US Client Data Privacy Notice

The policy of Enstar Group Limited and its subsidiaries (“The Company” “us” “our” or “we”) is to respect and protect the privacy of individuals whose personal information (“PI”) (also known as “PII” or Personally Identifiable Information) during the course of our business, including data relating to, customers, and claimants.

To fulfil this policy, we agree to exercise the safeguards and precautions set out in this written notice (the “Privacy Notice”) to maintain the confidentiality of information we process in the United States of America (US) and relating to US residents’ data that we control. Our representative office in the US is 55 West 46th Street, Suite 2805, New York, NY 10036, USA.

As a group with a global presence, we are subject to differing data protection legislation where we operate. Our aim is to be as consistent as possible, to obey all applicable laws, and apply the highest standard of privacy principles to our approach.

This Privacy Notice sets out our current policies and practices with respect to:

1. What PI we may hold or collect

We may process the following PI:

Sensitive Personal Information include:

2. How/when do we collect PI:

3. Why we process your PI

We process your PI for the following purposes:

4. Cookies

We use Essential Cookies.  These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms.

You can set your browser to block or alert you about these cookies, but some parts of the site will then not work.

These cookies do not store any personally identifiable information.

We may use further cookies e.g. functional or targeting cookies, but only where you consent.

5. Who we may transfer your PI to

We may transfer your personal data to third parties who are primarily business partners, reinsurers, third party administrators, and other parties involved in the processing of insurance claims.  In addition, we are sometimes required to share data with other entities to comply with a law or regulation.  This could include state or federal authorities, courts, external advisors, and similar third parties.

Our transfers are subject to a process of risk assessment.  We have formal agreements in place with recipients outside of the US to ensure they provide an adequate level of protection for your data, including technical and organizational security measures to protect your personal data.

6. International Transfers

Enstar Group Companies are also located in Australia, Bermuda, the United Kingdom, and Continental Europe. Where personal data transfers occur to these destinations, they are governed by safeguards which include International Group Data Transfer Agreements.  We may transfer any information we collect to Enstar Group companies within these destinations.

7. Consumer/Individual/Resident Rights (“Consumer Information Rights”/“CIR”)

We observe a number of data subject rights as required by law and adopted by Enstar Group as our standard.  You may have the following rights depending on the relevant State Law.

To exercise your Rights (apart from the final right, which you can exercise directly with the regulator) please contact us on [email protected] or toll-free on 1-877-878-2944. 

8. Automated Decision Making

Enstar does not engage in automated decision making or use artificial intelligence for processing the personal data it collects.

9. Retention Periods

We only retain data for as long as necessary to process your data. Our retention policy varies depending on the categories of information we collect and according to applicable law. Due to the nature of our business, we hold most information for ten years, but this could be longer depending on our obligations to you or whether we have an ongoing legal dispute with you. A copy of our retention policy can be obtained on request.

10. PI Security

We take the security of your PI seriously and we implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing. We ensure that those who have permanent or regular access to personal data, or that are involved in the processing of personal data, or in the development of tools used to process personal data, are informed of their responsibilities when processing personal data.

We ensure that those who have permanent or regular access to personal data, or that are involved in the processing of personal data, or in the development of tools used to process personal data, are informed of their responsibilities when processing personal data.

11. Interfaces with Third Party Websites and Services

Our websites and apps may contain links, references and content from other websites and services outside of our control.  We have limited or no control over these websites and services and this Privacy Notice does not apply to them. We suggest you read the Privacy Notices of the relevant third-party website or service.

12. Data Protection Policy

If you have any questions concerning this notice, please contact the Data Protection Officer at Enstar: [email protected]. 

Last revised: August 26