Vancouver · Closed, opens 10:00604-324-5711Delta · Closed, opens 09:00604-635-0890Surrey · Closed, opens 10:00604-319-1000
Business Insurance BC  /  Consultant & E&O Insurance BC  /  Client Data Leak: Which Policy Answers
Cyber and E&O together

You lose a client’s data. Which of your policies picks up the phone?

A laptop with a client’s files goes missing. A shared folder was left open. Your cyber policy and your professional liability policy both have something to say, and they do not say the same thing. Knowing which one answers is the difference between a covered claim and two insurers pointing at each other.

Build the practice file Read the short answer first
Cyber

Your systems and your breach costs.

E&O

Your advice and your client’s loss.

Still yours

Handing data to a vendor does not hand off the duty.

The quick version

When a consultant loses client data, is it a cyber claim or an E&O claim?

Often both, and the split matters. The breach itself, the notification, the forensic work and the credit monitoring, that is cyber. The client suing you because losing their data caused them a financial loss, that is usually professional liability. A policy built for one will not stretch to the other.

The Office of the Privacy Commissioner of Canada sets the starting point: “An organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing.” Your cloud provider losing it is still your breach. Your subcontractor losing it is still your breach.

The part people skip

Many consultants assume the client’s own cyber policy will handle it, because it is the client’s data. The Privacy Commissioner’s position is that whoever holds the data is responsible for it. If it was in your custody when it went, the duty and the first costs start with you, and your client will see it the same way. Read the Privacy Commissioner on accountability (opens in a new tab).

What to check

Four things to line up before something goes missing.

Which policy holds the breach costs

Notification, forensics and legal advice sit in cyber. Check your E&O does not assume they are somewhere else, and your cyber does not exclude data you hold for clients.

Whether your E&O sees data loss as a professional service

Some wordings treat losing client data as an error in your service. Some carve it out to cyber. Read the exclusion, not the summary.

What your contracts promise

If you signed a clause promising a standard of data protection, that promise is a contract. Your policies answer for negligence.

Where the data actually lives

Your laptop, your cloud, your sub’s laptop. The Privacy Commissioner says it is yours wherever it is. Your policies may not agree with each other about that.

How it usually happens

Three consultants, three losses.

The laptop on the train

A management consultant lost a laptop holding a client’s staff data. Cyber paid for notification and forensics. The client then sued for the cost of its own breach response. That part went to E&O.

The sub who lost it

An IT consultant used a subcontractor who left a database open. The client did not sue the sub. It sued the consultant it had hired, because that was who it had trusted with the data.

The two insurers who both said no

A consultant had E&O that excluded data loss and no cyber at all. Both routes were closed. The claim was paid from the firm’s own account.

SEND US BOTH WORDINGS

Send us your E&O and your cyber policy together.

We read the two side by side and tell you where they overlap and where neither answers. No sales call unless you ask for one.

Build the practice file
What people ask us

The questions consultants ask about this.

We are small. Do we really need both?

You need whichever one answers for the loss you are most likely to have. For a consultant holding client data, that is usually both, in modest amounts.

The client’s data sits on their system, not ours. Are we clear?

If you can reach it, you have custody of it while you are in there. Ask what your agreement says about your access.

Does cyber cover the client suing us?

Some cyber wordings include third party liability for a breach. Many do not. This is the gap to check first.

Our cloud provider lost it, not us.

The Privacy Commissioner treats data you transferred for processing as still yours. Your client will see it the same way.

We signed a data protection clause. Does that change anything?

Yes. A promise in a contract can go beyond negligence, and your policies answer for negligence. Send us the clause.

Two that sit next to this one: what errors and omissions cover actually answers for, and what a cyber policy leaves out.

Not the question you came with? Send it through the short contact form and we will answer the one you actually have.

Two policies, one loss, and only one of them should be arguing.

Send us both wordings and your standard client agreement. We will tell you where the gap is.