Kempron
Contact

Regulators · European Union

The European Union Framework.

One regulatory ceiling over twenty-seven national claims markets, and the densest set of supplier-facing obligations of any jurisdiction described on this site.

Kempron does not operate in the European Union. The EU framework is where supplier and automation obligations are most explicit.

The Bodies

European And National Supervision

EIOPA

European Insurance and Occupational Pensions Authority

The European supervisory authority for insurance and occupational pensions. It issues guidelines, opinions and technical standards and coordinates national supervisors; day-to-day supervision of individual insurers remains national.

Relevance: EIOPA's work on digitalisation and on the ethical use of data in insurance sets the tone that national supervisors follow.
NCAs

National Competent Authorities

Supervision of individual insurers sits with national regulators — among them BaFin in Germany, the ACPR in France, IVASS in Italy, the DGSFP in Spain, De Nederlandsche Bank and the AFM in the Netherlands, and the Central Bank of Ireland.

Relevance: there is no single European counterparty. A pan-European deployment is twenty-seven supervisory conversations.
EDPB · DPAs

European Data Protection Board And National Authorities

The EDPB ensures consistent application of the General Data Protection Regulation; enforcement sits with national data protection authorities.

Relevance: direct. GDPR Article 22 restricts decisions based solely on automated processing producing legal or similarly significant effects.
AI Office

European Commission AI Office

Monitors implementation and compliance of the EU Artificial Intelligence Act, particularly for general-purpose AI models, alongside national market surveillance authorities.

Relevance: see the instrument list below.

Instruments

The Rulebook A Supplier Inherits

  • Solvency II (Directive 2009/138/EC), the prudential regime for insurers and reinsurers.
  • The Insurance Distribution Directive (Directive (EU) 2016/97), governing distribution and conduct.
  • The Motor Insurance Directive (Directive 2009/103/EC, as amended by Directive (EU) 2021/2118), governing compulsory third-party motor cover, minimum cover amounts, national guarantee funds and claims history statements.
  • GDPR (Regulation (EU) 2016/679), the baseline for any processing of claims data.
  • DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), applying from 17 January 2025. It sets ICT risk management, incident reporting, resilience testing and third-party risk requirements for financial entities including insurers, with a contractual regime for ICT service providers and an oversight framework for those designated critical. This is the single most supplier-relevant instrument in any jurisdiction on this site.
  • The EU Artificial Intelligence Act (Regulation (EU) 2024/1689), in force 1 August 2024 and applying in stages. Annex III lists AI systems used for risk assessment and pricing in health and life insurance as high-risk. (Per the Future of Life Institute's AI Act resource, updated 31 August 2026 following the Digital Omnibus amendments; see our AI page for the staged dates.)

The stated tension. Insurance Europe has said publicly that GDPR and the AI Act together constrain the industry's ability to collect and process the data it needs to detect fraud. (Insurance Europe, 5 December 2024.) The design question is how to satisfy both and evidence it. The market context is here.

On Accuracy. These pages name real bodies and real instruments. They are summaries for orientation, not legal advice, and not a substitute for the instruments themselves. Regulators and supervised firms who find an error here are invited to write to info@kempron.io; it will be corrected.

Jurisdictions that could not be sourced to this standard are not listed.

Regulators By Jurisdiction