Which protocols apply to fraud investigations by an insurer?

23 September 2026
Picture of Arslan Advocaten

Arslan Advocaten

Foto van Arslan Advocaten

Arslan Advocaten

Need help urgently?

Choose a location

Which protocols apply to fraud investigations by an insurer?

A reference to “the fraud protocol” is not enough. In an insurance investigation, different rules may apply to personal data, medical information, investigations and fraud registration. Versions also change. Ask, therefore, which set of rules, which version and which section the insurer is applying to your file.

Nederlands: Lees dit artikel in het Nederlands: Welke protocollen gelden bij fraudeonderzoek door een verzekeraar?

Türkçe: Bu makaleyi Türkçe okuyun: Sigortacının dolandırıcılık soruşturmasında hangi protokoller geçerlidir?

Written by Onur Arslan, attorney at Arslan Advocaten. Do you have questions about your own situation? Get in touch.

Start with the date and the action

An investigation may begin under an old set of rules and later lead to a new decision. Note the dates on which data were collected, reported, rejected and registered. Then determine which rules apply to each action. The latest version is not automatically the only relevant standard for historical events.

In addition, distinguish between legislation, a sector code, policy conditions and internal work instructions. An internal instruction cannot override statutory privacy protection. Nor can a code of conduct simply be equated with a statute without further explanation.

Code of Conduct for Personal Investigations of 2011

The Code of Conduct for Personal Investigations 2011 (Gedragscode Persoonlijk Onderzoek, GPO) was withdrawn with effect from 1 January 2024. That code should therefore not be cited as an unchanged, current set of rules for every new investigation. It may still be relevant for older observations. The Dutch Association of Insurers (Verbond van Verzekeraars) describes the changes to self-regulation.

Withdrawal does not mean that a personal investigation may be carried out without limits. The GDPR, other applicable legislation and the relevant current sector rules remain important. Among other things, an investigation must have a legitimate basis and be appropriately limited in scope.

Processing of personal data

The Code of Conduct for the Processing of Personal Data by Insurers 2024 (GVPV) applies from 1 July 2024 within its scope. It must be read alongside the GDPR. Processing within the incident register and the External Reference Register (EVR) is governed by a separate protocol framework.

Ask which data were collected, for what purpose, who receives them and how long they are kept. A technical report may contain personal data; a report about complaints may also contain health data. The title given to a document does not change the nature of the data.

PIFI and fraud registrations

The PIFI 2026, the Dutch financial institutions’ incident warning protocol, governs incident registration and external referral within its scope. The conditions for inclusion, access and duration must each be assessed separately.

An ordinary claim entry in a system is not the same as an EVR fraud registration. An internal registration and an external referral also have different consequences. Ask the institution to state precisely where your data are recorded and on what grounds.

Personal injury and medical assessment

The Code of Conduct for Personal Injury Claims (GBL) and the accompanying Medical Section (Medische Paragraaf) focus on careful claims handling and medical assessment. They do not replace the rules of evidence for fraud, but they can help in assessing requests for information, communication and investigations.

Where the investigation is carried out by a private investigation agency, rules on private investigations and the professional position of the investigator may also be relevant. A quality mark or registration does not in itself prove that each individual investigation was carried out with due care. Ask for the specific assignment and method.

Frequently asked questions

Does the old GPO still apply to new investigations?

It was withdrawn with effect from 1 January 2024. For new actions, the applicable current framework must be established; for older actions, the old code may remain relevant.

Is PIFI also the general medical code of conduct?

No. PIFI concerns the incident warning system. Medical data and claims handling are governed by other frameworks as well.

Does a protocol error invalidate the entire report?

Not automatically. The nature of the breach and its consequences for the evidence and the decision must be assessed.

What should I ask the insurer?

The rules and version applied, the relevant dates, the investigation method and the separate legal grounds for any measures.

Read also about personal investigations, medical data and unlawfully obtained evidence.

Have the protocols that apply to your investigation and registration assessed.

This page provides general information and is not legal advice on your own situation. No rights can be derived from its content.


Related Legal Services

Share this message

Facebook
Twitter
LinkedIn

Categories

Personal injury

Recent Posts

Need help urgently?

Choose a location