Wrongful data collection exclusions are spreading – what brokers need to check in cyber policies

Rising frequency is putting policy wording under the microscope, as smaller businesses face growing exposure

Wrongful data collection exclusions are spreading – what brokers need to check in cyber policies

Cyber

By Gia Snape

Wrongful data collection claims are becoming a growing cyber insurance frequency problem, prompting more carriers to introduce specific exclusions and raising questions over whether some alleged privacy violations should be insurable at all.

Resilience’s midyear claims data shows frequency across its portfolio climbed to 45.9 claims per 100 policies in the first half of 2026, up from 40.5 in the previous six-month period, with the insurer attributing much of the increase to wrongful data collection claims. At the same time, only 3.4% of claims generated an incurred loss, the lowest proportion across the five reporting periods in its data.

Jeremy Gittler (pictured), global head of claims at cyber insurance firm Resilience said the trend reflects the enormous amount of customer information businesses now collect through their websites, often for marketing and sales purposes.

One source of these claims, he said, is self-represented plaintiffs, particularly in California, alleging that websites have tracked visitors and shared their information with third parties without consent. Other claims are being pursued by law firms through demand letters, arbitration or litigation. Many allege violations of the California Invasion of Privacy Act, alongside the Federal Wiretap Act and other statutory and common-law causes of action.

“It’s more of a volume situation… high volume, low severity,” Gittler said. “These are not multimillion-dollar losses associated with ransomware or a true data breach. They’re essentially resolving in the $10,000 to $30,000 range.”

High frequency creates coverage questions

The individual settlements involved can appear relatively modest compared with ransomware or major data breaches. However, hundreds of smaller claims can still create meaningful aggregate costs, particularly where insureds carry relatively low retentions. Legal fees, mediation, discovery and other defense expenses can further increase the cost.

The claims environment is also exposing substantial variation between cyber policies. “Depending on the policy, sometimes coverage is triggered, sometimes it’s not. That’s different industry-wide,” Gittler said. “It’s not 100% that it would be covered or wouldn’t. There might be an exclusion for it. It might pass an insuring agreement. It might not.”

That variation is becoming more significant as carriers respond to claims frequency through policy wording, Gittler added: “Because this is becoming so common, we’re also seeing more and more exclusions. A lot of companies will simply have a wrongful collection exclusion." The development puts greater emphasis on reviewing how privacy and wrongful collection exposures are addressed at renewal rather than assuming that otherwise broad cyber coverage will respond consistently.

Gittler also raised a more fundamental question around whether coverage should extend to deliberate business practices that are subsequently alleged to violate privacy law. He said: “If a company consciously decides to do something that is against the law, the question becomes whether that is something insurers should be covering at all. The flip side is a company saying, ‘We thought we were doing everything right. There was nothing nefarious there. We didn’t do it on purpose. We just didn’t realize what the law was.’”

Smaller businesses move into the firing line

While healthcare and media companies were among the prominent targets of earlier privacy litigation, Gittler said the current claims wave appears increasingly focused on smaller organizations. Larger corporations, by contrast, are now more likely to have general counsel and legal departments familiar with website tracking litigation and privacy requirements.

“Every company at this point has a website, and a lot of these companies might be smaller and not as sophisticated or sophisticated in the law,” he said. “They don’t realize they’re doing it, per se, or that it’s against the law. What we’re seeing today is more going after smaller entities, just to make a quick buck, versus going against a large corporation where there’s going to be a protracted and expensive litigation.”

This dynamic makes underwriting questions around data practices increasingly important. Gittler pointed to questions including what data a company collects, how long it keeps that information, whether customers are informed, whether information is shared and what safeguards govern third-party vendors.

Internal communication is another potential weakness. Marketing teams may introduce tracking technologies without legal, finance or risk management functions knowing how the tools operate or what information they collect.

Third-party providers do not necessarily remove the original exposure either. Gittler said an insured collecting customer information can still face a claim even where a vendor ultimately caused the alleged problem, leaving contractual indemnification and vendor oversight as important parts of the risk assessment.

With exclusions spreading and smaller companies increasingly exposed, wrongful data collection is becoming less of a niche privacy issue and more of a policy-wording and risk-governance problem across the cyber market.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!