Automated screening, without an automated decision about a person.
General counsel don't reject a screening vendor over the technology — they reject it over the questions it can't answer: Art. 22 GDPR exposure, who is liable when a report is wrong, and whether "GDPR-compliant" was ever actually tested against revDSG. Indicium answers all three before you sign, not after.
Three questions a screening vendor rarely answers straight.
VAG-ready reports, with the mapping as your contract annex.
Insurers supervise their outsourcing under their own logic. We deliver the report already shaped for it, rather than asking your team to translate a generic vendor report into your framework.
| Framework | What it requires | How Indicium documents it |
|---|---|---|
| VAG-Outsourcing (§ 32 VAG) | Insurance-specific outsourcing rules, BaFin supervisory & audit rights | Contract annex following § 32 VAG logic, with audit/instruction rights for you and your supervisor |
| EIOPA outsourcing guidelines | Concentration & substitutability risk assessment, register of outsourcing arrangements | Honest concentration/substitutability assessment; sample register entry on request |
| revDSG | Proportionality, data-subject rights, cross-border transfer logic distinct from GDPR | revDSG-native processing; CH↔EU transfer basis set out before signing |
| Art. 22 GDPR | No solely automated decision with legal effect about a person | Human final review at fixed trigger thresholds, four-eyes principle, audit trail |
Separately named, not merged: §203 StGB and §43e BRAO professional-conduct confidentiality apply wherever a check touches a privileged relationship — a distinction we keep explicit in the contract rather than folding it into a generic data-protection clause.
Sovereign deployment on request. Liability allocated before signing, not after.
One of Germany's largest insurance groups already runs on Indicium — under NDA, so we don't publish the name, but we can speak to the engagement directly on a call with your team.
From portfolio screening to the fraud-adjacent individual case.
Does Indicium make an automated decision about a person under Art. 22 GDPR?+
Is this built for Swiss revDSG, or is it GDPR with a Swiss flag on it?+
How does liability allocate if a report turns out to be wrong?+
What about § 32 VAG outsourcing requirements and EIOPA guidelines?+
Can we get a sovereign or on-premises-adjacent deployment?+
This page provides general information about Indicium's services and the regulatory frameworks named above (VAG, EIOPA guidelines, revDSG, GDPR). It does not constitute legal or regulatory advice and does not replace an assessment by your own counsel for your specific case. Regulatory mapping reflects our understanding of the cited frameworks and does not guarantee a particular compliance outcome or supervisory acceptance.