Profiling and automated decision-making by the insurance company in the light of personal data protection

Main Article Content

Jovana Rajić Ćalić
Iva Tošić


Insurance companies collect  personal data of their customers on a daily basis in their regular business, they are profiling their users and often make decisions in an automated way. Profiling is usually used in the insurance industry as a means of undertaking actions like setting premiums, uncovering possible fraud and planning marketing campaigns. For these reasons, the adoption of the General Data Protection Regulation and Law on Personal Data Protection of Serbia has a great impact on the insurance companies business, taking into account that those acts introduce mandatory notification when collecting data from data subjects. Namely, these acts introduced the obligation to inform data subject of the existence of automated decision-making, including profiling, as well as the obligation to provide the data subject with meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing.

The authors strive to address the impact of the General Data Protection Regulation, and above all Article 22, on profiling and automated decision-making by insurance companies, which is a regular activity within their business. According to this article data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. For these reasons, the authors will analyze the impact of this provision on the business of insurance companies.

