Who Inside a Carrier Sees the File
Families spend a great deal of due diligence on a carrier's rating and almost none on a question that is closer to what they actually mean when they say privacy: once the application is signed, who reads it. The honest answer is that a policy file passes through more hands than a brokerage account does, because underwriting a life requires medical information and because the risk is usually shared with a reinsurer. That is more exposure at the outset, not less. What compensates for it is that each of those hands is under a written confidentiality obligation the carrier is legally required to impose, and that in some of the jurisdictions that matter most a breach is a criminal offence rather than a contractual one.
This article sets out those duties and the policyholder's rights to find out who has had the file, as they actually stand in September 2026. It sits under our page on privacy and confidentiality, which maps the wider question of who can see a policy. What follows is the institutional layer: the rules that bind the people holding the paper.
The map, before the law
A single policy file is touched, in the ordinary course, by the carrier's new business and underwriting teams, a medical underwriter and often a physician reviewing attending physician statements, a reinsurer where risk is ceded, the policy administrator, the custodian bank holding the segregated account assets, the appointed investment manager, the statutory auditor, the supervisor on inspection, and the ICT providers running whatever systems hold all of it. In a cross-border case add local counsel and, where a trust owns the contract, the trustee and its own compliance function.
Nobody hands a family that list, and it is the list that decides how confidential the arrangement really is. Two of the names on it are worth pausing over. The investment manager is there because someone has to run the money, and where a family brings its own manager the diligence and documentation that involves is a project in itself, set out in our research on getting a manager onto a carrier's platform. The reinsurer is there because large face amounts are shared, and it sees the medical file. Most of what follows is about how each of those relationships is papered.
The rule that binds people rather than buildings
Where the carrier processes data in the European Union, the operating rule is Regulation (EU) 2016/679. Article 5(1)(f) sets the principle: personal data must be "processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures." Article 5(2) makes the controller responsible for demonstrating compliance, not merely achieving it.
The provision that does the real work on the question in the title is Article 28. A controller may use only processors offering "sufficient guarantees to implement appropriate technical and organisational measures," may not permit a processor to engage a sub-processor without written authorisation, and must impose a written contract. That contract must stipulate, among other things, that the processor "processes the personal data only on documented instructions from the controller" and, at Article 28(3)(b), "ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality."
Read that clause carefully, because it is the answer to the question. The confidentiality of the individual analyst at the administrator is not a matter of professional courtesy or internal policy. It is a contractual obligation the carrier is legally required to impose, backed by an audit right at Article 28(3)(h), under which the processor must "allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller." Article 32(1) then requires both controller and processor to implement measures appropriate to the risk, listing pseudonymisation and encryption, ongoing confidentiality and resilience, restoration after an incident, and a process for regularly testing effectiveness.
Health data is the hard part, and the usual gateway does not apply
Underwriting a life produces exactly the category the regulation treats most severely. Article 9(1) prohibits the processing of, among other things, "data concerning health." The prohibition is the default; processing is lawful only through one of the gateways in Article 9(2).
Two of those gateways realistically apply to insurance: 9(2)(a), explicit consent for specified purposes, and 9(2)(f), where processing is "necessary for the establishment, exercise or defence of legal claims." Practitioners occasionally reach for 9(2)(h), the medical purposes gateway, and it does not work. Article 9(3) confines it to processing "by or under the responsibility of a professional subject to the obligation of professional secrecy," for care and treatment purposes. Underwriting a risk is not treatment.
Which leaves explicit consent doing most of the load-bearing, and explains why the medical authorisation a family signs is drafted at the length it is. It also explains why practice differs across Europe: Article 9(4) permits Member States to "maintain or introduce further conditions, including limitations, with regard to the processing of genetic data, biometric data or data concerning health." There is no single European answer to what an insurer may ask, and a family with lives insured in two countries will find the underwriting experience differs for reasons that are legal rather than commercial.
The reinsurer, and the rule that does not exist
Large PPLI face amounts are routinely reinsured, and the reinsurer sees the medical file. Families expect there to be a specific rule about this. There is not, and we would rather say so than invent one.
The PPLI Playbook runs to 46 pages on mechanics, rules, jurisdictions, costs and implementation. Complimentary for qualified families and their advisors; each copy is sent personally.
Request your copy →We looked for a provision addressing insurer to reinsurer personal data sharing in the GDPR, in Solvency II, in DORA, in the Swiss data protection act and in the Swiss insurance supervision act. There is none, and no EDPB or EIOPA instrument specific to it surfaced either. What governs the cession is the general law: the reinsurer underwrites the ceded risk on its own account and therefore acts as a separate controller rather than as the cedent's processor, which means Article 28 does not apply and Articles 6 and 9 have to do the work. In practice that is Article 6(1)(b), performance of a contract, or 6(1)(f), legitimate interests, for ordinary data, and Article 9(2)(a) or 9(2)(f) for the medical file.
Where the reinsurer sits outside the European Economic Area, which is common, the cession is a Chapter V transfer and needs its own basis. That is the next section. What actually moves in a cession, as opposed to what may lawfully move, is market practice and we have found no authoritative source enumerating it, so treat any list you are given as the carrier's description of its own process rather than as a legal standard.
What a policyholder can demand to see
The most underused provision in this entire subject is Article 15. A data subject may obtain confirmation that data are being processed and access to them, together with a specified list of information. Three items on that list are worth knowing by number.
Article 15(1)(c) entitles the person to "the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations." Article 15(1)(g) entitles them, where the data were not collected from them, to "any available information as to their source." And Article 15(1)(h) covers automated decision-making including profiling, with "meaningful information about the logic involved." Article 15(2) adds a right to be informed of the Article 46 safeguards applying to a third country transfer, and Article 15(3) requires the controller to "provide a copy of the personal data undergoing processing," with a reasonable administrative fee only for further copies.
A family that wants to know who has seen the file does not need to negotiate for the information. They can ask for it, in writing, and the carrier has to answer. In our experience almost nobody does, and the answer is frequently more interesting than the question. Note that this is a right against the carrier, and it is a different thing entirely from what an opposing party can compel in litigation, which we deal with in our research on what an opposing lawyer can obtain.
Where the data goes, and the paperwork that permits it
Chapter V governs any transfer outside the EEA. Article 44 states the principle and extends it to onward transfers, so that the level of protection "is not undermined." Article 45 permits transfer where the Commission has decided the destination ensures an adequate level of protection. Article 46 permits it, absent adequacy, where the exporter has provided appropriate safeguards with enforceable rights and effective remedies, including standard contractual clauses adopted by the Commission.
Those clauses are in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and they come in four modules: controller to controller, controller to processor, processor to processor, and processor to controller. A cession to a non-adequate reinsurer is Module One. Getting the module wrong is a common and consequential drafting error, because the obligations differ.
On adequacy, the position as at September 2026 is worth stating precisely because it moves. Switzerland has been adequate since Commission Decision 2000/518/EC and the Commission confirmed that finding in its January 2024 review of the pre-GDPR decisions, noting the revised Swiss act and Convention 108+. The United Kingdom decision was renewed by Commission Implementing Decision (EU) 2025/2574 of 19 December 2025, with validity recorded to 27 December 2031. The United States is covered, for certified organisations, by the EU-US Data Privacy Framework decision of 10 July 2023, which remains in force: the challenge in Case T-553/23 Latombe v Commission was dismissed by the General Court on 3 September 2025, and an appeal, Case C-703/25 P, was lodged on 31 October 2025 and is pending. Separately, on 31 July 2026 the Chair of the European Data Protection Board wrote to the Commission asking it to assess whether the United States Supreme Court judgment in Trump v. Slaughter, which held that the Federal Trade Commission must be controlled by the Chief Executive, affects the functioning of the adequacy decision. That letter suspends nothing. It is, however, the sort of thing a family with data routed through an American service provider should know exists.
When something goes wrong
Article 33(1) requires the controller to notify the supervisory authority of a personal data breach "without undue delay and, where feasible, not later than 72 hours after having become aware of it," unless the breach is unlikely to result in a risk to rights and freedoms, with reasons required for any delay. Note the two qualifications people drop: the clock runs from awareness, and 72 hours is a "where feasible" outer limit rather than an absolute deadline. Article 33(2) requires a processor to notify the controller without undue delay.
Telling the policyholder is a separate and higher test. Under Article 34(1) the controller must communicate the breach to the data subject only where it is "likely to result in a high risk to the rights and freedoms of natural persons," and then without undue delay, in clear and plain language. Article 34(3) removes even that obligation where the controller had applied protection measures "in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption," or where subsequent measures mean the high risk is no longer likely, or where individual communication would involve disproportionate effort, in which case a public communication is substituted.
The practical reading is that a family may never hear about an incident that was notified to a regulator, and that this is the regulation working as drafted rather than a carrier behaving badly.
Which fine tier bites, and why it matters
Article 83(4) sets fines of up to 10,000,000 euros or 2 per cent of total worldwide annual turnover, whichever is higher, for infringements of controller and processor obligations under Articles 25 to 39. Article 83(5) sets 20,000,000 euros or 4 per cent, whichever is higher, for infringements of the basic principles under Articles 5, 6, 7 and 9, of data subject rights under Articles 12 to 22, and of the Chapter V transfer rules.
So the security obligation at Article 32 and the processor contract at Article 28 sit in the lower tier, while the confidentiality principle, the lawful basis, the health data prohibition, the access right and the transfer rules sit in the upper one. That allocation tells you what European regulators think the serious failures are, and it is a useful lens for reading a carrier's own compliance priorities.
Operational resilience became its own regime in 2025
Since 17 January 2025, European insurers have been subject to Regulation (EU) 2022/2554, the Digital Operational Resilience Act. EIOPA confirms that the entities in scope under Article 2(1) include insurance and reinsurance undertakings at point (n) and insurance intermediaries at point (o).
The part that matters for this article is the register of information: every financial entity must maintain a register of all contractual arrangements for ICT services provided by third party providers, on templates prescribed by Commission Implementing Regulation (EU) 2024/2956. There is now, in other words, a document at every European carrier listing exactly which outside providers touch its systems. DORA also creates an oversight regime for critical ICT third party providers at Union level.
One correction worth making because it appears in a good deal of otherwise careful material. EIOPA's Guidelines on outsourcing to cloud service providers, issued 6 February 2020 and applied from 1 July 2021, were revoked with effect from 17 January 2025, precisely to avoid duplication with DORA. They are historical. Anyone still citing them as current is working from a 2023 briefing note.
Luxembourg, and the letter you may already have received
Luxembourg's insurance professional secrecy sits at Article 300 of the law of 7 December 2015 on the insurance sector, enforced criminally through Article 458 of the Criminal Code, which carries imprisonment of eight days to six months and a fine of 500 to 5,000 euros. That is the framework we describe on the privacy and confidentiality page.
The law of 29 March 2024, published in Mémorial A number 136 of 2 April 2024, changed how it operates, and two details are worth getting right because they are usually reported loosely.
The first concerns storage. The amendment that permits an undertaking to outsource digital storage of documents and related data, and their processing, to a critical ICT third party service provider within the meaning of the DORA regulation, established in Luxembourg or another Member State and subject to European supervision, was made to Article 80, not Article 300. It replaced a prior requirement that records be kept within the Grand Duchy. If you have been told the 2024 law amended the secrecy article to permit cloud outsourcing, that is not quite what happened.
The second concerns consent, and it is more interesting than the summaries suggest. For life policyholders in classes I, III and VI, the mechanism is not an affirmative consent requirement. It operates by registered letter: the undertaking confirms by a first registered letter, and the verified text provides that "Le silence du preneur d'assurance à la deuxième lettre recommandée visée à l'alinéa 4 est présumé valoir acceptation." Silence in response to the second registered letter is presumed to constitute acceptance. If a Luxembourg policyholder has received two registered letters about data processing and filed them unread, they have consented.
Switzerland is not Luxembourg
The assumption that Swiss insurance carries bank-secrecy-grade protection is wrong, and the difference is structural rather than a matter of degree. Switzerland has no criminal insurance secrecy statute. We read the article list of the Insurance Supervision Act, and the only confidentiality provisions in it are directed at the supervisor rather than at the insurer: Articles 80 to 82 govern disclosure between authorities, and Article 45 imposes a transparency duty on intermediaries covering "the processing of personal data, in particular the purpose, extent and recipients of these data," which is a disclosure obligation, not a secrecy one.
What protects a policyholder at a Swiss carrier is the revised Federal Act on Data Protection, in force since 1 September 2023, together with contract and general personality rights. The Swiss definition of sensitive personal data at Article 5 is drawn slightly differently from the European one and expressly includes data relating to "health, the private sphere or affiliation to a race or ethnicity," which is broader on the private sphere than Article 9 GDPR.
Article 62 makes breach of professional confidentiality punishable, on complaint, by a fine not exceeding 250,000 francs. The shape of that provision matters. It is a criminal fine on a natural person practising a profession, prosecuted only if someone complains. Corporate exposure runs through Article 64, which permits the authority to order the business to pay where a fine of not more than 50,000 francs is in question and identifying the individual would require disproportionate investigation. There is no Swiss equivalent of a turnover-based administrative fine. Whether personal criminal liability or corporate administrative liability changes behaviour more inside an institution is a genuine question, and reasonable people answer it differently.
The United States runs on entirely different plumbing
Three points, because the American position is widely misdescribed.
First, and most importantly: life insurers are not covered entities under HIPAA. The Department of Health and Human Services says so directly in its own guidance, listing health plans, clearinghouses and providers conducting certain electronic transactions as covered, and giving employers, life insurance companies and social benefit agencies as express examples of businesses Congress did not authorise it to regulate. The definition of "health plan" at 45 CFR 160.103 enumerates health, dental, vision, prescription drug and long term care insurers and does not include life insurance. Two nuances follow. A life insurer that also writes long term care or health coverage is covered for that line of business only. And a life insurer routinely receives protected health information from a physician who is covered, under a HIPAA authorisation, which regulates the doctor at the point of disclosure and not the insurer afterwards.
Second, the constraint that does apply is the Fair Credit Reporting Act. Insurance underwriting is an enumerated permissible purpose at 15 U.S.C. section 1681b(a)(3)(C), and the definition of a consumer report at section 1681a(d)(1) expressly reaches information used to establish eligibility for "credit or insurance." Section 1681g gives the consumer the right to a full file disclosure on request, and section 1681j(a)(1)(A) makes one disclosure free in any twelve month period, including from nationwide specialty agencies, a category defined at section 1681a(x) to include agencies compiling files on medical records or payments and on insurance claims.
Third, that category is where MIB sits. The Consumer Financial Protection Bureau describes MIB, Inc. as a subsidiary of MIB Group that "collects information about medical conditions and hazardous avocations," maintains medical specialty reports used in underwriting individual life, health, disability income, critical illness and long term care policies, and reports to insurers with the consumer's authorisation. A consumer may request one free report every twelve months, to be provided within fifteen days, and may dispute inaccuracies. Very few families have ever asked for theirs.
Beyond that, the substantive state rules come from the NAIC Insurance Information and Privacy Protection Model Act, Model 670, which requires a notice of information practices, plain language authorisation forms valid for thirty months for life and health, access to recorded personal information within thirty business days, a correction procedure on the same timetable, specific reasons for adverse underwriting decisions within twenty one business days of request, and limits on disclosure. It is a model act. It binds only where a state has adopted it, and the NAIC has been working on a successor.
What to ask, and what a good answer sounds like
Five questions, all of which a competent carrier can answer in writing and an evasive one cannot.
Which entities receive the medical file, and is the reinsurer named. Where are the systems hosted, and is the provider on the DORA register of information. On what basis is data transferred outside the European Economic Area, and if standard contractual clauses are used, which module. What does the carrier's Article 15 response look like in practice, and how long does it take. And, for a Luxembourg contract, whether the registered letter procedure under the 2024 law has been run and what the family's file records as the answer.
A carrier that answers those five precisely is telling you something reliable about its operating standards. Discretion is not a legal category. Article 28(3)(b) is, and so is a criminal fine on the individual who breaches it, and those are the things worth checking.
Frequently asked questions
Who inside an insurance company can see a policy file?
In the ordinary course: underwriting and new business staff, a medical underwriter, the reinsurer where risk is ceded, the administrator, the custodian, the appointed investment manager, the auditor, the supervisor on inspection, and the ICT providers running the systems. Under GDPR Article 28(3)(b) the carrier must contractually require that persons authorised to process the data have committed themselves to confidentiality or are under a statutory confidentiality obligation.
Can a policyholder find out who has seen their data?
Yes. GDPR Article 15(1)(c) entitles a data subject to be told the recipients or categories of recipient to whom the data have been or will be disclosed, in particular recipients in third countries, and Article 15(1)(g) entitles them to any available information as to the source of data not collected from them. Article 15(3) requires the controller to provide a copy of the data being processed.
What is the legal basis for sharing a medical file with a reinsurer?
There is no provision specifically addressing insurer to reinsurer data sharing in the GDPR, Solvency II, DORA or Swiss law. The reinsurer underwrites the ceded risk on its own account and so acts as a separate controller rather than a processor, which means Articles 6 and 9 apply rather than Article 28. In practice the basis is Article 6(1)(b) or (f) for ordinary data and Article 9(2)(a) explicit consent or 9(2)(f) legal claims for health data. Article 9(2)(h) is not available, because Article 9(3) confines it to processing under a professional bound by secrecy for care purposes.
Does HIPAA protect information held by a life insurer?
No. Life insurers are not covered entities. HHS guidance lists health plans, health care clearinghouses and providers conducting certain electronic transactions as covered, and gives life insurance companies as an express example of businesses outside the rule, and the definition of health plan at 45 CFR 160.103 does not include life insurance. A life insurer writing long term care or health coverage is covered for that line only. In the United States the applicable constraints come from the Fair Credit Reporting Act, state insurance privacy law and the Gramm-Leach-Bliley privacy rules.
What is MIB and can I see my file?
MIB, Inc., a subsidiary of MIB Group, is a nationwide specialty consumer reporting agency that collects information on medical conditions and hazardous avocations and reports it to life and health insurers with the consumer's authorisation, for individual rather than group policies. Under the Fair Credit Reporting Act a consumer may request one free file disclosure in any twelve month period, to be provided within fifteen days, and may dispute inaccuracies.
Is a Swiss insurer bound by secrecy the way a Swiss bank is?
Not by an equivalent statute. The Insurance Supervision Act contains no professional secrecy article binding insurers to policyholders; its confidentiality provisions are directed at the supervisor. A Swiss insurer's duty rests on the revised Federal Act on Data Protection, contract and personality rights. Article 62 of that Act makes breach of professional confidentiality punishable on complaint by a fine of up to 250,000 francs, imposed on the individual rather than the company.
Does a carrier have to tell me about a data breach?
Only where the breach is likely to result in a high risk to rights and freedoms, under GDPR Article 34(1), and even then the obligation falls away under Article 34(3) if the data were rendered unintelligible, for example by encryption, if later measures mean the high risk is no longer likely, or if individual communication would take disproportionate effort. Notification to the supervisory authority is a lower threshold and is due without undue delay and, where feasible, within 72 hours of awareness under Article 33(1).
What changed for European insurers in January 2025?
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, became applicable on 17 January 2025 to insurance and reinsurance undertakings and to insurance intermediaries. Among other things it requires every financial entity to maintain a register of information covering all contractual arrangements for ICT services from third party providers, on templates set by Commission Implementing Regulation (EU) 2024/2956. EIOPA's 2020 guidelines on outsourcing to cloud service providers were revoked with effect from the same date to avoid duplication.
Sources and authorities
Regulation (EU) 2016/679, Articles 5, 6, 9, 15, 28, 32, 33, 34, 44, 45, 46 and 83. Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses. Commission Decision 2000/518/EC on Switzerland, with the Commission review COM(2024) 7 final; Commission Implementing Decision (EU) 2025/2574 amending the United Kingdom decision; Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy Framework, with Case T-553/23 Latombe v Commission (General Court, 3 September 2025) and the pending appeal Case C-703/25 P. Regulation (EU) 2022/2554 and Commission Implementing Regulation (EU) 2024/2956, with EIOPA's confirmation of scope and its revocation of the cloud outsourcing guidelines effective 17 January 2025. Luxembourg law of 7 December 2015 on the insurance sector, Article 300, as amended by the law of 29 March 2024, Mémorial A number 136 of 2 April 2024; Article 458 of the Luxembourg Criminal Code. Swiss Federal Act on Data Protection, SR 235.1, Articles 5, 62 and 64, and the Insurance Supervision Act, SR 961.01. 45 CFR 160.103 and Department of Health and Human Services guidance on covered entities. Fair Credit Reporting Act, 15 U.S.C. sections 1681a, 1681b, 1681g and 1681j, with the Consumer Financial Protection Bureau's description of MIB, Inc. NAIC Insurance Information and Privacy Protection Model Act, Model 670.
Our editorial standards explain how articles like this one are sourced and reviewed.
This article is educational only and does not constitute legal, tax, investment, or insurance advice. Data protection and insurance supervision rules differ by jurisdiction, adequacy decisions and litigation status change, and the treatment of any particular arrangement depends on its own facts. Engage qualified advisers in every relevant jurisdiction before acting.
Every inquiry to PPLI.com is read personally by a senior specialist and is never routed into a sales funnel. You receive a written reply, usually within one business day.
Prefer to begin with a single question? Write to info@ppli.com