Responsible Data Management
The availability and proper use of personal data lies at the heart of the process to create and develop innovative insurance products, services and solutions that respond to the actual needs of our customers. The creation of shared value for Unipol and for the community in which Unipol operates assumes the existence of a transparent, balanced relationship between the parties: this is the only way to realise the great social and economic development opportunities connected to the analysis of data.
The commitment of the Unipol Group to protect and add value to the personal data are contained in the “Policy to protect and add value to personal data” approved by the Board of Directors with the aim of consolidating the trust that customers and all stakeholders have in the Group.
In line with these principles, the Group ensures a high level of transparency, control, and protection for customers with regard to the processing of personal data throughout the entire customer lifecycle. In particular, the Group ensures that:
• all processing of personal data is carried out exclusively on the basis of defined legal grounds which no processing activities are performed;
• customers are clearly and comprehensively informed about the nature of the data collected, which may include identification data, socio-economic information, insurance-related data, payment data, and, where relevant, special categories of data, strictly limited to what is necessary for service provision;
• the purposes of data processing are transparently communicated and clearly defined in the privacy notices; the Group does not process personal data for undisclosed purposes and, therefore, no customer data are used for secondary purposes; any additional uses beyond the core purposes of each Group company (e.g., statistical analysis, fraud prevention, marketing activities, or uses related to artificial intelligence systems) are always explicitly included and communicated to customers as primary purposes;
• personal data may be shared with third parties (such as service providers, Group companies, insurance partners, and competent authorities) exclusively for legitimate purposes and subject to appropriate safeguards;
• all complaints and requests from data subjects regarding the exercise of their rights are promptly addressed and carefully managed;
• the highest security standards are adopted to ensure the protection of personal data throughout the entire data lifecycle.
Through these commitments, the Group promotes a responsible data management model, fully compliant with applicable regulations and aimed at strengthening customer trust and stakeholder confidence.




