Get a quote

Cyber-Insurance Renewals are Growing in Complexity

17 July 2026

Lisa Mahoney, Senior DPO Consultant

Blog

Data Protection

GDPR

Privacy

US claims linked to tracking tools and data misuse are increasing (estimates suggest over 3,000 claims in the last 18 months), and insurers are consequently paying much closer attention to how organisations manage data protection risk. What was once viewed primarily as a regulatory concern is now being treated as an underwriting issue, with insurers assessing whether organisations can demonstrate operational compliance in practice. Whilst this litigation is in the US, businesses based in the EU and UK, but with US operations or US consumers are also affected by these changes.

Renewals are getting more detailed. Insurers are no longer just looking at cyber security controls; they also want to see how well data protection works in day-to day practice.

Insurance assessments that previously focused primarily on information security risks and controls are now looking more closely at the maturity of an organisation’s data protection programme. Insurers are no longer satisfied with the existence of policies alone; they are seeking evidence that governance frameworks are actively maintained and embedded across the organisation.

Where formal programmes are missing or immature, organisations should expect closer examination of remediation plans, governance ownership and investment in compliance activity. Without evidence of such activity, a business faces the possibility of increased premiums, insurance refusal or denial of claims.

Baseline governance indicators are also being used to assess risk exposure, including whether organisations are properly registered with supervisory authorities and meeting mandatory data protection fee obligations where applicable.

Tracking technologies driving litigation risk

The use of tracking technologies on websites and digital platforms has become a significant concern for insurers due to increasing litigation activity and enforcement risk in the US. Recently, the CNIL (the French data protection authority), has issued recommendations relating to the use of tracking pixels in emails, and made clear that this use requires consent, under the same legal framework applied for website cookies.

Organisations are now expected to show that they have identified and assessed a l tracking technologies operating across their digital estate, including those deployed through third-party platforms, embedded services or externally managed websites.

There is also growing emphasis on regular cookie audits and security testing to detect newly introduced or unauthorised tracking tools. These challenges require that privacy, security and web development teams work in coordination to manage risk effectively.

Privacy notices must reflect real practice

Privacy notices and consent mechanisms are also coming under closer review. Insurers increasingly expect organisations to demonstrate that public-facing notices accurately reflect actual data co lection and processing activities, rather than sitting on the website as tick-box compliance documents that no longer reflect day-to day practice.

This includes making sure that:

  • Responsibility for data protection oversight is clearly defined, especially where there are multi-party relationships;
  • Privacy and tracking (cookie) notices align with operational practices; and
  • Consent mechanisms are appropriate to the categories of personal data being processed, including sensitive data such as health information or biometrics.

There is also increasing focus on how consent is recorded, managed and maintained over time, particularly where organisations rely on consent as a lawful basis for processing.

Policy frameworks under greater scrutiny

Insurers increasingly want to see not only a clear set of policies covering how data is collected, used, shared, kept and deleted, but also evidence these are implemented in practice and maintained through ongoing governance processes.

For international organisations, it can be harder to show accountability and operational assurance consistently across the business. In complex international operations, certifications such as ISO 27001 (information security management system), ISO 27701 (privacy information management system) and ISO 42001 (artificial intelligence management system) can help provide clear, independent evidence of good governance.

AI governance falls in scope

The governance of generative AI tools and AI agents is also beginning to feature in underwriting assessments.

If your organisation is developing or using AI tools, insurers are increasingly likely to ask how those tools are being governed, what risks have been assessed and what guardrails are in place.

While the EU AI Act is still under review, AI governance is rapidly becoming part of mainstream compliance evaluation. As the potential for fines grows across the combined GDPR, EU AI Act and EU Cyber Resilience Act, the potential cost of non-compliance increases, too, with insurance requirements starting to reflect that.

Third-party risk remains a focus

Third-party data processing arrangements continue to represent a significant area of insurer scrutiny.

Organisations are increasingly expected to show that contracts with vendors and service providers are current, legally compliant and reflect evolving regulatory requirements.

This includes alignment with laws such as the CCPA/CPRA, BIPA and emerging obligations under the EU AI Act where relevant. Recent attacks affecting Marks & Spencer and the Co-op are a reminder that third-party risk is not theoretical. Weaknesses in the supply chain can quickly become a direct business risk.

The headlines are reminders that organisations must proactively manage their service providers and remain accountable for processing activities throughout the supply chain.

Key takeaways

The insurance market is increasingly treating data protection maturity as a measurable indicator of organisational risk.

Tracking technologies, consent management, AI governance and third-party oversight are now important considerations during underwriting and policy renewal processes.

Organisations that cannot show that compliance works in practice may face increased scrutiny, higher premiums or reduced coverage. As regulation increases and threats become more complex, organisations need to be able to show that privacy and cyber risk are being actively managed, not just for compliance, but for insurability, too.

Data protection, delivered by experts
Our privacy team is made up of qualified data protection professionals with extensive practical data protection compliance experience.

We understand the law and how to translate it into organisational reality in a way that is both compliant and aligned to your goals and priorities.