GDPR and data-breach cover within professional indemnity
Reviewed by Apex Insurance Brokers · Last reviewed 2026-08-05
The short version of the problem
A client's personal data leaks because of something your firm did — a misdirected email, a lost laptop, a mistake by an employee. Two very different sets of costs land at once: the money you owe others (their claims, legal defence) and the money you spend on yourself (containing the incident, telling the regulator, restoring systems). PI was built for the first set. It was never designed for the second.
Many UK professionals assume one PI policy covers the whole event. It usually does not. Understanding which policy does what — before an incident — is the difference between a covered claim and a five-figure bill you pay yourself.
What PI actually covers in a data breach
Professional indemnity responds to your civil liability to a third party arising from a negligent act, error or omission in your professional services. In a data-breach context, that means the parts of the event where someone else has a claim against you.
- A client's claim against you for losses caused by your breach of duty — including a breach of confidentiality or a failure to keep their data secure.
- Legal defence costs for defending that claim, subject to the policy terms and limit.
- Damages or a settlement you become liable to pay the affected party.
Where a wording extends to breach of confidentiality or loss of documents and data, PI can be the right policy for the liability that flows to a client. But note the trigger: there must be a professional error and a third party bringing a claim. Remove either and PI has little to grip.
What PI does not cover — and cyber does
The costs that hit first, hardest and fastest after a breach are almost all first-party — your own money spent on your own recovery. A standard PI policy is not built to pay these:
- Breach response and forensics — specialist IT to find, contain and evidence what happened.
- Regulatory notification — the work of reporting a personal-data breach to the Information Commissioner's Office (ICO) within the 72-hour window the UK GDPR sets, and notifying affected individuals where required.
- ICO investigation and penalties — a monetary penalty issued by the ICO is generally not something a PI policy will fund, and in many cases fines are uninsurable as a matter of public policy.
- Credit and identity monitoring offered to affected data subjects.
- Business interruption and system restoration if the breach involved ransomware or an outage.
- Cyber extortion and ransom handling.
- PR and reputational management in the immediate aftermath.
These belong to a cyber insurance policy, which is designed around first-party incident response. That is the crux of the gap: PI looks backwards at your liability to a client; cyber looks forwards at your own recovery.
PI vs cyber for a data breach: side by side
| Cost after a breach | Professional indemnity | Cyber |
|---|---|---|
| Client's claim against you for a professional error | Typically covered | Sometimes, via liability section |
| Legal defence of that claim | Covered | Varies |
| Forensic IT and containment | Not covered | Covered |
| ICO notification & notifying individuals | Not covered | Covered |
| System restoration / business interruption | Not covered | Covered |
| Ransomware / cyber extortion | Not covered | Covered |
| ICO monetary penalty | Not covered | Where legally insurable only |
Cover always depends on the specific wording. Treat this as a map of where the two policies pull apart, not a guarantee of any one policy's terms.
Where the gap catches firms out
Three scenarios show why one policy rarely does the job:
- The pure own-cost breach. A staff error exposes client records but no client sues. There is no third-party claim for PI to answer — yet you still face forensics, ICO notification and monitoring. Without cyber, you fund all of it.
- The two-sided event. A client sues and you incur response costs. PI may take the claim; the response bill still has no home unless cyber sits alongside.
- The malicious attack. A ransomware incident locks your systems. There is no professional error toward a client at all, so PI simply does not engage.
The practical answer for most professional firms holding client data is to carry both, and to make sure the wordings dovetail rather than leave a seam between them.
Not sure where your PI ends and your cyber exposure begins? We will read your wording and map the gap.
Get a PI quote →Your GDPR duties don't wait for the insurer
Whatever your cover looks like, the UK GDPR and the Data Protection Act 2018 place the obligations on you as controller. A notifiable personal-data breach must be reported to the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it. High-risk breaches also require you to tell affected individuals. Insurance funds the response; it does not discharge the legal duty. Reviewing both your data-protection processes and your cover together is the sensible approach.
If you are unsure whether your current arrangement leaves you exposed, start a quote and tell us what you handle — the right structure depends on the data you hold and the work you do.
Common questions
Does my PI policy pay an ICO fine?
Generally no. A regulatory monetary penalty from the ICO is not the kind of civil liability PI is built for, and fines are frequently uninsurable as a matter of public policy. PI focuses on your liability to a client, not to the regulator.
If I have PI, do I still need cyber insurance?
In most cases, yes. PI can answer a client's claim, but it will not fund forensics, ICO and individual notification, credit monitoring, or business interruption. If you hold personal data, a cyber policy fills that first-party gap.
What if a client sues me after a breach caused by my mistake?
That third-party claim is exactly what PI is designed for, provided the loss stems from a negligent act, error or omission in your professional services and your wording covers breach of confidentiality or loss of data. Your defence costs typically fall under the same section.
Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This guide is general information, not advice on a specific policy or a substitute for your policy wording.
