Privacy Policy
Privacy
INTRODUCTION
Doha Insurance Group Privacy Policy
Last updated: 14th November 2025
1. About Doha Insurance Group (the Controller)
Doha Insurance Group Q.S.P.C. (“DIG”, “we”, “our”, “us”) is a publicly listed company regulated by the Qatar Central Bank (QCB) and licensed to provide insurance and reinsurance services.
Registered Address: 213, C Ring Road, Doha, Qatar
Commercial Registration Number: 22844
Contact Centre: +974 44292777
Official Website: online.dig.com.qa
Data Protection Officer (DPO): [email protected]
2. Purpose and Scope
This Privacy Policy explains how DIG collects, uses, stores, shares, and protects Personally Identifiable Information (PII) in accordance with Qatar’s Personal Data Privacy Protection Law (PDPPL), ISO/IEC 27701:2019, and Qatar Central Bank (QCB) regulations. It applies to all DIG services, including websites, mobile apps, call centres, brokers, branches, and subsidiaries, and to all visitors, customers, employees, contractors, and third parties interacting with DIG’s products, services, and digital platforms.
3. Definitions
Personal Data (PII): Any information relating to an identified or identifiable natural person.
Data Subject: The individual whose personal data is processed.
Controller: Entity determining the purposes and means of processing personal data.
Processor: Entity processing personal data on behalf of the controller.
Consent: Freely given, specific, informed, and unambiguous indication of the data subject’s wishes.
Data Breach: Any incident leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
4. Categories of Personal Data We Collect
Category
Examples
Identity & KYC Data
Full name, nationality, date/place of birth, QID/passport, gender, marital status, dependents, employer, job title
Contact Data
Address, email, phone numbers
Financial Data
Bank account, credit/debit card, salary, tax ID, income details
Policy & Contract Data
Product type, policy number, issue/expiry dates, premiums, claims history
Special Category Data
Medical records, health conditions, disability details, death certificates, genetic/biometric data
Risk & Underwriting Data
Vehicle details, property details, travel history, lifestyle or occupation risk factors
Anti-Fraud & Compliance Data
Sanctions, AML/CFT checks, criminal records, credit bureau reports
Surveillance Data
Visitor logs, CCTV, call recordings
Digital Data
IP address, geolocation, cookies, device/browser details, online interactions with DIG apps/websites
5. Data Collection and Processing Practices
DIG collects only the minimum personal data necessary for legitimate business purposes. Data is collected via online forms, applications, and other interactions, and is regularly reviewed to ensure minimization. Special categories of data (e.g., health, biometrics) are only collected with explicit consent and where legally required.
6. Legal Basis for Processing
DIG processes personal data based on:
- Contractual necessity: To deliver requested products/services.
- Legal obligation: To meet regulatory requirements (QCB, AML, MoPH).
- Legitimate interest: For business development, fraud prevention, and security.
- Consent: For direct marketing or where required by law.
- Vital interest: For emergencies.
7. Data Subject Rights
You have the right to:
- Access, correct, or delete your data.
- Restrict or object to processing (including marketing).
- Withdraw consent at any time.
- Request portability.
- Be notified of breaches within 72 hours.
- File a complaint with DIG or the National Cyber Security Agency (NCSA).
8. Consent Management
DIG obtains valid, informed consent before collecting or processing personal data. Consent requests are presented separately from other terms, written in plain language, and specific to each purpose. Consent is recorded, securely stored, and can be withdrawn at any time. Explicit consent is required for sensitive data. Cookie consent: Non-essential cookies are only set after explicit, informed user consent. Users can accept, reject, or customize preferences via a cookie banner.
9. Security and Confidentiality Measures
DIG applies security controls in accordance with ISO 27001, 27701, and 22309 standards. These controls include, but are not limited to:
- Encryption and pseudonymization.
- Role-based access and multi-factor authentication (MFA).
- Continuous security monitoring.
- Disaster recovery (DR) with backup in a secondary data center located in Qatar.
- Secure disposal of data at end-of-life.
- Privacy by Design and Default in all systems and processes.
10. Third-Party Sharing and Cross-Border Transfers
We may share data with subsidiaries, reinsurers, brokers, adjustors, TPAs, technology providers (hosting, cloud, payment gateways), regulators and authorities (QCB, MoPH, courts). International transfers: Your data may be transferred outside Qatar. DIG ensures compliance using Binding Corporate Rules, contractual safeguards, and adequacy decisions. DPIAs are conducted for high-risk transfers.
11. Retention and Disposal
- Policy term + 10 years.
- AML/KYC: minimum 15 years (QCB rules).
Data is securely deleted or anonymized after retention ends. DIG maintains defined retention periods, secure deletion, and records of disposal for compliance.
12. Automated Decision-Making
DIG may use automation for underwriting, fraud detection, and claims. You may request human review and contest decisions.
13. Children’s Data
DIG applies special safeguards for minors under 18. Parental/guardian consent is required. Child data is processed with enhanced security, age verification, and child-friendly privacy notices.
14. Compliance Monitoring and Breach Notification
DIG monitors compliance through regular audits, training, and management reviews. Any data breach is promptly reported to QCB, NCSA, and affected data subjects as required. Breach registers and incident logs are maintained, and corrective actions are taken to prevent recurrence.
15. Contact Us
Data Protection Officer (DPO): [email protected]
Call Centre: +974 44292777
Mail: Data Protection Officer, DIG, 213, C Ring Road, Doha – Qatar
16. Updates to this Notice
DIG may update this Notice from time to time to reflect legal, regulatory, or operational changes. Updated versions will be published on online.dig.com.qa and DIG mobile apps.