FCA authorised · FRN 724952 0117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
PI insurance explained

GDPR and data-breach cover within professional indemnity

Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-05

In short: Professional indemnity (PI) insurance can respond to a data breach only when it stems from a professional error you owe a client — typically the third-party claim they bring against you. It does not fund your own breach response: forensic IT, notifying the ICO, credit monitoring, or business interruption. Those first-party costs sit with a cyber policy, and the gap between the two is where firms get caught.

The short version of the problem

A client's personal data leaks because of something your firm did — a misdirected email, a lost laptop, a mistake by an employee. Two very different sets of costs land at once: the money you owe others (their claims, legal defence) and the money you spend on yourself (containing the incident, telling the regulator, restoring systems). PI was built for the first set. It was never designed for the second.

Many UK professionals assume one PI policy covers the whole event. It usually does not. Understanding which policy does what — before an incident — is the difference between a covered claim and a five-figure bill you pay yourself.

What PI actually covers in a data breach

Professional indemnity responds to your civil liability to a third party arising from a negligent act, error or omission in your professional services. In a data-breach context, that means the parts of the event where someone else has a claim against you.

Where a wording extends to breach of confidentiality or loss of documents and data, PI can be the right policy for the liability that flows to a client. But note the trigger: there must be a professional error and a third party bringing a claim. Remove either and PI has little to grip.

What PI does not cover — and cyber does

The costs that hit first, hardest and fastest after a breach are almost all first-party — your own money spent on your own recovery. A standard PI policy is not built to pay these:

These belong to a cyber insurance policy, which is designed around first-party incident response. That is the crux of the gap: PI looks backwards at your liability to a client; cyber looks forwards at your own recovery.

PI vs cyber for a data breach: side by side

Cost after a breach Professional indemnity Cyber
Client's claim against you for a professional errorTypically coveredSometimes, via liability section
Legal defence of that claimCoveredVaries
Forensic IT and containmentNot coveredCovered
ICO notification & notifying individualsNot coveredCovered
System restoration / business interruptionNot coveredCovered
Ransomware / cyber extortionNot coveredCovered
ICO monetary penaltyNot coveredWhere legally insurable only

Cover always depends on the specific wording. Treat this as a map of where the two policies pull apart, not a guarantee of any one policy's terms.

Where the gap catches firms out

Three scenarios show why one policy rarely does the job:

The practical answer for most professional firms holding client data is to carry both, and to make sure the wordings dovetail rather than leave a seam between them.

Not sure where your PI ends and your cyber exposure begins? We will read your wording and map the gap.

Get a PI quote →

Your GDPR duties don't wait for the insurer

Whatever your cover looks like, the UK GDPR and the Data Protection Act 2018 place the obligations on you as controller. A notifiable personal-data breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. High-risk breaches also require you to tell affected individuals. Insurance funds the response; it does not discharge the legal duty. Reviewing both your data-protection processes and your cover together is the sensible approach.

If you are unsure whether your current arrangement leaves you exposed, start a quote and tell us what you handle — the right structure depends on the data you hold and the work you do.

Common questions

Does my PI policy pay an ICO fine?
Generally no. A regulatory monetary penalty from the ICO is not the kind of civil liability PI is built for, and fines are frequently uninsurable as a matter of public policy. PI focuses on your liability to a client, not to the regulator.

If I have PI, do I still need cyber insurance?
In most cases, yes. PI can answer a client's claim, but it will not fund forensics, ICO and individual notification, credit monitoring, or business interruption. If you hold personal data, a cyber policy fills that first-party gap.

What if a client sues me after a breach caused by my mistake?
That third-party claim is exactly what PI is designed for, provided the loss stems from a negligent act, error or omission in your professional services and your wording covers breach of confidentiality or loss of data. Your defence costs typically fall under the same section.

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for your policy wording.

Get a quote →