Does the Applicant provide data processing, storage, or hosting services to third parties?
Holding other organisations data means a single breach produces claims from many parties at once.
What the carrier is actually asking
The carrier is asking whether you process, store, or host data on behalf of other organisations. It covers software vendors, hosting providers, outsourcers, and anyone whose service involves holding a client's data.
Why it is underwritten
A breach at a processor affects every client at once, and each client can claim. The liability is contractual as well as regulatory, and it is frequently larger than the processor's own balance sheet. Carriers underwrite this as an aggregation exposure and often push toward technology errors and omissions cover alongside cyber.
Where the answer lives in Microsoft 365, Entra ID, and Azure
This is a description of your services, and the useful supporting detail is scale and separation.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Services | What client data you hold and for how many clients | Volume and client count, which determines aggregation. Attested |
| Contracts | Liability caps, indemnities, and data processing agreements | What you owe each client, which is the exposure this question is sizing |
| Architecture | Whether client data is segregated or commingled | Tenant separation, since commingled data means one breach touches everyone |
| Azure | Isolation between client environments where hosted in the cloud | Separation enforced by design and measurable |
| Notification | Obligations to notify clients and their timelines | Contractual notification periods, which are often shorter than regulatory ones |
Processors frequently sign uncapped data liability or caps far above their cyber limit. That gap is real, uninsured exposure. Comparing your contractual commitments against your limit is a short exercise that occasionally changes a renewal.
What a defensible yes requires
- The scale is stated: client count and record volumes held on their behalf.
- Contractual liability positions are known and compared against your limit.
- Client data is segregated rather than commingled.
- Data processing agreements are executed with each client.
- Notification obligations and their timelines are documented and achievable.
How this answer goes wrong
The answer is yes with no accompanying detail, so the underwriter cannot size the aggregation and prices conservatively. Or the answer is no because the service is described as software rather than hosting, while the software holds client data on infrastructure you operate.
Frequently asked
Does software-as-a-service count?
Yes. If your platform holds client data, you are processing it on their behalf regardless of how the service is described commercially.
Do we need technology errors and omissions cover too?
Frequently, because client claims often allege service failure rather than only a data breach. The two covers address different parts of the same event.
Does segregation help?
It limits blast radius and it is worth describing. Logical separation with strong access control is the common design and it should be explained.
What about sub-processors?
Your clients hold you responsible for them. Maintain the register, and make sure your contracts with them mirror what you promised your clients.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture