Buy Insurance   Online   now and on the go with NSIA Mobile

Privacy Notice

Privacy Notice

Effective Date: 07 September 2026

1. Introduction

NSIA Insurance Company Limited (“NSIA”, “we”, “our”, “us”) is a subsidiary of Groupe NSIA, a Pan-African financial services group founded in 1995 and headquartered in Abidjan, Côte d’Ivoire. NSIA has provided insurance services in Ghana since 2010, offering Non-life Insurance products including Motor, Travel, Fire, Marine, General Accident, and Engineering insurance.

Our registered address is: NSIA Insurance Company Limited, Justice DF Annan Street, Tesano-Accra, Ghana.

NSIA is a Data Controller under the Ghana Data Protection Act, 2012 (Act 843) (“the Act”). This means we determine the purposes and the manner in which your personal data is processed.

This Privacy Notice explains, in plain language, what personal data we collect, why we collect it, how we use and protect it, who we share it with, and the rights you have over it under the Act. We are committed to processing your personal data lawfully, fairly, and transparently, and to putting in place the safeguards the Act requires.

This Notice applies to:

  • Customers and prospective customers
  • Website and mobile platform users
  • Employees and job applicants
  • Intermediaries, agents, brokers and service providers
  • Visitors to our offices

2. Definitions

  • Data Controller: A person or organisation that, alone or with others, determines the purposes for which and the manner in which personal data is processed. NSIA is a Data Controller in respect of the personal data described in this Notice.
  • Data Subject: An individual who is the subject of personal data — for example, a customer, employee, or website visitor whose data we hold.
  • Personal Data: Data about an individual who can be identified from that data, or from that data together with other information in our possession or likely to come into our possession.
  • Data Processor: A person, other than an employee of the Data Controller, who processes personal data on behalf of the Data Controller (for example, an IT service provider).
  • Processing: Any operation performed on personal data, whether automated or not, including collecting, recording, organising, storing, retrieving, using, disclosing, combining, blocking, erasing, or destroying it.
  • Data Protection Supervisor: A person appointed by a Data Controller, in accordance with section 58 of the Act, to monitor the Data Controller’s compliance with the Act.

3. The Personal Data We Collect

Depending on your relationship with us, we may collect, use, store, and share the following categories of personal data:

Data Type Description
Identity Information First and last name, date of birth, nationality, marital status, photograph, Ghana Card (national ID) number, other government-issued identification, and biometric data (where required by law).
Contact Information Residential and postal address, city, email address, and telephone number.
Financial Information Bank account and payment details, premium payment history, card information, and other financial information relevant to policy administration and claims.
Technical Information IP address, device ID, browser information and language, operating system and version, and browser fingerprint.
Usage Data Browsing history, interaction logs (e.g., clicks, pages visited, time spent on our website), and how you use our website and digital services.
Location Data Real-time location (e.g., GPS) and IP-based approximate location, where relevant to a product or service (for example, motor telematics or claims verification).
Marketing and Communication Data Your preferences in receiving marketing communications from us, and records of your communications with us.
Employment Information For job applicants and employees: CVs, references, qualifications, background-check results, and other information provided as part of recruitment or employment.
Special Category Data Health information (for example, in connection with a General Accident, Travel, or life-related claim) and, where relevant, other special personal data described in section 37 of the Act. We only process this data where permitted under the Act, such as with your consent or where necessary to assess or settle a claim.

4. How We Collect Your Data

We collect personal data:

  • Directly from you — for example, when you request a quote, complete a proposal form, apply for a policy, submit a claim, or contact us.
  • Through transactions — including premium payments, policy renewals, and claims processing.
  • From third parties — including insurance intermediaries and brokers, co-insurance and reinsurance partners, credit bureaus, and regulators such as the National Insurance Commission (NIC).
  • Automatically via technology — through cookies and similar tracking technologies when you use our website.
  • From public sources — where the data has been made publicly available or its collection is otherwise permitted under the Act.

5. Why We Process Your Personal Data

We use your personal data for the following purposes:

  • Service Delivery: To provide quotes, issue and administer policies, and process claims.
  • Communication: To respond to enquiries, send service updates, and provide customer support.
  • Contract Management: To enter into and perform our contract of insurance with you.
  • Compliance: To meet our legal and regulatory obligations, including those owed to the NIC.
  • Risk Management: To assess insurance risk, detect and prevent fraud, and manage our exposure.
  • Website Administration: To operate, secure, and improve our website and digital services.
  • Marketing: To send you information about our products and services, where you have consented or as otherwise permitted by law.
  • Recruitment: To assess and manage job applications and, where successful, the employment relationship.
  • Security: To protect our people, premises, and systems, including through authentication and fraud-prevention controls.

6. Legal Basis for Processing

Section 20 of the Act requires that personal data is only processed with the data subject’s prior consent, unless one of the other lawful bases below applies. We rely on the following legal bases:

  • Contract: Processing necessary to enter into or perform our insurance contract with you — for example, issuing a policy or settling a claim.
  • Legal Obligation: Processing necessary to comply with a legal or regulatory duty — for example, reporting to the NIC, anti-money laundering checks, or responding to a lawful request from an authority.
  • Legitimate Interests: Processing necessary to pursue our legitimate interests, or those of a third party to whom the data is supplied, such as fraud prevention, risk management, and IT security — provided this does not unduly prejudice your rights.
  • Consent: Where none of the above applies — for example, direct marketing communications — we will ask for your consent, which you may withdraw at any time as described in section 7 below.

Where our processing is necessary for contractual or legal reasons, we do not rely on your consent as the legal basis, and withdrawing consent in those circumstances will not stop that processing.

7. Your Rights

Under the Act, you have the following rights in relation to your personal data:

  • Right of Access (section 35): To be told whether we hold personal data about you, and to receive a copy of it together with information about how and why it is processed.
  • Right to Rectification (section 33): To request that we correct personal data about you that is inaccurate, incomplete, or out of date.
  • Right to Erasure (sections 33 and 44): To request that we delete or destroy personal data that we are no longer authorised to retain.
  • Right to Restriction: To request that we stop processing your personal data in a specified manner where it causes, or is likely to cause, unwarranted damage or distress to you.
  • Right to Object (section 20(2)): To object to the processing of your personal data, in which case we must stop that processing unless the law provides otherwise.
  • Right to Data Portability: Although the Act does not use this term, where reasonably practicable we will provide your personal data to you in a structured, commonly used format upon a valid access request.
  • Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time. See section 7.1 below.
  • Right to Prevent Processing (section 39): To require us, by written notice, to stop or not begin processing your personal data for a specified purpose or in a specified manner.
  • Right to Prevent Direct Marketing (section 40): To require us, at any time, to stop processing your personal data for direct marketing purposes. See section 12 below.
  • Rights Relating to Automated Decision-Making (section 41): To be informed where a decision that significantly affects you is based solely on automated processing, and to require us to reconsider that decision.
  • Right to Complain: To lodge a complaint with the Data Protection Commission if you believe we have not handled your personal data in accordance with the Act. See section 16 below.

To exercise any of these rights, please contact our Data Protection Supervisor at sbiney@nsiainsurance.com.gh. We will respond within the timeframe required by the Act (for example, requests for access are addressed within 40 days, as required by section 35(10)), and we may need to verify your identity before acting on your request.

7.1 Withdrawing Your Consent

Where you have given consent for processing, you may withdraw it at any time by contacting us at sbiney@nsiainsurance.com.gh. Once we receive your withdrawal, we will stop the processing that was based on your consent, unless another lawful basis under the Act permits us to continue. Please note that if the withdrawn consent relates to processing that is necessary to provide a particular product or service, we may no longer be able to provide that product or service, or certain features of it, from that point onward.

8. Data Sharing and Disclosure

We may share your personal data with the following categories of recipients, for the purposes described:

Recipient Category Examples Purpose
Regulators and authorities National Insurance Commission (NIC), Data Protection Commission, other lawful authorities Regulatory reporting and compliance with legal obligations
Insurance intermediaries and partners Brokers, agents, co-insurers, and reinsurers Policy placement, risk-sharing, and claims administration
Service providers IT, cloud hosting, and professional advisers Delivering and supporting our services under contractual confidentiality obligations
Credit bureaus Licensed credit bureaus Verification and risk assessment, where applicable
Law enforcement Police and other lawful authorities Where required or authorised by law
8.1 Third-Party Website Services

Our website uses the following Google services, which may process personal data as described below:

Service Provider Purpose(s) Personal Data Involved Privacy Policy
Google Analytics Google Ireland Limited Analytics and performance tracking Device ID, IP address, browser information, usage and interaction data business.safety.google/privacy
Google Maps Google LLC Customising and improving user experience Approximate location, IP address, interaction data google.com/policies/privacy
reCAPTCHA Google Ireland Limited Fraud prevention and risk management Device ID, IP address, browser information business.safety.google/privacy

We do not sell your personal data.

9. Data Security

In line with section 28 of the Act, we take appropriate technical and organisational measures to protect your personal data against loss, damage, unauthorised destruction, and unlawful access or processing.

9.1 Technical Measures
  • Encryption of data in transit and at rest
  • Access controls limiting data access to authorised personnel on a need-to-know basis
  • Continuous security monitoring to detect and respond to suspicious activity
  • Regular security audits and vulnerability assessments
9.2 Organisational Measures
  • Staff training on data protection and information security
  • Confidentiality obligations imposed on staff and third-party service providers
  • Data minimisation — collecting only the data necessary for the stated purpose
  • Incident management procedures to detect, assess, and respond to security incidents
  • Oversight of vendors and data processors to ensure they meet our security standards

Your personal data is stored on secure servers located in Ghana (GH) and Côte d’Ivoire (CI). Where data must be transferred internationally, we ensure equivalent data protection safeguards are maintained, consistent with section 18(2) of the Act.

10. Data Retention

In accordance with section 24 of the Act, we do not keep personal data for longer than is necessary to achieve the purpose for which it was collected. Our retention approach is as follows:

  • Active Relationship: We retain your personal data for as long as your relationship with us (for example, an active policy) remains in place.
  • Post-Relationship: We retain your personal data for two (2) years after it is no longer necessary for the purpose for which it was collected, unless a longer period is required or authorised by law.
  • Regulatory Requirements: Where applicable law or regulation requires a longer retention period (for example, for claims, audit, or anti-money laundering purposes), we will retain the data for that longer period.

At the end of the applicable retention period, we destroy or delete personal data, or de-identify it, in a manner that prevents its reconstruction in an intelligible form, as required by section 24(6) of the Act.

11. Data Breach Notification

Section 31 of the Act requires us to notify both the Data Protection Commission and affected individuals where there are reasonable grounds to believe that personal data has been accessed or acquired by an unauthorised person. Our procedure is as follows:

11.1 Detection and Assessment

We monitor our systems to detect potential security compromises. Where a suspected breach is identified, we promptly assess its nature and scope, including the type of personal data involved and the likely impact on affected individuals.

11.2 Notification

Where the assessment confirms unauthorised access or acquisition of personal data, we will notify the Data Protection Commission and affected individuals as soon as reasonably practicable after discovery, in accordance with section 31(2) of the Act. Notification to affected individuals may be made by registered mail, email, prominent notice on our website, publication in the media, or any other manner directed by the Commission.

11.3 Communication and Support

Any notification will include sufficient information to allow you to take protective measures, including the nature of the compromise and, where known, the identity of the unauthorised person. We will also take steps to restore the integrity of the affected systems. If you have any questions or concerns about a data breach, please contact us at sbiney@nsiainsurance.com.gh.

12. Direct Marketing and Communications

In accordance with section 40 of the Act, we will not use, obtain, procure, or provide your personal data for direct marketing purposes without your prior written consent.

You are entitled, at any time, to notify us in writing that you do not want your personal data processed for direct marketing purposes, and we will comply with that request. This is separate from communications we send you that are necessary to service your policy (such as renewal notices or claims updates), which are not direct marketing and are not subject to opt-out on this basis.

Where we do send you direct marketing, we may do so via:

  • Email
  • SMS
  • Telephone
  • Social media platforms

To opt out of direct marketing at any time, contact us at sbiney@nsiainsurance.com.gh.

13. Children’s Privacy

Our services are intended for individuals aged 18 and above. In accordance with section 37 of the Act, we do not knowingly process personal data relating to a child who is under parental control without the consent of a parent or legal guardian, except where the Act otherwise permits.

If we become aware that we have inadvertently collected personal data from a child without the necessary parental consent, we will take prompt steps to delete that information from our records. If you believe we may hold personal data from a child without appropriate consent, please contact us immediately at sbiney@nsiainsurance.com.gh.

Parents or legal guardians may contact us to review, correct, or request the deletion of personal data relating to their child, using the contact details above.

14. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to operate reliably, remember your preferences, and help us understand how our website is used.

  • Essential Cookies: Necessary for the website to function, including authentication and security. These do not require consent.
  • Performance Cookies: Help us understand how visitors use our website, including through Google Analytics.
  • Functional Cookies: Enable enhanced functionality and personalisation, such as remembering your preferences.
  • Targeting Cookies: Used to deliver more relevant content and measure the effectiveness of our communications.

On your first visit, you will be presented with a cookie consent banner where you can accept all cookies, reject non-essential cookies, or customise your preferences. You may also manage or disable cookies through your browser settings, though this may affect certain website functions. Further detail on the specific third-party services used on our website is set out in section 8.1 above.

15. Updates to This Notice

We may update this Privacy Notice from time to time to reflect changes in our practices, our services, or applicable law. The effective date at the top of this Notice indicates when it was last updated.

Where we make a material change that affects your rights or how we handle your personal data, we will notify you through appropriate channels, such as our website or email, and will seek your consent where the Act requires it. We encourage you to review this Notice periodically.

16. Contact Us

If you have any questions about this Privacy Notice, or would like to exercise any of your rights under the Act, please contact:

Data Protection Supervisor
NSIA Insurance Company Limited
Justice DF Annan Street, Tesano, Accra, Ghana
Email: sbiney@nsiainsurance.com.gh / info@nsiainsurance.com.gh
General enquiries: info@nsiainsurance.com.gh
Phone: (+233) 302210180

If you are not satisfied with our response, you may escalate your complaint to:

Data Protection Commission
East Legon, Accra, Ghana
Phone: +233 256301533
Email: info@dataprotection.org.gh