The protection of natural persons with regard to the processing of personal data is a fundamental right, as enshrined in the Charter of Fundamental Rights of the European Union. Due to the diversity of their activities, Groupama Insurance EAD and Groupama Life Insurance EAD process various types of personal data for a wide range of purposes. In the context of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter "GDPR"), each of the companies acts as a Data Controller with respect to its activities. Recognizing the importance of personal data protection, Groupama Insurance EAD and Groupama Life Insurance EAD strive to ensure compliance with the fundamental rights and freedoms of all data subjects, whether they are clients, users of insurance services, employees, representatives, or contact persons for partners and service providers. We take all necessary technical and organizational measures to protect your privacy, in accordance with the high standards and principles to which the Groupama Group adheres.
The management of each of the companies "Groupama Insurance" AD and "Groupama Life Insurance" EAD appoints the Head of the Risk Management function and the Compliance function of the companies as the Data Protection Officer (DPO) of the company. The appointment is based on professional abilities, and specifically on specialized knowledge in the field of data protection legislation and practice, as well as on achieved results for goal fulfillment. The Data Protection Officer reports to the highest level of company management. The DPO's duties, as outlined in the GDPR, are as follows: - The DPO coordinates the processing of requests related to the exercise of data subjects' rights (access, objections, complaints, etc.), being informed upon receipt of requests and how they are processed, and ensures compliance with response deadlines. For this purpose, the DPO's contact details are available to everyone.
As a Group company, each of Groupama Insurance AD and Groupama Life Insurance EAD implements organizational and technical measures to ensure and be able to demonstrate that data processing is carried out in accordance with personal data protection regulations at all times. These measures must be reviewed and updated when necessary. Each of Groupama Insurance AD and Groupama Life Insurance EAD introduces a policy and procedures as part of these measures and therefore has at least the following documents available: Internal Personal Data Management Policy of Groupama Insurance AD and Groupama Life Insurance EAD (a local version of this group policy), approved by the DPO and the Executive Director. This policy should be updated whenever necessary, and by default every three years. Internal Information Systems Security Policy (ISSP).
Validity of the Data Protection Policy of Groupama Insurance JSC and Groupama Life Insurance EAD
Approval
The Data Protection Policy of Groupama Insurance JSC and Groupama Life Insurance EAD is approved by the Executive Director after consultation with the Board of Directors.
Updates
The Data Protection Policy of Groupama Insurance JSC and Groupama Life Insurance EAD is reviewed by the approving bodies when a significant update occurs as a result of:
Internal events, including changes in the areas of activity of Groupama Insurance JSC and Groupama Life Insurance EAD or significant changes in their organization;
Regulatory or legislative changes that need to be incorporated;
By default, the Policy must be reviewed every three years.
Changes and additions to these Rules may be made in accordance with the procedure for their adoption.