IT and data
Yes: database and data migration specialists need professional indemnity insurance, because the work is judged on complete, accurate, usable data arriving at the other end and nothing readable left behind. A failed cutover, a mapping error or a missed copy on an old server causes financial loss rather than physical damage, so public liability will not respond. PI usually pays to defend those allegations and any compensation you owe. Cyber insurance sits alongside it for your own costs if an attack or breach hits during a project.
Part of: Professional indemnity for IT professionals
In short
Migration, database administration and secure data removal share one risk: the client relies on you for data it cannot easily recreate. Under the UK GDPR the accidental loss, destruction or alteration of personal data is a personal data breach, so a corrupted migration can be a regulatory event as well as a contract dispute. If you wipe or destroy media, your certificate of destruction is a statement the client relies on, and the ICO tells controllers to check certificates against what they sent. PI usually covers claims that your work was negligent; cyber covers your own response costs. Expect insurers to ask about testing, rollback and sanitisation methods.
Last reviewed 5 October 2026 by the Apex professional indemnity team.
Data work is judged by what arrives at the other end. After a migration the client expects every record to be present, correctly transformed and usable on the first working day. After a database support call it expects its backups to restore. After secure removal it expects nothing readable to remain on the media you took away. When any of that fails, the result is rework, downtime, wrong invoices, regulatory exposure or lost customers: financial loss, not physical damage.
Public liability insurance covers accidental injury and accidental damage to third-party property. If you knock a server off a rack at a client’s site, that is a public liability matter. If your transformation script silently truncates ten years of customer notes, it is not. That allegation is that you failed to use the skill and care of a competent data professional, and professional indemnity insurance is the policy written for it.
The gap is wider than it looks, because data loss is easy to cause and slow to discover. A mapping error may not show until month-end reporting, a missed staging copy until it turns up somewhere it should not be, and a failed backup only on the day a restore is needed.
These scenarios are illustrative, not real claims. Each shows what went wrong, who lost money and what they allege.
In every case the client’s argument is about the quality of your professional work. That is the ground PI is written to cover.
Disputes about data work are argued against the client’s legal duties, your contract and recognised good practice. These are the reference points most likely to appear in a letter of claim.
| Rule or standard | What it says | Why it matters to you |
|---|---|---|
| UK GDPR, Article 4(12) | A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data. | Accidental loss or alteration counts, so a corrupted migration of personal data can be a reportable breach for your client, not just a technical fault. |
| UK GDPR, Article 28 | The controller-processor contract must require the processor to act on documented instructions, keep data secure and, at the end of the service, delete or return all the personal data and delete existing copies unless the law requires them to be kept. | Staging tables, extracts and test copies are all copies. Leaving them behind can breach the contract. |
| ICO guidance on the right to erasure | When personal data has to be erased, copies in backups that cannot be overwritten straight away must be put ‘beyond use’ until they are. | Clients will ask how you treat legacy backups and archives when a system is retired. |
| ICO data protection audit framework (disposal and deletion) | Organisations should document secure disposal methods such as device wiping, degaussing or shredding, and assign someone to check destruction certificates match what was sent for destruction. | Your certificates will be checked line by line, so mismatches surface quickly. |
| NCSC, Secure sanitisation and disposal of storage media | Media that has held sensitive data should be sanitised before the device leaves organisational control. Where the sensitivity of the data calls for destruction, it describes destroying media to particles of 6mm or less. The NCSC runs the CAS-S scheme for sanitisation services to central government. | Government and security-conscious clients may expect you to work to this guidance or to hold CAS-S assurance. |
| BS EN 15713:2023 | Code of practice for the secure destruction of confidential and sensitive material, covering collection, storage, transport and destruction. It replaced the 2009 edition. | A common reference point in destruction contracts and certificates. |
| IEEE 2883-2022 | IEEE Standard for Sanitizing Storage, specifying methods for sanitising logical and physical storage. | If your certificates cite it, the method you used must match what it requires. |
| Usually covered by PI | Often excluded or limited | Needs a different policy |
|---|---|---|
| Mapping, transformation and load errors that damage or lose client data | Promises of zero data loss or a guaranteed go-live date | Ransomware or a breach of your own systems (cyber insurance) |
| The client’s losses from a failed or delayed cutover caused by your negligence | Liquidated damages for late delivery | Drives lost or stolen in transit (goods in transit, with cyber for the breach response) |
| Database administration errors such as missed backup failures or a damaging patch | Redoing your own work at your own cost on a fixed-price project | Injury or property damage at a client site (public liability) |
| Wiping and destruction failures, where that service is declared on the policy | Destruction or erasure services you did not tell the insurer about | Theft of client media by an employee (crime or fidelity cover) |
| Defence costs, including forensic and data recovery experts | Improving the data beyond its original state (betterment) | Damage to your own servers and shredding equipment (property insurance) |
Cover is subject to the policy wording and the insurer’s acceptance. If you offer secure erasure or destruction as well as migration, make sure the policy names both activities; some IT wordings were written with consultancy and development in mind.
A certificate of destruction is not paperwork for its own sake. It is a written statement that specific items were destroyed or sanitised by a specific method on a specific date, and your client relies on it to close its own records and to answer the ICO if a device resurfaces. If the statement turns out to be wrong, the claim follows the certificate.
Three things decide whether a certificate protects you or exposes you:
PI is designed for honest mistakes: a missed drive, a failed wipe, a broken chain of custody. Policies usually exclude dishonest acts by the business itself, so a certificate issued for work that was never done is not something the policy is there to absorb.
Data incidents during a project rarely fit one policy. PI for data work is usually written as technology errors and omissions cover, and it sits next to cyber insurance rather than replacing it. The useful question is whose loss you are looking at.
The client’s loss, caused by your work, is a PI matter. If your script corrupts records or your process leaves data exposed, the client’s claim against you for restoration, remediation and its own liabilities falls to PI, subject to the wording. Sometimes the claim arrives from the client’s insurer instead: having paid under the client’s own cyber policy, it may seek to recover that money from the business it says caused the loss.
Your own loss is a cyber matter. If ransomware reaches the migration environment on your side, or extracts held on your systems are stolen, cyber insurance usually pays for forensic investigation, legal advice, notification support, restoring your systems and the income you lose while you recover. Any claim the client then makes against you returns to PI.
Because the boundary moves with the facts, it helps to hold both policies and to check that neither excludes the other’s ground without saying so. Our guide to cyber insurance explained covers the cyber side in more detail.
The limit is usually set by the client. Large migrations are often run under the client’s own terms or a public sector framework, and both usually state a minimum PI figure. Set your limit by the value and data sensitivity of the largest project you take on, and check whether the requirement is each and every claim or in the aggregate.
A complete proposal gets better terms than a bare one, and a broker can only present what you tell us. Have these ready:
Speak to a broker
PI for database and data migration specialists, placed by a named broker
Start the online proposal and save it as you go, or leave your number and a named broker will call you back, usually the same working day.
Apex Insurance Brokers is an independent insurance broker based in Bristol, established in 2009 and authorised and regulated by the Financial Conduct Authority. We are not tied to one insurer: we work with over 30 markets, including Lloyd’s syndicates through wholesale brokers, and every client has a named broker who handles the placement, mid-term changes, certificates for clients and the renewal.
Yes. Clients rely on you for data they cannot easily recreate, and a mapping error, failed cutover or missed backup causes financial loss that public liability does not cover. PI pays your defence costs and compensation when a client alleges your data work was negligent, subject to the policy terms.
No law requires data migration or database specialists to hold PI. The requirement comes from clients: corporate contracts and public sector frameworks usually set a minimum PI limit, and agencies placing contractors on migration projects commonly ask for evidence of cover before work starts.
Usually, where the loss was caused by negligence in your work, such as a faulty mapping, an untested script or a missed reconciliation. PI responds to the client’s claim for restoration and its resulting losses, subject to the wording. Guarantees of zero data loss and fixed go-live promises are often excluded.
Only if the policy describes that work as part of your business. Some IT wordings were written for consultancy and development and say nothing about destruction services. Declare erasure and destruction, the methods you use and any subcontractors, so a claim about a drive that resurfaces is not disputed.
That depends on your contract, which is why it should say so. A common approach is that the client owns the quality of its source data and you own the transformation. Whatever the split, record data quality problems you find and tell the client in writing before go-live.
In most cases, yes. PI answers claims by clients that your work damaged their data. Cyber insurance usually pays your own costs if your systems are attacked or extracts you hold are stolen, including forensic work, legal advice and lost income. Holding both closes the gap when an incident has elements of each.
Apex arranges professional indemnity insurance for database and data migration specialists across the UK. Tell us about your work and we’ll find cover that fits. Or call 0117 325 0027.
Start your PI proposal Call 0117 325 0027Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information, not advice on your individual circumstances. Cover is always subject to the insurer’s acceptance and the policy terms, and this page does not guarantee that cover will be available or on what terms.