatch is a question to resolve, not proof of unlawful sharing.
A precise written response is useful evidence. It is not a certification that the insurer never has unauthorized access. Keep privacy review alongside carrier due diligence and the broader PPLI privacy framework.
Insurance-file privacy questions
Who inside an insurer can see a PPLI file?
Authorized staff can receive information needed for their role, subject to applicable law and controls. Underwriting, servicing and compliance functions may need different records. Ask specifically who can access medical data, who can export it and what access logs exist. A list of departments is not proof that each department may read the whole file.
Can I find out who has seen my personal data?
Where GDPR applies, access rights can establish recipient identities and the dates and purposes of consultations, with relevant limits. They do not automatically require disclosure of every employee's name. The right belongs to the data subject, so a trustee or policy owner requesting another person's medical information must establish appropriate authority.
What permits medical information to be shared with a reinsurer?
The parties need the applicable processing basis, health-data condition and transfer mechanism, as well as any insurance-specific authority. Explicit consent is not the only possible health-data route. Luxembourg Article 181-3 provides a conditional insurance and reinsurance basis, excluding genetic data; Article 300(5) addresses qualifying disclosures to reinsurers and co-insurers.
Does HIPAA protect information held by a life insurer?
Life insurers generally are not HIPAA-covered entities merely because they receive medical information. A covered physician's disclosure duties and the recipient's later duties are separate. Companies with covered health activities require an organizational analysis, including any hybrid-entity designation. Federal consumer-reporting and financial-privacy rules and applicable state laws may also govern.
What is MIB, and can I request my report?
MIB supplies medical specialty information used in individual insurance underwriting with consumer authorization. If it has a file about you, you may request one free report every 12 months and dispute inaccuracies. The CFPB describes a 15-day provision period for companies required to supply the annual free report. It is not the insurer's complete policy file.
Does a Swiss insurer provide the same secrecy as a Swiss bank?
Do not infer identical rules from the shared location. Review the insurer's duties under Swiss data-protection law, its contract and applicable insurance provisions. Intentional professional disclosure of secret personal data can attract criminal liability under Article 62 of the Federal Act on Data Protection, while civil liability follows separate rules.
Must the insurer tell me about every data breach?
Not under one universal rule. GDPR generally requires individual notification when high risk is likely, with specified conditions and alternatives under Article 34. Regulator notification uses a different threshold. Effective encryption can matter; merely having an encryption policy is insufficient. Other applicable laws may impose additional notification requirements.
What changed for European insurers in January 2025?
DORA became applicable on January 17, 2025 for entities within its scope, with express exclusions. It introduced harmonized operational-resilience obligations, including an ICT-contract register. That register is not an individual-file access log or automatically public. EIOPA's earlier cloud-outsourcing guidelines ended application on the same date.
Start with the issuer and the data-sharing question
For a PPLI research inquiry, identify the issuer jurisdiction and the issue you want to understand. Keep medical reports and identity documents out of an initial general inquiry. Send a PPLI inquiry.
This article is educational. A specific access request, authorization or cross-border transfer requires analysis of the actual parties, records and applicable law. See our editorial standards.
Use the consultation form to describe your question and the support you are seeking. Review the Privacy Policy before sharing personal information.
Prefer to begin with a single question? Write to info@ppli.com