External Consumer Data and Information Sources

Data about consumers from outside an insurer's own records, such as credit reports, public records, and behavioral data. Heavily regulated in insurance.

External consumer data and information sources, often abbreviated as ECDIS, are data points about consumers that insurers obtain from outside their own policyholder records. Examples include credit reports, public records, social media data, purchase history, marketing data, and behavioral tracking.

ECDIS is a central concern in both New York and Colorado AI regulation. NYDFS Circular Letter No. 7 says insurers must be able to demonstrate that the ECDIS they use in underwriting and pricing is not prohibited by the Insurance Law, and it expects them to evaluate whether that data correlates with protected-class status. Colorado’s SB 21-169 aims a comparable demand at insurers through the Division’s rules, though the quantitative testing regulation that would set the actual standards remains in draft. The New York and Colorado state pages track where each of those regimes departs from the NAIC model bulletin, quoted and dated.

New York’s definition also carves four things out of ECDIS, which surprises carriers who assume the riskiest inputs are automatically in scope: an MIB Group member information exchange service, a motor vehicle report, prescription drug data, and a criminal history search. A criminal history search used in underwriting is governed separately, under Executive Law § 296(16).

The challenge for carriers is that ECDIS is often opaque. The insurer may not know exactly how a score was built, what variables it contains, or whether those variables proxy for protected classes. Governance programs should identify all ECDIS inputs, document their sources, and test the outcomes they produce across protected classes. See our guides to NYDFS Circular Letter No. 7 and the Fair Credit Reporting Act.

Primary sources

Last reviewed JUL 31, 2026