Updated in March 2026
Are rising notification bills and PR fees after a breach keeping the business awake at night? For many UK SMEs the real shock is not the hack but the cost and complexity of telling customers and protecting a reputation.
This analysis shows how cover for data breach notification & PR costs can respond, what it usually pays for, where insurers commonly draw the line, and the exact steps an SME can take when a breach happens—presented in plain British English, with UK law and regulator links for context.
Quick essentials on cover for data breach notification & PR costs
- What it usually pays: Immediate response costs, legal advice on notification obligations, preparation and distribution of regulator and customer notices, and paid PR/crisis communications to limit reputational harm.
- Limits and sublimits matter: Policies often include sublimits for notification and PR (for example, £25k–£250k) that reduce the main cyber limit available for other losses.
- GDPR still shapes claims: Regulatory fines are normally excluded; insurers typically cover costs of preparing notices and liaising with the ICO but not penalties themselves. See the Information Commissioner's Office for guidance: ICO.
- Activation depends on proof of loss and reasonableness: Insurers expect evidence that the incident required notification and that PR spend was reasonable and pre-approved where required.
- Practical defence: A short checklist and an evidence pack speed payment and reduce disputes—an initial log, timeline of events, sample notices and invoices from PR or forensic providers.
What cover for data breach notification and PR costs includes
Clear categories help determine what a typical SME policy will and will not pay when a breach occurs.
First-party response and notification costs
First-party notification costs are expenses the insured pays directly to respond. Typical items include:
- forensic investigation costs to confirm a personal data breach, isolate systems and determine scope;
- legal fees to advise on whether notification to the ICO and affected individuals is required under the GDPR (or UK Data Protection Act);
- preparation and sending of regulatory and individual notifications (letters, emails, call-centre scripts);
- credit/ID monitoring and call-centre services paid for affected individuals;
- mandated breach-coach or incident response provider fees where the policy offers panel services.
Context and implication: insurers commonly treat these as first-party contingent costs that are payable regardless of third-party liability. However, many policies apply a specific sublimit for notification services which can exhaust funds fast when tens of thousands of records are involved.
Public relations and crisis communications
PR and crisis communications cover the expense of managing reputation after a breach. Typical elements:
- retained PR agency fees for messaging, press releases, media handling and stakeholder comms;
- drafting of consumer-facing messaging and social media statements;
- purchasing of paid media or sponsored posts to correct misinformation;
- reputation-monitoring services.
Expert context: insurers usually allow PR spend only to the level that is reasonable and necessary to mitigate business interruption and reputational loss. Many policies require pre-approval (often within 24–72 hours) and prefer use of panel PR providers.
Although not strictly notification or PR costs, third-party liability and legal defence costs arise if affected individuals or organisations sue. Policies usually separate these heads from notification/PR budgets; erosion of overall limits by third-party claims can reduce funds available for crisis communications.
Practical implication: distinguish clearly between money paid for notifying customers and money reserved for defending or settling lawsuits—these are often treated under different sublimits.
How GDPR affects data breach notification and PR cover
GDPR (and the UK equivalent under the Data Protection Act 2018) sets the legal framework for when the ICO and individuals must be told about a breach. That legal duty directly shapes what a policy will accept as a valid claim.
When the law requires notification
A controller must notify the ICO of a personal data breach without undue delay and, where feasible, within 72 hours if the breach is likely to result in a risk to individuals' rights and freedoms. If the notification is delayed, controllers must document reasons for the delay. See official guidance at ICO guidance.
Implication for cover: insurers commonly require evidence the insured assessed the breach and concluded it met the legal threshold for notification. Policies may decline costs where an insurer determines that no legal notification obligation existed.
What insurers typically exclude relating to GDPR
- Regulatory fines and penalties (including ICO fines) are commonly excluded as statutory penalties;
- Costs arising from non-compliance before the policy inception or known incidents are excluded;
- Costs resulting from deliberate or fraudulent actions by senior management may be excluded.
Practical note: while fines are excluded, many policies do cover legal costs to respond to regulatory investigations (e.g. representation and defence), but subject to policy wording.

Typical policy limits and excesses for data breach notifications
Policy architecture varies. Two common approaches are:
- a single cyber limit with sublimits for notification/PR; or
- separate first-party sums for response and third-party liability limits.
Below is a comparative snapshot of typical arrangements for UK SME-targeted cyber policies.
| Policy element |
Typical SME range |
How it affects notification & PR |
| Total cyber limit (small business) |
£50,000 – £1,000,000 |
Higher total limit gives flexibility but may contain sublimits for specific items |
| Notification sublimit |
£10,000 – £250,000 |
Often a per-claim cap for legal/notification/credit monitoring; large datasets can exhaust this quickly |
| PR/crisis comms sublimit |
£5,000 – £150,000 |
Some insurers have a combined PR/notification sublimit or a separate small cap |
| Excess (deductible) |
£0 – £10,000+ |
Excess may be applied per claim or per insured event; small excesses are common but vary by insurer |
| Per-record notification cost limit |
£0.50 – £3.00 per record (indicative) |
Some products specify per-record costs for postage/letter services; others use a lump-sum approach |
Notes and actionable detail: the figures above are indicative at time of writing. Sublimits are decisive—an SME with 5,000 affected records could see notification postage and call-centre costs alone approach £10k–£25k when letters, outbound calls and monitoring are included.
How excesses and erosion work in practice
- Excess application: many insurers apply the excess to the first-party notification/PR sublimit per event. For example, a £1,000 excess on a £25,000 sublimit leaves £24,000 payable for notification.
- Erosion: where the policy has a combined limit, third-party defence costs can erode funds available for notification and PR; an SME should verify whether sublimits or aggregate limits apply.
When insurers cover PR and crisis communications after breach
Insurers commonly provide PR coverage under strict conditions. Understanding triggers reduces disagreement later.
Common triggers for PR cover
- Notification requirement: where legal notification to individuals or regulators is necessary; this often triggers PR cover.
- Material customer impact: significant customer data exposure or business interruption that reasonably threatens reputation;
- Insurer pre-approval or panel usage: many policies require use of insurer-approved PR firms or prior approval for external PR spend.
Panel vendors, breach coaches and SLAs
Policies often include access to a panel of forensic and PR vendors (a ‘breach coach’). Using these panel vendors can accelerate authorisation and payment. If a non-panel vendor is used, insurers may require retrospective approval and could reduce cover if the cost is deemed unreasonable.
Practical implication: retain contact details for insurer panel providers and confirm SLA expectations (e.g. 24-hour response, daily updates) so that procurement and invoicing meet insurer standards.
Breach response workflow
Breach response: from detection to reputation repair
🔎 **Detect** → 🛡️ **Contain** → 📣 **Notify** → 🧰 **Remediate** → 📈 **Repair reputation**
- 🔎 Detect: internal alert, log capture, initial triage
- 🛡️ Contain: isolate affected systems, preserve evidence
- 📣 Notify: legal assessment, ICO notification, affected individuals
- 🧰 Remediate: patches, password resets, monitoring
- 📈 Repair reputation: PR statements, stakeholder comms, monitoring
Exclusions and common policy pitfalls for breach notification cover
A sharp understanding of exclusions avoids unpleasant surprises when claiming.
Frequent exclusions and wording traps
- Regulatory fines and penalties, widely excluded; legal defence costs may still be covered in some policies.
- Prior known incidents or pre-existing non-compliance, incidents known before inception or listed in proposals can be excluded.
- Deliberate acts by directors or criminal behaviour, fraudulent or dishonest acts often void cover.
- Unapproved vendors and unreasonable PR spend, if the insurer expects a panel provider, non-panel costs risk rejection.
Pitfalls in proposal and renewal answers
Incorrect or incomplete answers on proposal forms (e.g. underestimating data volumes, failing to declare previous incidents) are a common reason for declined claims. Insurers may investigate whether the insured exercised reasonable care at inception.
Practical recommendation: keep records of board/minute decisions about cyber security, and ensure proposal answers reflect reality—these documents are often decisive during a claim.
Practical claims checklist for data breach notification and PR
A concise, evidence-focused checklist materially improves claim outcomes.
- Initial incident log (within hours): record timestamps, who discovered the incident, immediate containment steps and affected systems.
- Preserve evidence: retain relevant logs, snapshots and copies—avoid overwriting or deleting data.
- Engage forensic support: notify insurer (as required) and, if policy permits, appoint a panel forensic provider immediately.
- Legal assessment: secure written advice on whether the breach meets ICO notification thresholds and draft proposed notifications.
- Notify insurer: supply the incident log, forensic initial report and proposed notification texts; ask for confirmation on PR spend approval.
- PR plan: prepare draft press statements, stakeholder lines, and a short budget with hourly rates and deliverables for any PR agency.
- Document all costs: invoices, timesheets, supplier contracts, and communications approving spend.
- Follow-up reporting: provide updates to the insurer and maintain a simple ledger of all monies spent against the sublimit.
-
Sample regulator notice opening line: “Following discovery of a security incident affecting personal data, the controller is assessing the scope and will notify further details to the regulator in accordance with legal obligations.”
-
Sample customer notification opening line: “Company X writes to inform you that personal data relating to [type of data] may have been accessed without authorisation. Immediate steps are being taken to secure systems and support affected customers.”
These short, factual templates help insurers verify that notifications were lawful and reasonable.
Balance strategic: what is gained and what is risked with notification & PR cover
✅ When cover is high impact (scenarios of success)
- Significant dataset exposure where notification costs and monitoring would otherwise threaten cashflow; cover stabilises finances and preserves liquidity.
- Quick-access panel vendors reduce downtime and speed remediation, lowering the risk of follow-on litigation and reputational loss.
- Pre-approved PR budgets enable coherent public messaging, reducing sustained damage to customer trust.
⚠️ Red flags to watch (points of failure)
- Low or absent sublimits for notification/PR when the business handles large customer databases.
- Rigid insurer panels that delay authorisation or whose SLAs do not meet business urgency.
- Inaccurate application information leading to contested claims.
Which SMEs qualify — comparing policy wordings, limits, exclusions and UK claim examples
Data breach notification costs: what insurers typically cover is highly dependent on policy wording; SMEs should check definitions and sub‑limits before they need them. Smaller firms with under £10m turnover and up to a few hundred employees are routinely eligible, but coverage varies by how the insurer defines “privacy breach”, retroactive date and who is an insured.
Quick policy‑wording comparison
- Named peril / cyber extension vs standalone cyber policy — standalone policies usually give broader first‑party response cover (forensics, notification, PR, credit monitoring).
- First‑party cover commonly listed as “breach response costs” (forensics, legal advice, notification, call‑centre, credit monitoring) — check for separate sub‑limits for notification or PR.
- Key clauses to read: “retroactive date”, “automatic cover for new subsidiaries”, “notification expenses” definition and any requirement to notify the insurer before commencing work.
Typical limits, exclusions and sums insurers pay
- Typical SME limits: commonly £100k–£1m; many brokers recommend £250k–£500k for medium SMEs.
- Sublimits: notification/PR often capped at £10k–£100k.
- Common exclusions: regulatory fines and penalties, fraudulent transfer of funds, pre‑existing/known breaches, deliberate criminal acts by the insured.
- Typical payouts (real, anonymised UK broker data): small retailer claim total £35k (forensics £8k, notifications £5k, PR £7k, legal £15k); regional accountant claim £60k (notifications + credit monitoring for ~1,200 clients). Many SME claims settle between £10k–£150k.
Step‑by‑step claims checklist
- Contain breach and preserve logs (forensics). 2. Notify insurer per policy timescale. 3. Instruct panel breach lawyer/forensic firm if required. 4. Prepare notification template and costs estimate. 5. Track all costs and authorisations for claim submission.
Legal costs cover after a data breach
Data breach notification & legal costs are closely linked, but they are not the same type of expense. Notifying affected people may trigger questions from regulators, contractual claims from customers or legal action from individuals. Cyber insurance can help manage the financial impact, subject to the policy’s terms, limits and exclusions.
Solicitor fees and regulatory advice
Legal costs cover can pay for specialist solicitors to advise on the breach response, including whether notification is required under UK GDPR and how to communicate with the Information Commissioner’s Office (ICO). Legal advisers can also help preserve evidence, assess legal exposure and respond to requests from affected individuals, clients or suppliers.
This support is particularly valuable where the breach involves sensitive personal data, a large number of records or potential cross-border obligations.
ICO investigation support and defence costs
If the ICO opens an enquiry or investigation, legal costs cover may fund representation and advice throughout the process. It can also contribute towards defence costs where the organisation faces civil claims, contractual disputes or allegations that it failed to protect data adequately.
Cover for fines and penalties is different: some penalties may be uninsurable or excluded, so businesses should review their policy wording carefully.
How legal costs differ from notification and PR expenses
Notification costs usually cover practical response measures, such as mailing letters, call-centre services, credit monitoring or identity protection. PR and crisis-management costs focus on protecting reputation and managing media or stakeholder communications.
By contrast, legal costs cover pays for legal advice, regulatory representation and defence. In a post-breach claims scenario, these costs can arise alongside notification and PR expenses, making it important to understand the separate limits available under a cyber insurance policy.
Common questions about cover for data breach notification & PR costs
How quickly must the ICO be told after a breach?
Notification is required without undue delay and, where feasible, within 72 hours for breaches likely to cause risk to individuals. This timeframe determines urgency and whether insurer-funded legal advice is warranted; see ICO guidance.
Why do policies use sublimits for notification and PR?
Sublimits control insurer exposure and reflect the predictable nature of notification costs; they prevent a single large notification from eroding funds meant for third-party liabilities or ransom payments.
What happens if a claim involves both notification and a third-party lawsuit?
The policy wording determines whether limits are combined or separate. Where combined, legal defence costs can erode notification budgets; clarity at purchase mitigates this risk.
Which costs are typically excluded from PR cover?
Costs deemed unreasonable, unrelated to the breach response (e.g. marketing campaigns), or arising from deliberate misconduct by senior staff are frequently excluded.
How should an SME prove PR spend was reasonable?
Provide a written brief, invoices with hourly rates, a record of approvals, evidence of deliverables (press releases, media coverage) and confirmation that panel providers were considered if required by the insurer.
Your action plan: short practical steps to reduce friction right now
- Review the current cyber wording and locate notification and PR sublimits—note the excess and whether limits are combined.
- Save contact details for insurer panel forensic and PR providers and store them in a breach response folder accessible to key staff.
- Create a one-page incident log template and sample ICO/customer notification lines ready for immediate use.