Insurance Coverage for Data Breaches and Unauthorized Privacy Disclosures
Total Page:16
File Type:pdf, Size:1020Kb
This material was published as chapter 16 in Proskauer on Privacy: A Guide to Privacy and Data Security Law in the Information Age (2nd ed.) by Ryan P. Blaney of Proskauer Rose LLP (©2016 & Supp. 2019 by Practising Law Institute), www.pli.edu. Reprinted with permission. Not for resale or redistribution. Chapter 16 Insurance Coverage for Data Breaches and Unauthorized Privacy Disclosures Steven R. Gilford JAMS Marc E. Rosenthal* Proskauer Rose LLP § 16:1 Overview § 16:2 Applicability of Historic Coverages § 16:2.1 First- and Third-Party Coverages for Property Loss [A] First-Party Property Policies [B] Third-Party CGL Policies: Coverage for Property Damage Claims § 16:2.2 CGL Coverage for Personal and Advertising Injury Claims [A] Publication Requirement [B] Right to Privacy As an Enumerated Offense [B][1] Telephone Consumer Protection Act Cases [B][2] Fair Credit Reporting Act Cases [B][3] “ZIP Code” Cases * The authors would like to thank Proskauer summer associates Dakota Treece and Libbie Osaben for their work researching and updating the current version of this chapter. (Proskauer, Rel. #6, 10/19) 16–1 ©2016 & Supp. 2019 by Practising Law Institute. Not for resale or redistribution. § 16:1 Proskauer on Privacy § 16:2.3 Other Coverages [A] Directors and Officers Liability Insurance [B] Errors and Omission Policies [C] Crime Policies § 16:3 Modern Cyber Policies § 16:3.1 Key Concepts in Cyber Coverage [A] Named Peril [B] Claims Made § 16:3.2 Issues of Concern in Evaluating Cyber Risk Policies [A] What Is Covered? [B] Confidential Information, Privacy Breach, and Other Key Definitions [C] Overlap with Existing Coverage [D] Limits and Deductibles [E] Notice Requirements [F] Coverage for Regulatory Investigations or Actions [G] Definition of Loss [H] Who Controls Defense and Settlement [I] Control of Public Relations Professionals [J] Issues Created by Involvement of Policyholder Employees [K] Coverage of a Threatened Security Breach [L] Coverage for “Breachless” Claims [M] The “Internet of Things” and Potential Physical Damage or Bodily Injury from a Cyber Attack [N] Governmental Activity Exclusion [O] Other Exclusions § 16:3.3 SEC Disclosure and Other Regulatory Initiatives § 16:1 Overview The unauthorized disclosure of personal and other confidential information has become a well-known and ever-increasing risk for holders of third-party information and business data.1 Notification letters from companies that have suffered data breaches have become 1. See, e.g., Taylor Armerding, The 17 biggest data breaches of the 21st cen- tury, CSO (Dec. 20, 2018), https://www.csoonline.com/article/2130877/ data-breach/the-biggest-data-breaches-of-the-21st-century.html; Dennis Green, If you shopped at these 14 stores in the last year, your data might have been stolen, BUS. INSIDER (Apr. 6, 2018), http://www. businessinsider.com/data-breaches-2018-4; Paige Leskin, The 21 scari- est data breaches of 2018, BUS. INSIDER (Dec. 30, 2018), https://www. businessinsider.com/data-hacks-breaches-biggest-of-2018-2018-12. Well- known companies like Sears, Delta, Best Buy, Marriott/Starwood, Chegg, Eventbrite, Facebook, MyFitnessPal, Under Armour, and Whole Foods experienced data breaches in 2017 and 2018. 16–2 ©2016 & Supp. 2019 by Practising Law Institute. Not for resale or redistribution. Insurance Coverage for Data Breaches § 16:1 commonplace, and high-profile breaches of millions of records at major companies have become the subject of headlines and board of directors meetings around the world.1.1 In addition to asserted claims of data privacy breaches, risks from technology exposures include business interruption, extortion demands, inability to perform obligations to others, damage to rep- utation, and loss or distortion of company and client data. As busi- nesses continue to evolve in a technology-driven environment, so too do practices for the handling and protection of sensitive information and data. Due to the ubiquity and increasing quantity of digital infor- mation, information holders are exposed to a multitude of risks that data can be lost or stolen.2 The costs associated with a data breach or unauthorized disclosure of confidential information can be sub- stantial,3 and they are likely to continue to increase as governmental 1.1. See, e.g., Maria Korolov, Cybersecurity on the Agenda for 80 Percent of Corporate Boards, CSO (May 28, 2015), www.csoonline.com/article/ 2927395/data-protection/cybersecurity-on-the-agenda-for-80-percent- of-corporate-boards.html; Eve Tahmincioglu, Report: Cybersecurity Remains a Top Company Threat for Directors (Dec. 6, 2018), https:// www.directorsandboards.com/news/report-cybersecurity-remains-top- company-threat-directors (noting that while a majority of directors report understanding cybersecurity issues, only 52% report being confident in providing “effective cyber-risk oversight” and 50% being “confident that their companies are secured against a cyber attack”). 2. Data loss or security breaches can occur in a number of ways, includ- ing network hacking, lost or stolen laptops, spyware, phishing, insecure media disposal, hacked card swiping devices, security vulnerabilities on mobile devices, misdirected mail and faxes, insecure wireless networks, peer-to-peer software, breaches in physical security, problematic software updates or upgrades, human error, rogue or disgruntled employees, and lost or stolen media. Even companies that specialize in storing personal information or passwords have been hacked. See, e.g., Jose Pagliery, Irony Alert: Password-storing Company Is Hacked, CNN (June 16, 2015), http:// money.cnn.com/2015/06/15/technology/lastpass-password-hack/index. html; Taylor Armerding, The 17 biggest data breaches of the 21st cen- tury, CSO (Jan. 26, 2018), https://www.csoonline.com/article/2130877/ data-breach/the-biggest-data-breaches-of-the-21st-century.html (in 2017, Equifax, one of the largest credit bureaus in the United States, expe- rienced a data breach that exposed the personal information of about 143 million consumers; 209,000 consumers also had their credit card data exposed); Paige Leskin, The 21 scariest data breaches of 2018, BUS. INSIDER (Dec. 30, 2018), https://www.businessinsider.com/data-hacks- breaches-biggest-of-2018-2018-12. 3. In 2018, the costs of a compromised record reportedly averaged $148 per record globally, and the average cost per data breach event was $3.86 million. Data breaches are most expensive in the United States where the average per capita cost of a data breach was $233 in 2018, and the aver- age cost per data breach event was $7.91 million. PONEMON INSTITUTE LLC, 2018 COST OF DATA BREACH STUDY: GLOBAL OVERVIEW (July 2018), (Proskauer, Rel. #6, 10/19) 16–3 ©2016 & Supp. 2019 by Practising Law Institute. Not for resale or redistribution. § 16:1 Proskauer on Privacy regulators become increasingly vigilant and sophisticated in the reg- ulation of cyber privacy issues and concerns.4 At the same time, cor- porate directors and officers are facing increased exposure to liability in relation to data breaches, as plaintiffs’ attorneys have endeavored to hold them responsible for allegedly inadequate attention to data security.5 As the risks associated with data and privacy breaches continue to grow and evolve, companies and individuals have turned, in vary- ing degrees, to their insurers for protection. One report estimates the market for cyber insurance at $3.89 billion in gross annual premiums and predicts it to increase to $23.07 billion in 2025.6 The number of companies and individuals buying cyber policies reportedly increased by 50% from 2015 to 2016, with companies that handle large amounts of personal data, such as health care, retail, manufacturing, logistics, and telecommunications, having the highest growth.6.1 The demand for cyber coverage is also increasing in the financial, energy, utilities, and transportation sectors due to the increasing risks they face from interconnectivity with consumers.6.2 Historically, claims for insurance for data privacy risks have been asserted under traditional coverages, including commercial general liability (CGL) policies, directors and officers (D&O) liability insur- ance, errors and omissions (E&O) policies, and commercial crime and first-party property and business interruption policies. Insurers, how- ever, have frequently taken the position that these traditional cover- ages do not cover claims for data and privacy breaches. https://public.dhe.ibm.com/common/ssi/ecm/55/en/55017055usen/2018- global-codb-report_06271811_55017055USEN.pdf. Costs associated with a typical data breach can include, but are not limited to, internal investigations, forensic experts, consumer notifica- tions, discounts for future products and services, credit monitoring, crisis management, call centers, attorney fees, payment card industry fines, increased processing fees, litigation (including damages, awards and set- tlements, agency and attorney general actions), reputational costs, and technology upgrades. Id. 4. See infra section 16:3.3. 5. See infra section 16:2.3[A]. 6. Adroit Market Research, Cyber Security Insurance Market to Reach $23.07 Billion by 2025 (Apr. 10, 2019), https://www.globenewswire.com/news- release/2019/04/10/1802202/0/en/Cyber-Security-Insurance-Market- to-reach-23-07-Billion-by-2025-Adroit-Market-Research.html. 6.1. John P. Mello, Jr., Cyberinsurance Report 2017, Cybersecurity Ventures (Mar. 6, 2017), https://cyberseucrityventures.com/cyberinsurance-report- 2017/. 6.2. Id. 16–4 ©2016 & Supp. 2019 by Practising