Life insurers and managing general agents routinely transfer client data across provincial and national borders, including to reinsurers, third-party administrators, and data processors outside Canada. PIPEDA requires organizations to ensure that personal information transferred outside Canada receives comparable protection to that required in Canada.
Practically, this means:
- The agent or insurer must have a contract or other mechanism ensuring the third party protects the data
- The client must be informed in the privacy notice that data may be transferred outside Canada and to which types of jurisdictions (general level of disclosure is sufficient; exact countries need not always be named)
- If the foreign jurisdiction's law requires disclosure to that country's authorities, the client should be made aware of that possibility
Common mistake: believing that client consent to data collection covers cross-border transfer automatically. The cross-border transfer must be disclosed as a purpose at collection, and adequate protection must be contractually required.
Recall: What two obligations does PIPEDA impose before an insurer transfers client personal information to a third-party processor outside Canada?