Privacy Policy
How BinderGroup processes personal data
Home / Privacy Policy / Privacy Policy Norway
Collection and registration of personal data
We only collect information that is necessary for our operations, and we always process personal data in accordance with applicable legislation and guidelines. The specific data required depends on the purpose for which the information is used. At BinderGroup, we process the following categories of personal data:
- Contact and identification details
- National identification number
- Policy and underwriting information
- Claims information
- Payment information
- Health information
We use this information for risk assessment, quotation, underwriting, policy administration, claims handling and general customer communication.
We may also receive information from partners, insurance companies, brokers or relevant registers within the insurance industry if this is necessary for assessing the insurance relationship.
In connection with the administration of your insurance or a claim, it may be necessary to collect information regarding the following individuals:
- Policyholders, insured persons and co-insured persons
- Beneficiaries
- Next of kin
- Injured parties
- Counterparties
- Mortgage holders
- Advisors (bank/lawyer/accountant)
- Medical professionals (doctors, psychologists, physiotherapists etc.)
Categories of recipients
BinderGroup is subject to confidentiality obligations and will therefore only disclose your information where necessary and in accordance with applicable legislation. As BinderGroup operates as an insurance agency, personal data will naturally be shared with the insurer or insurers. The name of your insurer(s) can be found in your policy terms or insurance certificate.
We may also share personal data with IT providers, Lloyd’s brokers and syndicates, claims handlers, financial institutions, insurance brokers and relevant partners when necessary to administer insurance products and claims.
We may be required to disclose information to public authorities. We may also disclose standard customer information about you if this occurs for purely administrative purposes.
In certain cases, we disclose information about you with your consent where such consent has been provided for the specific purpose. If you have not provided consent, customer information will only be disclosed to others within the framework of financial services legislation and only where necessary to enter into or administer an agreement with you as a customer or to process your case.
Transfer of personal data to third countries
In cases where personal data is transferred to recipients outside the EU/EEA, such as insurance providers, partners or service providers with functions located in third countries, such transfers will only take place when necessary to administer and deliver our insurance products, including underwriting, policy administration and claims handling.
When personal data is transferred to third countries, we ensure that a valid and lawful transfer mechanism is in place in accordance with data protection legislation. This may include the use of the EU Standard Contractual Clauses (SCCs) or other appropriate safeguards designed to protect your personal data.
We also ensure that all recipients handle the data responsibly and in accordance with applicable requirements.
Withdrawal of consent
Where the processing of your personal data is based on your consent, you have the right to withdraw that consent. This means that we will no longer rely on your consent as a legal basis for processing going forward.
Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn. The withdrawal applies only to data processed on the basis of consent and does not apply to data processed on another legal basis.
You may withdraw your consent by sending an email to: DPO@bindergroup.dk
How long do we retain your data?
BinderGroup is required to delete personal data when it is no longer relevant. However, we will retain personal data for as long as the insurance policy remains in force.
BinderGroup’s data retention policies are based on relevant Norwegian regulations regarding accounting, insurance operations and statutory retention periods.
BinderGroup retains data relating to all current customers and stores data relating to potential and former customers for a minimum of five years. In claims cases, personal data is also stored for a minimum of five years. This is done in accordance with applicable Norwegian requirements for storage and archiving.
Data security
Your security is important to us. We therefore use a range of technical, organisational and physical measures to protect your personal data against unauthorised access, loss or alteration. Our security measures are continuously reviewed and updated in accordance with applicable legislation, including the General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.
Among other measures, we use the following:
Access management and authentication
- Multi-factor authentication (MFA) on all systems that process personal data
- Role-based access control (RBAC), ensuring that employees only have access to the data necessary for their role
Infrastructure security
- Virus scanning and endpoint protection on all servers and workstations
- Firewall protection and network segmentation
- Automatic patching and updates of software and operating systems
Physical security
- Access control to offices, server rooms and archives
- Alarm systems and monitoring of physical access points
Regular testing and evaluation
In accordance with GDPR article 32(1)(d), we conduct regular testing and evaluation of the effectiveness of our technical and organisational security measures, including:
- Periodic vulnerability scans and penetration testing
- Annual security audits and risk assessments
- Ongoing evaluation of security policies and procedures
Management of security incidents
We have established procedures for managing personal data breaches, including:
- Internal reporting and escalation of identified or suspected security incidents
- Notification to the data protection authority within 72 hours of becoming aware of a breach, in accordance with GDPR article 33
- Notification of affected individuals where a breach is likely to result in a high risk to their rights, in accordance with GDPR article 34
- Documentation of all security incidents, including cause, scope and remedial measures
Employee training and awareness
- Mandatory data security training for all employees upon employment
- Regular awareness training (at least annually), including phishing simulations
- Written policies and procedures for the handling and communication of personal data
- Documentation of completed training for all employees
- Confidentiality agreements signed by all employees with access to personal data
Processing by data processors
BinderGroup uses data processors for IT operations, software, security and storage. This means that your information may be processed by third parties on our behalf.
We enter into data processing agreements with all suppliers and ensure that they follow our instructions and comply with GDPR. All third parties and data processors that handle personal data on our behalf are subject to equivalent security measures through written data processing agreements in accordance with GDPR article 28.
We also carry out regular follow-ups to ensure that our data processors comply with the agreed security requirements.
Your rights
You may exercise your rights at any time, subject to certain statutory limitations.
- You have the right to access the information we process about you.
- You have the right to object to the collection and further processing of your data, including automated individual decision-making.
- You may also request that we correct or delete the information. However, we only delete your information if you are no longer a customer and once no claims can be made against us as a result of previous claims or insurance policies.
- You have the right to receive the data you have provided to us in a machine-readable format and to have the data transferred to another data controller (data portability).
- If you have given consent, you may always contact us to obtain information about the scope of that consent, and you may withdraw it at any time. We will then cease processing your data unless we can continue the processing on another legal basis.
Right to lodge a complaint
If you are dissatisfied with BinderGroup’s processing of your information, you may lodge a complaint with:
Datatilsynet
Adress: Trelastgata 3, 0191 Oslo
Phone: +47 22 39 69 00
Website: https://www.datatilsynet.no
Lloyd’s specific information
In relation to insurance agreements established in cooperation with Lloyd’s Insurance Company S.A. (Lloyd’s Europe), Lloyd’s Europe acts as an independent or joint data controller.
Please also refer to Lloyd’s Europe’s Privacy Notice and contact their Data Protection Officer if you have questions regarding Lloyd’s processing of customer data.
Data Protection Officer – Lloyd’s Insurance Company S.A
Bastion Tower, Place du Champ de Mars 5, 1050 Bruxelles, Belgium
Email: LloydsEurope.DataProtection@lloyds.com
DPO at BinderGroup
At BinderGroup, the following person acts as Data Protection Officer:
Claes Djurhuus, Head of Portfolio Management
Mail: DPO@bindergroup.dk
If you have questions regarding the processing of your personal data or wish to exercise one of your rights, you are welcome to contact us.
Changes and version information
We update this privacy policy when necessary and indicate the date of the latest update.
Last updated: 09.03.2026