Policyholders should talk to their brokers and insurers to better understand exactly how biometrics-related exposures are treated under their insurance programs, according to experts.
Cyber liability, employment practices liability, general liability, and technology errors and omissions are some of the insurance coverages that may come into play, they say.
Businesses need to reach out to their broker and insurer and “have an honest conversation,” said Kevin Sandelin, Boca Raton, Florida-based director of risk management services at Argo Group.
It’s also a good idea for companies to consult with in-house, third-party counsel to explain how they are using biometric technologies, and work with an IT organization to address compliance issues, Mr. Sandelin said.
“There should be more conversation with the insurance industry around what does it mean to use and hold (biometrics) data and is there coverage,” he said.
If a company is using a biometric timeclock in Illinois and hasn’t notified and obtained written consent, an employee could file a lawsuit alleging that it failed to follow biometric privacy law, said Laura Lapidus, New York-based risk control director for CNA Financial Corp.’s management liability business.
An employment practices liability policy may cover the exposure, but “we are seeing more insurers exclude these types of claims,” Ms. Lapidus said.
Exclusions have also been added on general liability policies, but every policy is different, she said.
An Illinois appeals court recently upheld a lower court ruling that an insurer must defend a nail salon charged in a putative class action with sending a customer’s fingerprints to a third-party vendor in an alleged violation of the Illinois Biometric Information Privacy Act.