The rules and principles which apply
A core principle of the UK GDPR is integrity and confidentiality. This requires personal data to be processed securely by protecting it against unauthorised or unlawful processing, accidental loss, destruction, or damage.
Article 32 UK GDPR specifically requires controllers and processors to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
These measures must consider:
- nature of the data
- sensitivity
- volume
- likelihood of harm
- severity of harm
This guidance is intended to provide firms with an overview of the organisational and technical measures commonly adopted to support compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and recognised information security good practice.
The guidance reflects generally accepted controls and practices that are commonly implemented within the UK general insurance sector. Every firm’s information systems, technology, infrastructure, risk profile, and regulatory obligations will differ. Firms are therefore responsible for assessing the suitability and proportionality of the measures they implement, taking account of their own business operations, the nature of the personal data they process. and the risks to the rights and freedoms of individuals.
Where a firm operates complex IT environments, cloud-based infrastructures, bespoke applications or is exposed to heightened cybersecurity risks, it should seek advice from appropriately qualified information security, cybersecurity, legal or technical professionals. Independent specialist advice should also be obtained where there is uncertainty regarding the adequacy of technical controls, incident response, penetration testing, system architecture, or compliance with applicable legal or regulatory requirements.
This guidance is not intended to constitute specialist information technology, cybersecurity, legal or professional advice, firms must undertake their own risk assessments and implement appropriate safeguards to ensure ongoing compliance with applicable legislation and regulatory expectations
How this may affect firms
Firms should establish clear senior management accountability for data security, including assigning oversight to an appropriate senior management function and ensuring effective Board oversight. Where suitably qualified IT staff manage data security day to day, they should report regularly to senior management on key risks and issues. This should be supported by appropriate compliance oversight and, where necessary, independent audit activity carried out by suitably qualified individuals.
A firm’s security controls should ensure:
- Confidentiality of information
- Integrity of information
- Availability of information
- Resilience against cyber threats
- Lawful processing of personal data
- Protection of customer trust
- Regulatory compliance
- Effective operational resilience
Given the operational importance of data security, our view is that it would be prudent that the governing body of the firm receive a periodic report on the adequacy of the firm’s organisational and technical measures and senior management should also periodically review management information on data security risks, breaches, and incidents. Documented evidence of governance decisions relating to data security arrangements should be retained. The governing body should decide the frequency of monitoring and reporting based on the firm’s data security risk profile.
Firms should maintain an Information Asset Register which identifies what data is held in the organisation and via what systems, as well as who has access to the data and the security measures in place. See Section K.6.1 for more information on information asset registers and it is prudent for firms to document their data security controls in an Information Security Policy.
Access Control
Access should follow the principle of least privilege which means that users, programs, or processes are granted only the minimum access necessary to perform their tasks, examples of access controls can include:
- unique user accounts;
- strong authentication;
- multi-factor authentication;
- role-based access control;
- privileged account management;
- segregation of duties;
- periodic access reviews; and
- immediate removal of access upon termination.
Shared accounts should be avoided where possible and passwords should be unique and sufficiently complex. It is vital that passwords are stored securely and never shared. This should be supported by password managers and protected using multi-factor authentication (MFA) for high‑risk environments where sensitive data is stored or where critical operations are performed, for example administrator accounts, on-line accounts, finance and banking, HR systems etc. MFA can also be triggered where a risk increases for example remote access, unusual location, device, or time of access.
Security Measures
- Devices should be protected through centrally managed antivirus, endpoint detection and response, automatic patching, disk encryption, screen locking, device management, approved software controls, and secure configuration. Personal devices should only be permitted under a documented Bring Your Own Device (BOYD) policy and enforced security measures such as remote wipe, and restricted software installation.
- Network security controls should include firewalls, secure Wi-Fi, network segmentation, intrusion detection, VPN access for remote working, DNS filtering, and secure remote administration.
- Encryption should be applied both at rest and in transit. At rest, this should include laptops, mobile devices, portable media, and servers containing personal data. In transit, appropriate measures include TLS encryption, encrypted email where appropriate, secure portals and VPN connections. Portable USB devices should normally be encrypted.
- Email security controls should include phishing protection, malware, and spam filtering, DMARC, SPF and DKIM, attachment scanning and secure methods for transferring sensitive documents. Staff should verify payment requests and bank detail changes independently.
- Physical security controls should include secure premises, visitor management, locked cabinets, a clean desk policy, secure disposal arrangements, CCTV where appropriate and restricted access to server rooms.
- Remote working controls should typically include encrypted laptops, secure home Wi-Fi, VPN, MFA, secure document disposal
The firm should maintain appropriate logging and monitoring arrangements, including authentication logs, administrator activity logs, security alerts, privileged account monitoring, endpoint monitoring, and network monitoring. Logs should be protected from alteration. Vulnerabilities should be managed by:
- maintaining an asset inventory,
- applying security patches promptly,
- undertaking vulnerability scanning,
- conducting penetration testing,
- removing unsupported software and
- monitoring vendor security alerts.
Critical vulnerabilities should be prioritised according to risk.
Firms should regularly review whether unnecessary or duplicate records or unused databases are held and that data is not retained for longer than needed. Retention schedules should be documented (see document XXXX for a sample record keeping policy), and records should be securely destroyed when no longer required. Deletion should include electronic records, backups where feasible paper and archived files.
Third Party Management
Before appointing processors, the firm should assess whether a supplier has data security measures which are suitable for the nature and scale of processing and contracts should include UK GDPR processor clauses.
Cloud providers should be able to demonstrate UK GDPR compliance, contractual security commitments, appropriate processor agreements, encryption, audit logging, backup, resilience, disaster recovery arrangements, and regular penetration testing. Security configurations should be reviewed regularly.
We provide more information on contracts, supplier risk and outsourcing in Section K.6.3..
Transfers outside the UK should only occur where appropriate safeguards exist, there are specific obligations for firms when transferring data outside the UK which are explained in Section K.6.4..
Artificial Intelligence
Many firms may now be using Artificial Intelligence (AI), and we provide more information of the compliant use of AI in Section K.7. Firms are reminded that personal data should not be entered into public AI systems.
Where the firm enters into specific arrangements with technology suppliers for bespoke AI solutions these suppliers should undergo thorough due diligence and data processing agreements should be put in place.
Traditional information security controls such as multi-factor authentication, encryption and endpoint protection remain essential when deploying Artificial Intelligence (AI). However, AI systems introduce new attack vectors that require additional technical and organisational controls. Given the increasing use of AI within financial services, organisations should consider implementing enhanced security controls that address risks unique to AI systems.
Examples of these risks include:
- Prompt leakage – when an AI system reveals information that wasn’t meant to be exposed or the malicious extraction of such data such as system prompts, hidden instructions, proprietary data it has access to. It can also occur where this is information is extracted through malicious interactions.
- Unauthorised disclosure – AI systems may inadvertently disclose confidential information through generated outputs
- Model manipulation – Models may be manipulated through malicious inputs, poisoned training data, or adversarial attacks.
- Preventing excessive access – AI platforms often aggregate significant volumes of data, increasing the potential impact of unauthorised access.
- Securing API’s – Application Programming Interfaces (APIs) are frequently targeted as entry points into AI systems.
Enhanced monitoring can include AI-specific Security Information and Event Management (SIEM) rules, behavioural analytics to detect abnormal prompt patterns, detection of prompt injection attempts, monitoring for excessive token consumption, alerts for repeated failed authentication attempts and continuous threat intelligence relating to AI-specific vulnerabilities.
For further information, the National Cyber Security Centre (NCSC) guidance on secure AI system development and deployment can be accessed here.
Governance Controls
Technical measures should be supported by governance arrangements including:
- An AI security standard approved by senior management.
- Mandatory security review before deploying new AI systems.
- AI supplier assurance and contractual security requirements.
- Independent internal audit of AI controls.
- Periodic AI risk assessments.
- Incident response playbooks specific to AI-related events.
- Regular Board reporting on AI risks and control effectiveness.
AI outputs should always be subject to human intervention either via specific staff review or via quality monitoring, testing and calibration (depending on the nature of the output). Firms must ensure that confidentiality obligations remain in place when using AI.
Operational Resilience
Backups should be automated, encrypted, tested regularly, geographically separated, protected against ransomware, and supported by documented recovery objectives. Recovery testing should occur at least annually.
Security measures are critical to a firm’s operational resilience, and a data security incident response plan should be included in a firm’s business continuity planning. Controls should support disaster recovery including for example alternative working arrangements, supplier resilience, cyber incident recovery, and ransomware response. These plans should be tested regularly. in preparing an incident response plan firms should consider:
- identification
- containment
- investigation
- recovery
- communications
- regulatory reporting
In the event that an incident does occur it should be documented and any significant incident should conclude with a structured review covering:
- What happened?
- Why it happened?
- What worked well?
- What failed?
- Were impact tolerances exceeded?
- Were customers harmed?
- Were communications effective?
This review should identify any improvements needed to fully resolve the incident and strengthen future resilience. Any remedial actions should be assigned ownership and timelines and monitored through to completion.
All suspected breaches should be reported immediately to the ICO, we cover data breaches in Section K.6.5... Firms are also reminded of their obligation to inform the regulator of significant operational incidents which pose a risk of intolerable levels of consumer harm or to the safety and soundness of the firm or stability of the market. More information on operational resilience can be found in Section A.12.
Continuous Improvement
Information security should be treated as an ongoing process rather than a one-time exercise. Firms can promote continual improvement through:
- periodic maturity assessments
- lessons learned from incidents
- evolving threat intelligence
- regulatory developments
- independent assurance
- internal audit findings
- staff feedback
- technological improvements
The effectiveness of organisational and technical measures should be reviewed whenever there is a material change to business operations, technology, suppliers, processing activities, or the external threat landscape.
A compliant security framework is achieved not through any single control but through a layered combination of governance, risk management, technical safeguards, staff awareness, supplier oversight, and continual monitoring. Compliance officers should ensure that controls remain proportionate to the risks faced by the organisation and are capable of demonstrating accountability under the UK GDPR while supporting good customer outcomes and operational resilience.
It is important that data protection training for staff not only focuses on the legal requirements of data protection but also extends to how data should be handled and secured. For example, providing cyber security training, how to detect phishing, cyber fraud and social engineering, the importance of protecting passwords and disposing of personal data securely and the appropriate use of AI training should be appropriate to role and refreshed regularly, typically annual refresher training is appropriate, however this may also be triggered by particular risks or events.
For further information, the National Cyber Security Centre provides extensive guidance on data security which can be accessed here.