Written by Justin Goodman, CIC, CISC, CLCS, CEO and Co-Founder, Total CSR Published: September 30, 2026 · Last reviewed: September 30, 2026
In plain language: Invasion of privacy means someone accuses a business of improperly sharing or exposing private information about them. Standard business liability policies often cover the legal defense and settlement costs tied to these claims, as long as the disclosure was not intentional or excluded by other policy language.
Technical definition: Invasion of privacy is one of the enumerated offenses within the “personal and advertising injury” coverage of a Commercial General Liability policy, defined under ISO form CG 00 01. It triggers coverage for claims alleging wrongful publication or disclosure of material that violates a person’s right to privacy, subject to policy exclusions and conditions.
Invasion of Privacy at a Glance
| Attribute | Detail |
|---|---|
| Also known as | Right of privacy violation, personal injury offense |
| Category | Liability policy coverage, personal and advertising injury offense |
| Lines of business | Commercial General Liability, Cyber Liability, Media Liability, EPLI |
| Industries most affected | Retail, healthcare, technology, media, marketing, financial services |
| Related forms or endorsements | CG 00 01 (CGL coverage form), CG 00 68 (employment-related practices exclusion) |
| Who bears the risk | The business accused of disclosing or misusing private information |
| Common solution | CGL personal and advertising injury coverage; cyber liability policy for data breach exposure |
| Also interacts with | Defamation, data breach notification laws, employment practices claims |
Key Takeaways
- Invasion of privacy is a named offense under personal and advertising injury coverage that protects businesses accused of wrongfully disclosing private information about a person or organization.
- Agencies need to understand this coverage because many clients assume general liability handles all privacy-related exposures, including modern data breach and cyber incidents, when it typically does not.
- The most common pitfall is confusing invasion of privacy coverage under a CGL policy with cyber liability coverage, since CGL policies were not designed for electronic data breaches and often exclude them entirely.
- A best practice is pairing every CGL policy that includes personal and advertising injury coverage with a dedicated cyber liability quote, so the client makes an informed decision rather than assuming they are covered.
What Is Invasion of Privacy in Insurance?
Invasion of privacy is a coverage trigger found within the personal and advertising injury section of a Commercial General Liability policy. Carriers built this coverage to respond to traditional tort claims such as public disclosure of private facts, intrusion upon seclusion, or misappropriation of a person’s name or likeness. The coverage exists because businesses interact with the public in ways that can unintentionally expose private details, and courts have long recognized a legal right to privacy separate from defamation or negligence claims.
The legal doctrine behind this coverage traces to common law privacy torts recognized in most U.S. states, which allow individuals to sue when a business publicizes private information in a way that would be highly offensive to a reasonable person. A retail store, for example, might face a claim after an employee posts a customer’s purchase history and home address on social media as a joke. If the policy’s personal and advertising injury section includes invasion of privacy as a covered offense, the CGL carrier may owe a defense and indemnity, subject to intentional act and knowing violation exclusions.
Coverage for invasion of privacy under a CGL policy is narrower than many agents assume. It generally applies to oral or written publication of material, not to electronic data breaches involving hacked databases or stolen customer records. That gap is precisely why cyber liability insurance emerged as a distinct product line over the past two decades.
How Does Invasion of Privacy Work?
- The disclosure. A business, employee, or its advertising content reveals private information about a person without consent, such as medical history, financial details, or personal communications.
- The complaint. The affected individual claims the disclosure violated their right to privacy and caused humiliation, reputational harm, or financial loss.
- The lawsuit. The individual files suit alleging invasion of privacy, often alongside related claims like defamation or negligent supervision.
- The tender. The business notifies its CGL carrier and tenders the claim under the personal and advertising injury coverage section.
- The coverage determination. The carrier reviews the allegations against policy definitions and exclusions, then decides whether a duty to defend exists, often defending under a reservation of rights while the facts develop.
Real Claim Examples Involving Invasion of Privacy
Employee text messages shared without consent
A small medical billing company terminated an employee, and a manager forwarded the employee’s private text messages to coworkers to explain the decision. The former employee sued for invasion of privacy and emotional distress. The company’s CGL policy responded under personal and advertising injury coverage because the claim involved publication of private material rather than a data security failure, and the carrier provided a defense.
Customer photo used in advertising without permission
A fitness studio used a customer’s before-and-after photo in a social media ad campaign without getting written consent. The customer sued for misappropriation of likeness, a recognized invasion of privacy tort. The studio’s CGL policy covered the claim because the personal and advertising injury section explicitly includes unauthorized use of another’s likeness in advertising, and the insurer settled before trial.
Hacked customer database exposing personal records
A regional retailer suffered a data breach exposing thousands of customers’ names, addresses, and payment information. Affected customers alleged invasion of privacy and negligence. The retailer’s CGL carrier denied coverage, citing the electronic data exclusion, because the loss stemmed from a cyberattack rather than a traditional publication of private facts. The retailer’s separate cyber liability policy ultimately responded.
Invasion of Privacy vs. Data Breach: What Is the Difference?
Invasion of privacy is a personal and advertising injury offense under a CGL policy, while data breach is a distinct exposure typically handled by cyber liability insurance. Agencies frequently conflate the two because both involve mishandled personal information, but the coverage forms, triggers, and typical exclusions differ substantially.
| Comparison area | Invasion of Privacy | Data Breach |
|---|---|---|
| Primary use case | Wrongful publication or disclosure of private facts by a person or business | Unauthorized access, theft, or exposure of electronic data |
| Coverage / concept type | CGL personal and advertising injury offense | Cyber liability first-party and third-party coverage |
| Typical exclusions | Electronic data, knowing violation of rights, intentional acts | War, infrastructure failure, unencrypted data in some policies |
| Who is most affected by errors | Small businesses assuming CGL covers all privacy claims | Businesses without any cyber policy in place |
| Common mistakes | Treating CGL as sufficient for digital privacy exposures | Assuming CGL’s electronic data exclusion does not apply |
What Are the Most Common Mistakes With Invasion of Privacy?
- Agencies assume CGL personal and advertising injury coverage handles data breaches, leaving clients uninsured when a hacking incident occurs and the electronic data exclusion applies.
- Producers fail to explain that intentional or knowing violations of privacy rights are typically excluded, which surprises clients who assumed any privacy complaint would be covered.
- CSRs skip documenting that a cyber liability quote was offered and declined, creating E&O exposure when a client later suffers an uncovered breach.
- Agents overlook that employment-related invasion of privacy claims, such as an employer reviewing private employee communications, may fall under the employment-related practices exclusion (CG 00 68) rather than standard personal and advertising injury coverage.
- Marketing agencies and their clients underestimate how often misappropriation of likeness claims arise from social media advertising, leaving this exposure unaddressed in coverage conversations.
How to Explain Invasion of Privacy to a Client
Explaining invasion of privacy to a personal lines client
Invasion of privacy usually comes up for personal lines clients through a personal liability umbrella or a homeowners policy’s personal injury endorsement. It means if someone sues you because they feel you shared private information about them unfairly, this coverage can help pay for a lawyer and any settlement. It typically will not apply if you did it on purpose knowing it would hurt someone.
Explaining invasion of privacy to a small business owner
Your general liability policy includes coverage for invasion of privacy claims, which means if a customer or employee sues you for sharing their private information without permission, your policy may help cover the defense and damages. This is different from a data breach, where hackers steal customer records from your computer systems. That kind of loss needs a separate cyber liability policy, and I’d recommend we look at one together.
Explaining invasion of privacy to a CFO or risk manager
Your CGL policy’s personal and advertising injury section includes invasion of privacy as a covered offense, but it responds to traditional publication-based privacy torts, not electronic data compromise. Given your organization’s data handling exposure, I’d recommend we quantify the gap between what your CGL provides and what a cyber liability tower would add, particularly around notification costs, regulatory fines, and third-party liability. I can put together a coverage comparison so you can make a risk-based decision on limits.
Frequently Asked Questions About Invasion of Privacy
Does general liability insurance cover invasion of privacy?
General liability insurance can cover invasion of privacy when the policy includes personal and advertising injury coverage and the claim falls within that offense’s definition. Coverage typically applies to publication-based privacy violations, like sharing private facts or misusing someone’s likeness, rather than electronic data breaches. Always check the specific policy form since some carriers narrow or broaden this offense through endorsements.
Is a data breach the same as invasion of privacy for insurance purposes?
A data breach is not treated the same as invasion of privacy under most CGL policies. Data breaches typically fall under the electronic data exclusion found in standard ISO forms, which pushes that exposure toward a dedicated cyber liability policy. Agencies should offer cyber coverage separately rather than relying on CGL to respond to a hacking incident.
Can invasion of privacy claims be excluded from a CGL policy?
Invasion of privacy claims can be excluded from a CGL policy through endorsements that remove personal and advertising injury coverage entirely or narrow its scope. Some carriers also exclude claims arising from violations of statutes like the Telephone Consumer Protection Act or state biometric privacy laws through specific endorsements. Reviewing the declarations page and endorsement schedule confirms whether this coverage remains intact.
What is the difference between invasion of privacy and defamation?
Invasion of privacy involves disclosing true but private information that a person had a reasonable expectation would stay confidential, while defamation involves making false statements that damage someone’s reputation. Both are separate offenses listed under personal and advertising injury coverage, and a single incident can sometimes trigger both claims simultaneously. Carriers evaluate each offense independently against the policy’s definitions.
Does invasion of privacy coverage apply to employment-related claims?
Invasion of privacy coverage may not apply to employment-related claims if the CGL policy includes the employment-related practices exclusion, found in endorsements like CG 00 68. Claims involving an employer’s handling of employee private information often need to route through an Employment Practices Liability policy instead. Agencies should confirm which policy is designed to respond before a claim arises, not after.
Related Insurance Terms
- Personal and Advertising Injury: A broader CGL coverage category that includes invasion of privacy alongside offenses like defamation, false arrest, and wrongful eviction.
- Defamation: A separate personal and advertising injury offense involving false statements that harm someone’s reputation, often alleged alongside invasion of privacy in the same lawsuit.
- Cyber Liability Insurance: A specialized policy that covers data breaches and electronic privacy violations typically excluded from standard CGL coverage for invasion of privacy.
- Duty to Defend: The insurer’s obligation to provide a legal defense for covered claims, including invasion of privacy allegations, even if the claim ultimately proves groundless.
- Employment Practices Liability Insurance: A policy designed to cover employment-related privacy claims that a CGL’s employment-related practices exclusion removes from personal and advertising injury coverage.
- Intentional Acts Exclusion: A common CGL exclusion that bars coverage for invasion of privacy claims when the insured knowingly violated the claimant’s rights.
Sources and References
- Insurance Services Office (ISO). Commercial General Liability Coverage Form CG 00 01.
About the Author
Justin Goodman, CIC, CCIP, CISC, CLCS, CRIS, PCIA, QCLS, MFHR CEO and Co-Founder, Total CSR, Inc.
Justin Goodman is a third-generation insurance broker with over two decades in agency operations. He has trained more than 100,000 CSRs, account managers, and producers in commercial and personal lines coverage, from workers’ compensation to construction risk. He was named 2024 Insurance Journal Agent of the Year and one of the nation’s top five construction insurance experts by Risk & Insurance. He is the author of Retain, which applies cognitive science research on memory and knowledge transfer to insurance training, and speaks nationally on how agencies build durable technical expertise in their teams.