The rules and principles which apply
Under the UK GDPR, data controllers must provide data subjects with certain information about their processing activities, including the existence of automated decision making and profiling (Articles 13 and 14, UK GDPR).
Article 4 UK GDPR defines profiling as any form of automated processing of personal data used to evaluate certain personal aspects relating to an individual in particular to analyse or predict aspects concerning that individual’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements. Organisations must ensure that profiling is lawful, fair, transparent, proportionate, accurate and explainable.
Article 22 UK GDPR provides additional protection where a decision is made solely by automated means, and the decision produces legal or similarly significant effects
Where Article 22 applies, individuals generally have the right not to be subject solely to automated decisions, to obtain human intervention, to express their views and to challenge the decision.
The cross-cutting obligation under the Consumer Duty also requires firms to act in good faith, which is characterised by honesty, and fair and open dealing with retail consumers (see PRIN 2A.2.2R).
How this may affect firms
Artificial intelligence is rapidly becoming embedded within the insurance sector offering significant opportunities to improve efficiency, customer experience, and business performance. However, the use of AI also introduces significant legal, regulatory, and ethical responsibilities. We cover the topic of AI in greater detail in Section XX. In this section we look at obligations under the UK GDPR relating to transparency and automated decisions and profiling.
Using AI does not create a new lawful basis, firms must identify an existing lawful basis under Article 6 UK GDPR, you can only carry out automated decision making where it is:
- necessary for the entry into or performance of a contract; or
- authorised by domestic law applicable to the controller; or
- based on the individual’s explicit consent.
Where special category data, for example health information, is processed and Article 9 condition must also apply. Please see Section K.3.1 For more information on lawful basis.
Customers should understand that AI is being used, why it is being used, what data is used, how decisions affect them, whether humans remain involved and how they can challenge decisions. Privacy notices should therefore include information about profiling and automated processing; however, you should also consider whether additional disclosure may be required in other sales documentation.
Transparency is one of the most scrutinised aspects of AI compliance and you must provide meaningful information about the logic involved in the decision-making process, as well as the significance and the envisaged consequences for the individual. You must provide this in as format which easy for the individual to understand.
Automated Processing
The Information Commissioner’s Office places particular emphasis on fairness. Fairness should be considered throughout the AI lifecycle. Senior managers should therefore be asking themselves:
- Could using this AI potentially disadvantage particular groups?
- Has bias been assessed or outputs regularly monitored?
- Is the data representative?
- Can decisions be explained?
- Is there meaning for human oversight?
Decisions has a broad meaning, relating to “a conclusion or outcome, reached after consideration or analysis” where the conclusion may impact actions taken or engage a person’s rights. Systems that just apply a rule already set by a human will not engage the ADM rules (e.g. to accept certain payment cards not others) whereas systems that evaluate information about a person and pass judgement (e.g. eligibility for an insurance product do.
Examples of automated processing include:
- estimating insurance risk,
- predicting likelihood of fraud,
- customer segmentation,
- identifying vulnerable customers,
- assessing likelihood of policy renewal,
- marketing propensity scoring.
Examples of where automated decision making may apply include refusing insurance, materially increasing premiums, declining claims, cancelling policies, refusing finance, or refusing employment.
Individuals generally have the right not to be subject solely to automated decisions which means that they have the right to obtain human intervention i.e. to ask for a human to review the outcome of the decision, to express their views i.e. provide further information which may impact the decision and to challenge the decision i.e. if they believe it is inaccurate, biased or unfair. If meaningful human interview takes place before the decision is finalised, Article 22 may not apply.
Human involvement must be genuine, not merely a rubber-stamping exercise and carried out by a person who is suitably trained and qualified to understand the system’s logic, outputs, limitations, and risks.
You must tell individuals about their rights in relation to automated decision making and put in place a process to deal with requests from customers to exercise their rights and ensure appropriate technical and organisational measures are place, so that you can correct inaccuracies and minimise the risk of errors.
AI systems are only as reliable as the data on which they are trained. Poor data quality can lead to unfair pricing, inappropriate fraud alerts, incorrect customer records, discriminatory outcomes, support customer experience. Regular validation is therefore essential use appropriate mathematical or statistical procedures carry out regular checks to make sure that your systems are working as intended
For more information on artificial intelligence, please see Section 7.3 which provides further information of fairness and transparency including the avoidance of bias and discrimination.
Profiling for marketing purposes
Profiling for marketing purposes may involve using information about a customer’s behaviour, preferences, interests, products or interactions to segment audiences, personalise communications, predict likely needs, or assess the likelihood of renewal or buying additional products.
Where this involves personal data, firms must identify an appropriate lawful basis, usually consent or legitimate interests depending on the activity, and ensure the processing is fair, transparent, proportionate and clearly explained in the privacy notice. Individuals must be told if their data is used for profiling, what data is used, the purpose of the profiling, and how they can object, including where profiling is used to support direct marketing. Particular care is needed where profiling could lead to unfair exclusion, inappropriate targeting, intrusive personalisation or inferences about vulnerability or special category data.
Firms should also consider the Privacy and Electronic Communications Regulations where electronic marketing is involved, as separate consent or soft opt-in rules may apply (see Section K.3.2 for more information on marketing and the PECR.
Aggregate data, such as overall campaign performance or product trends, may generally be used with lower privacy risk where it does not identify individuals and properly anonymised data falls outside UK GDPR; however, anonymisation must be robust and irreversible in practice. If individuals can be singled out, re-identified, or linked back to other information, the data should still be treated as personal data and handled accordingly.
Cookies
A cookie is a small text file downloaded onto a user’s device, such as a computer or smartphone, when they visit a website. Cookies allow the website to recognise the device and store information about the user’s preferences, settings or previous activity.
Cookies and similar technologies, including tracking pixels, tags, scripts, web storage and device fingerprinting, are primarily regulated by the Privacy and Electronic Communications Regulations (PECR). Firms must provide users with clear and comprehensive information about the technologies used, explain what they do and why they are used, and obtain valid consent before setting any non-essential cookies or similar technologies on a user’s device.
Consent must be freely given, specific, informed and unambiguous, and should involve a clear affirmative action. Pre-ticked boxes, implied consent, or designs which make it easier to accept cookies than reject them should be avoided. Users should be able to reject non-essential cookies as easily as they can accept them.
Strictly necessary cookies may be used without consent where they are essential to provide a service requested by the user, such as enabling security, remembering items in a basket or maintaining a logged-in session. These cookies should still be explained in a cookie notice. By contrast, analytics, advertising, social media, retargeting and preference-based tracking cookies will usually require consent unless a specific exemption applies, and should not be set until consent has been obtained.
Where cookies or similar technologies involve personal data, the UK GDPR will also apply. Firms must identify a lawful basis for any subsequent processing, explain the processing in their privacy notice, keep data to the minimum necessary, and ensure that any profiling, segmentation or online advertising activity is fair, transparent and proportionate.
Firms do not need to repeat the consent process every time the same person visits the website, provided valid consent has already been obtained. However, they should consider refreshing consent at appropriate intervals, particularly where devices may be shared, cookie use changes, or new technologies are introduced.
Cookie banners and preference centres should be regularly reviewed to ensure they accurately reflect the technologies in use, record user choices, allow consent to be withdrawn easily, and are supported by a maintained cookie audit.
It is also important to distinguish between PECR and data protection requirements. PECR applies to cookies and similar technologies regardless of whether the information collected is personal data. The wider requirements of the Data Protection Act 2018 and UK GDPR will not apply where cookie data is truly anonymous, but firms must be confident that individuals cannot be identified, singled out or re-identified from the data, including when it is combined with other information.
The ICO has published detailed guidance on cookies which can be accessed here.