Claim file anonymization for insurers and brokers
A claim file is a mixed folder —claim form, photographs, expert report, medical report, repair invoices— that leaves the company towards adjusters, repair shops, medical assessors, reinsurers and shared databases while the forty-day deadline of article 18 of the Spanish Insurance Contract Act is running. Spain’s insurance law (LOSSEAR, article 99) says exactly how much of that file may travel without consent: only what is strictly necessary, and health data for no purpose other than paying the benefit. anonimiza.do leaves each delivery with what its recipient needs, handles licence plates and the other Spanish identifiers, and records every operation.
Which documents the claims department handles
Every file gathers, in different formats and from several sources:
- Insurance application and prior questionnaire, with the health questionnaire in life, health, accident and funeral insurance that article 10 of the Insurance Contract Act requires collecting.
- Policy, particular conditions, endorsements and premium receipts, with IBAN, licence plate or risk address and a QR code on the receipt.
- Claim form and joint accident report, with both parties’ data and both licence plates, often handwritten.
- Loss adjuster reports —motor, home, retail, industrial, agricultural— with photographic report, estimates and repair invoices.
- Medical documentation: emergency and treatment reports, discharge, rehabilitation and bodily injury assessment reports, diagnostic tests.
- Police and traffic police reports, complaints and proceedings.
- Fraud investigation files: investigator reports, statements, digital trail with IP and email addresses.
- Complaints and litigation: complaints to customer service and the policyholder ombudsman, lawsuits, defences and court expert reports.
- At the broker: client file, letter of appointment, comparative analysis of offers and the claims history attached to request quotes.
When the file must be anonymized, and what the law says
Paying the indemnity, filing in court proceedings, reporting to the supervisor and anti-money-laundering obligations go with full data. The rest are uses that Spanish insurance law limits:
Sending to adjusters, repair shops, medical assessors and lawyers
Article 99.5 LOSSEAR treats anyone providing outsourced services to the insurer as a data processor, and each needs a different part of the file: the repair shop does not need the health questionnaire, the loss adjuster does not need the IBAN, the medical assessor does not need the licence plate or the premium. It is pure minimisation and the most everyday case.
Reinsurance and sharing between companies
Claims against the other party’s insurer, direct settlement agreements, co-insurance and, above all, reinsurance, where the file or its statistics leave the company and often the country. Article 99.4 allows communicating to the reinsurer without consent “the data that are strictly necessary”: the legal authorisation itself is written as a minimisation mandate, and outside the EU the safeguards of GDPR Chapter V apply.
Shared databases, pricing and anti-fraud models
Article 99.7 allows shared databases to settle claims, price and select risks, produce actuarial studies and prevent fraud, without prior consent but informing the data subject, and closes with: health data “may only be processed with the express consent of the data subject”. To take a claim with a medical component to a shared database, a study or the training of an anti-fraud model, either there is express consent or the file goes anonymized.
Audit, supervision and internal control
Auditors, actuaries, technical reserve reviews, reports to the supervisor and internal claims committees need the content of the files, not the identity of policyholders and injured parties.
The broker requesting quotes from the market
Presenting a risk and its claims history to several companies that have no relationship with the client yet leaves identified data in the hands of all but one. Article 99.9 requires cancelling within ten days the data of a contract that is not concluded, with express consent if it is health data. Requesting quotes with an anonymized history removes the problem at the root.
Training, case studies and test environments
Using real claims to train handlers and the sales network, in internal circulars, or loaded into the test environment when changing the claims system is a purpose other than the contract’s, and article 99.1 requires specific consent for it. Anonymize first.
What data appears and what is distinctive of the sector
The licence plate is this vertical’s own data type: it is on the claim form, the police report, the adjuster’s report, the repair invoice and inside the photographs.
- Identification of policyholder, insured, injured parties and witnesses: names, NIF or NIE, passport, risk address, phone, email, date of birth, IBAN and premium and indemnity amounts.
- Licence plates, often two per claim; and inside the photographic report, readable plates, signs and door numbers.
- In medical and sick-leave documentation: Social Security number, centre name, CSV code and barcode of the hospital label; and diagnosis, treatment and medical record number, which are special-category data and not among the 20 catalogue types: covered with a custom type in plain language.
- In police reports and complaints: names, licence plate, name of the acting force, the officer’s professional identifier and the breathalyser result, which is health data.
- In fraud files: IP and email addresses from the digital trail, plus names, licence plate and amounts.
- Policy, receipt, file and report numbers: not in the catalogue, but described as custom types. And the same person appears in a police report as driver, defendant, “Mr So-and-so” and “the vehicle owner”.
How to fit it into claims handling with forty days running
- A policy per line of business —motor, home, health, liability— approved by the DPO: what is anonymized, for which recipient and with which technique.
- One processing template per recipient: loss adjuster, repair shop, medical assessor, lawyer, reinsurer, shared database, training. Each leaves only what that recipient needs.
- The whole file as a batch: the claim folder is uploaded as a ZIP and the result returns to the claims system through the API, without the handler changing screens.
- Reversible pseudonymization for everything that must later be paid or claimed; irreversible anonymization with k-anonymity verification for the pricing history, shared databases and models.
- Review by unique value instead of going over the same name forty times in a long file.
- Log every transfer in the record of processing activities, and destroy or cancel on time: ten days for the unconcluded quote.
What anonimiza.do brings to an insurer or a broker
- Detects the 20 data types in the catalogue —including licence plate, IBAN, amounts, dates, NIF and NIE, passport, Social Security, CSV codes, barcodes and QR codes and IP addresses— and validates NIF, NIE, Social Security and IBAN by check digit.
- Custom data types described in plain language —policy, file and report numbers, diagnosis, medical record number— with no rules to program and nothing to train.
- Coreference and relationship and role identifiers: it recognises that “the usual driver”, “the insured’s brother” and “Mr So-and-so” are the same person throughout the file, and treats them consistently.
- ZIP batches for the claim folder, spreadsheets column by column for histories, OCR for scanned reports and invoices and for the readable text in photographs, and a REST API to integrate with the claims system.
- Two modes by use: reversible pseudonymization with stable tokenization for what must be paid or claimed later, and irreversible anonymization with k-anonymity verification for shared databases, actuarial studies and models.
- Removes file metadata before download and keeps an audit log of every document processed.
- Data always in the European Union (AWS Frankfurt), with optional deployment in the AWS Spain region; Spanish National Security Framework (ENS) MEDIUM category and a data processing agreement.
- Enterprise plan with unlimited volume, SSO/SAML, dedicated account manager and SLA; free plan of 3 documents a month to try it.
Try for free: 3 documents a month
Frequently asked questions
Does it handle the licence plates and other data that appear in the adjuster’s photographs?
Images and scanned PDFs go through OCR: the readable text in a photograph —licence plates, signs, door numbers, photographed documents— is detected like any other catalogue data. Whatever is not readable text is not detected automatically and is reviewed by hand.
If we anonymize the history for the shared database or to train the anti-fraud model, does it stop being personal data?
Only if the anonymization is irreversible and nobody can re-identify by combining licence plate, postcode and date: that is what k-anonymity verification is for. Pseudonymization is not enough, because GDPR article 4.5 keeps it within the regulation. And with health data, article 99.7 LOSSEAR leaves two paths: express consent or anonymization.
How do we plug it into the claims system without the handler changing screens?
Through the REST API and ZIP batches: the file folder goes in, is processed with the recipient’s template and returns to the system. With the forty-day deadline of article 18 of the Insurance Contract Act running, a tool that forces you to download, upload and reload never gets adopted.
If we anonymize the file, how do we pay the indemnity afterwards?
For everything that must be paid or claimed you use reversible pseudonymization: identifiers are replaced by stable tokens and reversal is done with a key and logged. Irreversible anonymization is reserved for the history, shared databases and models, where you never need to go back to the insured.
Do we have to anonymize what we file in court, report to the supervisor or process for anti-money laundering?
No. Court proceedings, reporting to the insurance supervisor and the obligations of Law 10/2010 have their own legal basis and go with full data. What gets anonymized is the secondary use that article 99 LOSSEAR limits: suppliers, reinsurance, shared databases, unconcluded quotes, training and testing.