Home/Questions/Business and financial profile/Processing for third parties
Business and financial profile

Does the Applicant provide data processing, storage, or hosting services to third parties?

Holding other organisations data means a single breach produces claims from many parties at once.

Attested, not tenant-verifiable

What the carrier is actually asking

The carrier is asking whether you process, store, or host data on behalf of other organisations. It covers software vendors, hosting providers, outsourcers, and anyone whose service involves holding a client's data.

Why it is underwritten

A breach at a processor affects every client at once, and each client can claim. The liability is contractual as well as regulatory, and it is frequently larger than the processor's own balance sheet. Carriers underwrite this as an aggregation exposure and often push toward technology errors and omissions cover alongside cyber.

Where the answer lives in Microsoft 365, Entra ID, and Azure

This is a description of your services, and the useful supporting detail is scale and separation.

PlatformWhere the setting livesWhat has to be true
ServicesWhat client data you hold and for how many clientsVolume and client count, which determines aggregation. Attested
ContractsLiability caps, indemnities, and data processing agreementsWhat you owe each client, which is the exposure this question is sizing
ArchitectureWhether client data is segregated or commingledTenant separation, since commingled data means one breach touches everyone
AzureIsolation between client environments where hosted in the cloudSeparation enforced by design and measurable
NotificationObligations to notify clients and their timelinesContractual notification periods, which are often shorter than regulatory ones
Contractual liability can exceed the policy

Processors frequently sign uncapped data liability or caps far above their cyber limit. That gap is real, uninsured exposure. Comparing your contractual commitments against your limit is a short exercise that occasionally changes a renewal.

What a defensible yes requires

  • The scale is stated: client count and record volumes held on their behalf.
  • Contractual liability positions are known and compared against your limit.
  • Client data is segregated rather than commingled.
  • Data processing agreements are executed with each client.
  • Notification obligations and their timelines are documented and achievable.

How this answer goes wrong

The answer is yes with no accompanying detail, so the underwriter cannot size the aggregation and prices conservatively. Or the answer is no because the service is described as software rather than hosting, while the software holds client data on infrastructure you operate.

Frequently asked

Does software-as-a-service count?

Yes. If your platform holds client data, you are processing it on their behalf regardless of how the service is described commercially.

Do we need technology errors and omissions cover too?

Frequently, because client claims often allege service failure rather than only a data breach. The two covers address different parts of the same event.

Does segregation help?

It limits blast radius and it is worth describing. Logical separation with strong access control is the common design and it should be explained.

What about sub-processors?

Your clients hold you responsible for them. Maintain the register, and make sure your contracts with them mirror what you promised your clients.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture