Data Protection for Insurers and Brokers
Introduction
Since the revised Federal Act on Data Protection (DSG) entered force in 2023 and the revised Swiss Insurance Contract Act (VVG, in force since 1 January 2022), Swiss insurers and brokers have operated within a markedly tighter compliance corset. They process sensitive personal data (health and claims data, biometric data in identification, socio-economic profiles), perform profiling for pricing and underwriting decisions, cooperate with reinsurers in the EU and overseas, and are closely supervised by the Federal Financial Market Supervisory Authority (FINMA) through the Insurance Supervision Act (VAG), the Insurance Supervision Ordinance (VAV) and circulars. In 2026 complexity has increased further through the EU AI Act and FINMA expectations on model risk. Insurers and brokers without clean data-protection and model governance face FINMA measures, DSG fines, and reputational and market-value damage.
What this article delivers:
- The interface VVG/VAG vs DSG and its hierarchy
- Claims data, health data, application and underwriting
- Profiling and AI in underwriting/pricing under DSG and the EU AI Act
- FINMA supervision, Insurance Intermediaries Act (VersAG), Circular 2023/1 on operational resilience
- Data flows between broker, insurer and reinsurer
- Concrete TOMs and a prioritised action plan
Legal framework and hierarchy
Swiss insurers are governed primarily by the Insurance Supervision Act (VAG), the Insurance Supervision Ordinance (VAV) and FINMA circulars (Circ. 2017/2 corporate governance for insurers, Circ. 2018/3 outsourcing, Circ. 2023/1 operational risks, Circ. 2024/4 on ICT and the forthcoming operational-resilience regime). The contractual relationship between insurer and policyholder is governed by the Insurance Contract Act (VVG). Intermediaries are additionally subject to the Insurance Intermediaries Act (VersAG, in force since 1 January 2024) regulating registration, training and conduct duties.
The DSG applies to all personal-data processing in parallel and subsidiarily. Where VVG/VAG/VersAG provide specific duties – e.g. the applicant's disclosure duty (Art. 4 VVG), retention duties, information duties toward the policyholder (Art. 3 VVG) – these prevail as lex specialis. The DSG right of access (Art. 25 DSG) remains, as does the breach notification duty (Art. 24 DSG). With EU exposure (establishment, marketplace principle), GDPR layers on with its own thresholds, duties and fines. For insurers with a significant share of EU insureds, an integrated compliance model is unavoidable.
Application, underwriting and claims data
Across the value chain insurers process several data types of varying sensitivity:
- Application data: identity, address, date of birth, occupation, health questions (in life/health/accident insurance), risk features (residence, vehicle class, prior losses). Collection is grounded in contract preparation (Art. 31(1)(a) DSG); the applicant's disclosure duty (Art. 4 VVG) legitimises detailed health questions. Retention: contractually and statutorily structured, often 10 years after contract end.
- Contract data: policy, premiums, payments, communications. Retention per CO and VAG.
- Claims data: notifications, expert reports, medical reports, police/garage reports, photo/video documentation, occasionally private investigators (high legal threshold, restrictive FDPIC position). Highly sensitive; access tightly documented on need-to-know.
- Profile data: for pricing and underwriting, fraud detection, cross-selling. Profiling is particularly delicate.
Data-subject information must be layered and phased: applicants at application, insured persons at each new processing purpose, third parties (e.g. injured persons) as early as possible. Breaches involving claims or health data almost always require FDPIC notification and information of data subjects.
Profiling and AI in underwriting and pricing
Insurers increasingly deploy statistical models and AI in underwriting, pricing, claims review and fraud detection. At least four regimes intersect:
- DSG profiling definition: Art. 5(f) DSG; deep assessment of material aspects (pricing, underwriting, claim payment) qualifies as "high-risk profiling" under Art. 5(g) – a DPIA under Art. 22 DSG is required.
- Automated individual decisions: Art. 21 DSG protects data subjects from purely machine decisions with legal effect; insurers must ensure either human involvement or that the exceptions (consent, necessity for contract performance, statutory basis) apply, plus information and right to be heard.
- EU AI Act: life and health insurance are classified as high-risk in Annex III; Swiss insurers with EU business must meet the high-risk obligations (risk management system, data governance, documentation, oversight, robustness, cybersecurity, transparency).
- FINMA expectations: on model risk (model governance, validation, monitoring) – concretised in supervisory dialogues and upcoming circulars.
Practically: every AI/model system needs a model inventory, a use-case DPIA with bias testing, versioning, monitoring for drift and fairness, a human-in-the-loop for decisions with impact, and transparent explanation toward the insured. A 2026 "black box" without human validation is no longer defensible.
FINMA, VAG and operational resilience
Insurers are FINMA-supervised; supervisory expectations bear materially on data protection and information security:
- Outsourcing (Circ. 2018/3): PMS, claims handling, accounting, IT, cloud – every outsourcing of a material function needs inventory, contract, audit right, exit plan.
- Operational resilience (Circ. 2023/1): identification of critical functions, impact tolerances, scenario analyses, recovery – touching reporting and business-continuity planning.
- Cyber-incident reporting: in parallel to FDPIC notification (Art. 24 DSG) and BACS/NCSC reporting under Art. 74b ISG, FINMA must be informed within 24 hours where a cyber incident threatens the continuity of the insurance business.
- Corporate governance: board and executive responsibility for ICT and data-protection risk with measurable reporting.
- VersAG for intermediaries: brokers must register from 2024, complete continuing education and meet conduct duties – including transparent disclosure of data flows between broker and insurer.
Several ISO standards interlock: ISO/IEC 27001:2022 for ISMS, ISO/IEC 27701 for privacy information management, ISO/IEC 22301 for business continuity, ISO/IEC 42001 (AI management system) increasingly for model governance.
Data flows: broker, insurer, reinsurer
In a typical distribution chain personal data flows several times: applicant to broker, broker to insurer, insurer to reinsurer (often in the EU or UK), insurer to medical experts, vehicle assessors, police and authorities. Three central questions follow:
- Role allocation: who is controller, processor or joint controller? Brokers are often independent controllers for customer advice and processors for specific insurer tasks. Reinsurers are regularly independent controllers for risk acceptance. Roles must be defined contractually.
- Data-processing agreements: Art. 9 DSG (and Art. 28 GDPR) require DPAs with clear TOMs, sub-processor lists, audit rights, data return/erasure.
- International transfers: to EU/EEA reinsurers (adequacy) unproblematic; to UK, Bermuda, US: Standard Contractual Clauses plus Transfer Impact Assessment required. For Swiss insurers with US reinsurance, a vetted mechanism choice (Swiss-U.S. DPF, SCC plus TIA) is standard.
Customer information must transparently reflect these flows: which data goes where, for what purpose, on what legal basis. A concise layered privacy notice with links to deeper detail is best practice in 2026.
Technical and organisational measures
In 2026 insurers and larger brokers should at least have reached the following TOM standard:
- ISMS per ISO/IEC 27001:2022, ideally certified; complemented by ISO/IEC 27701 for PIMS and ISO/IEC 22301 for BCMS.
- Model governance: inventory, DPIA per AI use case, drift and fairness monitoring, model versioning, human-in-the-loop, validation by an independent function.
- Identity architecture: phishing-resistant MFA, privileged access management, just-in-time access to claims data, monthly reviews of privileged accounts.
- Detection & response: 24x7 SOC or MDR, ATT&CK-mapped use cases, detection engineering on a maturity programme.
- Resilience: documented RTO/RPO per critical function, quarterly recovery tests, cyber crisis drills with supervisory notification as part of the play.
- Data-protection function: appointed Data Protection Adviser under Art. 10 DSG; in larger insurers a GDPR DPO under Art. 37 GDPR; reporting independently from the executive, with team and budget.
- Audit readiness: ISAE 3402 Type II for outsourced functions, annual FINMA dialogues, documented risk inventory.
How SIDD supports you
SIDD supports Swiss insurers, intermediaries and insurance IT providers on data protection, FINMA compliance, ISMS and model governance. Our team combines Swiss and EU data-protection expertise (Dr iur), ISO 27001 Lead Auditor qualification, former FINMA experience and operational security practice. We deliver the processing register, DPA templates for broker-insurer-reinsurer chains, DPIAs for underwriting and claims models, FINMA reporting templates, a cyber and breach playbook aligned with BACS, FDPIC and FINMA. Our data-protection adviser mandate is regularly combined with a GDPR DPO mandate for EU subsidiary or branch setups. For security and resilience build-out we offer ISO 27001 implementations, external CISO mandates and targeted penetration tests following TIBER-EU / TLPT methodology. Speak with us via our contact form or request a confidential quote.
