Short answer: for a research nonprofit the exposure that matters most is not the office floor, it is the information. Identifiable respondent data belongs to a cyber and privacy policy. Allegations about the quality or content of your findings belong to a professional liability form. One set of facts can touch both — a respondent who says their data was mishandled and that the published report identified them — and which policy responds depends on how each form defines the act it insures.
The general liability form is built to stay out of this
Most organizations buy general liability first and assume it is the floor under everything. For data it is not.
The current ISO commercial general liability coverage form, CG 00 01 04 13, carries a Coverage A exclusion titled Electronic Data. It removes damages arising out of the loss of, loss of use of, damage to, corruption of, inability to access, or inability to manipulate electronic data, preserving only liability for bodily injury. The same form states, in its definition of property damage, that electronic data is not tangible property. A destroyed dataset is therefore not damaged property the way a flooded file room would be.
ISO went further in May 2014 with a family of endorsements — CG 21 06, CG 21 07 and CG 21 08 — excluding liability arising out of access to or disclosure of a person's or organization's confidential or personal information. CG 21 08 is the Coverage B version.
Coverage B is not the publication backstop you would expect
The form's personal and advertising injury grant does list publication offenses: oral or written publication of material that slanders or libels a person or organization, and publication that violates a person's right of privacy. That sounds like the answer to a defamation claim over a report.
But the same form carries Coverage B exclusion j., Insureds In Media And Internet Type Businesses, which applies to an insured whose business is advertising, broadcasting, publishing or telecasting. It has a carve-back, and the carve-back restores only the first three offenses in the definition: false arrest or detention, malicious prosecution, and wrongful eviction. Libel and right of privacy are not restored.
An organization whose principal output is published research is arguably in the business of publishing. Whether a carrier would press that exclusion against a research nonprofit is a live question, and not one to open for the first time after a demand letter arrives.
Where the seam between cyber and E&O opens
Neither specialty line is written on a single industry-standard form the way general liability is, so definitions matter more than labels. Cyber and privacy liability is generally triggered by a privacy or security event involving information the policy itself defines. Professional liability, or errors and omissions, is generally triggered by a wrongful act in the rendering of professional services, and "professional services" is usually a description scheduled on the declarations page.
Two carve-outs then create the gap, each reasonable alone. Professional liability forms commonly exclude claims arising out of a network security failure or unauthorized access to data, on the reasoning that cyber is the right home for those. Cyber forms commonly exclude claims arising out of the rendering of professional services, on the reasoning that E&O is. Buy the two from different carriers, with different definitions of the excluded activity, and a claim that is genuinely both can meet an exclusion in each.
Both lines are also usually claims-made, so the retroactive or prior acts date governs how far back covered conduct can reach. Research has a long tail: changing carriers without carrying that date forward can quietly strip cover for every study already in the archive.
What the federal rules require, and what they do not
The Common Rule at 45 CFR part 46 is a human subjects protection rule, not an insurance mandate; the word insurance does not appear in it. At § 46.116(b)(6), and only for research involving more than minimal risk, it requires the informed consent to explain whether any compensation and whether any medical treatments are available if injury occurs. That is a duty to disclose what exists, not to buy anything. Institutions and funders may impose their own conditions.
A Certificate of Confidentiality is not a financial backstop either. After the 21st Century Cures Act amended the Public Health Service Act, NIH began automatically issuing certificates for NIH-funded research collecting identifiable, sensitive information. It shields against compelled disclosure; it does not fund a breach response.
HIPAA is narrower than most assume. The Privacy Rule reaches covered entities — health plans, health care clearinghouses, and health care providers transmitting health information electronically in covered transactions — and their business associates. A researcher does not become one merely by holding identifiable health information, so many research nonprofits hold health-related survey data with HIPAA never applying.
State law does not care, though. All fifty states have breach notification statutes and they are not uniform. Missouri's sits at Mo. Rev. Stat. § 407.1500; Kansas at K.S.A. 50-7a02, which calls for a prompt good-faith investigation and notice where misuse has occurred or is reasonably likely. Survey nationally and your obligations follow your respondents' residences, not your office.
The requirement you must actually meet usually arrives by contract — a grant agreement, a subaward, a data use agreement — and is routinely found after signature.
What to check on your own policy
- Read the professional services description on your errors and omissions declarations against what you actually do. Evaluation, survey administration, technical assistance and testimony are distinct activities.
- Find the retroactive or prior acts date on both claims-made policies and confirm it reaches the oldest study still in your files.
- Put the cyber form's professional services exclusion and the E&O form's data or network security exclusion side by side and read them as one document.
- Check whether the cyber definition of protected information reaches identifiers that are neither financial nor clinical — immigration status, criminal history, income.
- Check your general liability declarations for CG 21 06, CG 21 07, CG 21 08 or a carrier equivalent, and ask whether exclusion j. would be argued against you.
- Pull the insurance clause out of every funder agreement before signing the next one; additional insured status is a general liability mechanism that often does not transfer.
How this fits the rest of the program
General liability still handles the ordinary premises and fieldwork injury claim; disputes over what to publish sit closer to directors and officers liability. For the whole program see our social science research insurance page and the nonprofit insurance overview; by line, cyber insurance for nonprofits and professional liability essentials; and the nonprofit insurance checklist.
Frequently Asked Questions
We do not collect health data. Does that make cyber optional? No. State breach statutes are generally built around a name combined with an identifier, and many have been amended to reach further data elements. Beyond the statutes, you promised confidentiality to people who answered questions they would not want disclosed.
A respondent says our findings defamed them. Which policy answers? That depends on the forms you hold and the facts alleged, and it is exactly the claim that lands in the seam. Professional liability is the line typically looked to for allegations arising out of the rendering of professional services, subject to the policy form, its retroactive date, exclusions and limits.
Does IRB approval or a Certificate of Confidentiality substitute for insurance? No, and neither is trying to. IRB review is an ethics and compliance process; a certificate is legal protection against compelled disclosure. Neither funds a defence, a notification programme or a settlement.
Should we buy cyber and E&O from the same carrier? It is one way to close the seam: a single carrier writing both is less likely to leave a claim pointing at itself in two directions. Two forms negotiated so the carve-outs meet works just as well. Buying them independently and hoping does not.
Have the two forms read together
If you would rather have someone read the two wordings side by side — the professional services description, the retroactive dates, the exclusions that create the gap — we will. Request a review or get in touch.
General information, not legal or insurance advice. Coverage, endorsements, exclusions and limits vary by carrier and by policy, and whether any particular claim is covered depends on the policy language and the facts.
