pi_circular Compliance & regulationInsurance & claims American P&I Club
A merican Club Circular No. 17/18 1 MAY 23, 2018 CIRCULAR NO. 17/18 TO MEMBERS OF THE ASSOCIATION Dear Member: IMPLEMENTATION OF GDPR PRINCIPLES IN CLAIMS HANDLING As advised in Circular No. 09/18 of February 23, 2018, the General Data Protection Regulation (GDPR or Regulation) provides for significant penalties in the event of a data breach. This Circular supplies Members, correspondents and others with further guidance on how to try and reduce the risk of a breach. It also contains news of some changes the Club will be making in how it handles personal data. Claims involving people, such as crew or passenger illness and injury matters, present the greatest challenge to the Club in ensuring the adequate protection of personal data. Data minimisation and privacy by design As mentioned in the Circular referred to above, the Club is a controller for the purposes of the GDPR, and thus responsible for demonstrating compliance with the Regulation. As a result, and in line with the key GDPR principles of data minimisation and privacy by design, the Club wishes to: • start limiting the amount of personal information in circulation; and • make greater use of existing technology to transfer personal data more securely; and • where possible, anonymise the data that is exchanged. E-mail circulation lists continue to expand. This means it can be difficult to spot when someone who should not be included has inserted themselves into an email chain. In addition, attempted fraud by e-mail is increasing, with communications received from impersonators of those involved in the industry. These imposters are usually seeking financial gain, but responding to such a message could lead to a data breach by the Club as well. In handling personal illness or injury files, it is often necessary to exchange sensitive personal data with Members, correspondents and service providers around the world on an urgent basis. Implementing GDPR principles is particularly important in this connection. Accordingly, the following “best practice” guidance in the form of ten tips for the treatment of personal data may be helpful: 1. Respect - Treat everyone’s personal data with the same respect you would wish for your own. 2. Minimise the generation of personal data by email and on paper – The less personal data being created and circulated, the easier it is to protect. Only send information which is necessary for the handling of the claim. A merican Club Circular No. 17/1 8 2 3. Cybersecurity – Ensure computer systems are secure and make use of security measures such as password protection and secure email servers when transferring attachments containing passports, medical reports, contracts of employment etc. Encryption or secure web portals should be used when appropriate to protect sensitive information. 4. Anonymisation – Aim to use identifiers for individuals, like crewmember, broker, surveyor etc. instead of names and dates of birth. Other identifiers could be the vessel name, the nature of the incident, or the port of disembarkation, with a reference number. This applies not just to the subject heading and body of an e-mail but also, where possible, to any documents which support the claim. If there is no alternative to using a name, it is recommended that it is cited with as few other identifiers as possible. It is also intended to adopt this approach for claim descriptions. If these steps are put into practice, it is hoped that, except for those directly handling the cl
Circular No. 17/18 - Implementation of GDPR Principles in Claims Handling
American P&I Club
Read full article at American P&I Club →
Opens American P&I Club in a new tab