Does Your Business Insurance Cover CIPA Claims? The Exclusion Problem
General liability and cyber policies don't automatically cover CIPA claims, and many explicitly exclude statutory privacy violations. Here's what to actually check with your broker.
If a CIPA demand letter or lawsuit lands on your desk, one of the first practical questions is whether any of your existing business insurance applies. The honest, general answer: it’s genuinely policy-specific, and a meaningful share of standard policies either don’t clearly cover this kind of claim or explicitly exclude it. This is worth checking before you need it, not after.
Why this isn’t a straightforward yes or no
CIPA claims sit in an awkward spot for insurance categorization. They’re not a data breach in the traditional sense (no unauthorized outside hacker, no stolen database), which is the scenario most cyber liability policies are built around. They’re also not the kind of bodily injury or property damage claim general liability policies are built for. And because the underlying statute involves a form of “invasion of privacy,” some policies bucket it with personal injury/advertising injury coverage, while others carve that category out specifically for statutory violations.
Where exclusions commonly show up
Three places worth specifically asking your broker about:
- “Violation of statutes” exclusions. Many general liability and cyber policies exclude claims arising from violation of a specific statute (sometimes naming categories like TCPA, CCPA, BIPA, or wiretapping laws directly), which can sweep in CIPA claims explicitly or by close analogy.
- “Intentional acts” language. Some policies exclude coverage for conduct characterized as willful, and CIPA’s own statutory language uses “willfully”, creating a potential argument that the underlying conduct falls outside coverage by the statute’s own wording, regardless of intent in the ordinary sense.
- Prior-acts and retroactive-date limitations, relevant if a tracker has been running unmodified for a long period before a claim arrives.
Enzuzo
Insurance coverage is uncertain enough that prevention is the more reliable strategy, closing the underlying gap with a consent tool like Enzuzo reduces reliance on a coverage question you may not be able to answer confidently until a claim actually arrives.
What to actually ask your broker
Rather than assuming coverage either way, bring your broker a specific question: “Does my current [cyber / general liability / management liability] policy cover claims under California’s wiretapping statute (CIPA), including claims related to website tracking technology, and does it exclude claims based on alleged willful conduct or statutory violations generally?” A specific question gets a more useful answer than “am I covered for privacy stuff.”
Why this matters even if you think your risk is low
Even a low-probability claim is worth understanding your coverage position on, because the cost of finding out you’re not covered arrives at the same time as the cost of the underlying claim, not a convenient moment to be doing policy research for the first time. If you’ve read our piece on what to do after a demand letter arrives, checking your insurance posture is explicitly one of the first steps, and it’s far easier to do calmly in advance.
This is general educational information, not insurance or legal advice, and not a review of any specific policy language. Insurance coverage is policy-specific, consult your broker or an attorney to review your actual policy.