Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Fintech & financial services

Privacy & Security for Insurtech Companies

Insurtech companies answer to two audiences that rarely move on the same clock: the carrier whose OSFI B-10 vendor review decides whether a pilot ever launches, and the privacy regulators watching how quote funnels, telematics feeds and underwriting models handle personal information. Privacy Horizon builds the security leadership, privacy accountability and audit-ready evidence a digital MGA, embedded-insurance platform or claims-automation vendor needs before either audience says no.

Reviewed by the Privacy Horizon team · Last reviewed

Who this is for

Digital MGAs and embedded-insurance platforms selling or advising on coverage, where provincial licensing (RIBO, FSRA, the AMF) and CCIR/CISRO Fair Treatment of Customers guidance reach the business directly rather than through a carrier contract alone.

Claims-automation, underwriting-AI and comparison-site vendors that hold no distribution licence at all. OSFI never regulates you directly — your carrier client's B-10 third-party due diligence does, through a security schedule you must satisfy before the first policy binds.

Québec-facing insurtechs running a French quote funnel or distributing without a representative under the Regulation respecting alternative distribution methods, where Law 25's privacy-officer, PIA and automated-decision duties stack on top of the distribution rules.

Venture-backed teams between Series A and a national carrier rollout, where one OSFI-flavoured questionnaire, one AMF filing or one AI underwriting launch can stall a partnership that took a year to negotiate.

Office, night and businessman with computer for research, online information and solution for startup. Screen, male employee or digital marketing specialist with laptop for seo, ke

Services

Privacy & security services for insurtech companies

Each service below is scoped for how insurtech companies actually operate — their systems, their regulators and the reviews they face.

What you hold

What a digital MGA or claims-AI vendor actually has to protect

Insurtech data sets look like nothing a generic SaaS business carries, and mishandling any one of them can end a carrier relationship outright.

Quote-flow personal information

Addresses, driver's licences, VINs and claims history get collected the moment someone starts a quote, often before a policy exists or a consent conversation has happened.

Telematics and UBI driving data

Continuous location and driving-behaviour feeds from usage-based insurance programs are sensitive by nature, and the retention and sharing terms attached to them get read closely by regulators and carrier partners alike.

Claims files with photos and injury detail

FNOL intake and claims-automation pipelines gather images, medical detail and financial loss information that goes well beyond an ordinary customer record.

Accelerated-underwriting medical and lifestyle answers

Life insurtechs collecting health questionnaires outside a full paramedical exam hold data as sensitive as anything a clinic keeps, scored by a model instead of an underwriter.

Bordereaux and carrier data-sharing feeds

The batch files exchanged with carrier partners over managed file transfer carry policyholder detail at volume, and that channel is a known target in its own right.

Underwriting and claims model inputs and outputs

What a model scores on, and the decision it produces, remain personal information subject to the same accountability as a manual file, with far less visibility into how the outcome was reached.

Regulatory map

The regulatory stack an insurtech answers to at once

No neighbouring fintech carries this exact combination: distribution licensing where you sell, carrier oversight where you don't sell at all, and AI-specific guidance layered over both.

Provincial licensing where you distribute or advise

RIBO for Ontario P&C brokering, FSRA for life agencies and the incoming Ontario life & health MGA licence class, and the AMF in Québec apply the moment a platform sells or advises rather than merely routing a quote to a licensed party.

Primary source →

Québec's alternative-distribution regime

Selling insurance online without a representative in Québec falls under Distribution Without a Representative, with disclosures and conditions set by the Distribution Act, the Insurers Act and the Regulation respecting alternative distribution methods.

Primary source →

OSFI B-10 flowing down from carrier clients

A pure technology vendor is not a FRFI and OSFI does not license it, but a carrier client's B-10 third-party risk management obligations turn the vendor's security posture into a documented, monitored condition of the contract.

Primary source →

CCIR/CISRO Fair Treatment of Customers guidance

FTC guidance reaches intermediaries and outsourced functions and names protection of personal information as one of its outcomes, so a carrier's oversight of an insurtech is partly a consumer-protection exercise, not only a security one.

Primary source →

PIPEDA, Law 25 and Alberta PIPA

PIPEDA governs commercial handling of quote and policy data everywhere in Canada; Québec's Law 25 adds a designated privacy officer, PIAs before new systems launch and section 12.1 disclosure for automated decisions such as instant-quote declines; Alberta PIPA carries its own mandatory-reporting duty.

Read our guide →

AI-specific guidance from privacy regulators and OSFI

The OPC and provincial commissioners' joint principles for generative AI, and the OSFI-FCAC risk report, both single out underwriting and claims management among the AI use cases carrying data, model and third-party risk.

Primary source →

What goes wrong

Where insurtech incidents actually start

The pattern in this sector rarely resembles generic ransomware. It follows how insurtechs concentrate carrier trust, money-adjacent data and machine decisions inside one small team.

  • Third-party concentration risk

    The OSFI-FCAC report treats the July 2024 global IT outage as the concentration-risk exemplar for the financial sector, and an insurtech is precisely the kind of third party a carrier is now expected to assess for that failure mode.

    Source →

  • File-transfer and vendor compromise

    The 2023 MOVEit campaign, which reached roughly 100,000 Nova Scotians through a single government deployment, mirrors the exposure carrier–vendor bordereaux exchange creates whenever the transfer tool itself is the weak point.

    Source →

  • Quote-flow data leakage and scraping

    A public quote API that returns enriched personal data invites enumeration, and Equifax's Canadian finding shows how bureau-linked flows go wrong on safeguards, retention and cross-border consent.

    Source →

  • Insider misuse of policyholder books

    Desjardins, where insurance-adjacent data on roughly 9.7 million people was monetized through an advisor network, is the OPC and CAI reference case for what an insider with broad book access can do unchecked.

    Source →

  • Automated-decision complaints

    A declined applicant invoking Law 25's section 12.1 explanation rights against a black-box underwriting model turns a quiet engineering decision into a documented regulatory exchange.

  • Broker-channel email compromise

    Compromised mailboxes upstream or downstream of the platform are a recurring cause in Alberta's breach reporting, and an insurtech sitting between brokers and carriers inherits that exposure from both directions.

    Source →

When organisations call us

The moments that bring insurtechs to Privacy Horizon

Engagements start at a specific event on the calendar, not from abstract risk appetite.

  • A carrier opens B-10 due diligence

    The moment a national or regional carrier proposes a partnership, its risk or procurement team sends a third-party security schedule built on OSFI B-10 expectations, and the pilot stalls until someone credible answers it.

  • An AMF filing is due for a Québec launch

    Selling or distributing insurance to Québec residents without a representative triggers the alternative-distribution filing, and the disclosures and safeguards it requires need to exist before the French quote funnel goes live, not after.

  • An underwriting or claims model moves to production

    Straight-through processing, accelerated underwriting or an FNOL triage model leaving pilot for production is the point where data, model and third-party risks stop being theoretical.

  • SOC 2 becomes a procurement condition

    A carrier or enterprise partner names SOC 2 Type II as a contract condition, turning a roadmap item into a deadline with a named auditor attached.

  • A cyber-insurance or E&O renewal is coming up

    Insurers underwriting insurtechs ask increasingly detailed questions about the applicant's own posture, and a thin renewal application is its own kind of exposure.

  • Series A or B diligence opens the data room

    Investor technical diligence increasingly includes a privacy and security review, and gaps found there get negotiated into the term sheet if they aren't closed first.

Insurtech Companies: privacy & security questions, answered

Not directly, in most cases — RIBO, FSRA and the AMF licence and supervise distributors and advisors, not the software underneath them. But your carrier client is a federally or provincially regulated insurer, and its OSFI B-10 third-party risk management obligations require it to assess and monitor you contractually. In practice you end up answering the same expectations a licensee would face, delivered through a security schedule instead of a licence application.

Fewer than the full list, usually. Most early-stage insurtechs start with a vCISO or VPO to own the security schedule and privacy answers, a policy set that closes the obvious carrier gaps, and a penetration test if the quote API is already live. SOC 2, ISO 27001 and a formal AI-PIA tend to arrive once a specific carrier, reinsurer or model launch demands them. We scope from the pilot you're actually negotiating, not a generic checklist.

Yes. The OPC and provincial commissioners' joint AI principles and the OSFI-FCAC risk report both focus on how a model is used and what data feeds it, not who wrote the code. If your platform sends applicant or claims data into a third-party underwriting or claims model and acts on its output, you carry accountability for that use, including the transparency Law 25 requires when a decision is made exclusively by automated means.

Often, yes. Institutional investors increasingly run a privacy and security review alongside legal and financial diligence, and findings can turn into term-sheet conditions or post-closing covenants. Insurtechs that get ahead of it, an accountable privacy or security lead, current policies, a documented view of where data lives, tend to close diligence faster and negotiate from a stronger position.

A questionnaire answered once is a snapshot; carrier oversight is ongoing. B-10-style relationships expect monitoring, incident notification capable of feeding the carrier's own 24-hour OSFI or AMF clock, and periodic re-assessment, not a single form. The gap usually surfaces at renewal, at a second carrier's onboarding, or the first time an incident tests whether the program behind the answers actually exists.

Hosting on a policy administration platform or carrier-provided infrastructure narrows the job; it doesn't remove it. You still control application logic, API access, staff accounts, integrations and how personal information moves in and out of that environment, and carriers and auditors will ask about exactly those layers. Shared infrastructure changes the scope of a security or SOC 2 review; it rarely changes whether one is needed.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.