Privacy Statement

Introduction

This Privacy Statement relates to Foresters Healthcare Insurance Ltd. (“Foresters Insurance”) and Foresters Healthcare LBG (“Foresters LBG” and, together with Foresters Insurance, “Foresters”). Foresters Insurance has entered into arrangements pursuant to which it issues and administers insurance policies that replace or succeed policies previously issued by another insurer or entity (the “Former Insurer”), and processes Personal Data in connection with the continuation and administration of such insurance policies.

Foresters Insurance and Foresters LBG are each Guernsey-based companies and are each registered with the Office of the Data Protection Authority as independent data controllers. The clients, policyholders or members of Foresters are resident in the Bailiwick of Guernsey or Bailiwick of Jersey. Foresters has appointed BWCI Insurance Management Limited as a data processor.

Foresters has to comply with applicable legislation in respect of data protection, being the Data Protection (Bailiwick of Guernsey) Law, 2017 and any other applicable data protection laws or regulations.

Additionally, Foresters has contractual confidentiality obligations which are owed to members, clients, prospective clients, Service Providers and potentially others.

In the ordinary course of business, Foresters comes into possession of personal and / or confidential information (“Data“) in respect of individuals (“Individuals”), such as:

  • Clients/policyholders & prospective clients/policyholders
  • Members and prospective members
  • Complainants, correspondents and enquirers
  • Advisers, consultants and professional experts and their directors, officers, employees, agents and representatives
  • Directors and employees (including temporary and casual workers) of Foresters

Foresters will process personal data for the following applicable purposes:

  • Accounting, bookkeeping and related services
  • Advertising, marketing and public relations
  • Customer & client administration
  • Insurance administration
  • Membership administration

including, where applicable, the administration, replacement, succession or continuation of insurance business and related policies, and associated legal and regulatory processes.

For the purposes of this privacy statement, Data may include personal information, contracts and related documents between Foresters and other parties (whether or not Individuals) including the service providers to Foresters (“Service Providers”), and includes any information that relates to an identified or identifiable living Individual from which that Individual can be identified (whether from that information alone, or in conjunction with other information which Foresters has or is likely to obtain) (“Personal Data”). Personal Data may be obtained directly from Individuals or, where applicable, from third parties including other insurers, intermediaries, service providers or entities involved in arrangements relating to the cessation, replacement or continuation of insurance policies. This includes Personal Data received from a Former Insurer in connection with such arrangements.

Personal data is defined in the relevant legislation, the data classes that Foresters may process include:

  • Personal details
  • Employment details
  • Financial details
  • Goods or services provided

Foresters may also process special category data (including sensitive personal data), including:

  • Physical or mental health or condition
  • Trade union membership

In obtaining and using Personal Data in connection with policyholders and/or members or prospective policyholders and/or members, Service Providers and others (as may be applicable), Foresters Healthcare and Foresters LBG will each act as an independent data controller.

The Personal Data may be held electronically, processed via automated processes, or held in general files, and where processed on Foresters’ behalf by Service Providers, will be subject to written contracts governing that processing and setting out the security and confidentiality measures which the Service Providers have committed to implement.

This document sets out Foresters’ policies and guidelines with regard to the obtaining, storing, processing, use, disclosure, transfer and safeguarding of Personal Data as data controller.

For the avoidance of doubt and notwithstanding anything to the contrary in this privacy statement, nothing in this privacy statement shall prevent Foresters from complying with any legal or regulatory obligation to disclose data in accordance with applicable law or regulation.

Obtaining and Using Personal and Confidential Data

Personal Data may only be processed if the data subject has given his / her consent, or if the processing is necessary for the performance of a contract to which the data subject is party, for the taking of other pre-contractual measures at his / her request, where processing is otherwise necessary for compliance with legal obligations, to protect the vital interests of the data subject; or is otherwise necessary for legitimate interests or on public interest grounds.

Where Personal Data includes special category data (including health data), Foresters will only process such data where one or more conditions in Part II or Part III of Schedule 2 to the Data Protection

(Bailiwick of Guernsey) Law, 2017 are satisfied. In particular, Foresters may process special category data (including health data) where such processing is authorised pursuant to paragraph 17(a), Part II of Schedule 2 of the Data Protection Law and regulation 11 of the Data Protection (General Provision) (Bailiwick of Guernsey) Regulations, 2018 (the “DP Regulations”), including where:

(a) the processing is carried out by a person carrying on insurance business, or on its behalf, for the purpose of enabling or facilitating the carrying on of insurance business;

(b) the processing is necessary for a purpose relating to an objective that is in the public interest; and

(c) the applicable conditions set out in regulation 11 of the DP Regulations are satisfied.

Where Personal Data has been received from a Former Insurer or another third party, Foresters Insurance processes such Personal Data for the purposes of issuing, administering and performing insurance contracts that replace or succeed previous policies and to comply with legal and regulatory obligations.

As a Data Controller, Foresters is responsible for, and must be able to demonstrate, compliance with the Data Protection Principles:

  • Personal Data must be processed fairly, lawfully and in a transparent manner
  • Personal Data must be collected for specified, explicit and legitimate purposes, and not further processed in a manner which is incompatible with those purposes
  • Personal Data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is collected
  • Personal Data must be accurate and, where necessary, kept up to date, and reasonable steps must be taken to ensure that Personal Data that is inaccurate is erased or corrected without delay
  • Personal Data must be kept in a form which permits identification of the data subject for no longer than is necessary for the purposes for which it is processed
  • Personal Data must be processed in a manner that ensures its security appropriately, including protecting it against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures

In addition, Foresters imposes confidentiality obligations on its Service Providers and is subject to confidentiality obligations regarding policyholders (and prospective policyholders), members and Service Providers.

Foresters does not make decisions about Individuals based on automated processing of Personal Data.

Accordingly:

  • Only Data, which is strictly necessary for the purpose of the insurance contract between Foresters and a policyholder or prospective policyholder or a Service Provider or which relates to the relationship between Foresters and its members or prospective members, should be requested or obtained from the relevant party
  • Through the application forms, privacy statement(s) and policy documentation, Foresters makes policyholders, prospective policyholders, members, Service Providers and relevant Individuals aware of;
    • the specific legal basis relied upon for each category of processing, including where applicable reliance on statutory authorisations for special category data;
    • the identity of Foresters;
    • the purposes for which the Data relating to that relevant Individual will be stored and used;
    • the legal basis for that processing and
    • where that legal basis is a legitimate interest of Foresters or a third party, a description of those legitimate interests and the right to object to the processing; and
      • where the legal basis is consent, the right to withdraw consent;
      • the recipients or categories of recipients (if any) of the Data;
    • where applicable, details of international data transfers;
    • details of storage and retention periods;
    • details of any automated decision-making, including any profiling;
    • the right of Individuals to get access to their Personal Data, to rectify any such Personal Data, and their other rights applicable to data protection laws;
  • the right to lodge a complaint with the Office of the Data Protection Authority (“ODPA”), which can be contacted at: Block A, Lefebvre Court, Lefebvre Street, St Peter Port, Guernsey, GY1 2JP, by telephone on 01481 742074, or by email on enquiries@odpa.gg
  • Foresters will not use Data other than for the purposes which have been brought to the attention of the relevant Individual and, if consent is required, to which the relevant Individual has consented.
  • Where Service Providers process Personal Data for Foresters pursuant to contracts between Foresters and the Service Providers, the Service Providers act as data processors of Foresters. Foresters will ensure that:
    • appropriate due diligence is undertaken on such Service Providers to confirm that the Service Providers provide sufficient guarantees to implement appropriate technical and organisational security measures so as to meet the requirements of applicable law and to ensure the protection of the rights of the Individuals with regard to their Personal Data; and
    • any contracts with such Service Providers impose obligations on the Service Providers which are required under applicable law and which assist Foresters in complying with its own obligations under applicable law.
  • Where Service Providers are dealing with existing policyholders or members, the Service Providers have confirmed that they have procedures in place to verify on behalf of Foresters that all existing Data held relating to those existing policyholders or members is accurate and up to date.

Processing of Special Category Data (including Health Data)

Foresters Insurance may process special category data (including information relating to an Individual’s physical or mental health) in connection with the administration and ongoing management of insurance business. This includes Personal Data received from a Former Insurer and processed by Foresters Insurance to ensure the succession and proper administration of insurance policies.

Where Foresters Insurance relies on regulation 11 of the DP Regulations:

(a) such processing will only be undertaken where it is necessary for a purpose relating to an objective in the public interest, including the proper administration and continuity of insurance business;

(b) such processing may, in certain circumstances, be undertaken without obtaining the explicit consent of the Individual where Foresters Insurance cannot reasonably be expected to obtain such consent and is not aware of the Individual withholding consent, including where Personal Data has been provided to Foresters Insurance by a Former Insurer and it is not reasonably practicable to obtain consent from each Individual in connection with the replacement or continuation of insurance policies; and

(c) such processing will not be used to take measures or decisions in relation to an Individual where the conditions under regulation 11 do not permit such use.

Foresters Insurance will implement appropriate safeguards in relation to such processing, including restrictions on access, confidentiality obligations and enhanced security measures.

Foresters Insurance considers such processing to be fair and proportionate having regard to the nature of the insurance relationship, the necessity of such processing to ensure continuity of insurance cover and administration, and the safeguards implemented to protect Individuals. In particular, such processing is considered necessary to ensure that Individuals continue to benefit from insurance cover and that policies can be effectively administered following arrangements under which new or replacement policies are issued.

Recipients of Data held by Foresters may include:

  • Employees and agents of Foresters
  • Another organisation acting on behalf of Foresters (a data processor)
  • Debt collection, tracing & private investigation agencies
  • Ombudsman & Regulatory Authorities
  • Government Departments
  • The individual or customer themselves
  • Relatives, Guardians or Other Persons Associated with the Customer or Individual
  • Current, Past or Prospective Employers of the Individual
  • Suppliers, Providers of Goods or Services
  • Healthcare, Social & Welfare Advisers or Practitioners
  • Trade, Employer Associations & Professional Bodies
  • Any Former Insurer or other entity involved in arrangements relating to the cessation of previous policies or the issuance and administration of replacement policies

Storage and Security of Data

Each of Foresters and the Service Providers is obliged to implement appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, or accidental loss, alteration, unauthorised disclosure or access. This applies particularly where such Personal Data will be transmitted over a network. Similar security measures should also apply to the other Data.

Generally, Foresters shall, and where it appoints the Service Providers, shall ensure that the Service Providers shall:

  • considering the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of Individuals, implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, which shall include, as appropriate:
    • pseudonymisation and encryption;
    • the ability to ensure ongoing confidentiality, integrity, availability and resilience;
    • the ability to restore availability and access in a timely manner in the event of a technical incident;
    • a process for regular testing, assessing and evaluating the effectiveness of those measures;
  • take all reasonable steps to ensure that employees and other agents are aware of and comply with the security measures which have been implemented, including training of their respective relevant employees and agents;
  • ensure that technical security controls are implemented to limit access to the Data on a “need to know” basis; and
  • ensure that all hard copies of Data are securely stored and are only accessed on a “need to know” basis.

Retention Periods

Foresters is obliged to retain certain information to ensure accuracy, to help maintain quality of service and for legal, regulatory, fraud prevention and legitimate business purposes.

It is obliged by law to retain customer-related identification and transaction records for five years from the end of the relevant member or policyholder relationship or the date of the transaction respectively. Other information, including personal data of the directors and business contact information, will be retained for no longer than is necessary for the purpose for which it was obtained by Foresters or as required or permitted for legal, regulatory, fraud prevention and legitimate business purposes. In general, Foresters (or its service providers on its behalf) will hold this information for a period of seven years from the termination of the relevant business relationship, unless it is obliged to hold it for a longer period under law or applicable regulations. Certain director information may be held indefinitely where it forms part of the statutory books and records of Foresters.

Foresters (or its service providers on its behalf) will also retain records of telephone calls and any electronic communications for a period of five years from the date of such call or communication.

Breach Notifications

In accordance with applicable data protection laws, Foresters will be obliged to notify the ODPA of any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data (each a “personal data breach”) within 72 hours of becoming aware of same, unless the personal data breach is unlikely to result in risks to Individuals. Furthermore, Foresters will need to notify any impacted Individuals without undue delay where a personal data breach is likely to result in a high risk to those Individuals.

In the event of a personal data breach:

  • Foresters shall consider the likely risks arising from the Personal Data breach, taking into account the nature and scope of the personal data in question, the extent of the breach, the period of the breach, and any security measures which may militate against risk, such as encryption. In doing so, the potential consequences for the affected Individuals will be considered;
  • any incident in which Personal Data has been put at risk will be reported to the ODPA within 72 hours of Foresters becoming aware of the incident. Where a report is made to the ODPA, Foresters will provide such information and detail as is required under applicable data protection laws or as the ODPA may request, which shall include:
    • a description of the nature of the personal data breach, including where possible, the categories and approximate numbers of impacted Individuals, and the categories and approximate number of personal data records concerned;
    • a description of the likely impact of the personal data breach;
    • a description of measures to mitigate possible adverse effects;
  • reporting to the ODPA may be conducted in phases where the full extent of the personal data breach is not known within 72 hours of Foresters becoming aware of same. Any such phased reporting will be conducted in consultation with the ODPA;
  • any incidents which are likely to result in high risk to Individuals will be notified to the impacted Individuals without undue delay unless this would involve disproportionate effort. In this latter case, a public communication or similar equally effective notification measure shall be implemented by Foresters;
  • Where, having considered the matter, Foresters comes to a determination that no notification need or will be made to the ODPA and / or the affected data subjects, Foresters shall in any event keep a summary record of each incident which has given rise to the risk of unauthorised disclosure, loss or alteration of personal data, which will include an explanation as to why Foresters did not consider it necessary to inform the ODPA.
  • Records of security incidents will be made available to the ODPA on request.

Foresters shall ensure that the Service Providers notify Foresters without delay of any security incident and provide all reasonable assistance to Foresters to enable it to comply with its obligations under data protection law.

Privacy Impact Assessments

Foresters may be required to undertake privacy impact assessments in relation to the processing of Personal Data in certain circumstances and will undertake an impact assessment where the processing in question, taking into account the nature, scope, context and purposes of the processing, is likely to result in a high risk to Individuals.

Without limitation, the following may be indicative of high-risk processing:

  • a significant change to the processing operations relating to the Personal Data, including where implemented by one of the Service Providers;
  • processing involving evaluation, scoring, monitoring or profiling of Individuals;
  • Combining of two or more data sets arising from separate processing operations conducted for different purposes;
  • Innovative use of technologies or of organisational measures to protect Personal Data;
  • Data transfers across borders outside the European Economic Area (the “EEA”) or equivalent jurisdictions (including Guernsey).

Any privacy impact assessment shall include:

  • a systematic description of the envisaged processing operations and the purposes of the processing, including where applicable the legitimate purposes pursued by Foresters;
  • an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
  • an assessment of the risks to Individuals; and
  • the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure protection of Personal Data and to demonstrate compliance with applicable data protection laws taking into account the rights and legitimate interests of Individuals.

Foresters shall consult with the ODPA where necessary in accordance with applicable data protection laws, and where appropriate shall seek the views of Individuals or their representatives.

Foresters shall ensure that the Service Providers notify Foresters without delay of any new processing or change in processing arrangements (including implementation of any new technology) to facilitate Foresters in determining whether the processing is likely to result in high risk to Individuals and shall provide all reasonable assistance to Foresters to enable it to comply with its obligations under applicable data protection laws with regard to undertaking a privacy impact assessment.

Transfers of Data from the EU or equivalent jurisdictions

The transfer and distribution of Personal Data, whether to a Service Provider or a third party, is restricted, and is only permitted in limited circumstances. Particular restrictions and limitations apply to the transfer of Personal Data to jurisdictions which do not provide an adequate level of protection under Guernsey data protection law.

Where Personal Data is transferred outside the Bailiwick of Guernsey or to a jurisdiction not recognised as providing an adequate level of protection, Foresters will ensure that appropriate safeguards are implemented in accordance with applicable data protection law.

Subject Access Requests

Where an Individual makes a subject access request in writing, there is an obligation on the data controller to provide certain information to the data subject.

Accordingly, on receipt of any data subject access request, Foresters shall:

  • inform the Individual as to whether the data processed by or on behalf of Foresters includes Personal Data relating to the Individual, and where it does, to provide a description of:
    • the categories of the Personal Data;
    • the Personal Data constituting the data;
    • the purposes for which they are being or are to be processed;
    • the recipients or categories of recipients to whom they are or may be disclosed;
    • information as to source, where not obtained directly from the Individual;
    • where possible, the envisaged storage period, or alternatively the criteria used to determine that period;
    • the right to lodge a complaint to the Office of the Data Protection Authority;
    • details of any automated decision making or profiling;
    • the appropriate safeguards with regard to international data transfers.
  • provide the Individual with a copy of the information Personal Data of the Individual;
  • provide the relevant information to the Individual free of charge, in an easily visible, intelligible and clearly legible manner within one month of a proper request from the data subject, unless an exception applies under applicable data protection laws.

If Foresters does not intend taking action at the request of the data subject, Foresters shall inform the Individual without delay and the reasons for not taking action, as well as the right of the Individual to complain to the ODPA.

Foresters shall ensure that the Service Providers notify Foresters without delay of any data subject access request and provide all reasonable assistance to Foresters to enable it to comply with its obligations under applicable data protection laws in relation to any data subject access requests.

Other Data Subject Rights

Individuals have the following rights, in certain circumstances:

  • the right to rectify Personal Data
  • the right to restrict processing
  • the right to object to processing
  • the right to be forgotten
  • the right to data portability.

Foresters shall comply with applicable data protection laws in honouring Individual rights as set out above. However, if Foresters does not intend taking action at the request of the data subject, Foresters shall inform the Individual without delay and the reasons for not taking action, as well as the right of the Individual to complain to the ODPA.

Foresters shall ensure that the Service Providers notify Foresters without delay of any data subject requests to enforce the above rights and provide all reasonable assistance to Foresters to enable it to comply with its obligations under applicable data protection laws in relation to any such data subject requests.

Contacting Foresters

Foresters can be contacted at its office: Albert House, South Esplanade St Peter Port, Guernsey, GY1 1AW. For any queries or concerns relating to data protection, please contact clair.lepoidevin@bwcigroup.com or via the contact details provided on our website.

Updates to this Privacy Statement

Any changes Foresters makes to its Data protection and Privacy Statement in the future will be posted on its website, please check back frequently to see any updates or changes.