Security and regulatory law — transparently documented.
For insurers, in our assessment, AI recourse review is generally not an outsourcing arrangement under § 32 VAG. We disclose our technical and organizational measures (TOMs) and our regulatory classification here — the full documentation is available on request.
At a glance
The starting point
An external provider reviews claim files — three questions decide.
Regulatory law
Is commissioning recourse review an outsourcing arrangement within the meaning of § 32 VAG — and if so, with which obligations?
Data protection
Claim files sometimes contain special categories of personal data — their processing must be fully secured.
Control
The insurer should retain data sovereignty at all times — subject to instructions, documented and revocable.
Regulatory law
Why recourse review is generally not an outsourcing arrangement under § 32 VAG.
We have summarized our own legal opinion on whether commissioning the review of closed claim files for recourse potential constitutes an outsourcing arrangement subject to the outsourcing-control requirements of § 32 VAG. Four points support our assessment:
No connection to the original insurance business
Recourse pursuit only begins after the actual claims settlement is complete — it is subsequent to it, not directly related to the conduct of the insurance business. This already lacks the factual connection that § 32 VAG requires.
Legal advice is not outsourcing
Commissioning a legal service provider to enforce claims brings legal expertise into the insurance company — functionally an addition, not a handover of a core function. According to the prevailing commentary literature, this also applies to ongoing claim cases.
Volume does not change this
Even a large-scale, systematic review of closed claim files does not change this assessment. The insurer retains control at all times over the type, scope and content of the review within the scope of the mandate granted.
In the alternative: supervision-exempt in any case
Even under a different view assuming an outsourcing arrangement, a teleological interpretation would still classify it as a supervision-exempt activity: the AI review unlocks additional recourse potential, rather than creating risk for the insurer's financial and earnings position.
Note: This summary represents our own legal opinion and is not legal advice. We are happy to provide your legal and compliance department with the full, fully referenced assessment under an NDA.
Data protection & data security
Technical and organizational measures at a glance.
The overview below summarizes our binding TOM documentation under Art. 32 GDPR in abstracted form. We provide the full, signed version with all individual measures under an NDA.
All data processing takes place within the European Union, with a focus on Germany, the Netherlands and France. There is no processing in third countries and no dependency on non-European cloud providers.
Processing of personal data from claim files uses exclusively self-operated LLM resources. External providers such as ChatGPT or Gemini are excluded without exception; the data is also not used to train our own models.
Multi-tier authentication including two-factor authentication for case and claims handling, a tiered access-control concept, and state-of-the-art encryption. The platform has been penetration-tested by TÜV Rheinland i-sec GmbH with a positive result.
Data from recourse review is stored organizationally on a dedicated tenant, with its own access-control concept that ensures separate processing from other clients.
A complete backup and recovery system with daily backups, a tested disaster-recovery and business-continuity procedure, and a failover data center with a shortened ramp-up time.
Where the activity does not constitute the original review and enforcement of claims, processing takes place under a DPA pursuant to Art. 28 GDPR. Subprocessors used are based in the EU without exception and are likewise contractually bound to comply with data-protection requirements.
Frequently Asked Questions
What legal and compliance departments clarify beforehand.
In our legal assessment, generally not: recourse review is subsequent to the actual claims handling and is not directly related to the conduct of the insurance business. Even under a different view, the prevailing commentary literature would in any case classify it as a supervision-exempt activity. Details are set out in the "Regulatory law" section below.
No. The assessment summarized here is our own legal opinion and not legal advice for your organization. We recommend having your legal and compliance department cross-check it against your specific contractual arrangements — we are happy to provide the full, fully referenced assessment for that purpose.
Exclusively within the European Union, with a focus on Germany, the Netherlands and France. No processing takes place in third countries.
No. Recourse review uses exclusively self-operated LLM resources — providers such as ChatGPT or Gemini are excluded from the processing of personal data. The data never leaves the self-operated or leased servers at any point.
Yes. Where the activity does not constitute the original review and enforcement of claims, processing takes place under a DPA pursuant to Art. 28 GDPR — including with subprocessors used, all of which are based in the EU without exception.
Data is stored organizationally on a dedicated tenant, with its own access-control concept for processing separately from other clients.
Yes. We are happy to provide the full, signed overview of technical and organizational measures, as well as the detailed, fully referenced regulatory assessment, under an NDA.
Talk to us about your compliance requirements.
We provide the full TOM documentation and our regulatory assessment under an NDA.
Book a demo for insurers