Showing posts with label wrongful act. Show all posts
Showing posts with label wrongful act. Show all posts

Monday, September 16, 2013

An Ironshore Cyberpolicy--Part VI: Insuring Agreement I.E.

TechDefender

Tech E&O, Network Security, Internet Media and MPL Insurance Policy 

Insuring Agreement I.E: Regulatory Proceeding Coverage
Remember: This Blog is organized around insuring agreements, definitions and exclusions. Conditions, etc., may be remarked upon briefly, they often resemble not only each other but those found in currently existing policies.
The first specific thing to notice here in I.E. is that the Insurer agrees to reimburse the Insured.  Be mindful of the fact that this concept is quite different from "pay on behalf of" or "pay for."  "Reimburse," literately understood, means that the insured pays first. There is no reason to believe that a court will not take this language literally.

Second, and very important, this entire section is attached to two concepts: Privacy Incident
and Regulatory Proceeding.  The first of these concepts was discussed in Part V, and a concept related to the second one, Privacy Regulation, was also discussed there. Much of what was written there is reprinted in the next paragraph.

The phrase Privacy Incident briefly put includes (i) the disclosure, etc., of some information or another, that is secret, or close to it; and the disclosure is in the care, custody or control of the Insured or Service Provider.  (ii) That disclosure must result from a Privacy Regulation or a failure of the Company to comply with its own privacy policies. The concept of Privacy Regulation includes a slew of  named statues, both state and federal, plus regulations under those statutes, and "any similar state, federal or foreign identity theft or privacy protecting statute." 

[MSQ:  Does the reader realize how controversial the phrase "care, custody and control" can be in insurance disputes?  And here only immaterial entities are involved. Will that complicate matters? Does the reader recognize that there may be controversies generated by the word "similar"?  Or what about this what about the word "any"?  What about when they don't apply? Are Bolivian privacy administrative rules applicable to problems in Oklahoma?  (Perhaps not; but consider the twists and turns, "New York lawyers" might generate out of these two ideas.)  Remember: the phrase "care, custody and control" has caused lots of  insurer-insured disputes for many years.

Now for the second of the two crucial concepts, Regulatory Proceeding.  This topic has not been written about in this (group of) blog(s).  The idea is pretty clear from the language.  The phrase means (1) a governmental investigation of an Insured, e.g., perhaps leading up to a adjudicative governmental hearing concerning a Privacy Incident and/or (2) an adjudicative administrative hearing on either a Privacy Wrongful Act or a Network Wrongful Act including an appeal, either of them begun by the receipt of "a subpoena, a formal investigative demand, complaint or similar document."

It seems odd to me, at least appears, that one of the types of wrongful acts is covered for investigations and the other one is not. Indeed, this seems so unlikely that I think I must have missed something.

The Insured's right to be paid for its expenses in this arena is huge. This fact indicates that the insured should make sure that everyone in its organization involved knows well the terms of the policy, consults with risk management, stays in close contact with the IT and IS departments, and ask in-house or outside counsel for advice.  (Perhaps there will be an appropriately specializing attorney included within the in-house counsel department. This is not uncommon in really large law firms.) In addition, the Insured should monitor its work on these matters carefully, make sure that accurate records are kept, make sure that confessionary, personal, and other assorted messages are not entered into the cyber-systems.  It would be a good idea for the insured to institute a special, nearly unique kind of specialized "Product Management," as it is now called.

The Insured should also make sure that it has enough coverage. The problem here is that no one really knows what is adequate coverage.  The whole field is too new; there has not been enough time to develop helpful statistical data.

On to I.F.


Monday, September 9, 2013

An Ironshore Cyber Policy--Part IV--Ins Ag I.C


TechDefender

Tech E&O, Network Security, Internet Media and MPL Insurance Policy 

Insuring Agreement I.C--Privacy Liability Coverage
__________________________________________________
 
Remember: This Blog is organized around insuring agreements, definitions and exclusions. Conditions, etc., may be remarked upon briefly, but they often resemble not only each other but those found in currently existing policies.
 
This is Part IV of a series of blogs about the above named policy.  Part I was an introduction and a discussion of Insuring Agreement insofar as it closely resembled "physical-world" policies, as opposed to "cyber-world" policies.  The topic pertained to D & O insurance.  Part II was a discussion of the substantive content of the Insuring agreement Ins Ag I.B, again regarding a type of D & O liability insurance.  I.A. pertained to network security and privacy wrongful acts, both of which are extensively discussed in society.  Ins. Ag. I.B concerns the same range of problems and is a broader D & O liability policy.   As already set forth in Part I, what is written here is nothing more than a sketch and the observations are not guaranteed.

I.C. Privacy Liability Coverage
This Insuring Agreement sets forth liability insurance for Damages the Insured is legally obligated to pay for losses directly resulting from any covered claim alleging a Privacy Wrongful Act  against the Insured. (The last term includes not only the Company, plus directors and officers, but a variety of others, e.g.,  employees of various sorts, among others.)  [This passage is a bit confusing.  It  might apply to a duty to defend, or something like it, but it well not apply to actual damages suffered.  The idea in the claim is that if an insured has a legal obligation to pay something that is damages, the insurer will pay it on its behalf.
The substantive components of this Insuring Agreement are, first, the idea of Privacy Wrongful Act (PWA), second,  the idea of Privacy Incident, and third, the idea of  Damages (D).  

First we examine PWA, since the term "privacy" is not independently defined, so we start with PWA.
This is a blessed definition since it is short and direct.  PWA "means any actual or alleged act, unintentional error, omission, neglect or breach of duty by an Insured or a Service Provider that results in a" PI. 

PI--and now we arrive at the crucial part of the insuring agreement--is, roughly speaking (1) the unpermitted disclosures of Non-Public Personal Information or Confidential Corporate Information that "is in the care, custody, or control of any Insured or Service Provider, ad defined., or (2[a]) it is a violation of any Privacy Regulation or (2[b]) or is a "failure to comply with the  Company's own privacy policy."

Privacy Regulation is a concept of extraordinary significance.  It includes a number of named federal and state statutes "associated with the control and use of personally identifiable financial, medical, or other sensitive information," plus "any similar, state federal or foreign identity theft or privacy protection statute."


 
DEFINITIONS

Damages of course, is a crucial idea in all insurance policies.  The definition of Damages in this policy is a complex one, to say the least. There are 4 components of what the term means, and there are 9 lines setting forth what the terms does not mean, and the 9th line contains at least 13 different concepts which the term does not cover.

Here is that which the term applies.  It resembles traditional lists of damages in some "so-called" real world policy:
  • that for which the insured is legally obligated to pay as the result of a covered judgment, award or settlement
  • monies the  court victorious victim has been able to impose on the insured, e.g., attorney fees and so forth
  • pre- and post-judgment interest (with exceptions)
  • punitive, exemplary or multiple damages to the extent that an state law applies and to the extent more that one applies, the one which is most favorable to the insurer if insurable.
Defense costs are usually covered else where in the policy; they are usually not found in the definitions of damages.
An apparent complexity in the definition of Damages is to be found in a list of that to which the term does not refer.  The positive side of the definition is straight forward and relatively simple.  Most of its components resemble the definition or characterizations of Damages found in so-called "real-world" policies, except for defense costs.  That matter is usually set forth else where in at least most policies. The "Damages do not include" section explicitly sets forth a number of situations to which the term Damages does not apply. These matters are usually found in exclusionary sections.

There are several special components "added" on, as it were, to the definition of Damages, which are "not included" in the definition section or other sections of so called, "real-world" policies--as already stated, one would expect these to be in an exclusion section. The following are included among the not included:

#6. nearly 5 lines of activities which might have to be undertaken, including "Computer System of the Company, [its] security system and Electronic Publishing."  Significantly,  Electronic Publishing includes Electronic Data, and other things, objects, events and activities.  [MSQ:  Obviously this definition of what is not included in the a covered definition is enormously complex.] 

#7. "any discount, coupon, prize, award, redemption or other incentive;"

#8. "Bodily Injury or "Property Damage;"  [MSQ: It is easy to see why they are let's say excluded, by definition, they are two of the principal coverages under some significant "real world" insurance policies, e.g., the Commercial General Liability.

#9. Business Interruption Income Loss, Claim. . . . Regulatory Proceeding.  [In total, there are 13 separate categories included in this "not included in the definition of Damages" category.]

 And so forth. Significantly, all definitions found in the definition section are used throughout the policy.  In many "real world" policies, different sections may have at least some different definitions
EXCLUSIONS
 
The list of exclusions is a long, long one, so not many of them can be addressed.  Some are repetitions of what is in the definition or the "not included" definition of Damages and perhaps elsewhere to boot. Many of them resemble, or are analogues of exclusions found in so-called "real world" policies.
For example, there is an exclusion for Losses resulting from various causes, most of them contract based (or likely contract based).  It is more complex than the usual exclusion of that sort; it takes up 7 lengthy subsections. Perhaps what is happening here is that given the "new-ness" of this type of policy, the insurer is trying to make sure nothing is left out. Perhaps it believes that details cut exposure. Of course, this may be wrong. It may be that all they do is create new exposures.
Here are some other exclusions:
  • based on actions brought by some trade associations, particularly an international array of those from the IP sector
  • based on violations of various statutes
  • resulting from various kinds of discrimination
  • resulting from various types of unsolicited cyber misconduct
  • thefts of various sorts
  • IP misconducts of various sorts related to thefts  [Some of these pertain to the proposition that there is no insurance for many types of intentional acts and especially for those involving crimes.]
  • mechanical and electrical faults
  • gambling, etc. 
Thus, this insurance policy in general and perhaps this section in particular resemble "real world" insurance policies, but in vastly more important ways, they are a new species--one filled with new ideas, new definitions, and new coverages. Interestingly, most of the new coverages are, in one way or another, topics widely discussed in various media.
Now, for Insuring Agreement I.D Privacy Breach Expenses Coverage.  See Part V.