The Right to Be Forgotten Meets an Insurer That Can't Find the Data
A customer sends a deletion request — the right to erasure under privacy law — and asks you to remove everything you hold about them. It sounds like a simple instruction. Then someone has to actually do it, and the uncomfortable truth surfaces: the insurer doesn't know everywhere the customer's data lives. It's in the policy system, the claims system, a data warehouse, three spreadsheets, an email archive, a marketing tool, and a couple of vendor platforms nobody fully maps. You can't delete what you can't find, and most insurers can't find all of it.
Why "delete my data" is so hard to honor
Fulfilling an erasure or access request assumes something most insurers don't have: a reliable, complete view of where a single customer's data is scattered. Data has spread across decades of systems, integrations, and copies, and nobody maintained a map of it. So the request either gets a partial, best-effort response — which is a compliance risk if a copy is missed — or it triggers a frantic manual hunt across teams, which doesn't scale past a handful of requests. Neither is a real answer; both are symptoms of not knowing your own data landscape.
Where it breaks down
- No customer-level data map. You can list your systems, but you can't say with confidence which ones hold this specific person's data, in what fields, under what identifiers.
- Broken identity. The customer is "J. Smith" in one place and "John Smith" in another with a different ID, so a deletion in one system leaves copies untouched elsewhere.
- Uncontrolled copies. Extracts, backups, and analyst spreadsheets hold shadow copies no governance process tracks.
- Manual fulfilment. Each request is a bespoke project, so volume — or an audit — turns a legal right into an operational crisis.
Why it's really a data-foundation problem
The privacy request is just the moment the weakness becomes visible. The underlying issue is that you don't have a resolved view of the customer and a map of where their data lives — the same gap that breaks customer 360, fair-value reviews, and open-insurance data sharing. An insurer that can resolve a customer across every system and knows what each system holds can fulfil erasure as a routine, auditable process. One that can't will keep discovering, request by request, that its data owns it rather than the other way around. Privacy readiness is a data-governance and entity-resolution capability, not a legal form.
What good looks like
- A resolved customer identity that ties every record across every system to one real person.
- A living data map that says where a customer's data lives, in which fields, under which identifiers.
- Governed copies so extracts and backups are tracked, not shadow data nobody can reach.
- Automated, auditable fulfilment that executes and evidences a request end to end.
Privacy law didn't create the problem — it exposed one that was already there. The insurers who handle erasure and access requests calmly are the ones whose data foundation already knows the customer and the map. Building that foundation — resolution, cataloguing, governed copies — is exactly the kind of work we do with insurers at IntelliBooks.
"Delete everything you have about me" is a one-sentence request. Whether you can answer it honestly is a measure of whether you actually know your own data.
Comments
Post a Comment