Limiting collection means the agent must collect only the personal information that is necessary for the identified purpose. Collecting broad swaths of data "because it might be useful later" violates this principle. Each piece of information collected should map to a specific underwriting, administrative, or regulatory purpose.
Safeguards require the agent to protect personal information against unauthorized access, use, disclosure, loss, or theft. Practical safeguards appropriate to insurance agents include:
- Password-protected and encrypted digital client files
- Secure disposal of physical documents containing personal data
- Not discussing client information in public spaces or open-plan offices where others can overhear
- Not sending sensitive client data by unencrypted email without client consent to that method
- Physical security of paper files
The sensitivity of the data governs the level of safeguard required. Medical information, financial statements, and government identification are highly sensitive and require more robust safeguards than general contact data.
Common mistake: treating digital security as the only safeguard obligation. Physical files, oral conversations, and paper documents are equally within scope.
Recall: What is the principle of limiting collection and why does it exist? Name two practical safeguards an agent must apply to protect client personal information.