GROUPAMA / 2019 Universal Registration Document

4 CORPORATE SOCIAL RESPONSIBILITY (CSR) Declaration of Extra-financial Performance

The issue of policyholder data protection (d) Is a key element of trust – and thereforepotential loss of trust if the risk materialises.The societal context is expandingon this subject, with increasing requests to “exercise personal rights” and the growing litigiousnessof relations. Cyber risk (attacks on the Group’s informationsystems),one of the most serious emerging risks in the sector, is addressed as part of the Group’sMajor Risks framework. Regarding the risk of non-compliantdata processing:the Group’s Code of Conduct specifies that the companies must ensure that any collectedand processedpersonal informationdoes not infringe privacy or individual freedoms. The companiesare also committed to respecting the rights of the data subjects and taking all necessary measures to protect theirconfidentiality. Since the GDPR  (3) came into force on 25 May 2018, the Group Data Protection Correspondent(CIL) has given way to the France DPO (Data Privacy Officer), who also takes over the duties of the Group CPO (CorporatePrivacy Officer). In anticipationof the entry into force of the regulation, the Group appointed a Group CPO in 2016. The interest in this designationlies mainly in the introduction of managementand coordinationof “PersonalData” governanceat the Group level by capitalisingon the frameworkfor governanceof personaldata implementedin Franceby the CIL (FranceDPO), thus reducing the risks. Each international subsidiary has also designateda DPO withits nationalsupervisoryauthority. The France DPO (& Group CPO), assisted by his/her team, fulfils this role and performs these duties for all companiesof the Group. The function of Shared France DPO is independent by law and reports to the General Secretary, a member of the General Management Committee of Groupama Assurances Mutuelles. It meets the legal and regulatory requirements governing the conditionsfor designationof a DPO and has been designatedwith the CNIL  (4) . This function is subject to a whistleblowingduty and must report on activities by preparing an “annual activity review” presentedto the datacontrollerand held available for the CNIL. With regard to personal data, compliance control is one of the duties carried out by the France DPO & Group CPO and his/her teams.The complianceof personaldata processingcoversnot only the above topics pertaining to the Group’s core business (non-life insurance, life insurance, asset management, property, etc.) but also all other topics as long as personal data are concerned ( e.g., human resources, video surveillance devices, service activities, etc.).

Prevention has taken shape over time throughmultiple individualor collective, innovative or original actions seeking to reinforce the safety of individuals and property on all of their private and professionalrisks. The deploymentof preventionactions conforms to a strategy specific to the Group, a source of expertise and legitimacy: integrationof dedicated resources (teams of prevention inspectors, Centaure centres, etc.), partnerships of excellence (Predict, Météo France, the Prévention Routière road safety association, national police force, highway companies, etc.), and local actions thanks to exceptional coverage of the territory. For example,the “Groupama,ma préventionmétéo” app has been extendedto beneficiariesregisteredon the “Groupama,toujours là” app, as part of the extension of the Groupama Predict service (prevention for local authorities) to individuals, professionals, and businessesfor all several regionalmutuals. The Group is developing – and will increasingly develop – prevention services in connection with the growth of connected objects (particularlythroughauto, home, health, with young people, seniors, professionals including farmers, businesses, etc.). Our preventionactionsgroup togetherfive majorareas: health,road safety, home risks, agricultural prevention, and industrial risks and local authorities. Content on prevention is regularly posted on the social networks, Twitter accounts, or Facebook pages of the various entities of the Group. Closer look at the Centaure centres (11 centresdedicated to road safety, of which Groupama is a shareholder alongside motorway companies): Centaure with Preventis Card Pro is recognised by the ● government application dedicated to the CPF  (1) launched in 2019. This application, managed by Caisse des Dépôts, allows the 30 million employees to register directly with their personal training account for certificate-issuing training courses eligible for the CPF. This training course is the only one among the thousands of certificate-issuing courses devoted toroad safety, apart from driving licences; In 2019, Centaure partnered with BMW Motorrad to provide ● motorcyclistswith one-day training to improve their everyday riding. This nationwide offering is unique in France. The trust and quality of our partner testify to Centaure’s ambition and ability toinnovatefor yearsto comein this new area. Performance indicator ● Number of people (internal and external)made aware of prevention actions in 2019:94,083 (85,472 in 2018). Centaure indicator (drivingcentres dedicatedto prevention) ● Number of trainees in the Centaure road accident prevention centres in 2019:38,775  (2) (37,733 in 2018).

Personal Training Account. (1) Including 660 roadworthiness tests. (2) General Data Protection Regulation. (3) French national data protection commission. (4)

78 Universal Registration Document 2019 - GROUPAMA ASSURANCES MUTUELLES

Made with FlippingBook Ebook Creator