Data handling and policy

Does the Applicant collect, store, process, transmit PII / PHI / PCI?

This answer sets the size of the loss the carrier is underwriting. Everything else on the form modifies a number that starts here.

Partly verifiable from your tenant

What the carrier is actually asking

The carrier is asking which categories of regulated data you handle: personal information, protected health information, and payment card data. It is asking about collection, storage, processing, and transmission, which together cover data you never intended to keep as well as data you deliberately store.

Why it is underwritten

Notification cost, regulatory exposure, and the applicable legal regime all follow from the data types. Health information triggers one framework, payment card data another, and personal information triggers a patchwork that varies by jurisdiction and by resident. The carrier prices the notification exercise before it prices the intrusion.

Where the answer lives in Microsoft 365, Entra ID, and Azure

Where regulated data lives in Microsoft 365 and Azure is partly discoverable, which is useful because the honest answer to this question is often broader than the intended one.

PlatformWhere the setting livesWhat has to be true
Microsoft 365Sensitive information types and content explorer in PurviewWhere regulated data actually sits, including collaboration sites and mailboxes nobody designated for it
Microsoft 365Data loss prevention policy matches over timeMatch volume by information type, which is a measured footprint rather than an assumed one
Microsoft 365Sensitivity labels and auto-labelling coverageClassification applied, so data types are known rather than inferred
AzureDatabases with sensitive data classification and vulnerability assessmentThe structured data footprint, including copies in test and reporting environments
Data mapA record of systems, data types, and residencyA maintained inventory. Attested, and the artefact that makes the rest of the privacy block answerable
Mail and collaboration hold data your systems do not

The formal data footprint is the application database. The real one includes the spreadsheet a colleague was sent, the export sitting in a mailbox, and the file in a shared site from a project three years ago. Content discovery finds these, and they are inside the scope of any breach.

What a defensible yes requires

  • The answer is based on discovery rather than on the intended design.
  • Mail, collaboration, and file storage are included, not only line-of-business systems.
  • Test, reporting, and archive copies are counted.
  • Record counts are estimated with a method you can describe.
  • Data types are mapped to the jurisdictions of the individuals concerned, not only to where the systems sit.

How this answer goes wrong

Organisations answer for the primary system. The breach scope turns out to include a decade of exports in mailboxes, a reporting copy in a test environment, and a third-party platform holding a synchronised subset. The application answer understated the footprint, and the notification population is set by the actual data rather than by the answer.

Frequently asked

Does employee data count?

Yes. Human resources records are personal information, often including health data, and they are frequently omitted because the question is read as being about customers.

What if we only process data for clients?

You still handle it, and the question still applies. Your role as processor rather than controller affects liability allocation, not whether the data is in scope.

How precise do record counts need to be?

An order of magnitude with a stated method is acceptable and better than a precise-looking number with no basis. The method is what makes it defensible.

Does discovery risk finding things we would rather not know?

It finds what a breach would find. Discovering it now costs a cleanup; discovering it during notification costs considerably more.

Related questions

Stop answering this from memory

Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.

Assess your posture