pi_circular Compliance & regulation Britannia P&I
31 July 2018 Implementation of the General Data Protection Regulation (“GDPR” or “Regulations”) in claims handling The purpose of this circular is to provide Members, correspondents and others with further guidance on how to reduce the risk of a breach and inform you of some changes we will be making in how we handle personal data. People claims, such as those involving crew or passenger illness and injury, present the greatest challenge to Britannia in ensuring the adequate protection of personal data. Data minimisation and privacy by design Britannia is a controller of personal data for the purposes of the GDPR, and therefore responsible for demonstrating compliance with the Regulations. As a result, and in line with the key GDPR principles of data minimisation and privacy by design, Britannia wishes to: • limit the amount of personal information that is routinely circulated; • make greater use of existing technology to securely transfer personal data; and, • anonymise personal data, where this is possible. Email circulation lists continue to expand, which means it can be difficult to spot when someone who should not be included has inserted themselves into an email chain. In addition, attempted fraud by email is increasing, with communications received from impersonators of those involved in the industry. These imposters are usually seeking financial gain but responding to such a message could additionally lead to a data breach by Britannia. In handling personal illness or injury files it is often necessary to exchange sensitive personal data with Members, correspondents and service providers around the world on an urgent basis. This makes understanding and implementing GDPR principles of particular importance. Recognising that Members, brokers and external service providers such as correspondents, surveyors, and experts will generally be data controllers in their own right, we would like to offer readers some “best practice” guidance in the form of 10 tips for the treatment of personal data: 1. Respect - treat everyone’s personal data with the same respect you would wish for your own. 2. Minimise the transmission of personal data by email or recorded on paper – the less personal data being created and circulated, the easier it is to protect. Only send information which is necessary for the handling of the claim. 3. Cybersecurity – ensure computer systems are secure and make use of security measures such as password protection and secure email servers when transferring attachments containing passports, medical reports, contracts of employment etc. We use enforced encryption or web portals to protect information. 4. Anonymisation – aim to use identifiers for individuals, like crewmember, broker, surveyor etc. instead of names and dates of birth. Other identifiers could be the ship name, the nature of the incident, or the port of disembarkation, with a reference number. This applies not just to the subject heading and body of an email but also, where possible, to any documents which support the claim. If there is no alternative to using a name, we would recommend that it is cited with as few other identifiers as possible. In the future we will adopt this approach for our communications, including claim descriptions. Once these steps are put into practice, we hope that, except for those directly handling the claim, it will not be possible to identify the individual who is the subject matter of the claim. 5. Start afresh - if you cannot
Implementation of the General Data Protection Regulation GDPR in claims handling 31 07 2018
Britannia P&I
Read full article at Britannia P&I →
Opens Britannia P&I in a new tab