Insurance

The industry files

An insurer's file moves through support organisations you never named and stays about six years by default, held as long as the insurer determines a need. The no-sale promise is pinned to a definition of selling that permits a lot of sharing.

The read at a glance

Tracking priority Recommended

Your medical history sits in an underwriting file for years.

If it leaks High

A leak exposes your health, your claims, and the risk scores drawn from them.

Expect it kept Years

Claims and underwriting files are kept for years for regulatory and fraud reasons.

Identity demanded ID documents

A policy requires identity and often health or driving history.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

If it leaks

A claims file can hold health details, and shared industry databases mean one leak reaches insurers you never applied to. A diagnosis or a refused claim on that record can shape what you are offered for years.

What repeats in the policies

How it moves

You're quoted on files you have never seen

Your file is built partly from records you never handed over: insurers commonly buy claims histories, credit data and, on motor cover, your driving record before they quote you. It moves both ways, because what happens next goes into shared industry databases other insurers consult. Cover bought for your work is assembled the same way, on your trade and your claims record rather than your car.

How long

Kept about six years, by default

Keeping your whole file for about six years after you leave is the norm, with reasons stacked so one always applies. The period is set by how long a claim could still be brought, so a file outlasts the cover it belongs to. On motor cover, driving data from your car and the quotes you asked for feed the models that set prices, by default rather than by consent.

The fine print

The no-sale promise is pinned to a definition

Insurers commonly say they neither sell nor share your information, then attach the statutes' own definitions to both words. Passing your file to vendors, affiliates, credit agencies and shared fraud databases sits outside the promise. One large insurer skips the hedge and publishes what it does sell: identifiers, browsing activity and employment details, for advertising.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileIdentity DocumentsFinancial Location · maybeHealth · maybeCriminal & Offence Records · maybe

Which of those a company actually holds is the one thing the cover decides: on life or health cover the underwriting file is a medical file, and on motor cover the question asked is your driving convictions.

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Health Highly likely

Health and medical history drive underwriting.

Money and net worth Likely

Assets and history set what you can insure.

What lawfully stays after you leave

Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.

Financial regulatory records Law sets it around 5 to 7 years

Financial regulators require advice, suitability, and transaction records.

Fraud-prevention markers They set it about 2 to 6 years

To flag suspected fraud, often on a shared industry database you cannot reach through the company.

Identity / anti-money-laundering records Law sets it about 5 years

Money-laundering rules require ID and transaction records after an account closes.

Tax and accounting records Law sets it about 6 years

Tax and company law makes them keep billing and payment records.

Records tied to a live or potential dispute They set it the limitation period of the claim

They can keep records to defend a live or possible legal claim.

Who wants this data

How you drive has a proven paid market. Carmakers sold driving records to risk-scoring firms, who packaged them into reports insurers used to set prices, until a regulator stopped it. Claims and application data flow into shared databases by design.

Sold or shared Possible

Risk data is shared across insurers and with brokers.

AI training Moderate

Claims and risk data train pricing and fraud models.

Even anonymised, this can still be you

Health-linked records re-identify the way the first study proved: a researcher matched a US governor's anonymous hospital record to him using postcode, date of birth, and sex (Sweeney, 2000).

Name, date of birth, postcode Typical

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces Sometimes

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns Typical

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.

The move An objection tells them to use your data to run the service and nothing more.

“we do not sell your personal information”

“we do not sell your personal information”

Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.

The move Use the do-not-sell switch where there is one, and put an objection in writing as well.

“service providers, partners, and affiliates”

“service providers, partners, and affiliates”

This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.

The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.

“aggregated or de-identified information”

“aggregated or de-identified information”

Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.

The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

“retained as long as necessary, or as required by law”

They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.

The move Which reasons apply to you, and how long each runs, is a request of its own.

“you grant us a licence to use your content”

“you grant us a licence to use your content”

This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.

The move Their terms say whether the licence ends when the account does. Close the account and log the date here.

“with insurance-support organizations that detect and prevent fraud”

“with insurance-support organizations that detect and prevent fraud”

Your claims and application details go into shared industry databases other insurers check. A flag there follows your quotes everywhere.

The move Those databases answer for your data too. Once a reply names them, the same requests work on them.

“persons or organizations that we have determined need the information to perform an insurance function”

“persons or organizations that we have determined need the information to perform an insurance function”

Your file can go to almost any vendor or organisation the insurer picks; an insurance function stretches across marketing, analytics and audit.

The move An access request asks who actually received your file, and you can ask for their names, not only the categories they fall into.

“we do not and will not sell or share your personal information, as those terms are defined under data protection laws”

“we do not and will not sell or share your personal information, as those terms are defined under data protection laws”

Both words are read as the statutes define them, not as you would. Disclosures to service providers, affiliates, credit reporting agencies and industry fraud databases carry on underneath the promise.

The move An access request asks which disclosures actually happened, whatever they are called.

Their own policy is the one that binds them. Pin it down with a request, and keep the reply.