Protecting your privacy is very important to us. The purpose of this Privacy Notice is to set out what data we collect, how we collect it, why we process it, who we may share it with and, where the data we collect is personal data, what your rights are with respect to such personal data.
Who we are
The privacy and security of your personal information and data is important to us. We are Resolution Re Ltd. of Wessex House, Second Floor, 45 Reid Street, Hamilton HM11, Bermuda (Resolution Re or the Company) and we are part of the Resolution Life group of companies (Resolution Life). Resolution Life is a global life insurance group focusing on the acquisition and management of portfolios of life insurance policies. Resolution Re, Resolution Life’s Bermuda-based licensed reinsurance business, is a Bermuda exempted limited company regulated and authorised by the Bermuda Monetary Authority as a Class E long-term life insurer. Resolution Re is a provider of reinsurance solutions for primary life insurers globally, focused on reinsuring policyholder and pension liabilities from the UK, Europe, the USA and Asia.
Resolution Re applies the data protection standards set out in the Bermuda Personal Information Protection Act 2016 (PIPA) and, as applicable, the UK version of the EU General Data Protection Regulation 2016/679 as it forms part of the law of each applicable jurisdiction of the United Kingdom pursuant to the European Union (Withdrawal) Act 2018, as amended from time to time (UK GDPR) and/or the EU General Data Protection Regulation 2016/679 (EU GDPR) to the extent that these are applicable to us, as well as other data protection standards applicable to us in the jurisdictions in which we do business.
The terms used in this privacy notice are based on the requirements and recommendations of the Bermuda Office of the Privacy Commissioner. You can find out more about the Bermuda Privacy Commissioner here: https://www.privacy.bm.
You can contact the Resolution Re Data Privacy Officer with any data protection queries by email to: firstname.lastname@example.org.
What personal data and information do we collect?
As a reinsurer, Resolution Re may receive or gain access to personal data (which may include special categories of personal data) in connection with the reinsurance and other agreements that it enters into in connection with the reinsurance solutions that we offer to our primary life insurer clients.
The types of personal data and information we may process in relation to the reinsurance transactions that we have entered into may include policyholder and/or pension scheme member data, which may extend to policyholders’ and/or pension scheme members’ policy numbers, postcode details, gender, date of birth and/or other identifiers, together with seriatim data, i.e. line by line but anonymised data on the membership of a relevant scheme or product cohort, and claims data, also on a line by line basis but anonymised, in respect of the liabilities that we have agreed to reinsure.
We may on occasion process special categories of personal data and information or sensitive personal data and information such as health data, marital status and racial or ethnic origin if this information is passed to us by the primary life insurer clients who we work with as part of the data files that they share with us, where any of this information is necessary for the purposes of performing or exercising our rights or obligations as a reinsurer.
How do we use personal data and information?
We will use personal data and information that we receive only in the context of our role as a reinsurer for the primary life insurance industry clients with whom we work.
The legal basis for our processing of personal data and information includes:
- For pre-contractual and contractual purposes
- For compliance with legal and regulatory obligations
- Where the processing is necessary for our legitimate interests
Securing personal data and information
We follow strict security procedures in the storage and disclosure of personal data and information in line with the international standards of ISO 27001. This means that we have put in place an infrastructure which is designed to manage risks related to the security of data owned or handled by the Company.
When do we share personal data and information?
We may share personal data and information with other companies in Resolution Life and with external service providers in the day to day running of our business, such as actuarial consultants or IT consultants engaged to support us in building our IT ecosystem or managing our IT security, some of whom may have access to or otherwise process personal data and information on our behalf. We have contracts with all such providers that contain confidentiality provisions and that mandate how they process and secure that data.
We may also share personal data and information with regulators, other professional bodies, law enforcement or other government agencies to comply with legal or regulatory obligations or valid requests from such bodies in the jurisdictions in which we do business.
Where will we process personal data and information?
Since we are based in Bermuda, the data and information we collect about you is likely to be transferred to, stored at, and otherwise processed outside of the European Economic Area (EEA) in server locations in EU GDPR or UK GDPR territories. We transfer data within our group on the basis of our binding corporate rules and pursuant to international intra-group data processing and transfer agreement terms which meet EU GDPR and UK GDPR standards and which establish adequate protection for personal data and information controlled or processed by any of our Resolution Life group companies.
Personal data and information may be processed by third party providers to us outside of the EEA, subject to contractual restrictions regarding confidentiality and security in line with applicable data protection laws and regulations.
How long do we keep your data and information for?
We will not keep your personal data and information for longer than is necessary for the purpose for which it was provided, unless we are required to by law or have other legitimate reasons to keep it for longer.
There are a number of rights that you have under applicable data protection laws. You have the right to:
- Access to the personal data we hold about you.
- Advise us to correct your personal data when incorrect, out of date or incomplete.
- Deletion of the data we hold about you, in specific circumstances. For example, when you withdraw any consent given to a provider of life insurance or protection products, or object and we have no legitimate overriding interest, or once the purpose for which we hold the data has come to an end.
- Require a computer file in a common format (e.g. CSV or similar) containing the personal data that you have previously provided to a provider of life insurance or protection products with whom we are working or your information within it to be transferred to another entity where this is technically possible.
- Restriction of the use of your personal data, in specific circumstances, generally whilst we are deciding on an objection you have made.
- Require that we stop processing your personal data, in specific circumstances. For example, when you have withdrawn consent, or object for reasons related to your individual circumstances.
- Require that we stop any consent-based processing of your personal data after you withdraw that consent.
If you wish to action any of the above rights, you can contact the Resolution Re Data Privacy Officer with any data protection queries by email to: email@example.com.
If you are unhappy about the way you believe that we have handled your data or upheld your rights, you can request a review or initiate a complaint to the Privacy Commissioner at any time via: https://www.privacy.bm.
If you have any questions or concerns regarding the way in which your personal data has been processed, please contact the Resolution Re Data Privacy Officer with any data protection queries by email to: firstname.lastname@example.org or write to us at:
Resolution Re (Attention: Data Privacy Officer)
Wessex House, Second Floor
45 Reid Street
We may make changes to this Privacy Notice from time to time. We will post any changes on the Resolution Life website. You may also request a copy of the current version of this Privacy Notice from the Resolution Re Compliance team via email@example.com.
This version of our Privacy Notice was updated on 31 October 2023.