FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →

IT and data

Professional indemnity insurance for database and data migration specialists

Yes: database and data migration specialists need professional indemnity insurance, because the work is judged on complete, accurate, usable data arriving at the other end and nothing readable left behind. A failed cutover, a mapping error or a missed copy on an old server causes financial loss rather than physical damage, so public liability will not respond. PI usually pays to defend those allegations and any compensation you owe. Cyber insurance sits alongside it for your own costs if an attack or breach hits during a project.

In short

Migration, database administration and secure data removal share one risk: the client relies on you for data it cannot easily recreate. Under the UK GDPR the accidental loss, destruction or alteration of personal data is a personal data breach, so a corrupted migration can be a regulatory event as well as a contract dispute. If you wipe or destroy media, your certificate of destruction is a statement the client relies on, and the ICO tells controllers to check certificates against what they sent. PI usually covers claims that your work was negligent; cyber covers your own response costs. Expect insurers to ask about testing, rollback and sanitisation methods.

Start your PI proposal →or call 0117 325 0027 to speak to a broker

Why data professionals need PI rather than public liability alone

Last reviewed 5 October 2026 by the Apex professional indemnity team.

Data work is judged by what arrives at the other end. After a migration the client expects every record to be present, correctly transformed and usable on the first working day. After a database support call it expects its backups to restore. After secure removal it expects nothing readable to remain on the media you took away. When any of that fails, the result is rework, downtime, wrong invoices, regulatory exposure or lost customers: financial loss, not physical damage.

Public liability insurance covers accidental injury and accidental damage to third-party property. If you knock a server off a rack at a client’s site, that is a public liability matter. If your transformation script silently truncates ten years of customer notes, it is not. That allegation is that you failed to use the skill and care of a competent data professional, and professional indemnity insurance is the policy written for it.

The gap is wider than it looks, because data loss is easy to cause and slow to discover. A mapping error may not show until month-end reporting, a missed staging copy until it turns up somewhere it should not be, and a failed backup only on the day a restore is needed.

How claims arise on migration and database work

These scenarios are illustrative, not real claims. Each shows what went wrong, who lost money and what they allege.

  1. A cutover with no way back. An ERP migration goes live over a weekend. Reconciliation on Monday shows open orders missing, but the legacy system has already taken new transactions and cannot be restored cleanly. The client trades on partial data for a fortnight and claims lost sales and overtime, alleging there was no tested rollback plan.
  2. Dates read the wrong way round. A billing migration converts day and month fields the wrong way round for part of the customer base, so renewal notices and direct debits go out on the wrong dates. The client claims the cost of refunds, complaint handling and a remediation exercise, alleging your test data never covered the affected records.
  3. Records merged that belonged to different people. A deduplication rule merges member records with the same name and date of birth. Letters and account details reach the wrong members. The client treats it as a personal data breach and claims its response costs and the compensation demands it receives.
  4. Backups that never ran. Under a database support contract you are responsible for monitoring backups. Jobs have been failing for weeks when a storage array dies, and a quarter’s transactions are lost. The client claims the cost of re-keying and lost revenue, alleging you missed the failure alerts.
  5. A drive that outlived its certificate. You certify the destruction of a batch of hard drives. One later appears for sale online with the client’s data on it. The client faces an investigation and claims its costs, alleging your certificate was wrong and your chain of custody broke down.

In every case the client’s argument is about the quality of your professional work. That is the ground PI is written to cover.

Rules and standards your data work is judged against

Disputes about data work are argued against the client’s legal duties, your contract and recognised good practice. These are the reference points most likely to appear in a letter of claim.

Rule or standardWhat it saysWhy it matters to you
UK GDPR, Article 4(12)A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.Accidental loss or alteration counts, so a corrupted migration of personal data can be a reportable breach for your client, not just a technical fault.
UK GDPR, Article 28The controller-processor contract must require the processor to act on documented instructions, keep data secure and, at the end of the service, delete or return all the personal data and delete existing copies unless the law requires them to be kept.Staging tables, extracts and test copies are all copies. Leaving them behind can breach the contract.
ICO guidance on the right to erasureWhen personal data has to be erased, copies in backups that cannot be overwritten straight away must be put ‘beyond use’ until they are.Clients will ask how you treat legacy backups and archives when a system is retired.
ICO data protection audit framework (disposal and deletion)Organisations should document secure disposal methods such as device wiping, degaussing or shredding, and assign someone to check destruction certificates match what was sent for destruction.Your certificates will be checked line by line, so mismatches surface quickly.
NCSC, Secure sanitisation and disposal of storage mediaMedia that has held sensitive data should be sanitised before the device leaves organisational control. Where the sensitivity of the data calls for destruction, it describes destroying media to particles of 6mm or less. The NCSC runs the CAS-S scheme for sanitisation services to central government.Government and security-conscious clients may expect you to work to this guidance or to hold CAS-S assurance.
BS EN 15713:2023Code of practice for the secure destruction of confidential and sensitive material, covering collection, storage, transport and destruction. It replaced the 2009 edition.A common reference point in destruction contracts and certificates.
IEEE 2883-2022IEEE Standard for Sanitizing Storage, specifying methods for sanitising logical and physical storage.If your certificates cite it, the method you used must match what it requires.

What PI covers for data specialists, and what it doesn’t

Usually covered by PIOften excluded or limitedNeeds a different policy
Mapping, transformation and load errors that damage or lose client dataPromises of zero data loss or a guaranteed go-live dateRansomware or a breach of your own systems (cyber insurance)
The client’s losses from a failed or delayed cutover caused by your negligenceLiquidated damages for late deliveryDrives lost or stolen in transit (goods in transit, with cyber for the breach response)
Database administration errors such as missed backup failures or a damaging patchRedoing your own work at your own cost on a fixed-price projectInjury or property damage at a client site (public liability)
Wiping and destruction failures, where that service is declared on the policyDestruction or erasure services you did not tell the insurer aboutTheft of client media by an employee (crime or fidelity cover)
Defence costs, including forensic and data recovery expertsImproving the data beyond its original state (betterment)Damage to your own servers and shredding equipment (property insurance)

Cover is subject to the policy wording and the insurer’s acceptance. If you offer secure erasure or destruction as well as migration, make sure the policy names both activities; some IT wordings were written with consultancy and development in mind.

Certificates of destruction: the document claims are built on

A certificate of destruction is not paperwork for its own sake. It is a written statement that specific items were destroyed or sanitised by a specific method on a specific date, and your client relies on it to close its own records and to answer the ICO if a device resurfaces. If the statement turns out to be wrong, the claim follows the certificate.

Three things decide whether a certificate protects you or exposes you:

PI is designed for honest mistakes: a missed drive, a failed wipe, a broken chain of custody. Policies usually exclude dishonest acts by the business itself, so a certificate issued for work that was never done is not something the policy is there to absorb.

Corruption, attack or both: where PI ends and cyber begins

Data incidents during a project rarely fit one policy. PI for data work is usually written as technology errors and omissions cover, and it sits next to cyber insurance rather than replacing it. The useful question is whose loss you are looking at.

The client’s loss, caused by your work, is a PI matter. If your script corrupts records or your process leaves data exposed, the client’s claim against you for restoration, remediation and its own liabilities falls to PI, subject to the wording. Sometimes the claim arrives from the client’s insurer instead: having paid under the client’s own cyber policy, it may seek to recover that money from the business it says caused the loss.

Your own loss is a cyber matter. If ransomware reaches the migration environment on your side, or extracts held on your systems are stolen, cyber insurance usually pays for forensic investigation, legal advice, notification support, restoring your systems and the income you lose while you recover. Any claim the client then makes against you returns to PI.

Because the boundary moves with the facts, it helps to hold both policies and to check that neither excludes the other’s ground without saying so. Our guide to cyber insurance explained covers the cyber side in more detail.

Choosing a limit for project work, and keeping cover afterwards

The limit is usually set by the client. Large migrations are often run under the client’s own terms or a public sector framework, and both usually state a minimum PI figure. Set your limit by the value and data sensitivity of the largest project you take on, and check whether the requirement is each and every claim or in the aggregate.

What insurers will ask you

A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:

Speak to a broker

PI for database and data migration specialists, placed by a named broker

Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.

Start your PI proposal →or call 0117 325 0027

How Apex places this cover

Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.

Related guides

Sources

Frequently asked

Do database and data migration specialists need professional indemnity insurance?

Yes. Clients rely on you for data they cannot easily recreate, and a mapping error, failed cutover or missed backup causes financial loss that public liability does not cover. PI pays your defence costs and compensation when a client alleges your data work was negligent, subject to the policy terms.

Is PI a legal requirement for data migration specialists?

No law requires data migration or database specialists to hold PI. The requirement comes from clients: corporate contracts and public sector frameworks usually set a minimum PI limit, and agencies placing contractors on migration projects commonly ask for evidence of cover before work starts.

Does PI cover data lost or corrupted during a migration?

Usually, where the loss was caused by negligence in your work, such as a faulty mapping, an untested script or a missed reconciliation. PI responds to the client’s claim for restoration and its resulting losses, subject to the wording. Guarantees of zero data loss and fixed go-live promises are often excluded.

Does my PI cover secure data erasure and destruction?

Only if the policy describes that work as part of your business. Some IT wordings were written for consultancy and development and say nothing about destruction services. Declare erasure and destruction, the methods you use and any subcontractors, so a claim about a drive that resurfaces is not disputed.

Who is responsible for poor-quality source data?

That depends on your contract, which is why it should say so. A common approach is that the client owns the quality of its source data and you own the transformation. Whatever the split, record data quality problems you find and tell the client in writing before go-live.

Do I need cyber insurance as well as PI for migration projects?

In most cases, yes. PI answers claims by clients that your work damaged their data. Cyber insurance usually pays your own costs if your systems are attacked or extracts you hold are stolen, including forensic work, legal advice and lost income. Holding both closes the gap when an incident has elements of each.

Ready to compare cover?

Apex arranges professional indemnity insurance for database and data migration specialists across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.

Start your PI proposal Call 0117 325 0027

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.