
The policy of Enstar Group Limited and its subsidiaries (the “Company”) is to respect and protect the privacy of individuals whose information we process during the course of business, including personal information (which may also refer to genetic information or sensitive personal information) relating to candidates and employees (current and former), contractors, directors (including certain information about their spouse, dependents and emergency contacts where applicable), individual shareholders of the Company (where applicable), customers, claimants and visitors to our website.
This notice (the “Privacy Notice”) is intended to inform individuals about our use of your personal information in Bermuda, and in certain instances outside Bermuda, as well as provide clear and easily accessible information about our practices and policies with respect to your personal information. It does not form part of your contract with us (if any), nor does it confer any contractual rights and obligations on you or the Company. Our office in Bermuda can be found in the AS Cooper Building, 4th Floor, 26 Reid Street, Hamilton, Bermuda.
As an organization with a global presence, we are subject to various legal requirements for data protection. Our aim is to be as consistent as possible and, in addition to complying with the Personal Information Protection Act, 2016 (“PIPA”), obey all applicable laws in the countries where we operate, and apply the highest standard of privacy principles in our approach.
This Privacy Notice sets forth the Company’s policies and practices with respect to:
We may process the following types of personal information and sensitive personal information depending on the nature of our relationship with you:
To the extent permitted by applicable laws, we may also collect and process a limited amount of personal information falling into special categories, called “sensitive information”. For example, sensitive information may include, but is not limited to, the following types of information:
The Company may collect personal information in various ways depending on the circumstances and nature of our relation. By way of example, we primarily collect information from the following sources:
We may use your personal information for the following purposes:
Our lawful basis for which we may process your personal information varies depending on the purpose of processing, as exampled below.
We may ask for your consent to perform certain processing which is not otherwise provided for under one of the above or other lawful bases. We shall provide clear, prominent, easily understandable, accessible mechanisms for you to give consent in relation to the use of your personal information, unless it can be implied from your conduct that you consent to the use of your personal information (excluding sensitive personal information) for the intended purposes that we have notified you of. You should be aware that it’s not a condition or requirement of your employment or use of our services to agree to any request for consent from the Company. Where consent is given, it may be withdrawn by you at any time, but this will not impact on any other lawful basis for processing relied on by the Company. In some cases, your withdrawal of consent may be treated by us as an objection to us processing your information.
Your personal information will only be used and disclosed as permitted by applicable law. Generally, any personal information collected by the Company will remain under our custody and control and will only be accessed and used internally by authorised individuals in accordance with our access protocols. We may, however, transfer your information to third parties – including our subsidiaries and affiliated companies in the provision of our services and/or to comply with a law or regulation.
We may transfer your personal information to other third parties, for example, in connection with the provision of our insurance services, third parties who are primarily business partners, reinsurers, third party administrators, and other parties involved in the processing of insurance claims. In respect of our employees and other staff, we may share your information with our service providers, including for example PwC Bermuda (for tax purposes), HSBC (for payroll purposes) and the Caribbean Investigation Network (our background and reference check provider), Argus (our Bermuda benefits provider).
We may also share your information with other service providers. For example, we use software and applications such as DocuSoft, Bridger Insight, CODA, UKG and DocuSign. Your personal information may also be accessed by third parties whom we work together with in connection with IT services (e.g. hosting, supporting and maintaining our IT systems). Your personal information may also be shared with certain interconnecting systems. Personal information contained in such systems may be accessible by providers of those systems, their associated companies and sub-contractors.
In addition, we are sometimes required to share data with other entities to comply with a law or regulation. This could include government authorities (e.g. Bermuda’s Department of Social Insurance, Department of Payroll Tax and the Department of Immigration), state or federal authorities, regulators (e.g. the Bermuda Monetary Authority, courts and/or professional bodies (e.g. CPA Bermuda and the Bermuda Bar Association).
We may also need to share your personal information in the context of litigation, or a potential company or asset sale.
Our transfers, including our international transfers as described below, are subject to a process of risk assessment. We have formal agreements in place with recipients outside of Bermuda to ensure they provide a comparable level of protection for your data, including technical and organisational security measures to protect your personal information.
Enstar Group Companies are also located in Australia, the USA, the United Kingdom, and the European Economic Area. Where personal data transfers occur to these destinations, they are governed by safeguards which include International Group Data Transfer Agreements. We may transfer any information we collect mentioned above to these destinations.
Some of our service providers listed at 4 above may be based outside of Bermuda (for example, the Caribbean Investigation Network and some of our software and IT solutions), therefore, we may transfer your information to these overseas third parties.
Where your personal information is transferred to a third party located outside of Bermuda, we will take steps to ensure that your personal information is adequately protected and transferred in accordance with data transfer requirements as prescribed under section 15 of PIPA.
As an individual whose personal information we process, you have a number of data subject rights as required by PIPA and which we observe as our standard at Enstar Group. You may have the following rights depending on the circumstances of your case and applicable law.
To exercise your Rights, please contact the Data Protection Officer at Enstar: [email protected].
Any request must be in writing and provide sufficient detail to enable us to identify the personal information to which the request relates.
In some circumstances, for example where an exemption is provided under applicable law or where an access request is manifestly unreasonable, the Company may refuse your request in whole or in part depending on the circumstances. If this is the case, we will inform you and explain why in our response.
Enstar does not engage in automated decision making or use artificial intelligence for processing the personal data it collects.
We only retain data for as long as necessary to process your data and/or in accordance with any applicable legal or other regulatory requirements. Our retention policy varies depending on the types of information we collect and according to applicable laws. Due to the nature of our business generally, we may hold information for periods that will account for circumstances such as ongoing legal disputes with claimants, or possible future liabilities. A limited and reasonable amount of personal data may also be kept for archiving purposes and even where you have requested we no longer keep in touch with you, we will need to keep a record of the fact in order to fulfil your wishes.
We take the security of your data seriously and we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing, including:
We ensure that those who have permanent or regular access to personal information, or are involved in the processing of personal data, or the development of tools used to process personal data, are informed of their responsibilities when processing personal information.
If you have any questions concerning this notice, please contact the Data Protection Officer at Enstar: [email protected].
Our Data Privacy Policy, outlining the measures we have in place, can be requested from the Data Protection Officer at Enstar: [email protected].
This Privacy Notice is subject to change in accordance with changes to applicable laws or our internal policies and procedures. The date below indicates when this Privacy Notice was last revised.
Any changes to this Privacy Notice will be effective upon publication of the revised Privacy Notice.
Last revised: 21st January 2025