GRID Privacy Notice

1. Introduction and Scope

This Privacy Notice (“Notice”) explains how Greenlight Reinsurance Ireland DAC (hereinafter referred to as “Greenlight”, “GRID”, “we”, “us”, or “our”) collects, uses, stores, discloses, and otherwise processes personal data in connection with our business operations as a reinsurer.

Through this Notice we are informing you (in particular as policyholders, contracting parties, injured parties and claimants, beneficiaries of our customers, negotiating partners, brokers, interested parties, investors, suppliers, service providers, as well as other interested parties) about the processing of your personal data that we, have received directly and/or indirectly and about the rights to which you are entitled under data privacy law(s).

Greenlight operates in a business-to-business (B2B) reinsurance context. Our counterparties are institutional entities, including cedants, brokers, and other commercial entities. We do not have retail customers. Accordingly, this Notice is directed primarily at:

  • Business contacts at our institutional counterparties (cedants, reinsurance brokers, and other commercial partners);
  • Directors, officers, and authorised signatories of counterparty entities;
  • Individuals whose personal data is contained in reinsurance claims or underwriting submissions received from cedants;
  • Visitors to our website; and
  • Third-party service providers and their personnel.

This Notice is provided in a single-document format. Given our exclusively B2B operating model and the sophisticated institutional nature of our audience, we have determined that a single comprehensive notice best serves transparency obligations while providing all required information in one accessible location.

2. Data Controller

For general inquiries about this Privacy Notice or our data processing practices, or to exercise your data subject rights, you may contact us at:
Greenlight Reinsurance Ireland DAC
A. 50 City Quay, Dublin 2, D02 F588, Ireland
E. compliance-ie@greenlightre.com
T. +353 1687 0534
Company Number: 475022

Our Data Protection Officer can be reached by post at the relevant address for the respective locations noted above, please include the additional address line “Data Protection Officer”) or by e-mail through the email address provided above.

3. Purposes and Legal Bases for Processing

We process personal data for the purposes set out below. For each purpose, we identify the applicable legal basis under Article 6(1) GDPR. Where special category data (Article 9) is processed, the applicable condition is also identified.

3.1 Business Contacts at Institutional Counterparties

Purpose Legal Basis
Managing and maintaining business relationships with cedants, brokers, and other counterparties Legitimate interests (Article 6(1)(f)) — the Company’s legitimate interest in conducting its reinsurance business and maintaining commercial relationships
Negotiating, placing, and administering reinsurance contracts Performance of a contract to which the data subject’s employer/principal is a party, or legitimate interests (Article 6(1)(b)/(f))
Communicating regarding reinsurance matters, renewals, and market developments Legitimate interests (Article 6(1)(f))
Compliance with anti-money laundering (AML), counter-terrorist financing (CTF), and sanctions obligations Legal obligation (Article 6(1)(c)) — Criminal Justice (Money Laundering and Terrorist Financing) Acts 2010-2021
Due diligence on counterparties and their personnel (KYC/KYB) Legal obligation (Article 6(1)(c)) and legitimate interests (Article 6(1)(f))

 
3.2 Claims and Underwriting Data Subjects

Purpose Legal Basis
Processing, adjusting, and settling reinsurance claims Performance of a contract to which the data subject’s employer/principal is a party, or legitimate interests in fulfilling reinsurance obligations (Article 6(1)(b) / (f)).
Underwriting assessment and risk pricing Legitimate interests (Article 6(1)(f))
Fraud detection and prevention Legitimate interests (Article 6(1)(f)); legal obligation (Article 6(1)(c)) where applicable
Actuarial analysis and reserving Legitimate interests (Article 6(1)(f))
Dispute resolution and litigation Legitimate interests (Article 6(1)(f)); establishment, exercise, or defence of legal claims

Special category data (Article 9): Where claims data includes health or medical information, we rely on Article 9(2)(f) (establishment, exercise, or defence of legal claims) and/or Section 55 of the Data Protection Act 2018 (insurance purposes).

3.3 Website Visitors

Purpose Legal Basis
Providing and maintaining the website Legitimate interests (Article 6(1)(f)) — operating the Company’s online presence
Security monitoring and fraud prevention Legitimate interests (Article 6(1)(f))

 

4. Categories of Personal Data We Process

Given our B2B reinsurance operations, we process the following categories of personal data:

Category Types of Personal Data
Business contact data Name, job title, business email address, business telephone number, business address, professional qualifications, LinkedIn/professional profile information.
Claims-related personal data Names, dates of birth, addresses, health/medical data, financial information, and other personal data of individuals contained in reinsurance claims received from cedants.
Underwriting-related personal data Names, dates of birth, occupations, and risk-related personal data contained in underwriting submissions.
Due diligence and compliance data Identity verification documents, PEP/sanctions screening results, and beneficial ownership information.

 

5. Sources of Personal Data

Where we do not collect personal data directly from the data subject, we obtain personal data from the following sources:

  • Cedants and ceding insurers: personal data contained in reinsurance submissions, bordereaux, and claims files;
    Reinsurance brokers: business contact details of counterparty personnel and claims-related personal data;
  • Publicly accessible sources: Companies Registration Office, professional directories, company websites, sanctions/PEP databases;
  • Regulatory authorities: the Central Bank of Ireland, Data Protection Commission, and equivalent bodies locally and in other jurisdictions as appropriate;
  • Third-party service providers: background screening providers, IT service providers;
  • Industry bodies and databases: insurance industry fraud databases, actuarial databases and other industry bodies.

6. Recipients and Disclosures of Personal Data

We may share personal data with the following categories of recipients:

  • Reinsurance counterparties: cedants, retrocessionaires, and reinsurance brokers, as necessary for the performance of reinsurance contracts;
    Group companies: entities within our corporate group for internal administrative and business purposes;
  • Professional advisers: legal, actuarial, accounting, and auditing firms;
  • Regulatory authorities: the Central Bank of Ireland and other regulatory bodies as required by law;
  • IT and service providers: cloud hosting providers, IT support, claims management systems, and other processors acting on our behalf;
  • AI service providers: for data analysis and process automation solutions
  • Industry bodies: Industry fraud databases, and similar bodies; and
  • Law enforcement: law enforcement bodies where required by law or in connection with fraud prevention.

7. Retention of Personal Data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. In this context it may occur that personal data is stored for the period in which claims can be asserted against our company (statutory limitation periods vary by jurisdiction).

Retention of specific personal data may be necessary for one or more of the following reasons:

  • To fulfil statutory or other regulatory requirements;
  • To evidence events/agreements in case of disputes;
  • To meet our operational needs; or
  • To save data for historical purposes.

We will securely delete or erase your personal information if there is no valid business reason for retaining your data.

8. International Transfers of Personal Data

As a reinsurer operating in the global reinsurance market, we may transfer personal data to recipients located outside the European Economic Area (EEA). Where such transfers occur, we ensure that appropriate safeguards are in place in accordance with Chapter V of the GDPR.

Transfer mechanisms we employ include:

  • Adequacy decisions: transfers to countries that the European Commission has determined provide an adequate level of data protection (e.g., the EU-U.S. Data Privacy Framework for certified U.S. entities);
  • Standard Contrac0tual Clauses (SCCs): the European Commission’s approved standard contractual clauses under Article 46(2)(c) GDPR, supplemented by transfer impact assessments where required;
  • Binding Corporate Rules: where applicable within our corporate group; and
  • Derogations: in limited circumstances, derogations under Article 49 GDPR (e.g., where a transfer is necessary for the establishment, exercise, or defence of legal claims).

We conduct transfer impact assessments for transfers relying on SCCs and implement supplementary technical, contractual, and organisational measures where necessary.

9. Data Subject Rights

In accordance with Data Protection laws, individuals whose personal data we process have certain rights in relation to that data. This section explains each right, and limitations or qualifications that may apply.

To exercise any of the rights described in the table below, please contact us using the details set out in Section 2 of this Notice. We may need to verify your identity before acting on a request.

Data protection rights attach to individuals, not to the organisations they represent. Accordingly, individual business contacts at our institutional counterparties and employees of cedants and brokers whose data appears in claims files may exercise these rights. However, the practical scope and application of certain rights may be affected by the context in which data is processed.

Data Subject Right Description of Rights
Right to Be Informed Right to be informed about how we collect and use personal data. This Privacy Notice fulfils our obligation to provide this information.
Right of Access Right to obtain confirmation as to whether we process personal data and, if so, to obtain a copy of that data together with specified supplementary information (purposes, categories, recipients, retention periods, rights, source, automated decision-making).
Right to Rectification Right to have inaccurate personal data corrected and incomplete personal data completed.
Right to Erasure Right to request deletion of personal data in certain circumstances, including where the data is no longer necessary for the purpose for which it was collected, where consent is withdrawn, or where processing is unlawful.

Limitations

Erasure may be refused where:

  • processing is necessary for compliance with a legal obligation;
  • processing is necessary for the establishment, exercise, or defence of legal claims (particularly relevant for long-tail reinsurance liabilities);
  • regulatory record-keeping obligations override erasure requests; and
  • data forms part of an active reinsurance contract or claim file, and erasure may not be possible during the life of the contract and applicable limitation periods.
Right to Restriction of Processing Right to request restriction of processing in certain circumstances, including where the accuracy of data is contested (pending verification), where processing is unlawful but erasure is opposed, where we no longer need the data but you require it for legal claims. Where processing is restricted, we will store the data but not otherwise process it without consent (unless for legal claims, protection of another person’s rights, or important public interest reasons).
Right to Data Portability Right to receive personal data provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller, where processing is based on consent or contract and is carried out by automated means.
Right to Object Right to object to processing based on legitimate interests or public interest grounds. Upon objection, processing must cease unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.

 

10. Complaints

If you believe that we have breached applicable data protection law when processing your personal data, you can contact us using the information in Section 2 of this Notice or the data protections authorities as follows:

Ireland Data Protection Commission
A: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
T: +353 (0)1 765 0100 / 1800 437 737
E: info@dataprotection.ie
W: www.dataprotection.ie

11. Changes to This Privacy Notice

We may update this Privacy Notice from time to time to reflect changes in our processing activities, legal requirements, or regulatory guidance. We encourage you to review this Notice periodically (current version: September 2026)