ProtDonnees1

General data protection policy

Respect for Privacy and Protection of Personal Data: A Foundation of Trust

Respecting privacy and protecting personal data are core values upheld by the companies of the Groupama Group, reflecting their commitment to fundamental rights and freedoms.

Purpose of This Policy

This policy outlines the commitments implemented in daily operations to ensure the responsible use of personal data.

Data Protection Officer (DPO)

To safeguard privacy and personal data, Groupama appointed a Data Protection Correspondent (CIL) in 2007-now known as the Data Protection Officer (DPO). The DPO operates independently across all French entities of the Group.

The DPO is a symbol of trust: a specialist in data protection, responsible for ensuring compliance with data protection rules, and the key contact for both the CNIL (French Data Protection Authority) and individuals whose data is collected or processed.

Principles Governing Personal Data Protection

Groupama Group companies process personal data in accordance with applicable laws and regulations, including the General Data Protection Regulation (GDPR), the amended French Data Protection Act of January 6, 1978, and CNIL guidelines.

1. Specific, Explicit, and Legitimate Purpose
Data is collected for clearly defined purposes, communicated to individuals. It cannot be used in ways incompatible with those purposes. Collection is fair-no data is gathered without informing the data subject.

2. Proportionality and Relevance
Only data strictly necessary for the intended purpose is collected. Groupama strives to minimize data collection and keep it accurate and up to date, facilitating individuals’ rights.

3. Limited Retention Period
Personal data is retained only as long as necessary for its intended purpose. Retention periods are communicated and vary based on data type, processing purpose, and legal requirements.

4. Confidentiality and Security
Information System Security Policies (ISSP) are tailored to the nature of the data and business activities. Physical, logical, and organizational safeguards are in place to prevent unauthorized access. Subcontractors must also provide appropriate guarantees for data security and confidentiality.

Data may be transferred within or outside the EU. If so, individuals are informed, and specific safeguards are applied.

5. Data Subject Rights
Groupama ensures individuals can exercise their rights easily and freely:

  • Clear, accessible information on data processing
  • Easy access to personal data
  • Rights to rectify, delete, restrict use, or request portability of data provided under consent or contract

Requests can be made online or by other means, including contacting the DPO.

Monitoring and Updates

This policy is publicly available on Groupama websites and updated regularly to reflect legal changes and organizational developments.

It is supplemented by:

  • Detailed information on processing purposes, data recipients, retention periods, and rights procedures
  • A cookie notice
  • Security recommendations for users, including password management

Contact the DPO France

Groupama Assurances Mutuelles – Data Protection Officer 8-10 rue d’Astorg, 75383 Paris Email: contactdpo@groupama.com