CII publishes vulnerability guidance to help firms manage Consumer Duty and UK GDPR – The Intermediary
The guidance sets out how firms can handle vulnerability data in line with UK data protection requirements and the FCA’s Consumer Duty.
The Chartered Insurance Institute (CII) has published new guidance to help insurance and personal finance firms manage data linked to customers in vulnerable circumstances.
The guidance sets out how firms can handle vulnerability data in line with UK data protection requirements and the Financial Conduct Authority’s (FCA) Consumer Duty.
The launch event in London included a panel discussion with representatives from the FCA, ICO, MorganAsh, RB Compliance Consultancy, and the CII Group.
The guidance aims to clarify how firms can collect, store and use vulnerability information responsibly, supporting a more consistent and customer-centred approach across the sector.
It highlights three key purposes for processing vulnerability data: supporting customers and preventing harm, meeting reporting requirements, and improving products and services.
Matthew Hill, CEO at the CII, said: “Too often data protection is used as an excuse not to do the right thing.
“Our new guidance should give insurance professionals the confidence to make data work for better consumer outcomes.”
Robert Bell, coauthor of the guide and director at RB Compliance Consultancy, said: “We live in a world where health and support needs are increasingly openly discussed, as reflected in expanding regulatory expectations meaning firms have to be laser focused on supporting customers who find themselves in vulnerable circumstances.
“It is also important to use this data to amend the product design as part of the expectations of the Consumer Duty.
“However, none of this is possible without data and this is where many organisations believe they run into a barrier – UK GDPR.”
Bell added: “The CII identified this problem and the need to form a clear set of standards to guide firms through recording vulnerability data whilst maintaining compliance with UK GDPR.
“It has been a pleasure to be involved in creating this important guidance document which I hope proves useful for the industry.”
Andrew Gething, guidance co-author and managing director at MorganAsh, said: “The FCA and ICO have been absolutely clear that GDPR is not a barrier to processing customer vulnerability data.
“This excellent guidance from the CII marks significant progress in establishing clear standards for effective vulnerability data management.
“Importantly, it gives firms a practical roadmap to turn this clear declaration from the regulators into the tangible action both expect to see.”
Gething added: “To deliver on that expectation, firms need the right systems in place to manage vulnerability data safely, securely and consistently across the customer lifecycle.
“That means not only protecting sensitive information, but ensuring it can be accessed by the right people at the right time, shared appropriately across teams and the wider distribution chain, and used to evidence good outcomes.
“With Consumer Duty placing greater emphasis on monitoring, management information and demonstrable action, robust vulnerability data infrastructure is absolutely essential. Expert guidance such as this from the CII will help firms considerably in their data journey.”