Regulators · European Union
The European Union Framework.
One regulatory ceiling over twenty-seven national claims markets, and the densest set of supplier-facing obligations of any jurisdiction described on this site.
Kempron does not operate in the European Union. The EU framework is where supplier and automation obligations are most explicit.
The Bodies
European And National Supervision
European Insurance and Occupational Pensions Authority
The European supervisory authority for insurance and occupational pensions. It issues guidelines, opinions and technical standards and coordinates national supervisors; day-to-day supervision of individual insurers remains national.
National Competent Authorities
Supervision of individual insurers sits with national regulators — among them BaFin in Germany, the ACPR in France, IVASS in Italy, the DGSFP in Spain, De Nederlandsche Bank and the AFM in the Netherlands, and the Central Bank of Ireland.
European Data Protection Board And National Authorities
The EDPB ensures consistent application of the General Data Protection Regulation; enforcement sits with national data protection authorities.
European Commission AI Office
Monitors implementation and compliance of the EU Artificial Intelligence Act, particularly for general-purpose AI models, alongside national market surveillance authorities.
Instruments
The Rulebook A Supplier Inherits
- Solvency II (Directive 2009/138/EC), the prudential regime for insurers and reinsurers.
- The Insurance Distribution Directive (Directive (EU) 2016/97), governing distribution and conduct.
- The Motor Insurance Directive (Directive 2009/103/EC, as amended by Directive (EU) 2021/2118), governing compulsory third-party motor cover, minimum cover amounts, national guarantee funds and claims history statements.
- GDPR (Regulation (EU) 2016/679), the baseline for any processing of claims data.
- DORA, the Digital Operational Resilience Act (Regulation (EU) 2022/2554), applying from 17 January 2025. It sets ICT risk management, incident reporting, resilience testing and third-party risk requirements for financial entities including insurers, with a contractual regime for ICT service providers and an oversight framework for those designated critical. This is the single most supplier-relevant instrument in any jurisdiction on this site.
- The EU Artificial Intelligence Act (Regulation (EU) 2024/1689), in force 1 August 2024 and applying in stages. Annex III lists AI systems used for risk assessment and pricing in health and life insurance as high-risk. (Per the Future of Life Institute's AI Act resource, updated 31 August 2026 following the Digital Omnibus amendments; see our AI page for the staged dates.)
The stated tension. Insurance Europe has said publicly that GDPR and the AI Act together constrain the industry's ability to collect and process the data it needs to detect fraud. (Insurance Europe, 5 December 2024.) The design question is how to satisfy both and evidence it. The market context is here.
On Accuracy. These pages name real bodies and real instruments. They are summaries for orientation, not legal advice, and not a substitute for the instruments themselves. Regulators and supervised firms who find an error here are invited to write to info@kempron.io; it will be corrected.
Jurisdictions that could not be sourced to this standard are not listed.