AWP P&C S.A. (UK Branch) and AWP Assistance UK Ltd ('we', 'us' 'our'), part of the Allianz Group of companies are authorised and regulated by the Financial Conduct Authority in the United Kingdom to distribute insurance products and services. The insurance is provided by AWP P&C S.A. This is a French company authorised in France and acting through its UK Branch. AWP Assistance UK Ltd manages the day-to-day handling of your policy on AWP P&C S.A.’s behalf.

AWP Assistance UK Ltd also trades as Allianz, Allianz Assistance, Allianz Partners and Allianz Global Assistance.

Protecting your privacy is a top priority for us. This notice explains how and what type of personal data will be collected, why it is collected and with whom it is shared. Please read this notice carefully.

A data controller is the individual or legal person who controls the use of the data and is responsible for keeping it safe. The laws apply to personal data in both paper and electronic files.

AWP P&C S.A. (UK Branch) is your insurer and the data controller for the personal data described in this notice. AWP Assistance UK Ltd, a fellow Allianz Partners Group company, manages the day-to-day handling of your policy on behalf of AWP P&C S.A. (UK Branch), including managing requests to exercise your data protection rights (such as subject access requests).

Our Data Protection Officer (DPO) can be contacted at: AzPUKDP@allianz.com or by post at Customer Service (Data Protection), AWP Assistance UK Ltd, 102 George Street, Croydon CR9 6HD.

We will collect and process different types of personal data about you as follows:

  • data relating to the identification of persons who are parties, interested or involved in the contract; 
  • interactions with automated systems, including virtual assistants (such as “voicebot” or similar artificial intelligence technologies), and
  • any other data necessary for the conclusion and/or performance of the contract.

In this context, we may collect and process "sensitive personal data" relating to you.

NOTE: Where we collect personal data about third parties from you (for example, other policyholders, beneficiaries, witnesses or people to be notified in an emergency), we ask you to make those individuals aware that their personal data will be shared with us.

We collect personal information direct from individuals, their representatives, business partners, digital applications (such as the Allianz Service Partner app and Allianz Provider app) or from information they have made public, for example, on social media. We also collect personal information from other persons or organisations, for example: emergency services, law enforcement agencies, medical and legal practices; fraud prevention agencies and industry registers and databases used to detect and prevent insurance fraud; other insurers or service providers who underwrite the insurance or provide the services for our products, other Allianz Group companies. We use technology on our website, apps and emails, such as the use of cookies or small text files on our website or pixels within emails.

Depending on the type of insurance product or service we provide to you, we will collect and process various types of personal data about you including:

  • Surname, first name
  • Address
  • Place of residence
  • Date of birth
  • Gender
  • Telephone numbers
  • Email address
  • Credit/debit card and bank account details
  • CCTV / video images (we may collect this if you visit one of our offices)
  • Location / GPS information
  • Flight and travel plans
  • Call recordings (phone coversations with us)
  • Medical information
  • Policyholders and anyone named on or covered by the policy
  • Data relating to children in some circumstances, for example where the child is a beneficiary under a policy or is involved in a claim (sensitive data)
  • Anyone who may benefit from or be directly involved in the policy or a claim, including claimants and witnesses
  • Anyone seeking an insurance quote from us or whose details are provided during the quotation process
  • Identification checks and details including previous claims information
  • Tracking and location information if it is relevant to the insurance policy or claim
  • Voice when you use the digital/virtual assistant tool (Voicebot or equivalent)
  • Customer satisfaction surveys on the services/products
  • IP addresses and information about the technology you are using
  • Where applicable, we’ll collect data relating to criminal offences, including previous criminal convictions, bankruptcies and other financial sanctions such as County Court Judgements
  • Information collected from your devices relating to your use of our websites, including via the use of cookies
  • In the event of a claim under our warranty and roadside assistance products where a hire car is provided, we will collect and process data relating to driving related convictions which may affect our ability to provide a hire car to you
  • We may also collect and process special category data about you, such as medical information, where you have purchased a travel product from us or in case of 3rd party electric bicycle and electric scooter rental
  • In the event of a claim we may need to obtain and share data with retailers and authorised repairers; where the device was purchased or repaired (for mobile device and retail product insurance)
  • We may also need to collect and process special category data about you, such as medical information.
     
We will collect and process your personal data that you communicate to us,  that we receive from third parties and call recordings of phone conversations with us (as explained below) for a number of purposes and subject to your express consent, unless the latter is not required by applicable laws and regulations as shown below:

Swipe to view more

Purpose Is your express consent required?
Quote and subscription to the insurance contract. No, to the extent that the activities of processing are necessary to execute the insurance contract to which you are a party and to take the necessary steps to put the insurance in place prior to the conclusion of this contract.
Administration of the insurance contract (i.e. handling claims and complaints, investigating claims and seeking confirmations necessary to determine the existence of an insured event and the amount of compensation to be paid or the type of assistance to be provided etc. in relation thereto.

For ordinary personal data:

No. Processing is necessary to perform the insurance contract (Article 6(1)(b)) or is based on our Legitimate Interests in managing claims, and vulnerable customers (Article 6(1)(f)).

For special category data including health data:

No. Explicit consent is required where we rely on the DPA 2018 Schedule 1, paragraph 20 insurance condition — processing necessary for an insurance purpose (including administering a claim) in the public interest. This applies to the majority of health data processed in connection with claims.

Where we need to process your special category data to monitor the treatment of vulnerable customers or those with protected characteristics, we rely on DPA 2018 Schedule 1, paragraph 9 (equality of opportunity and treatment) or, where appropriate, the insurance condition. Explicit consent under Article 9(2)(a) is only sought for specific processing activities that fall outside the insurance condition and for which no other Schedule 1 condition is available.

To conduct quality surveys on the services provided, in order to assess customer satisfaction and improve it.

No. Our specific Legitimate Interest is to ensure that we have fulfilled our contractual obligations satisfactorily and to identify service improvements. We have assessed that this interest is proportionate and does not override your rights. You have the right to object at any time to this processing by contacting us as explained in section 12 below. On receipt of a valid objection, we will cease processing your data for this purpose.

To comply with any legal obligations (for example, those arising from laws that apply to insurance contracts and insurance activities, compliance with tax obligations, accounting laws and administrative obligations.

No. In these circumstances, the processing activities are expressly and legally permitted without the requirement for express consent.

For verifications purposes, to comply with legal and/or contractual obligations or internal procedures.

No. We may process your personal data as required to comply with both internal or external audit requirements that are required  by law or external/internal procedures. We will not request your express consent for these purposes if the reason for processing is justified under the regulations in force or under our Legitimate Interest. However, we will ensure that only personal data that is strictly necessary will be used  for this purpose and that the data will be held in strict confidentiality.

To analyse the data for the purposes of carrying  out statistical and qualitative analysis based on the rate of compensation claims.

No. In these circumstance, we will only be processing anonymised personal data. Anonymized data is not considered to fall into the category of personal data and your express consent is therefore not required.

For debt collection management (i.e. to request payment of the premium or claims from third parties, allocating compensation between different insurance companies covering the same risk)

No, our specific Legitimate Interest is in recovering premiums owed, managing subrogation, and allocating compensation between co-insurers. Where this involves the processing of special category data (such as health data relevant to the disputed claim), we rely on Article 9(2)(f) of the UK GDPR (processing is necessary for the establishment, exercise or defence of legal claims), without requiring explicit consent. You may object to processing based on Legitimate Interests by contacting us as set out in section 12.

For the purposes of  detecting and preventing fraud, compliance with anti-money laundering requirements and compliance with applicable civil and/or criminal regulations, including, economic sanctions and where applicable, the comparison of your information to that appearing on previous requests/claims with us or other organisations.

No. Our specific Legitimate Interest is to detect, prevent and investigate insurance fraud, money laundering, economic sanctions breaches and other unlawful acts, in order to protect our business, our customers and the wider insurance market. From February 2026, certain fraud prevention processing also qualifies as a Recognised Legitimate Interest under Article 6(1)(ea) of the UK GDPR as amended by the Data (Use and Access) Act 2025. You have the right to object to processing based on Legitimate Interests by contacting us as set out in section 11, although we may be able to demonstrate compelling legitimate grounds that override your objection where fraud prevention is concerned.

To transfer risk via reinsurance and co-insurance

We may process and share your personal data with other insurance or reinsurance  companies with which we have signed, or will sign agreements of coinsurance or reinsurance. Coinsurance is where a risk is covered by several insurance companies by means of a single contract, each assuming each a percentage of the risk or in dividing the covers between them. Reinsurance is  an insurance policy covering an insurer's exposure to a policy or class of policies that it has insured. However, this is an internal agreement between us and the reinsurer and you have no direct contractual link to it. These risk transfers occur under the Legitimate Interests of an insurance  company which are generally authorised by law (including sharing personal data strictly necessary for this purpose).

Additional requirements for Call Recordings

 

Recording calls is a standard practice aimed at ensuring quality monitoring, providing training, and fulfilling legal and compliance obligations.

 

The recordings are encrypted and stored securely. Only authorised and trained personnel will use these recordings for the purposes outlined in this privacy notice.

 

For ordinary personal data captured in call recordings:

No. Our primary lawful bases are:

  • Legal obligation (Article 6(1)(c)):
  • Contract performance (Article 6(1)(b)): where a recording documents the terms of an insurance contract agreed on the call;
  • Legitimate Interests (Article 6(1)(f)): for quality monitoring, staff training, fraud detection and demonstrating regulatory compliance.

For special category data (e.g. health information discussed during a travel or personal accident claim call):

No. Explicit consent is required. We rely on the DPA 2018 Schedule 1, paragraph 20 insurance conditions (substantial public interest, insurance purpose). You will be informed by automated message at the start of a call that it may be recorded and for what purposes. You have the right to object to processing based on legitimate interests by contacting us as set out in section 12.

However, in cases where we may need to:

  • assist in the quality monitoring of staff performance, to investigate any concern you express about our dealings with you, and preventing or detecting fraud and/or abuses; or
  • to cooperate with public and government authorities, courts or regulators in accordance with our legal obligations under applicable laws to the extent this requires the processing or disclosure of personal data to protect our rights or is necessary for our legitimate interest in protecting against misuse or abuse of our business, protecting personal property or safety, pursuing remedies available to us and limiting our damages, complying with judicial proceedings, court orders or legal processes; or
  • to demonstrate compliance with regulatory obligations,

we will not request your express consent for these purposes if the reason for processing is justified under the regulations in force or under our Legitimate Interest.


From time to time:

  • We may wish to inform you, or permit Allianz Group companies and selected third parties to inform you about products and services that we feel may be of interest to you in accordance with your marketing preferences.  However, we can only do this with your express written consent or on the basis of Legitimate Interests. You can change your mind about this at any time by contacting us as set out in section 11 below.
  • We will process personal data we receive about you from third parties such as brokers and business partners, other insurers and fraud prevention agencies.
  • We will process your personal data where it is necessary for us to comply with our legal and/or contractual obligations to you, or where we need to take pre-contractual steps at your request.
  • We will process your personal data where it is necessary for us to comply with our legal and/or contractual obligations to you, or where we need to take pre-contractual steps at your request.We will process your personal data where necessary for the purposes of our legitimate interests.

    'Legitimate interests' means the interests of our company in conducting and managing our business, to enable us to give you the best service/products and the best and most secure experience. For example, we may process your information to invite you to complete a customer feedback survey, to renew your policy upon expiry or protect you against fraud when transacting on our website and to ensure that our websites and systems are secure. When we process your personal information for our legitimate interests, we make sure that we consider and balance any potential impact on you and your rights under data protection laws. Our legitimate business interests do not automatically override your interests. We will not use your personal data where our interests are overridden by the impact on you (unless we are required or permitted by law).
  • 'Special category data' is personal data which is regarded as more sensitive and so needs greater protection, such as health records. Where we process special category data (including medical information) in connection with insurance distribution, administration, claims handling, or the exercise of rights under an insurance contract, we rely primarily on Schedule 1, paragraph 20 of the Data Protection Act 2018 (the insurance condition) — processing necessary for an insurance purpose that is in the substantial public interest. This applies, for example, to health data collected when you purchase a travel product, make a personal accident claim, or use our 3rd party electric bicycle and electric scooter rental product. We maintain an appropriate policy document as required by Schedule 1, paragraph 39 of the Data Protection Act 2018, which is available to the Information Commissioner on request.

    In a medical emergency, where we must share your health data urgently with doctors, hospitals or airline companies for repatriation purposes, we may additionally rely on Article 9(2)(c) of the UK GDPR (vital interests) where you are physically or legally incapable of giving consent at the relevant time. Outside of genuine emergencies, vital interests is not used as a routine basis. Where we share special category data with other business partners (such as banks or mobility companies) for the purpose of ensuring fair outcomes for you, we do so on the basis of the insurance condition, regulatory requirement or, where applicable, your explicit consent. In some instances, and where applicable, we may also process your data to ensure that we achieve fair outcomes across the board for our customers.
  • We will need your personal data and use it for the purposes described above if you would like to buy our products and services.  If you do not wish to provide this to us, we may not be able to provide the products and services to you.
  • CCTV cameras are in operation at our offices for health and safety, prevention of crime and prevention of damage to our building and company assets. We may collect video recordings and still pictures which feature you, if you are in the field of vision of any of our CCTV system. These images are only held for a period of ninety days.
  • Voice recognition technology (such as Voicebot or equivalent) may be used for initial interaction with you when you call us to understand the reason for your call and/or to re-direct your call to the relevant department.  We may collect such voice recordings which are held for at least 2  years and up to a retention period determined by the purpose of the call (see section 8). The voicebot and associated AI technologies are used solely for call routing, query understanding purposes. They do not use your voice to uniquely identify or authenticate you as an individual (biometric identification) and accordingly do not constitute processing of biometric data within the meaning of Article 4(14) of the UK GDPR. If this use changes in future, we will update this notice and obtain any additional consent or authorisation required before doing so. The lawful basis for voicebot processing is our Legitimate Interest (Article 6(1)(f)) in efficiently routing calls and improving service delivery, and legal obligation (Article 6(1)(c)) where applicable regulatory requirements apply. You have the right to object to processing based on Legitimate Interests by contacting us as set out in section 12.
  • Where AI is used as part of a decision-making process that has a legal or similarly significant effect on you, we ensure that meaningful human involvement is applied before any such decision is taken or confirmed, consistent with Articles to 22D of the UK GDPR as amended by the Data (Use and Access) Act 2025. This means a human agent will review and, where appropriate, override any AI-generated outcome before it affects you. See section 9 for further detail on automated decision-making.
  •  

We will ensure that your personal data is processed in a manner that is compatible with the purposes indicated above.

For the reasons stated above, your personal data may be disclosed to the following parties who operate as third party data controllers depending on the type of policy you have bought from us:

  • Other Allianz Group companies, industry governing bodies, regulators, fraud prevention agencies and claims databases, for underwriting and fraud prevention purposes;
  • Our external providers who provide services necessary for the provision of our services, call centres, IT companies, and consulting and auditing companies;   
  • Third-party providers that perform services for us, such as service providers at home and abroad who process personal data about you on our behalf or in joint responsibility with us, or receive personal data about you from us within their own sphere of responsibility;
  • The manufacturer of your vehicle and their franchised dealers, authorised repairers and vehicle recovery operators;
  • The manufacturer of your mobile device and their franchised dealers and authorised repairers;
  • Retailers of insured products;
  • Doctors and other health professionals concerning your medical conditions, in the event of a medical emergency, or personal accident;
  • Other business partners such as banks and mobility companies linked to your product for reporting purposes and product performance analysis to help identify ways to improve the product and customer experience (where they are also a Data Controller and they carry out processing on the basis of their and our legitimate interest to improve our products and services). In some instances, this may also include the sharing of special category data to ensure that we arrive with fair outcomes for you;
  • Any organisation where you have agreed for them to receive that data as part of the terms and conditions of your membership or affiliation; 
  • Airline companies in the event of repatriation; and
  • Competent public authorities or other third parties (if required by law or reasonably necessary to protect the rights, property and safety of ourselves or others).  

For the reasons stated above, we may also share your personal data with the following, who act as data processors under our instruction:

  • Other Allianz Group companies; experts such as technical consultants, lawyers and loss adjustors; repairers, taxi companies and car hire companies in the event of a claim under our warranty or roadside assistance products; ticket sellers under our event cancellation products; homecare providers under our homecare products; engineers to provide boiler breakdown and repair services under our home emergency products; third party repairers in respect of our appliance protection products; service companies to discharge operations (claims, IT, postal, document management); 
  • Advertisers and advertising networks to send you marketing communications, as permitted under local law and in accordance with your communication preferences.  We do not share your personal data with non-affiliated third parties for marketing purposes without your permission; and
  • Providers of data services and data analysts who support us with developing our products and enhancing customer service and experience.

Finally, we may share your personal data in the following instances:

  • In the event of any contemplated or actual reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in any insolvency or similar proceedings); and
  • To meet any contractual and/or legal obligation, including to the Financial Ombudsman Service if you make a complaint about the product or service we have provided to you.

Your personal data may be processed both inside and outside of the United Kingdom (UK) and the European Economic Area (EEA) by the parties specified in section 4 above, subject always to contractual restrictions regarding confidentiality and security in line with applicable data protection laws and regulations.  We will not disclose your personal data to parties who are not authorised to receive it.

Whenever we transfer your personal data for processing outside of the UK and the EEA to another Allianz Group company, we will do so on the basis of appropriate safeguards recognised under the UK GDPR, such as a Data Protection Agreement incorporating the UK's International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, or another approved transfer mechanism. These arrangements are legally binding and are designed to ensure that your personal data receives the same high level of protection wherever it is processed, regardless of where it is transferred. Where these specific mechanisms do not apply, we will instead take steps to ensure that the transfer of your personal data outside of the UK and the EEA receives the same level of protection as it does in the UK and the EEA.

Where permitted by applicable law or regulation, you have the following rights in relation to your personal data:

  • Right of access: to receive confirmation of whether we process the personal data about you and if so, to access the personal data and information about the origin of the data, the purposes and basis of processing, the data controller and processor and the parties to whom the data may be disclosed;
  • Right to withdraw consent: where processing is based on your consent (including explicit consent for special category data), you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal;
  • Right to rectification: to have inaccurate personal data corrected or incomplete data completed;
  • Right to erasure (“right to be forgotten”): to request deletion of your personal data where it is no longer needed for the purposes for which it was obtained, where you have withdrawn consent (and there is no other legal ground for processing), or where processing is unlawful. Note: that we may be entitled to retain certain data for legal, regulatory or claims-handling purposes;
  • In respect of call recordings specifically: we can delete a call recording on request. If we do so, we may retain a written note of the substance of the conversation;
  • Right to restriction of processing: to request that we limit how we use your personal data in certain circumstances, for example while the accuracy of data is being verified;
  • Right to data portability: where processing is based on your consent or on contract performance and is carried out by automated means, you may request that we provide your personal data in a structured, commonly used, machine-readable format for you or, where technically feasible, for transmission directly to another controller (such as a new insurer);
  • Right to lodge a complaint: you have the right to lodge a complaint with us directly or with the Information Commissioner's Office (ICO). The ICO can be contacted at: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; telephone: 0303 123 1113; website: www.ico.org.uk.

You may exercise these rights by contacting us as detailed in section 12 below. 

Since 19 June 2026, where we receive a complaint from you under this section, we must acknowledge receipt of your complaint within 30 days of receiving it. Without undue delay, we will then take appropriate steps to respond to your complaint, including making enquiries into its subject matter to the extent appropriate and keeping you informed of progress, and we will inform you of the outcome.

You also have the right to make a complaint directly to us about how we have handled your personal data; we will investigate and respond to your complaint. You can raise your complaint by means such as phone, email or by post. If you are not satisfied with our response, you may also complain to the Information Commissioner's Office as set out above.

Right to object (Article 21 UK GDPR) - IMPORTANT: Where we process your personal data on the basis of our Legitimate Interests (Article 6(1)(f)) - including for quality surveys, marketing, fraud prevention, or other purposes identified in Section 3 above - you have the right to object at any time on grounds relating to your particular situation.

Once you have objected, we will stop processing your data for that purpose unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms, or the processing is necessary for the establishment, exercise or defence of legal claims.

Where your personal data is processed for direct marketing purposes (including profiling related to direct marketing), you have an absolute right to object at any time, with no requirement to give reasons, and we will stop processing immediately. You may exercise your right to object by contacting us as set out in Section 12.  

We retain your personal data only for as long as is necessary for the purposes for which it was collected, in accordance with the storage limitation principle.

Our standard retention periods by product or processing activity are:  

  • For voice recordings, a minimum of two (2) years, up to a maximum retention period of 10 years.
  • For all other data, we will retain your personal data for a maximum of 10 years from the date the insurance relationship ends.
  • CCTV images: 90 days from the date of recording.

Where a legal hold applies (for example, in connection with litigation, a regulatory investigation, or an outstanding claim), we may retain relevant data beyond these standard periods for the duration of that hold. Where data is no longer required for the purpose for which it was obtained, we will delete or anonymise it as soon as reasonably practicable.

We may use automated-decision making, including profiling and AI supported technologies, to assess insurance risks, detect fraud, and administer your policy. This helps us decide whether to offer insurance and determine prices.

The rules governing such processing are set out in Articles 22A–22D of the UK GDPR, as amended by the Data (Use and Access) Act 2025.

A significant decision is one based solely on automated processing that produces a legal effect for you or has a similarly significant effect on you.

  • Underwriting (acceptance/rejection and pricing): When you purchase a travel insurance product, we carry out automated decision-making to determine whether to offer cover. For example, we may accept or reject an application based on age; if accepted, the automated calculation of a person's age may be used to determine the premium payable. Where a rejection is based on automated processing and involves health or other special category data, we rely on explicit consent under Article 9(2)(a) or, where applicable, the DPA 2018 Schedule 1, paragraph 20 insurance condition, together with a requirement or authorisation under law.
  • Online medical screening: We ask customers to respond to a series of medical questions. The responses are processed using automated rules to determine whether the customer is accepted or rejected for cover and whether an additional premium applies to cover a pre-existing medical condition. The logic applied is: if the disclosed condition falls within a pre-determined list of conditions for which cover is not available or is restricted, the system applies a loading or exclusion accordingly. This is an automated application of our underwriting criteria.
  • Claims processing: We use automated technologies including Optical Character Recognition (OCR) and workflow automation to check the completeness of submitted information and documents and validate them against your policy terms. Automated assessment is used only where it results in a decision to uphold your claim in full (subject to any agreed excess). All other outcomes - partial payment, rejection, or any outcome requiring discretion - are reviewed by a human agent.

Your safeguards for significant automated decisions (Article 22C) are:

  • You will be informed when a significant decision has been made about you by automated means.
  • You have the right to make representations to us about the decision.
  • You have the right to request human intervention on our part in relation to the decision.
  • You have the right to contest the decision.

To exercise any of these rights, please contact us using the details in section 12. We will arrange for a qualified person to review the decision.

In all cases involving automated decisions, you may contact us at the details set out in section 12 to exercise your Article 22C rights, including the right to have a person review the outcome. Our complaints process is also available to you if you believe a decision has been made in error.

We handle recorded calls securely and take appropriate technical and organisational security measures to protect the confidentiality, integrity and availability of your personal data, to protect it against unauthorised or unlawful processing and to protect it against the risk of loss, accidental alteration, unauthorised disclosure or access. We use recognised security standards such as ISO 27001. However, security risks cannot generally be ruled out completely; certain residual risks are unavoidable. When recorded calls are transmitted, we protect those during transmission using suitable encryption mechanisms. However, we can only secure areas that are under our control. 

If you have any queries about how we use your personal data, you can contact us through the dedicated portal to exercise your rights under applicable data protection laws:

a.      AWP Assistance UK Ltd portal:
AzP UK Data Privacy Portal

 

b.      AWP P&C (UK Branch) portal:
AWP P&C UK Data Privacy Portal

 

c.       By email:
AzPUKDP@allianz.com

 

d.      By post:
Customer Service (Data Protection), AWP Assistance UK Ltd, 102 George Street, Croydon CR9 6HD

We will need details of your name, email address, policy number, and purpose of your request.

We regularly review this privacy notice. This privacy notice was last updated in September 2026.