FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Cyber & data

GDPR and ICO fines: the PI implications for UK professional firms

In short: A UK GDPR penalty is not a loss you can plan to insure. Whether a regulatory fine is insurable at all under English law is legally uncertain, and cyber and professional indemnity policies commonly exclude fines and penalties outright — so no firm should treat its insurance as the answer to an ICO penalty. What insurance can realistically respond to is different: the cost of responding to and defending a regulatory investigation where the policy provides it, and the civil claims that clients and data subjects bring alongside it.

What the ICO actually regulates, and what it can do

The Information Commissioner’s Office is the UK’s independent regulator for data protection and information rights, enforcing the UK GDPR and the Data Protection Act 2018. Its powers go well beyond fining: it can issue information notices requiring a firm to produce material, assessment notices allowing audit, enforcement notices requiring a firm to do or stop doing something, and reprimands. In practice the non-financial powers are used far more often than penalties, and an enforcement notice can be more disruptive to a professional practice than a fine.

Our entry on the ICO covers the regulator itself, the data protection fee and the breach reporting duty, and the Data Protection Act 2018 sets out the statutory framework.

The penalty levels

Penalty notices under the UK GDPR have two tiers. The standard maximum is £8.7 million or, for an undertaking, 2% of total worldwide annual turnover in the preceding financial year, whichever is higher — the basis is Article 83(4) UK GDPR with section 157(6) of the Data Protection Act 2018. The higher maximum is £17.5 million or 4% of total worldwide annual turnover, whichever is higher, under Article 83(5) UK GDPR with section 157(5) of the Act. Which tier applies depends on which provision has been infringed.

For the overwhelming majority of professional firms the headline maxima are not the realistic exposure. The ICO’s published approach is to fine where it considers a penalty effective, proportionate and dissuasive, taking account of the nature and gravity of the infringement, culpability, mitigation and turnover.

Why a fine cannot be treated as an insurable loss

This is the part firms most often get wrong, and it is the reason this page exists. There are two independent obstacles.

Public policy. English law will not generally allow a person to insure against, or recover from someone else, the consequences of their own wrongdoing where the conduct is sufficiently blameworthy. In Safeway Stores Ltd & Ors v Twigger & Ors [2010] EWCA Civ 1472 the Court of Appeal held that a company could not recover competition penalties it had incurred from its own directors and employees, applying the illegality principle. There is no decided English authority determining whether a UK GDPR penalty is insurable, and commentary is genuinely divided: an argument exists that a fine following a sophisticated criminal attack, where the firm’s own conduct is not criticised, sits differently from one imposed for careless or reckless practice. That argument has not been tested. Uncertainty is not cover.

The policy wording. Even where insurability is arguable, most UK cyber and professional indemnity wordings exclude fines, penalties and punitive damages, or cover them only “where insurable by law” — a phrase that puts the legal uncertainty straight back onto the insured. A wording that appears to offer regulatory fines cover will very often be qualified in exactly this way.

The practical conclusion for any UK professional firm is simple: budget for a penalty as an uninsured cost and manage the risk down, rather than assuming a policy will pay it.

What insurance can realistically respond to

The insurable part of a data protection event is the cost and the civil liability around the penalty, not the penalty itself. Depending entirely on the wording actually in force, that can include:

Breach response costs — forensic investigation, IT remediation, legal advice on notification, and the mechanics of notifying the ICO and affected individuals within the statutory timescales. Regulatory defence and representation costs — the legal costs of dealing with an ICO investigation, where the policy expressly provides for them and to the extent they are insurable. Third-party civil claims — claims by clients or data subjects for damages, including distress, arising from the same facts. Business interruption and cyber extortion under a cyber policy, which are distinct covers again.

Cyber insurance is where most of this sits. Professional indemnity is a different instrument: it responds to claims arising from the firm’s professional services.

Where professional indemnity fits — and where it does not

PI answers the question “did the firm’s professional work cause a client a loss?” If a solicitor, accountant, surveyor or consultant loses client data through a failure in the way it delivered its professional services, a client claim for the resulting loss can be a PI claim. That is a real and frequently overlooked overlap: the loss of documents extension in many PI wordings deals expressly with the cost of reconstituting client documents and data.

What PI does not do is act as a substitute for cyber cover. It generally does not pay for forensic response, system rebuild, or the firm’s own business interruption, and it does not pay regulatory penalties. Firms that carry PI and assume it covers a cyber event usually discover the gap during the event. Our page on ransomware and professional firms works through where the two policies meet and where neither responds.

The professional-conduct dimension

For regulated professionals a data breach is rarely only a data protection matter. Client confidentiality obligations sit alongside the UK GDPR and are enforced by the professional regulator, not the ICO. A breach can therefore generate a personal data breach report to the ICO, a notification to the professional regulator, a notification to the PI insurer as a circumstance, and a separate conversation with the affected clients — on different timescales and to different standards. Working out that sequence in advance, rather than during the incident, is the single most useful preparation a firm can do.

Practical steps that reduce the exposure

Know what personal data the firm holds, why, and for how long — most professional firms hold far more than they need, and retained data they no longer use is pure downside. Keep the records of processing and the security decisions documented, because the ICO’s assessment of culpability turns on what the firm did before the breach. Rehearse the seventy-two hour reporting timetable rather than reading about it during an incident. Read your cyber and PI wordings together and identify the gap between them in writing. And check the fines and penalties clause in every quotation before you buy, rather than assuming.

Frequently asked questions

Will cyber insurance pay an ICO fine?

You should not assume so. Most UK wordings exclude fines and penalties, or cover them only to the extent insurable by law — and whether a UK GDPR penalty is insurable under English law is unsettled, with no decided authority on the point. Treat a penalty as an uninsured cost and read the fines clause in any quotation before relying on it.

Does professional indemnity cover a data breach?

Only in part, and only through the professional-services route. If a client suffers a loss because of a failure in the firm’s professional work, the resulting claim can be a PI claim, and many PI wordings include a loss of documents extension. PI does not usually pay forensic response, system restoration, the firm’s own interruption loss, or regulatory penalties.

What are the maximum ICO fines?

The standard maximum is £8.7 million or 2% of total worldwide annual turnover, whichever is higher, and the higher maximum is £17.5 million or 4% of total worldwide annual turnover, whichever is higher. These derive from Articles 83(4) and 83(5) of the UK GDPR read with sections 157(6) and 157(5) of the Data Protection Act 2018.

Do we have to notify our PI insurer after a data breach?

If the breach could give rise to a claim against the firm, yes — a claims-made policy responds to circumstances notified during the period, and a known circumstance left unnotified is normally excluded from any later policy. Notify the cyber insurer under the incident-response provisions at the same time, because those are usually subject to strict conditions about using the insurer’s panel.

This page is general insurance information, not legal advice, and describes the position as at August 2026. Cover depends on the wording of the policy actually in force.

Read your cyber and PI wordings together
We map where cyber cover ends, where PI begins and what neither policy pays. Bristol-based, FCA-regulated, wordings first.
Call 0117 325 0027  info@apexinsurancebrokers.co.uk

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.

Want a broker to look at your commercial cover?
If you have your renewal pack, Statement of Fact or schedule, send it over and we’ll come back with options — no forms to fill in. Arranging cover for the first time? That works too. Or call 0117 325 0027.
Start a commercial quote →
Larger or multi-site risk? We’ll come and see you.
Get a quote →
="font-size:12px;color:#777;">Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.

Want a broker to look at your commercial cover?
If you have your renewal pack, Statement of Fact or schedule, send it over and we’ll come back with options — no forms to fill in. Arranging cover for the first time? That works too. Or call 0117 325 0027.
Start a commercial quote →
Larger or multi-site risk? We’ll come and see you.
Related reading: Commercial property owners · Manufacturers’ insurance · Buildings underinsurance explained · Scenario: machinery damage and BI · Wiki: increased cost of working · Wiki: indemnity period · Gross profit vs gross revenue · Choosing an indemnity period · Renewal gone up? Why premiums rise · Making a business insurance claim
Get a quote →