Propel provides innovative insurance solutions to thousands of companies across the country. We make it our business to know your world inside and out.
Claims & Risk Management, Commercial, Cyber Security, Insights, Risk Management, Senior Care
Trending Alert: The Risk of Information Collection, Storage, and Usage
Recently, several invasions of privacy allegations have manifested into legal complaints with identical fault-based wording: obtaining, collecting, storing, and sharing user data without notice or consent.
California’s Invasion of Privacy Act (CIPA) has been the basis of recent complaints for senior care providers operating in this state, but has now migrated to other states and is being used routinely as a doorstep to invasion of privacy litigation.
Multiple recent claims have been submitted by this self-represented individual, who has become well known for filing a high volume of similar privacy-related demands nationwide.
The approach is straightforward. Software tools are used to identify whether a website may be collecting or tracking user data before giving notice or obtaining visitor consent.
A demand for compensation is then generated, threatening litigation if terms are not met.
Cyber insurers and defense counselors are increasingly familiar with these claims, and in recent discussions with carriers, adjusters have described the increase as voluminous.
With the advancement of reliance on technology, risk mitigation will require a new proactive approach.
Key Takeaways
Mitigating this Specialized Claim Risk
- Regularly review website technology and tracking tools.
Businesses should routinely audit their websites to understand which cookies, pixels, analytics tools, and other tracking technologies are being used, and to ensure they align with privacy requirements. - Keep privacy policies and website terms up to date.
Privacy notices and terms of use should accurately reflect current website practices, including the types of information collected, use of tracking technologies, and whether information is shared with third parties. - Obtain clear, affirmative consent from website visitors.
Simply posting a privacy policy or terms of use may not be enough. Businesses should provide clear notice and require users to take affirmative action, such as accepting cookie settings or agreeing to terms, before proceeding. - Implement strong cookie consent practices.
Use a compliant cookie banner that clearly explains tracking technologies, provides options to accept, reject, or customize cookies, and prevents non-essential tracking tools from activating before a user makes a choice. - Know and manage your third-party vendors.
Companies can face liability for the actions of vendors that provide website tools or services. Review vendor practices, understand what data is collected or shared, and ensure contracts address privacy responsibilities and protections.
Coverage for these claims vary widely by policy. Notify Propel immediately if you receive any communications regarding an alleged invasion of privacy.


