End of Brexit transitional period may cause annuity issues for members resident in EEA
Following the end of the Brexit transitional period, UK insurance companies no longer enjoy "passporting" rights allowing them to conduct insurance business in the EEA. This has raised concerns that insurers may no longer be permitted to service annuity policies in respect of EEA residents. Some insurers have addressed this issue by transferring policies to an insurance company in the EEA. Some EEA member states have established "run off" regimes to ensure continuity of service in relation to policies already in existence at the end of the transitional period, but the terms of any such run off regime will vary between member states.
The opinion of the European Insurance and Occupational Pensions Authority (EIOPA) is that if a UK policyholder subsequently moves to the EEA, this does not give rise to cross-border business and so does not require the insurance company to be authorised in the EEA in order to continue to service the policy. However, EIOPA's opinion is not binding, so individual member states may interpret the rules differently, and we understand that France is adopting a more restrictive approach on this issue. In any event, EIOPA's opinion does not cover the position where a member is already resident in the EEA at the time the annuity policy is taken out, giving rise to the risk that both the issue of the policy and subsequently making payments under it could amount to carrying on business in the EEA.
A policy held in the name of UK-based trustees should arguably be viewed as solely UK business even if the member concerned is resident in the EEA, but whether individual member states would agree with this analysis remains untested. It is also unclear how individual member states would view the situation where a UK trustee transfers a policy into the name of a member resident in the EEA.
GDPR following end of Brexit transitional period
Following the end of the Brexit transitional period on 31 December 2020, the GDPR will be incorporated into "retained EU law" (ie EU law that is retained as part of UK law until such time as it is amended by UK legislation). The term "UK GDPR" will be used to refer to (a) the GDPR as it applied in the UK before the end of the transitional period, and (b) the version of the GDPR applicable in the UK following the end of the transitional period. The GDPR as it applies in the EU will be referred to as "EU GDPR". This means that there will effectively be two parallel data protection regimes with very similar requirements, one in the EU and one in the UK, though it is possible the two regimes may diverge over time.
The EU GDPR allows personal data to be freely transferred from one country to another within the EU. However, where personal data is being transferred outside of the EU, the person who is the data controller in relation to that data (generally the scheme trustees in a pensions context) must ensure that appropriate data protection safeguards are in place unless the European Commission has decided through an "adequacy decision" that the country to which data is being transferred has adequate data protection principles enshrined in its law.
During the Brexit transitional period, the UK was effectively treated as a member of the EU for data transfer purposes. Following the end of the transitional period, the Brexit deal provided for the continued free flow of data for up to six months following the end of the transitional period pending the anticipated adoption of a formal adequacy decision to allow free flow of data on a more permanent basis. On 19 February the European Commission published a draft decision to grant the UK adequacy status providing for the free flow of personal data between the UK and EU. The decision will remain in force for four years, but can be extended. The decision still needs to go through further approval processes, but we now have more certainty that the UK will be granted adequacy status before expiry of the current interim regime on 30 June 2021.
What does this mean for trustees?
If personal data is being shared with organisations in the EU, trustees need to monitor developments in relation to data transfer and be ready to put in place additional safeguards in the event that the expected adequacy decision fails to materialise. Trustees should also consider whether they have any contracts with provisions dealing with data transfer which need updating because they are drafted on the assumption that the UK is a member of the EU.