pi_circular Insurance & claimsCompliance & regulation London P&I Club
25 May 2018 TO ALL MEMBERS AND ASSUREDS Dear Sirs GDPR guidelines for claims handling As advised in our Circular dated 26 February 2018, the General Data Protection Regulation (“GDPR”) provides for significant penalties in the event of a data breach. The purpose of this Circular is to provide members, correspondents and others with further guidance on how to try and reduce the risk of a breach and advise you of some changes we will be making in how we handle personal data. People claims such as those involving crew or passenger illness and injury present the greatest challenge to the Association in ensuring the adequate protection of personal data. Data minimisation and privacy by design As mentioned in our previous Circular, the Association is a controller for the purposes of the GDPR, and thus responsible for demonstrating compliance with the Regulation. As a result and in line with the key GDPR principles of data minimisation and privacy by design, the Association wishes to: • start limiting the amount of personal information in circulation, • make greater use of existing technology to transfer personal data more securely and, • where possible, anonymise the data that is exchanged. E-mail circulation lists continue to expand which means it can be difficult to spot when someone who should not be included has inserted themselves into an email chain. In addition, attempted fraud by e-mail is increasing, with communications received from impersonators of those involved in the industry. These imposters are usually seeking financial gain but responding to such a message could lead to a data breach by the Association as well. - 2 In handling personal illness or injury files it is often necessary to exchange sensitive personal data with members, correspondents and service providers around the world on an urgent basis. Implementing GDPR principles is particularly important. We would like to offer readers some “best practice” guidance in the form of 10 tips for the treatment of personal data: 1. Respect - treat everyone’s personal data with the same respect you would wish for your own. 2. Minimise the generation of personal data by email and on paper – the less personal data being created and circulated, the easier it is to protect. Only send information which is necessary for the handling of the claim. 3. Cybersecurity – ensure computer systems are secure and make use of security measures such as password protection and secure email servers when transferring attachments containing passports, medical reports, contracts of employment etc. The Association intends to explore the use of secure email portals to protect information. 4. Anonymisation – aim to use identifiers for individuals, like crewmember, broker, surveyor etc. instead of names and dates of birth. Other identifiers could be the vessel name, the nature of the incident, or the port of disembarkation, with a reference number. This applies not just to the subject heading and body of an e-mail but also, where possible, to any documents which support the claim. If there is no alternative to using a name, we would recommend that it is cited with as few other identifiers as possible. We also intend to adopt this approach for claim descriptions. If these steps are put into practice, we hope that, except for those directly handling the claim, it will not be possible to identify the individual who is the subject matter of the claim. 5. Start afresh - if you cannot avoid identifying an individ
Circular 5.557: GDPR guidelines for claims handling
London P&I Club
Read full article at London P&I Club →
Opens London P&I Club in a new tab