Does the Applicant collect, store, process, transmit PII / PHI / PCI?
This answer sets the size of the loss the carrier is underwriting. Everything else on the form modifies a number that starts here.
What the carrier is actually asking
The carrier is asking which categories of regulated data you handle: personal information, protected health information, and payment card data. It is asking about collection, storage, processing, and transmission, which together cover data you never intended to keep as well as data you deliberately store.
Why it is underwritten
Notification cost, regulatory exposure, and the applicable legal regime all follow from the data types. Health information triggers one framework, payment card data another, and personal information triggers a patchwork that varies by jurisdiction and by resident. The carrier prices the notification exercise before it prices the intrusion.
Where the answer lives in Microsoft 365, Entra ID, and Azure
Where regulated data lives in Microsoft 365 and Azure is partly discoverable, which is useful because the honest answer to this question is often broader than the intended one.
| Platform | Where the setting lives | What has to be true |
|---|---|---|
| Microsoft 365 | Sensitive information types and content explorer in Purview | Where regulated data actually sits, including collaboration sites and mailboxes nobody designated for it |
| Microsoft 365 | Data loss prevention policy matches over time | Match volume by information type, which is a measured footprint rather than an assumed one |
| Microsoft 365 | Sensitivity labels and auto-labelling coverage | Classification applied, so data types are known rather than inferred |
| Azure | Databases with sensitive data classification and vulnerability assessment | The structured data footprint, including copies in test and reporting environments |
| Data map | A record of systems, data types, and residency | A maintained inventory. Attested, and the artefact that makes the rest of the privacy block answerable |
The formal data footprint is the application database. The real one includes the spreadsheet a colleague was sent, the export sitting in a mailbox, and the file in a shared site from a project three years ago. Content discovery finds these, and they are inside the scope of any breach.
What a defensible yes requires
- The answer is based on discovery rather than on the intended design.
- Mail, collaboration, and file storage are included, not only line-of-business systems.
- Test, reporting, and archive copies are counted.
- Record counts are estimated with a method you can describe.
- Data types are mapped to the jurisdictions of the individuals concerned, not only to where the systems sit.
How this answer goes wrong
Organisations answer for the primary system. The breach scope turns out to include a decade of exports in mailboxes, a reporting copy in a test environment, and a third-party platform holding a synchronised subset. The application answer understated the footprint, and the notification population is set by the actual data rather than by the answer.
Frequently asked
Does employee data count?
Yes. Human resources records are personal information, often including health data, and they are frequently omitted because the question is read as being about customers.
What if we only process data for clients?
You still handle it, and the question still applies. Your role as processor rather than controller affects liability allocation, not whether the data is in scope.
How precise do record counts need to be?
An order of magnitude with a stated method is acceptable and better than a precise-looking number with no basis. The method is what makes it defensible.
Does discovery risk finding things we would rather not know?
It finds what a breach would find. Discovering it now costs a cleanup; discovering it during notification costs considerably more.
Related questions
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture