We process personal information in order to be able to provide our customers with the best possible service/product. We always ensure we have a legitimate purpose and appropriate legal basis to hold personal information. We strive to maintain the highest possible data protection standards and to handle all data with the upmost care and we will only use your data in a safe and ethical way.
Your trust is important to us, so we want you to be aware of our Privacy Policy which explains how we collect, store and handle your personal information. ‘Personal information’ in this Privacy Policy has the same meaning as ‘personal data’ in the EU General Data Protection Regulation 2016/679/EU (GDPR) and equivalent UK legislation. Essentially, it means any information which is connected to a living individual who can be identified from that information, either by itself or when combined with other data which might come into our possession. Information about individuals acting as sole traders and certain partnerships, where they are individually identifiable, and the information relates to them as an individual may also constitute personal data.
If you suspect data about QBE EO’s customers, staff or other contacts has been inappropriately disclosed or you find QBE EO property which may contain confidential or personal information, please let our Data Protection Team know as soon as possible by completing our Data Breach Form.
QBE European Operations (‘QBE EO’) is committed to ensuring your privacy is protected. This Fair Processing Notice sets out details of the information that we may collect from you and how we may use that information. Please take your time to read this notice carefully. When using a QBE EO website, this notice should be read alongside the website terms and conditions and cookie policy.
QBE EO is part of a wider group of companies, the QBE Insurance Group, one of the world’s leading international insurers and reinsurers. As a business insurance specialist, we offer a range of insurance products from the standard suite of property, casualty and motor to the specialist financial lines, marine and energy. All are tailored to the individual needs of our client base of small, medium and large businesses.
To enable us to provide insurance services, including providing a quote and then insurance, and dealing with any claims or complaints that might arise, we need to collect and process data. This makes us a ‘data controller’ for any personal information that you provide to us which makes us responsible for complying with data protection laws.
The specific company acting as a data controller of your personal information will be listed in the documentation we provide to you. A list of all the companies within QBE EO which act as data controllers is set out below.
If you are unsure about who the data controller of your personal information is, you can also contact us at any time by e-mailing us at dpo@uk.qbe.com.
Insurance involves the use and disclosure of your personal information by various insurance market participants such as intermediaries, insurers and reinsurers. The London Insurance Market Core Uses Information Notice sets out those core necessary personal information uses and disclosures. Our core uses and disclosures are consistent with the London Market Core Uses Information Notice. We recommend you review this notice (by clicking the link above).
The types of personal information that we collect, and our uses of that personal information depend on your relationship with us. For example, we will collect different personal information depending on whether you are a policyholder, a beneficiary or a third party covered by an insurance policy we provide, a website user, a claimant, a witness, an intermediary, an expert or another third party.
We may use your personal information for a number of different purposes and in each case, we must have a ‘legal ground’ to do so. We will rely on the following ‘legal grounds’ when we process your ‘personal information’:
Sometimes we will request or receive some of your ‘special category/sensitive personal information’, which includes information that relates to your physical and/or mental health, genetic or biometric data, sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership. We may also need details of your criminal convictions including information relating to any unspent convictions, pending prosecutions, fixed penalty notices or other relevant elements such as arrests or unspent cautions for fraud prevention purposes or to carry out money laundering checks. We won’t actively collect information about your sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership although it is possible that this could be disclosed indirectly in certain circumstances when answering our questions.
Where you provide personal information to us about other individuals (for example, members of your family or your employees) we will also be data controller of and responsible for their personal information. You should refer them to this notice.
When we process such ‘special category/sensitive personal information’, we must have an additional ‘legal ground’. We will rely on the following legal grounds when we process your ‘special category/sensitive personal information’:
In order to make this notice as user friendly as possible, we have split it into different sections. Please click on the link below that best describes your relationship with us.
Prospective policyholders or beneficiaries (PDF 55Kb)
Policyholder or beneficiary under an insurance policy (PDF 60Kb)
Claimants and prospective claimants and third parties under commercial insurance policies (PDF 59Kb)
We may use your personal information to provide you with information about products or services which may be of interest to you where you are an existing customer or business contact or where you have provided your consent for us to do so. We may do this by post, email, telephone and social media.
We are committed to only sending you marketing communications that you have clearly expressed an interest in receiving. If you wish to opt out of marketing, you may do so by clicking on the 'unsubscribe' link that appears in all emails or telling us when we call you. Otherwise you can always contact us using the details set out in section 10 to update your contact preferences.
Please note that, even if you do choose not to receive marketing messages, we may still send you service-related communications where necessary.
Unsubscribe from QBE EO Marketing Communications.
We will retain your Personal Information for as long as is reasonably required for the purposes explained in this Privacy Policy. We are also required to keep certain information, which may include personal information, to meet legal, regulatory, tax or accounting needs. For example, we may also retain your personal information for longer periods of time so that we have an accurate record of your dealings with us in the event of any complaints or challenges you or others might raise later, or if we reasonably believe there is a prospect of litigation.
The specific retention period for your personal information will depend on your relationship with us, the type of personal information we hold and the reasons we hold your personal information.
We maintain a data retention policy to assist us in managing how long we hold your personal information and our record management, and this includes clear guidelines on data retention and deletion.
Where your personal information is no longer required we will ensure it is either securely deleted, anonymised such that any information that could identify an individual is removed or it is stored in a way which means it will no longer be used by the business.
If you would like more information about the periods for which your personal information will be stored or our data retention policy, please contact us using the details set out in section 10.
Sometimes we (or third parties acting on our behalf) may need to store or process your personal information in countries outside of the UK.
Where we need to transfer your personal information outside the UK and the EEA, we will take steps to ensure that your personal information is protected. We will do this using a number of different methods including:
Depending on our relationship and your particular circumstances, we might transfer personal information anywhere in the world.
If you would like further information regarding our data transfers and the steps we take to safeguard your personal information, please contact us using the details set out in section 10.
We have a package of technical, organisational and contractual measures in place to protect your personal information which have been adopted to comply with the latest data protection requirements. The measures cover various aspects of data security including the following:
Our security measures are kept under periodic review and are regularly updated to reflect developments in technology and security and changes to our business. However, please be aware that there are inherent security risks in transmitting data, such as e-mails or via the Internet, because it is impossible to safeguard completely against unauthorised access by third parties.
Profiling is any form of automated processing of personal information and information provided by third party sources, to evaluate certain personal aspects. Insurance underwriting, and sometimes claims payment, is based on profiling as it assesses the event that you are seeking to insure and the likelihood of that event occurring.
We use profiling as part of:
We keep our profiling process under regular review, and, in most cases, an individual will then make a decision based on the outcome of that profiling.
Automated decision making refers to a situation where a decision is taken using personal information that is processed solely by automatic means (i.e. using an algorithm or other computer software) rather than a decision that is made with some form of human involvement.
Automated decision making is widely used in the insurance industry to offer and administer insurance efficiently and accurately.
Where an automated decision produces a legal or other similarly significant effect concerning you (for example, where your policy or claim is rejected), we will only carry out automated decision making:
In all other cases, we will ask for your consent in advance.
We currently use automated decision in our SME motor business. We use an electronic-trading system called Acturis to help us assess the risk and calculate what premium we charge. We have certain pricing rules which are fed into the system. For example, whether you have had a claim in the last 5 years will affect the price as will the amount you wish us to cover. Using these rules, the system automatically decides whether to accept, decline or refer your application to an underwriter for further consideration.
You have the right in certain circumstances not to be subject to a decision which is based solely on automated processing. Please see section 9 for further details of your rights in this respect.
Under data protection law you have a number of rights in relation to the personal information that we hold about you which we set out below. These rights might not apply in every circumstance. You can exercise your rights by contacting us at any time using the details set out in section 10.
We will not usually charge you in relation to a request. We may ask you for proof of identity to ensure that we only disclose information to the right individual.
We aim to respond to all valid requests within one month. However, it may take us longer if the request is particularly complicated or you have made several requests. We will always let you know if we think a response will take longer than one month. We may also ask you to provide more detail about what you want to receive or are concerned about, as this will help us to provide you with a prompt response.
We take your rights seriously but there may be some circumstances where we cannot comply with your request, for example if complying with it would mean that we couldn't comply with our own legal or regulatory obligations. In these instances, we will let you know why we cannot comply with your request.
In some circumstances, complying with your request may mean that we are unable to continue providing you with insurance and may need to cancel your insurance policy or discontinue your claim. For example, if you request erasure of your personal information, we will not have the information required to pay your claim. We will inform you of this at the time you make a request.
You are entitled to a copy of the personal information we hold about you and certain details about how we use it.
We will usually provide your personal information to you in writing unless you request otherwise. Where your request has been made electronically (e.g. by email), a copy of your personal information will be provided to you by electronic means where possible.
We always take care to ensure that the information we hold about you is accurate and where necessary up to date. If you believe that there are any inaccuracies, discrepancies, or gaps in the information we hold about you, you can contact us and ask us to update or amend it.
In certain circumstances, you are entitled to ask us to stop using your personal information, for example where you think that the personal information we hold about you may be inaccurate or where you think that we no longer need to use your personal information.
Where we rely on your consent in order to process your personal information, you have the right to withdraw such consent to further use of your personal information.
Please note that for some purposes, we need your consent in order to provide your policy or handle your claim. If you withdraw your consent, we may need to cancel your policy, or we may be unable to pay your claim. We will advise you of this at the point you seek to withdraw your consent.
This is sometimes known as the 'right to be forgotten'. It entitles you, in certain circumstances, to request deletion of your personal information. For example, where we no longer need your personal information for the original purpose we collected it for or where you have exercised your right to withdraw consent.
Whilst we will assess every request, there are other factors that will need to be taken into consideration. For example, we may be unable to erase your information as you have requested because we have a legal or regulatory obligation to keep it.
In certain cases, you have the right to object to our processing. This arises in relation to:
Marketing: You have control over the extent to which we market to you and you have the right to request that we stop sending you marketing messages at any time. You can do this either by clicking on the 'unsubscribe' button in any email that we send to you or by contacting us at any time using the details set out in section 10. Please note that even if you exercise this right because you do not want to receive marketing messages, we may still send you service-related communications where necessary.
Processing based on our legitimate interest: Where we process your personal information on the basis of a legitimate interest, you can object to such processing, unless our purpose outweighs any prejudice to your privacy rights.
In certain circumstances, you can request that we transfer personal information that you have provided to us directly to a third party.
Where an automated decision produces a legal or other similarly significant effect concerning you (for example, where your policy or claim is rejected), you have the right to ask us to reconsider a decision taken by automated means or to take a new decision on a different basis (e.g. by introducing some form of human involvement).
You have a right to complain to the Information Commissioners Office (ICO) if you believe that we have breached data protection laws when using your personal information. You can visit the ICO's website at www.ico.org.uk for more information. Please note that lodging a complaint will not affect any other legal rights or remedies that you have.
If you would like further information about any of the matters in this notice or if have any other questions about how we collect, store or use your personal information, you may contact our data protection officer by emailing dpo@uk.qbe.com or writing to:
The Data Protection Officer
QBE European Operations
30 Fenchurch Street
London EC3M 3BD
From time to time we may need to make changes to this notice, for example, as the result of changes to law, technologies, or other developments. We will provide you with the most up-to-date notice and you can check this page periodically to view it.
This notice was last updated on 3rd June 2024.
We process personal data in order to be able to provide our customers with the best possible service/product. We always ensure we either have a legitimate purpose to hold personal data or obtain consent. We strive to maintain the highest possible Data Protection standards and we will handle all data with the upmost care.
Your trust is important to us, so we want you to be aware of our Privacy Policy which explains how we collect, store and handle your personal data.
If you suspect data about QBE’s customers, staff or other contacts has been inappropriately disclosed or you find QBE property which may contain confidential or personal data, please let our Data Protection Team know as soon as possible by completing our Data Breach Form.
QBE European Operations ("QBE") is committed to ensuring your privacy is protected. This Fair Processing Notice sets out details of the information that we may collect from you and how we may use that information. Please take your time to read this notice carefully. When using a QBE website, this notice should be read alongside the website terms and conditions and cookie policy.
QBE is part of a wider group of companies, the QBE Insurance Group, one of the world’s leading international insurers and reinsurers. As a business insurance specialist, we offer a range of insurance products from the standard suite of property, casualty and motor to the specialist financial lines, marine and energy. All are tailored to the individual needs of our small, medium and large client base.
To enable us to provide insurance services, including providing a quote and then insurance, and dealing with any claims or complaints that might arise, we need to collect and process data. This makes us a "data controller" for any personal information that you provide to us which makes us responsible for complying with data protection laws.
The specific company acting as a data controller of your personal information will be listed in the documentation we provide to you.
A list of all the companies within QBE European Operations which act as data controllers is set out below.
If you are unsure about who the data controller of your personal information is, you can also contact us at any time by e-mailing us at dpo@uk.qbe.com.
Insurance involves the use and disclosure of your personal information by various insurance market participants such as intermediaries, insurers and reinsurers. The Code of Practice on Data Protection for the Insurance Sector sets out the obligations of insurers operating in Ireland in respect of the use and processing of personal information. We recommend you review this notice.
The types of personal information that we collect, and our uses of that personal information will depend on your relationship with us. For example, we will collect different personal information depending on whether you are a policyholder, a beneficiary or a third party covered by an insurance policy we provide, a website user, a claimant, a witness, a broker, an expert or another third party.
Sometimes we will request or receive some of your “sensitive personal information”. Sensitive personal information is information that relates to your health, genetic or biometric data, criminal convictions, sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership. For example, we may need access to information about your health in order to provide you with a quote, provide your insurance policy, or process any claims you make.
We may also need details of any unspent criminal convictions you have for fraud prevention purposes or to carry out money laundering checks. We won’t actively collect sensitive personal information about your sex life, sexual orientation, racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership although it is possible that this could be disclosed indirectly in certain circumstances when answering our questions.
Where you provide personal information to us about other individuals (for example, members of your family or your employees) we will also be data controller of and responsible for their personal information. You should refer them to this notice.
In order to make this notice as user friendly as possible, we have split it into different sections. Please click on the section below that best describes your relationship with us.
If you apply for an insurance policy with us or where someone else (such as your employer) applies for an insurance policy which will benefit you, this section will be relevant to you and sets out our uses of your personal information.
What personal information will we collect?
What sensitive personal information will we collect?
How will we collect your personal information?
We will collect information directly from you when:
As well as obtaining information directly from you, we will collect information from:
What will we use your personal information for?
We may use your personal information for a number of different purposes. In each case, we must have a "legal ground" to do so. We will rely on the following “legal grounds”, when we process your "personal information":
When the information that we process is classed as “sensitive personal information", we must have an additional “legal ground". We will rely on the following legal grounds when we process your "sensitive personal information":
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
---|---|---|
To set you up as a policyholder including carrying out fraud, sanctions, credit and anti-money laundering checks. |
|
|
To evaluate your insurance application and provide a quote. |
|
|
Communicating with you and resolving any complaints that you might have. |
|
|
Providing improved quality, training and security (for example, with respect to recorded or monitored phone calls to our contact numbers). |
|
|
Complying with our legal or regulatory obligations. |
|
|
Managing our business operations such as maintaining accounting records, analysis of financial results, internal audit requirements, receiving professional advice (e.g. tax or legal advice). |
|
|
Monitoring applications, reviewing, assessing, tailoring and improving our products and services and similar products and services offered by the QBE Group. |
|
|
Investigating or detecting the unauthorised use of our systems, to secure our system and to ensure the effective operation of our systems. |
|
|
Transferring or selling part of our business or re-organising our company structure. |
|
|
Who will we share your personal information with?
We will keep your personal information confidential and we will only share it where necessary for the purposes set out above with the following parties:
If you take out an insurance policy with us (e.g. a business interruption policy) or if you are listed as an applicant or beneficiary under a policy that someone else has with us (such as a named solicitor under a professional indemnity policy), this section will be relevant to you and sets out our uses of your personal information.
What personal information will we collect?
What sensitive personal information will we collect?
How will we collect your personal information?
We will collect information directly from you:
As well as obtaining information directly from you, we will collect information from:
What will we use your personal information for?
We may use your personal information for a number of different purposes. In each case, we must have a "legal ground" to do so. We will rely on the following “legal grounds”, when we process your "personal information":
When the information that we process is classed as “sensitive personal information", we must have an additional “legal ground". We will rely on the following legal grounds when we process your "sensitive personal information":
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
---|---|---|
To administer and manage the insurance policy. |
|
|
Handling and paying insurance claims |
|
|
Prevention and detection of and investigating and prosecuting fraud and sanctions checking. This might include sharing your personal information with third parties such as An Garda Siochana, and other insurance and financial services providers and insurance industry databases. |
|
|
Complying with our legal or regulatory obligations. |
|
|
Communicating with you and resolving any complaints that you might have. |
|
|
Providing improved quality, training and security (for example, with respect to recorded or monitored phone calls to our contact numbers). |
|
|
Managing our business operations such as maintaining accounting records, analysis of financial results, internal audit requirements, receiving professional advice (e.g. tax or legal advice). |
|
|
Monitoring applications, reviewing, assessing, tailoring and improving our products and services and similar products and services offered by the QBE Group. |
|
|
Tracing and recovering debt. |
|
|
Investigating or detecting the unauthorised use of our systems, to secure our system and to ensure the effective operation of our systems) |
|
|
To apply for and claim on our own insurance. |
|
|
Transferring or selling part of our business or re-organising our company structure. |
|
|
Who will we share your personal information with?
We will keep your personal information confidential and we will only share it where necessary for the purposes set out above with the following parties.
If you make a claim, or are intending to make a prospective claim, against a third party who has an insurance policy with us, this section will be relevant to you and sets out our uses of your personal information.
What personal information will we collect?
What sensitive personal information will we collect?
How will we collect your personal information?
As well as obtaining information directly from you, we may collect information from:
What will we use your personal information for?
We may use your personal information for a number of different purposes. In each case, we must have a "legal ground" to do so. We will rely on the following “legal grounds”, when we process your "personal information":
When the information that we process is classed as “sensitive personal information", we must have an additional “legal ground". We will rely on the following legal grounds when we process your "sensitive personal information":
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
---|---|---|
Handling and paying claims. |
|
|
Prevention and detection of and investigating and prosecuting fraud and sanctions checking. This might include sharing your personal information with third parties such as An Garda Siochana, and other insurance and financial services providers and insurance industry databases. |
|
|
Complying with our legal or regulatory obligations. |
|
|
Communicating with you and resolving any complaints that you might have. |
|
|
Providing improved quality, training and security (for example, with respect to recorded or monitored phone calls to our contact numbers). |
|
|
Managing our business operations such as maintaining accounting records, analysis of financial results, internal audit requirements, receiving professional advice (e.g. tax or legal advice). For business processes and activities including analysis, review, planning and business transaction. |
|
|
Tracing and recovering debt. |
|
|
To apply for and claim on our own insurance. |
|
|
Investigating or detecting the unauthorised use of our systems, to secure our systems and to ensure the effective operation of our systems). |
|
|
Transferring or selling part of our business or re-organising our company structure. |
|
|
Who will we share your personal information with?
We will keep your personal information confidential and we will only share it where necessary for the purposes set out above with the following parties.
If you are a witness to an incident or an individual who otherwise provides us with information in relation to an incident which is the subject of a claim, this section will be relevant to you and sets out our uses of your personal information.
What personal information will we collect?
What sensitive personal information will we collect?
We do not routinely process sensitive personal information of witnesses. However, we may do so if it is relevant to the incident that you have witnessed (for example, if you have a health condition which may affect your witness statement).
How will we collect your information?
As well as obtaining information directly from you, we will collect information from:
What will we use your personal information for?
We may use your personal information for a number of different purposes. In each case, we must have a "legal ground" to do so. We will rely on the following “legal grounds”, when we process your "personal information
When the information that we process is classed as “sensitive personal information", we must have an additional “legal ground". We will rely on the following legal grounds when we process your "sensitive personal information":
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
---|---|---|
Handling and paying claims. |
|
|
Managing our business operations such as maintaining accounting records, analysis of financial results, internal audit requirements, receiving professional advice (e.g. tax or legal advice). For business processes and activities including analysis, review, planning and business transactions. |
|
|
Complying with our legal or regulatory obligations. |
|
|
Prevention and detection of and investigating and fraud. This might include sharing your personal information with third parties such as An Garda Siochana and other insurance and financial services providers and insurance industry databases. |
|
|
Providing improved quality, training and security (for example, with respect to recorded or monitored phone calls to our contact numbers). |
|
|
Investigating or detecting the unauthorised use of our systems, to secure our system and to ensure the effective operation of our systems) |
|
|
Transferring or selling part of our business or re-organising our company structure. |
|
|
Who will we share your personal information with?
We will keep your personal information confidential and we will only share it where necessary for the purposes set out above with the following parties:
If you are a broker or sub-broker doing business with us, an appointed representative or other business partner such as a lawyer or claims handler, this section will be relevant to you and sets out our uses of your personal information.
What personal information will we collect?
What sensitive personal information will we collect?
How will we collect your information?
As well as obtaining information directly from you, we will collect information from:
What will we use your personal information for?
We may use your personal information for a number of different purposes. In each case, we must have a "legal ground" to do so. We will rely on the following “legal grounds”, when we process your "personal information":
When the information that we process is classed as “sensitive personal information", we must have an additional “legal ground". We will rely on the following legal grounds when we process your "sensitive personal information":
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
---|---|---|
Managing our business operations such as maintaining accounting records, analysis of financial results, internal audit requirements, receiving professional advice (e.g. tax or legal advice). For business processes and activities including analysis, review, planning and business transaction. |
|
|
To provide key business services such as policy and claims administration |
|
|
To build and maintain our business relationships |
|
|
To communicate with you and provide you with marketing communications. |
|
|
Complying with our legal or regulatory obligations. |
|
|
Providing improved quality, training and security (for example, with respect to recorded or monitored phone calls to our contact numbers). |
|
|
Communicating with you to manage and handle your queries. |
|
|
Investigating or detecting the unauthorised use of our systems, to secure our systems and to ensure the effective operation of our systems). |
|
|
Transferring or selling part of our business or re-organising our company structure. |
|
|
Who will we share your personal information with?
We will keep your personal information confidential and we will only share it where necessary for the purposes set out above with the following parties:
If you are a user of the QBE websites, this section will be relevant to you and sets out our uses of your personal information.
What personal information will we collect?
What sensitive personal information will we collect?
Information submitted through the claim reporting tool for motor incidents including:
How will we collect your personal information?
We will collect your information directly from our website.
What will we use your personal information for?
We may use your personal information for a number of different purposes. In each case, we must have a "legal ground" to do so. We will rely on the following “legal grounds”, when we process your "personal information":
Purpose for processing | Legal grounds for using your personal information | Legal grounds for using your sensitive personal information |
---|---|---|
To follow up on enquiries you make. |
|
|
To provide marketing information to you (including information about other products and services and undertaking customer surveys) in accordance with preferences you have expressed. |
|
|
Who will we share your personal information with?
We will keep your personal information confidential and we will only share it where necessary for the purposes set out above with our QBE Group companies.
We only send marketing communications to our business contacts such as brokers, sub-brokers, appointed representatives and other business partners. We will send marketing communications via post, email, telephone and social media.
You can opt-out of marketing communications at any time by contacting us using the details set out in section 11 below.
We will keep your personal information for as long as reasonably necessary to fulfil the purposes set out in section 3 above and to comply with our legal and regulatory obligations.
We have a detailed retention policy in place which governs how long we will hold different types of information for. The exact time period will depend on your relationship with us and the type of personal information we hold, for example:
If you would like further information regarding the periods for which your personal information will be stored, please contact us using the details set out in section 11.
Sometimes we (or third parties acting on our behalf) will transfer personal information that we collect about you to countries outside of the European Economic Area ("EEA").
Where a transfer occurs we will take steps to ensure that your personal information is protected. We will do this using a number of different methods including:
Depending on our relationship and your particular circumstances, we might transfer personal information anywhere in the world. A summary of our regular data transfers outside the EEA is set out below:
Country of transfer | Reason for the transfer | Method we use to protect your information |
---|---|---|
Australia | Reporting to our parent company | Standard Contractual Clauses |
Philippines | Some of our back-office functions are provided by our Group Shared Services Centre in the Philippines. | Standard Contractual Clauses |
USA | Our email system is provided through a hosted service with servers located in the USA. | Standard Contractual Clauses |
India | Some of our third party IT and technology suppliers provide some of their services from India. | Standard Contractual Clauses |
If you would like further information regarding our data transfers and the steps we take to safeguard your personal information, please contact us using the details set out in section 11.
We have a package of technical and organisational measures in place to protect your personal information which have been adopted to comply with the latest data protection requirements. The measures cover various aspects of data security including the following:
Our security measures are kept under periodic review and are regularly updated to reflect developments in technology and security and changes to our business. However, please be aware that there are inherent security risks in transmitting data, such as e-mails or via the Internet, because it is impossible to safeguard completely against unauthorised access by third parties.
Profiling is any form of automated processing of personal information to evaluate certain personal aspects. Insurance underwriting, and sometimes claims payment, is based on profiling as it assesses the event that you are seeking to insure and the likelihood of that event occurring.
We use profiling as part of:
We keep our profiling process under regular review and, in most cases, an individual will then make a decision based on the outcome of that profiling.
Automated decision making refers to a situation where a decision is taken using personal information that is processed solely by automatic means (i.e. using an algorithm or other computer software) rather than a decision that is made with some form of human involvement.
Automated decision making is widely used in the insurance industry to offer and administer insurance efficiently and accurately. Where an automated decision produces a legal or other similarly significant effect concerning you (for example, where your policy or claim is rejected), we will only carry out automated decision making:
In all other cases, we will ask for your consent in advance.
Please see section 9 for the rights that arise when we carry out automated decision making.
Under data protection law you have a number of rights in relation to the personal information that we hold about you which we set out below. These rights might not apply in every circumstance. You can exercise your rights by contacting us at any time using the details set out in section 11. We will not usually charge you in relation to a request.
Please note that although we take your rights seriously, there may be some circumstances where we cannot comply with your request such as where complying with it would mean that we couldn't comply with our own legal or regulatory obligations. In these instances we will let you know why we cannot comply with your request.
In some circumstances, complying with your request may result in your insurance policy being cancelled or your claim being discontinued. For example, if you request erasure of your personal information, we would not have the information required to pay your claim. We will inform you of this at the time you make a request.
You are entitled to a copy of the personal information we hold about you and certain details about how we use it.
We will usually provide your personal information to you in writing unless you request otherwise. Where your request has been made electronically (e.g. by email), a copy of your personal information will be provided to you by electronic means where possible.
We always take care to ensure that the information we hold about you is accurate and where necessary up to date. If you believe that there are any inaccuracies, discrepancies or gaps in the information we hold about you, you can contact us and ask us to update or amend it.
In certain circumstances, you are entitled to ask us to stop using your personal information, for example where you think that the personal information we hold about you may be inaccurate or where you think that we no longer need to use your personal information.
Where we rely on your consent in order to process your personal information, you have the right to withdraw such consent to further use of your personal information.
Please note that for some purposes, we need your consent in order to provide your policy or handle your claim. If you withdraw your consent, we may need to cancel your policy or we may be unable to pay your claim. We will advise you of this at the point you seek to withdraw your consent.
This is sometimes known as the 'right to be forgotten'. It entitles you, in certain circumstances, to request deletion of your personal information. For example, where we no longer need your personal information for the original purpose we collected it for or where you have exercised your right to withdrawn consent.
Whilst we will assess every request, there are other factors that will need to be taken into consideration. For example we may be unable to erase your information as you have requested because we have a legal or regulatory obligation to keep it.
In certain cases, you have the right to object to our processing. This arises in relation to:
Marketing: You have control over the extent to which we market to you and you have the right to request that we stop sending you marketing messages at any time. You can do this either by clicking on the "unsubscribe" button in any email that we send to you or by clicking the link in section 11. Please note that even if you exercise this right because you do not want to receive marketing messages, we may still send you service related communications where necessary.
Processing based on our justifiable purpose: Where we process your personal information on the basis of a justifiable purpose, you can object to such processing, unless our purpose outweighs any prejudice to your privacy rights.
In certain circumstances, you can request that we transfer personal information that you have provided to us directly to a third party.
Where an automated decision produces a legal or other similarly significant effect concerning you (for example, where your policy or claim is rejected), you have the right to ask us to reconsider a decision taken by automated means or to take a new decision on a different basis (e.g. by introducing some form of human involvement).
You have a right to complain to the Data Protection Commission (DPC) if you believe that we have breached data protection laws when using your personal information. You can visit the DPC's website at www.dataprotection.ie for more information. Please note that lodging a complaint will not affect any other legal rights or remedies that you have.
If you would like further information about any of the matters in this notice or if have any other questions about how we collect, store or use your personal information, you may contact our data protection officer by emailing dpo@uk.qbe.com or writing to:
The Data Protection Officer
QBE European Operations
30 Fenchurch Street
London EC3M 3BD
Unsubscribe from QBE Marketing Communications.
From time to time we may need to make changes to this notice, for example, as the result of changes to law, technologies, or other developments. We will provide you with the most up-to-date notice and you can check our website https://qbeeurope.com/privacy-policy/ periodically to view it.
This notice was last updated on 4th January 2021.