Who pays if a supplier loses customer data, the business, the supplier or the insurer? Owners and directors at UK SMEs face that exact worry when choosing cover or signing supplier contracts. This piece maps likely insurer responses, gives editable contract clauses and a simple purchase checklist.
Data processors vs controllers guidance: Quickly understand who is legally responsible for personal data and what that means for cyber cover. See the difference between controllers and processors under UK GDPR, who usually pays after a breach, and a short checklist of covers and clauses SMEs should check before signing.
Why controller or processor status matters for insurance
Controllers usually carry regulatory risk and reporting duties. That fact drives insurer scrutiny and claim allocation.
Insurers look at who decided why and how data was processed. They treat operational control as a key trigger for liability.
A clear role helps buyers choose cover. Unclear roles create disputes at claim time and slow recovery.
Keep this checklist handy during broker and legal discussions.
How insurers define control
Insurers ask who decided the purposes and means of processing. That mirrors UK GDPR but insurers test the real facts.
They probe contracts, technical logs and who configured systems; the insurer then decides which policy should respond.
Why this changes cover and limits
An insurer may refuse regulatory fines cover without an explicit extension. Buyers must check the schedule and endorsements.
The insurer also checks whether the insured held reasonable controls. Poor controls can lead to refusal or reduced pay‑out.
If the controller kept duties but outsourced operations, the controller still faces regulatory exposure under UK GDPR. Insurance cannot erase that legal risk.
Keep this checklist handy during broker and legal discussions.
How insurers assess controller and processor liabilities
Insurers assess actual behaviour, not labels. They want evidence of security and written roles.
Claims handlers trace who failed to apply controls; that tracing determines whether first‑party or third‑party cover applies.
Policies vary in wording, exclusions and how they treat contractual indemnities. Read the policy text and get broker confirmation.
Typical insurer checks on claims
Insurers verify incident timelines and access logs. They also ask for DPAs, sub‑processor lists and audit trails.
They review whether the insured followed published security practices. That evidence affects settlement and subrogation.
Common error insurers see
The common error is relying on a supplier DPA without checking the supplier's insurance. This mistake causes recovery gaps.
Many policies exclude fines unless the insured bought a specific extension. That gap proves costly in practice.
Keep this checklist handy during broker and legal discussions.
Common policy gaps when using third‑party processors
Controllers often assume that a processor's insurance covers all loss. That belief raises post‑breach risk.
Processors often hold low third‑party limits that do not meet controller indemnities. That mismatch leaves unpaid losses.
Policies commonly lack sub‑processor cover and retroactive dates that match the contract start. Check these items before signing.
Table: policy types and typical gaps
| Policy |
Main cover |
Common gap for SMEs |
| Cyber insurance |
Incident response, forensics, BI, ransom |
No regulatory fines extension and low BI sublimits |
| Professional indemnity (PI) |
Negligent advice or faulty services |
Often excludes first‑party cyber loss and fines |
| Business continuity/BCP |
Replacement costs, contingency suppliers |
May have low limits for cyber BI tied to other events |
Sub‑processor and retroactive risks
Processors may add sub‑processors without updating insurance. That removes a recovery route for controllers.
If the policy retroactive date predates the contract, insurers may accept historic claims. If not, claims can be denied.
Key difference: controllers remain regulatorily liable even if a DPA assigns operational duties. Insurance cannot erase regulatory liability. Insurance can fund defence and remediation when the policy covers those costs.
Keep this checklist handy during broker and legal discussions.
Does cyber insurance cover GDPR fines and costs?
Some policies cover defence costs and fines only with a specific extension. Buyers must confirm that extension in writing.
Most standard cyber wordings exclude regulatory fines by default. Buyers must check the policy schedule for a fines extension.
If a policy includes fines, limits and excesses often differ from other sections. Verify the limit before relying on cover.
What insurers pay for usually
Insurers commonly pay for forensics, breach notification, PR and legal defence. These items fall under defence or first‑party cover.
Ransom payments and business interruption often trigger the main cyber section. Each element may have sublimits.
When fines are excluded
The common cause of a refused fines claim is a missing extension. The insured often assumed fines were included.
A second cause is a deliberate or dishonest act exclusion. Insurers do not pay for wilful behaviour.
ICO guidance explains controller obligations and the 72‑hour notification duty to the regulator.
Keep this checklist handy during broker and legal discussions.
Contract clauses every SME must use
A clear DPA and an insurance clause reduce claim friction and speed recovery. Use concrete wording in contracts.
Require evidence of cover, minimum limits, retroactive dates and notification duties. These items stop surprises in a claim.
Add audit rights and incident co‑operation obligations. That proves due diligence and helps insurers accept claims.
Processor insurance clause
Processor shall, at its own cost, hold cyber insurance with limits of not less than GBP [amount], to include:
- (a) first‑party incident response (forensic investigation, notification and PR) with clear sublimits where applicable
- (b) third‑party liability for privacy and data breach claims
- and (c) contractual indemnity cover only where the insurer has provided a written endorsement accepting such indemnities
The policy shall include sub‑processor cover or an endorsement extending cover to named sub‑processors, and a retroactive date no later than the start of processing under the DPA. Processor shall give Controller a certificate of insurance and copies of the policy schedule and any endorsements within 7 days of request. Processor shall notify Controller and its insurer of any incident within 72 hours of becoming aware. Processor shall co‑operate with any forensic investigation and claim handling.
Any subrogation waiver must be accepted in writing by the insurer and recorded as an endorsement to the policy.
Controller protective clauses
Controller requires encryption, MFA, backups and a documented sub‑processor list. These controls lower insurer disputes.
Controller includes stepwise notification and co‑operation obligations for ICO reporting and forensic work. That speeds remediation.
Expanded contract clauses that insurers accept
Processor shall hold and produce on request a valid cyber insurance policy with limits of not less than GBP [amount] that includes: (a) first‑party incident response (forensic investigation, breach notification costs and PR), (b) third‑party liability for privacy and data breach claims, and (c) cover for contractual indemnities where the insurer has provided a written endorsement accepting such indemnities. The policy shall include sub‑processor cover or an endorsement extending cover to named sub‑processors, a retroactive date no later than the commencement of processing, and clear sublimits for business interruption and regulatory fines where available.
Processor will give Controller a certificate of insurance, a copy of the policy schedule and any relevant endorsements within 7 days of request.
Processor must notify Controller and its insurer of any incident within 72 hours of becoming aware and co‑operate with any forensic investigation and claim handling. Where the Controller requests a subrogation waiver, such waiver shall only be effective if the insurer gives written acceptance of the waiver and any premium or endorsement required is stated in writing.
Keep this checklist handy during broker and legal discussions.
Negotiating indemnities and subrogation with insurers
Indemnities change how insurers recover losses. Negotiations should align contract wording with policy terms.
Insurers commonly rely on subrogation to recover from negligent processors. Ambiguous indemnities hinder recovery.
A subrogation waiver can be agreed, but insurers often require explicit wording and may charge extra for acceptance.
How insurers treat indemnities
Claims handlers check whether indemnities are enforceable and whether the insured actually followed controls. That check affects settlement.
If the insurer pays and subrogates, it pursues the party at fault. Poor or absent indemnities can leave the insurer with no recovery path.
SME negotiation steps
Ask the broker to confirm insurer acceptance of any proposed indemnity or waiver. This avoids refused claims after an incident.
If acting as a processor, offer stronger limits or proof of controls to win better contract terms.
Keep this checklist handy during broker and legal discussions.
Mapping incidents to likely responsible party
Mapping incident types to roles helps choose cover and draft clauses. Practical scenarios make responsibilities clear.
The table below helps a buyer see who usually pays and which policy responds. Use it when negotiating DPAs and insurance.
Ransomware on supplier servers
If a processor manages the servers, the processor commonly bears operational fault. The processor's cyber policy often responds first.
The controller must still notify the ICO and manage data subject communications. Both parties need co‑operation clauses.
Accidental disclosure by processor staff
The controller holds reporting duties and regulator exposure. A processor may owe indemnity under contract.
Insurers check whether the processor kept agreed access controls. Missing controls can void a processor's claim.
Keep this checklist handy during broker and legal discussions.
This guidance does not apply to large organisations with bespoke programmes or to incidents governed entirely by non‑UK law. Complex litigation or multi‑jurisdictional breaches need legal advice tailored to the facts.
Comparative responsibility matrix
A simple comparative matrix helps cut through labels and shows who normally bears data breach liability. It also shows which insurance responds first.
For example: (1) Ransomware on a supplier‑managed server — operational fault usually lies with the processor or sub‑processor. The processor's cyber insurance commonly responds first for forensics, ransom and business interruption. The controller keeps UK GDPR reporting duties and may rely on a fines extension or its own cyber policy for defence costs.
(2) Accidental disclosure by supplier staff — the controller has primary regulatory reporting duties under UK GDPR but a processor may owe contractual indemnities. Third‑party processor insurance and processor indemnity determine recovery. Insurers will test access controls and adherence to the DPA.
(3) Misconfigured cloud storage by controller — the controller is likely both operationally and regulatorily liable. The controller’s cyber and business interruption insurance respond for incident response and BI.
For each scenario the matrix should record (a) proximate legal responsibility, (b) likely responding policy, (c) subrogation prospects, and (d) documentation insurers will demand.
Keep this checklist handy during broker and legal discussions.
Practical opinion for SME decision makers
Controllers should buy strong first‑party cyber cover and secure a regulatory fines extension where possible. Insurer confirmation in writing that the extension applies to controller liabilities is essential.
Processors avoid disputes by holding cyber cover and enough third‑party limits. Name sub‑processors in contracts and keep proof of controls.
Match policy wording to contract duties and get broker confirmation in writing before signing any DPA.
Practical purchase checklist by role
Controller, minimum covers to check: primary cyber insurance with limits sized to potential business interruption and regulatory fines where the insurer will underwrite a fines extension. Also check explicit defence and indemnity wording for data breach liability and cyber BI sublimits. Ask for insurer confirmation in writing that the policy wording applies to controller liabilities and any contractual indemnities.
Processor, minimum covers to check: comprehensive cyber insurance with third‑party liability for privacy claims, contractual indemnity cover with insurer endorsement, sub‑processor cover or named sub‑processor endorsement, a fitting retroactive date and BI limits tied to service continuity. For both, ask for a certificate of insurance, full policy schedule and endorsements. Also request written broker confirmation on indemnities and subrogation waivers and evidence of MFA, encryption and backups.
As a rule of thumb for many SMEs, consider GBP 1m–5m limits for third‑party liability depending on data sensitivity and sector. Increase limits where BI exposure or likely regulatory fines are material.
Keep this checklist handy during broker and legal discussions.
Decision flow for buyers
Which insurance to buy: quick flow
Are you the decision maker for data processing?
Yes → Controller: buy cyber + fines extension
No → Processor: buy cyber + third‑party limits
Also require: DPA, proof of cover, retroactive date and sub‑processor list.
Dealing with ICO investigations and insurer notifications
Report personal data breaches to the ICO within 72 hours of becoming aware. This is a legal duty under UK GDPR.
Insurers commonly require prompt notice and co‑operation. Late notification can jeopardise cover and delay payment.
Keep a documented incident timeline, forensic reports and communications. These items help both the insurer and the regulator.
What to tell your insurer first
Tell the insurer who suffered the breach, when it was discovered and what data is affected. This anchors the claim.
Provide any immediate containment steps and whether a ransom demand exists. The insurer uses this to instruct forensics.
Send the ICO a factual notification and keep a copy. Share a coordinated response plan with your insurer to align defence costs.
Legal counsel and a DPO can draft the ICO submission. Insurers often accept counsel costs under defence cover.
For brokered advice, ask a cyber broker with UK GDPR experience to review your policy and draft DPA wording before you sign a contract.
Keep this checklist handy during broker and legal discussions.
Frequently asked questions
What is the main difference between a controller and a processor?
A controller decides why and how personal data is processed. That choice determines who faces regulatory duties.
The processor acts on the controller's instructions. The processor has contractual duties but less regulatory exposure in simple cases.
Can a processor be fined by the ICO?
Yes, a processor can face enforcement action and fines under UK GDPR. Liability depends on the facts and the processor's conduct.
If the processor failed to follow instructions or accepted unlawful processing, the ICO may act against it. Insurance must reflect that risk.
How soon must I notify my insurer after a breach?
Notify your insurer as soon as possible and within any contractual time limit. Late notice can jeopardise coverage.
Many insurers expect notice within 72 hours of discovery. Follow the insurer's claim guidance and give requested evidence.
What minimum limits should SMEs require?
A sensible floor for many SMEs is GBP 1m to GBP 5m depending on data sensitivity. Adjust limits to match potential BI and regulatory exposure.
Ask a broker for an assessment tied to your sector and the volume of personal data processed.
Can a subrogation waiver be agreed with insurers?
Yes, but insurers must accept it in writing. Acceptance often depends on premium, wording and proof of controls.
If the insurer refuses, align contractual indemnities to reflect likely recovery paths and insurer preferences.
What to do next
Identify whether you act as controller, processor or joint controller for each service. This single step guides buying decisions.
Bring the editable clause and checklist to your broker and legal counsel. Let them confirm policy wording and insurer acceptance.
Keep DPAs, insurance certificates and incident runbooks in one folder. That preparation speeds claims and reduces costs.
Will my PI policy cover a cyber breach?
Often not. PI policies may exclude first‑party cyber loss and regulatory fines. Confirm with your broker and review the policy wording.
A specific cyber policy commonly covers incident response and BI that PI does not include. Check both to avoid gaps.
Who pays if a sub‑processor caused the breach?
Contractual indemnities and insurance determine who pays. Insurers often subrogate against the at‑fault sub‑processor after paying a claim.
If no insurer or indemnity exists, the controller may ultimately meet costs and then sue the processor or sub‑processor.