A technology company inverts the usual risk profile. Its physical assets are modest and replaceable;
what is valuable is the code, the data it holds on behalf of third parties and the continuity of a
service promised under contract. Classic property covers therefore protect very little of what can
actually go wrong.
Regulatory risk multiplies by client
In most B2B contracts the technology company acts as processor: it does not decide about the
personal data, but it answers for how it is handled. That has a counter-intuitive consequence: a
single breach in its infrastructure triggers the notification obligation of each and every affected
client.
The General Data Protection Regulation
allows 72 hours from becoming aware to notify the supervisory authority, and requires
communication to the data subjects without undue delay where the risk to them is high. That clock runs
for the controller —the client— but the party holding the facts and the forensic evidence is the
supplier. Processing agreements tend to pass the consequence back up the chain.
It is also worth separating two penalty tiers that most commercial content conflates: failing to
notify is sanctioned under article 83(4), up to €10 million or 2% of worldwide turnover;
infringing the principles or data subjects' rights falls under 83(5), up to €20 million or 4%.
The typical loss leaves no physical trace
A failed implementation, a calculation error in an algorithm or a badly executed migration produce
pure financial loss: cost overruns, delays, processes that have to be redone. No general liability
policy responds to that, because it excludes it by definition.
And there is a boundary better written into the contract than into the policy: penalties for
breaching a service-level agreement are commercial risk, not insurable loss, and policies exclude
them. What is insurable is the loss the failure causes beyond the agreed penalty.
Selling to government changes the requirements
When the company bids for a public tender, three requirements arrive together and to a deadline:
compliance with the National Security Framework,
the definitive guarantee, and a liability certificate with minimum limits and the exact wording the
tender documents call for. The last two are resolved within the insurance programme; the first is not,
but it arrives in the same envelope.
Why through a broker
As a broker registered with the Spanish Directorate-General for Insurance and Pension Funds under
reference J0140, New Brokers works on the client's mandate, not on behalf of any insurer.
In technology the work starts before the policy: in the client contracts. That is where it is settled
what liability is assumed, which penalties are accepted and which data protection obligations are
passed on. An insurance programme that has not been read alongside those contracts covers a different
risk from the one the company has signed up to.