Data Protection Policy

PRIVACY POLICY

Date last revised: April 2025

MAG SPA (UK Branch) (we/us/our) are committed to respecting your privacy and protecting your personal data. We recognise that your personal data is your property and that you have loaned it to us for specific purposes.

Unless otherwise required by applicable data protection laws, the Information Commissioner’s Office (ICO) guidance or best practice, or to perform our contract with you, we will only process personal data in the way we tell you, or in the way you ask us to, and we will give it back to you if we no longer need it.

1. THIS POLICY

1.1 This policy sets out how we process your personal data. This policy applies to the personal data we process and you are advised to read it carefully.

1.2 Terms used within this policy shall have the meaning(s) given in the Data Protection Act 2018 (Act) and/or the UK and EU General Data Protection Regulations (as applicable).

1.3 By providing your personal data to us, you understand, accept and consent to the practices set out in this policy.

1.4 Any changes we make to this policy will be posted on this You must check back frequently as any changes will be binding on you when you continue to work with us after the date of the relevant change. More information about your rights are set out in section 9.

1.4 If you have any queries relating to this policy, please contact us at uk@maglondon.com in the first instance.

2. WHO WE ARE

2.1 For the purposes of the Act, the data controller is MAG SPA (UK Branch), a company registered in England & Wales (number BR022052) with our registered office at 1 Minster Court, London, Mincing Lane, EC3R 7AA.

2.2 We are registered with the ICO to process your personal data and our registration number is ZB317809. We are also regulated by the Financial Conduct Authority (FCA registration number 970562) and the IVASS.

2.3 Your personal data will be held and stored by us in our internal management information systems on servers located in Italy. All personal data is processed by UK based staff who are regulated by our internal staff data protection policy.

2.4 All staff are made aware of this policy and their duties and responsibilities under

3. YOUR CONSENT

We do not ordinarily rely on your consent to process your personal data. We process your personal data primarily to perform our insurance contracts with you. We consider that the personal data we obtain is reasonable and necessary for these purposes. However, we review this intermittently and remove any inaccurate or obsolete data.

4. WHAT WE COLLECT

4.1 Where you are a current, potential or former employee, worker or other member of our staff, we may collect additional categories of your personal data to provide you with the necessary benefits under your contract with A separate privacy notice applies and a copy is available on request.

4.2 We process personal data as required in connection with our insurance policies, including all necessary claims data and any data relating to complaints. We collect different information depending on your role as a policyholder, beneficiary, claimant, witness, broker or other third

5. HOW DO WE COLLECT IT

5.1 Personal data in connection with insurance risks we place are provided to us from our network of producing brokers, which changes from time to time. We don’t obtain personal data from policyholders directly.

5.2 Any personal data that is provided to us from our producing brokers is in accordance with the written binders we have with those brokers, and should have been subject to the relevant broker’s privacy policy, over which we have no control and which should identify MAG SPA (UK Branch) as one of the intended recipients for that data.

5.3 When we collect it from

  • When you use our website, we automatically collect technical information about the device you use to visit, including your IP address, browser type/version and related
  • We also monitor your use of the website, including full URLs, clickstreams, pages you view and how you interact with them from time to time.
6. WHAT WE USE YOUR DATA FOR

6.1 We use your personal data to provide our insurance services, and supply you with the support you have requested from us, and to contact you in relation to any enquiries or requests you raise with us.

6.2 We also use your personal data to send you information by email about us, our products and our services that may be similar to those insurance products that you have already purchased or enquired about.

6.3 Technical information we collect about your visit to our website is used to enable us to:

  • personalise and improve functionality and security (to keep it safe and secure);
  • administer and monitor traffic behaviours on our website for analysis, testing, research, statistical and survey purposes; and
  • ensure that we can offer you the most effective and efficient browsing experience, and make improvements where necessary.

6.4 Once collected, your personal data will be retained by us for as long as is necessary for us to provide you with our insurance products and services, to market our services to you (where requested) and to enable us to improve our website. After this point, your data will be securely deleted and we will not contact you unless you ask us to.

7. SECURITY

7.1 We have an appointed Privacy Officer with specific responsibility for data protection within our organisation. The Privacy Officer reports to the Board to oversee the effectiveness of our data protection compliance.

7.2 We operate a ‘need to know’ principle of minimised access to confidential data, set out in the Cabinet Office’s ‘Minimum Data Handling Measures’ when providing access to confidential data. This ensures that all staff only ever have access to the minimum amount of confidential data required to perform their valid business role and for which appropriate consent or other lawful basis exists.

7.3 We implement our principle through effective ICT user account management processes; by limiting the number and use of privileged accounts and by monitoring the use of ICT systems and limiting access to other physical areas which house confidential data.

7.4 The Branch ensures via initial and refresher training that all staff understand that the Branch is legally responsible for the security of data sent whilst in transit, including but not limited to data sent via email, webchat, fax, video, mobile applications, the Portal, and post. The Branch ensures that any email containing confidential information is adequately secured by adopting secure email procedures.

7.5 The Branch mitigates against the high risks of potential data loss associated with the use of removable media (laptops, USB sticks, DVDs, CDs etc.) by avoiding the use of removable media wherever possible and, where its use cannot be avoided, by ensuring that media is adequately encrypted with a secure password.

7.6 The Branch ensures that only authorised ICT equipment and media will be used to handle, transport, store, or process personal Privately owned ICT equipment is not permitted to be used.

8. HOW AND WHY WE DISCLOSE YOUR DATA

8.1 Personal data may be shared with:

    • companies within the wider MAG group;
    • our insurers and re-insurers, as necessary in connection with your policy;
    • our advisers, such as loss adjusters, solicitors and claims experts who assist us with policy administration;
    • industry bodies, such as the Association of British Insurers or Lloyd’s Market Association; or
    • those third parties where necessary to comply with our legal and regulatory

8.2 The only third parties with or to whom we disclose or receive your personal data are those listed in this policy, for the purposes listed in this policy.

8.3 Any websites which are linked to or from our website are outside of our control and not covered by this policy. If you access those websites using the links provided, the website operators may collect information from you which will be used by them in accordance with their own privacy policies (if any). These policies may differ from ours, and we cannot accept any responsibility or liability in respect of these.

9. YOUR RIGHTS

9.1 In relation to all of your personal data, you have the following rights (in addition to any rights you may have under the Act or the GDPR) to ask us:

    • not to process your personal data for marketing purposes;
    • to clarify what data we hold about you, how it was obtained, to whom it has been disclosed and for how long it will be stored;
    • to amend any inaccurate data we hold about you;
    • to delete any of your data (where you no longer think we need to hold it, or you think we have obtained or processed it without your consent at any time); and
    • to only process your personal data in limited circumstances, for limited

9.2 We can extract your personal data from our databases and provide it to you in a structured, commonly used way (typically by .csv file).

9.3 If you wish to exercise any of your rights at any time, please contact us on the details in section 1.5. We will require you to verify your identity to us before we provide any personal data to you, and reserve the right to ask you to specify the types of personal data to which your request relates.

9.4 Where you wish to exercise any of your rights, they may be subject to payment of a nominal administration fee (to cover our costs incurred in processing your request) and any clarification we may reasonably require in relation to your request. Such fees may be charged where we consider (acting reasonably) that your request is excessive, unfounded or repetitive.