Nullifying Data Vulnerability In One’s Asset Management
CIOREVIEW >> Digital Asset Management >> NEWS

Allianz

Dr Philipp Raether, Group Chief Privacy Officer

Nullifying Data Vulnerability In One’s Asset Management

Dr Philipp Raether, Group Chief Privacy Officer
Dr Philipp Raether, Group Chief Privacy Officer,Allianz

The EU General Data Protection Regulation (“GDPR”) just had its 4th anniversary. Can you give us some insight how the GDPR has influenced the processing of personal data by Allianz?

Allianz is a global insurance and asset manager and we have over 120 million customers and of course many of them are individual customers. We are active in more than 60 countries and have a 150,000 employees. Our data privacy footprint is large. And with the ongoing digitalization of the business, you know its very important that our customers, also our employees trust us in what we are doing with their data. And as we have seen in the last years, technology always evolved. Data give us a lot of opportunities to improve services but at the same time risks have increased. In that sense we really welcomed GDPR which assists in protecting personal data. We had to implement GDPR by 2018, it was a big project for Allianz. We have now tools just to record which personal data we use where and it is important that we make the use very transparent to our customers and employees. We also make sure that the data is used in a legal way. We do this by performing Privacy Impact Assessments with a tool.

Can technology also assist in finding privacy frienfly solutions?

Technology is really enabling privacy friendly solutions: I will give you one example: data encryption. As you know, there are more and more data localization laws which restrict the sharing of personal data cross border. For example we sometimes have a hard time sharing personal data with US service providers as according to European regulators the US has not have an adequate data protection level. Encryption of data is often assisting us in mitigating the risks as the recipients cannot read the data and the risks are adequately mitigated.

"We live in an unpredictable world. Thus, there are legitimate reasons to prepare one for unannounced curveballs"

What are other regulatory requirements in data privacy relevant for companies like Allianz around the world?

Many countries have followed the example of GDPR and have enacted data protection laws, like Brazil California and China, only to mention a few. It is really key for us to really comply with these. But also in countries which do not have data privacy laws, we follow an internal Allianz standard and follow these rules to protect the data.

And we are looking at the very future, maybe 12-18 months down the line, do you particularly consider any development within the industry as promising or even noteworthy for that matter?. Any piece of technology or innovation that you are likely fascinated by that you could recommend to some of our readers?

There are two interesting initiatives by the European Union. The first one is to strengthen the data sharing economy. The EU is drafting laws which will facility the exchange of personal data between companies but also between the state and governments. In the future, for example, it will become for insurers easier to obtain data from car manufacturers about how cars are driven. This will obviously only happen with the consent of the driver but will better assist us assessing the relevant insurance risks.

The second one is about regulating Artificial Intelligence (AI). The EU is also drafting an AI Act. AI has many opportunities to make processes quicker and more efficient. However, when AI is working which some biases (because it was trained with data which contained biases) we have to make sure that we discover and eliminate them. At the same time – and this is part of the EU proposal – we will have to be transparent where and how AI is used. Lastly, in cases of automated decision making we will have to give the attected individual the chance to have the AI decision to be revised by a human. However, at the end of the day it is important that we are not overregulating AI as this is a great opportunity for our economy and society.

And finally before we conclude this conversation, one last thing that I wanted to ask you. As a follow up to this response is there any piece of advice you want to give to some of the newer aspirants within the GDPR space? Of course an industry that has just seen various headline changes over the last decade, is there any piece of advice that you would like to give to anyone who is looking to make a career as well recognized as yours?

Data privacy is a fascinating space and I encourage people to choose that career. Also organizations should take data privacy really seriously and do not see it as a red tape. We have the principles of privacy by design and privacy by default to really help the businesses to have privacy be implemented as a DNA in their products and services. At the end of the day privacy can really be an enabler and create additional trust of customers, employees and the society at large.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.