Security and regulatory law — transparently documented.
For insurers, in our assessment, the review and assessment of claim files is generally not an outsourcing arrangement under § 32 VAG. We disclose our technical and organizational measures (TOMs) and our regulatory classification here — the full documentation is available on request.
At a glance
The starting point
An external provider reviews claim files — three questions decide.
Regulatory law
Is the review and assessment of claim files an outsourcing arrangement within the meaning of § 32 VAG — and if so, with which obligations?
Data protection
Claim files sometimes contain special categories of personal data — their processing must be fully secured.
Control
The insurer should retain data sovereignty at all times — subject to instructions, documented and revocable.
For demanding projects in a highly regulated environment, DEPLAW has no equal. The platform combines deep automation with the compliance rigor it needs — not a siloed tool, but a thoughtfully designed overall architecture.
Josephine Hillmann · Advisory Board, Jusperta GmbH
Regulatory law
DORA instead of VAIT: a new framework for ICT third-party providers.
Our clients are overwhelmingly insurance companies supervised by BaFin. Until January 2025, the review of external IT providers was guided by BaFin's circulars on IT supervisory requirements — known as VAIT for insurance undertakings. With Regulation (EU) 2022/2554 (DORA, the Digital Operational Resilience Act) becoming directly applicable on 17 January 2025, BaFin repealed its VAIT circulars with effect from 16 January 2025. Reviews of DEPLAW as an ICT third-party provider have since been based on Art. 28 to 30 DORA. We align our evidence practice accordingly:
- Minimum contractual content
- The contractual content required under Art. 30 DORA — service description, location of data processing, information and audit rights among others — is part of our data processing agreement.
- Information and audit rights
- Insurers and their competent supervisor receive the information and audit rights against LDT as an ICT third-party provider that DORA provides for.
- Exit scenarios
- Exit and transition scenarios are documented for critical services, as DORA requires for ICT third-party service contracts.
- TOM documentation under Art. 32 GDPR
- Our binding overview of technical and organizational measures is available to your legal and compliance department under NDA.
- Data protection impact assessment for AI processing
- A data protection impact assessment under Art. 35 GDPR is on file for the AI-assisted success-prospect and recourse review, maintained alongside our record of processing activities under Art. 30 GDPR.
§ 32 VAG
Why the review and assessment of claim files is, as a rule, not outsourcing.
We hold a clear legal opinion on whether commissioning the review and assessment of claim files — whether as part of success-prospect or recourse review — constitutes an outsourcing arrangement subject to the outsourcing-control requirements of § 32 VAG. Four points support our assessment:
No connection to the original insurance business
The review and assessment of claim files only begins after the actual claims settlement is complete — it is subsequent to it, not directly related to the conduct of the insurance business. This already lacks the factual connection that § 32 VAG requires.
Legal advice is not outsourcing
Commissioning a legal service provider to enforce claims brings legal expertise into the insurance company — functionally an addition, not a handover of a core function. According to the prevailing commentary literature, this also applies to ongoing claim cases.
Volume does not change this
Even a large-scale, systematic review of closed claim files does not change this assessment. The insurer retains control at all times over the type, scope and content of the review within the scope of the mandate granted.
In the alternative: supervision-exempt in any case
Even under a different view assuming an outsourcing arrangement, a teleological interpretation would still classify it as a supervision-exempt activity: the AI-assisted review unlocks additional claim and recourse potential, rather than creating risk for the insurer's financial and earnings position.
Well-founded, not arbitrary: This assessment rests on prevailing commentary literature and our own contractual arrangements — it does not replace legal advice tailored to your organization. We are happy to provide your legal and compliance department with the full, fully referenced analysis under an NDA.
Data protection & data security
Technical and organizational measures at a glance.
The overview below summarizes our binding TOM documentation under Art. 32 GDPR in abstracted form. We provide the full, signed version with all individual measures under an NDA.
All data processing takes place within the European Union, with a focus on Germany, the Netherlands and France. There is no processing in third countries and no dependency on non-European cloud providers.
Processing of personal data from claim files uses exclusively self-operated LLM resources. External providers such as ChatGPT or Gemini are excluded without exception; the data is also not used to train our own models.
Multi-tier authentication including two-factor authentication for case and claims handling, a tiered access-control concept, and state-of-the-art encryption. The platform has been penetration-tested by TÜV Rheinland i-sec GmbH with a positive result.
Data from claim-file review is stored organizationally on a dedicated tenant, with its own access-control concept that ensures separate processing from other clients.
A complete backup and recovery system with daily backups, a tested disaster-recovery and business-continuity procedure, and a failover data center with a shortened ramp-up time.
Where the activity does not constitute the original review and enforcement of claims, processing takes place under a DPA pursuant to Art. 28 GDPR. Subprocessors used are based in the EU without exception and are likewise contractually bound to comply with data-protection requirements.
A named information security officer is responsible for our information security management system, aligned with ISO/IEC 27001:2022 — with documented risk management and an annual management review by our leadership.
All employees are bound to confidentiality and complete recurring information security and data protection training with a pass/fail check. Suppliers undergo a security and privacy review before being engaged and are bound contractually.
New business partners, suppliers and clients are screened against the consolidated EU and UN sanctions lists before any contract is signed. A zero-tolerance policy on corruption and an anonymous reporting channel for violations round out our compliance organization.
Frequently Asked Questions
What legal and compliance departments clarify beforehand.
In our legal assessment, generally not: it is subsequent to the actual claims handling and is not directly related to the conduct of the insurance business. Even under a different view, the prevailing commentary literature would in any case classify it as a supervision-exempt activity. Details are set out in the "Regulatory law" section below.
This assessment is our well-founded legal opinion, grounded in prevailing commentary literature — like any legal assessment, it does not replace legal advice tailored to your organization in an individual case. We are happy to cross-check it together with your legal and compliance department against your specific contractual arrangements, and to provide the full, fully referenced analysis for that purpose.
Exclusively within the European Union, with a focus on Germany, the Netherlands and France. No processing takes place in third countries.
No. The review and assessment of claim files uses exclusively self-operated LLM resources — providers such as ChatGPT or Gemini are excluded from the processing of personal data. The data never leaves the self-operated or leased servers at any point.
Yes. Where the activity does not constitute the original review and enforcement of claims, processing takes place under a DPA pursuant to Art. 28 GDPR — including with subprocessors used, all of which are based in the EU without exception.
Data is stored organizationally on a dedicated tenant, with its own access-control concept for processing separately from other clients.
Yes. We are happy to provide the full, signed overview of technical and organizational measures, as well as the detailed, fully referenced regulatory assessment, under an NDA.
With Regulation (EU) 2022/2554 (DORA) becoming directly applicable on 17 January 2025, BaFin repealed its circulars on IT supervisory requirements — VAIT, for insurance undertakings — with effect from 16 January 2025. Reviews of DEPLAW as an ICT third-party provider have since been based on Art. 28 to 30 DORA, together with the outsourcing requirements of § 32 VAG, which remain in force.
Yes. We provide the evidence customary for onboarding and risk reviews — TOM documentation, the record of processing activities, hosting infrastructure certificates and penetration test reports — and answer security questionnaires through one fixed point of contact.
Exit and transition scenarios are documented for critical services, as Art. 28 DORA requires for contracts with ICT third-party providers — your data sovereignty remains intact throughout.
Talk to us about your compliance requirements.
We provide the full TOM documentation and our regulatory assessment under an NDA.
Book a demo for insurers