Skip to main content
Category: Regulatory & Privacy Compliance

Nonpublic Information

Also known as: NPI, Material Nonpublic Information, MNPI
Simply put

Nonpublic information is any information that has not been made available to the general public. Depending on the context, it can mean confidential facts about a company that could move its stock price if released, or personal details about an individual, such as a Social Security number, that are not meant to be publicly accessible. The exact meaning varies by field, and it is important to note that the securities-law concept (material nonpublic information) and the personal-data concept are distinct usages.

Formal definition

Nonpublic information refers to information that has not been broadly disseminated to, or otherwise become available to, the general public. The term is used differently across contexts. In securities and insider-trading contexts, information is considered nonpublic if it has not been disseminated broadly to the marketplace (for example, via a press release or analyst report) and has not yet permeated the market; when such information would also have a definite or material impact on a security's price, it is characterized as material nonpublic information (MNPI). In a data-protection or privacy context, nonpublic information typically relates to the personal information of an individual that is not and should not be available to the public, such as a Social Security number. In a public-sector ethics context, it can also mean information received because of one's employment that the recipient knows or reasonably should know has not been made public. These usages should not be conflated; the applicable definition depends on the governing regime, and this entry does not resolve how any specific insurance policy, statute, or regulator defines the term.

Why it matters

The term "nonpublic information" carries materially different meanings across the fields that intersect in cyber insurance and organizational resilience, and conflating them can lead to serious errors in coverage analysis, compliance, and incident response. In securities and insider-trading contexts, the concern is material nonpublic information (MNPI), facts about a company not yet disseminated broadly to the marketplace that would have a definite or material impact on a security's price if released. In a data-protection or privacy context, the same phrase points instead to personal details about an individual, such as a Social Security number, that are not and should not be available to the public. A public-sector ethics regime adds yet another usage: information an employee receives because of their federal employment that they know or reasonably should know has not been made public.

For practitioners, the risk is treating these usages as interchangeable. A privacy breach exposing individuals' personal nonpublic information raises questions that may implicate third-party privacy liability and regulatory exposure, and those questions turn on how the governing statute, regulator, or insurance form defines the protected data category. Whether any specific loss connected to nonpublic information is covered depends on the policy wording, applicable exclusions and conditions, and the jurisdiction, this entry does not resolve those questions. The securities-law concept of MNPI, by contrast, is primarily an insider-trading and market-integrity concern and does not describe the same universe of data that privacy-focused definitions address.

Because the applicable meaning is determined by the governing regime rather than by the label alone, risk managers, underwriters, and compliance professionals should confirm which definition a given contract, statute, or regulator is using before drawing conclusions. Assuming a single, uniform meaning across the securities, privacy, and ethics contexts is a common and consequential mistake.

Who it's relevant to

Cyber underwriters and brokers
When a policy or endorsement references nonpublic information, underwriters and brokers should determine which usage the form intends, personal nonpublic information in a privacy sense, or something else, because the scope of protected data drives exposure analysis. Whether losses tied to exposed nonpublic information fall within first-party or third-party coverage, and whether they are covered at all, depends on the specific wording, exclusions, and conditions rather than on the term in isolation.
Chief information security officers and privacy teams
Security and privacy teams handling personal nonpublic information, such as Social Security numbers, need to classify and protect data that is not and should not be publicly available. Note that data classification and protection controls are security and governance measures; they reduce the likelihood or impact of exposure but are distinct from insurance risk transfer, which does not by itself prevent an incident.
Legal and compliance professionals
Compliance staff must keep the securities-law concept of material nonpublic information distinct from privacy and ethics usages, since each rests on a different test, market dissemination and materiality for MNPI, individual privacy for personal nonpublic information, and manner of receipt for the public-sector ethics definition. Applying the wrong framework can misstate obligations under the governing statute or regulator.
Public-sector and government-adjacent organizations
Entities subject to public-sector ethics rules face a definition keyed to information received because of employment that the recipient knows or reasonably should know has not been made public. This usage should not be assumed to match either the securities or privacy definitions, and the applicable regime should be confirmed.

Inside NPI

Personally Identifiable Information (PII)
Data that can identify a specific individual, such as name combined with Social Security number, driver's license number, financial account credentials, or similar identifiers. Definitions vary across data protection regimes and insurer forms, so the precise scope depends on the applicable law and the policy or endorsement wording.
Protected Health Information (PHI)
Health-related data about an individual that is treated as sensitive under applicable healthcare privacy regimes. Whether a given cyber policy responds to a PHI breach depends on the policy's definitions, endorsements, and any regulatory-defense provisions, subject to the specific wording.
Confidential corporate or third-party information
Nonpublic business information, such as trade secrets, proprietary data, or information entrusted by third parties under confidentiality obligations, that is not publicly available. Coverage implications differ depending on whether a loss is framed as first-party (the insured's own loss) or third-party (liability to others).
Distinction from publicly available information
Nonpublic information excludes data lawfully made available to the general public, such as information published in widely distributed media or lawful public records. What qualifies as 'publicly available' can be defined differently across regulatory regimes and insurer forms.
Relevance to coverage triggers and obligations
The presence and category of nonpublic information can bear on breach-notification obligations and on whether privacy-related first-party or third-party coverage responds. Whether any particular incident is covered remains conditional on policy wording, exclusions, conditions precedent, and jurisdiction.

Common questions

Answers to the questions practitioners most commonly ask about NPI.

Is nonpublic information the same thing as personally identifiable information (PII)?
No. While the two overlap, they are not interchangeable. Personally identifiable information refers specifically to data that identifies an individual. Nonpublic information, as the term is often used in insurance and regulatory contexts, can be broader and may also include categories such as business or corporate information not available to the public, protected health information, and certain financial account information. Because definitions vary across insurer forms and regulatory regimes, you should check the specific policy wording or regulation to see exactly which categories of data fall within its definition of nonpublic information rather than assuming it means only PII.
If my policy references nonpublic information, does that automatically mean any breach of that data is covered?
No. The presence of a defined term does not by itself establish coverage. Whether a loss involving nonpublic information is covered depends on the coverage grants, the applicable exclusions, conditions precedent, retentions, sublimits, and the specific policy wording, as well as jurisdiction. A definition simply describes what the policy means by the term; it does not determine whether a given incident triggers first-party or third-party coverage. Review the operative insuring agreements and exclusions, not just the definitions section, to understand potential coverage.
How do I confirm what my policy counts as nonpublic information?
Locate the definitions section of the policy and read the full definition of nonpublic information, then trace how that defined term is used within the insuring agreements, exclusions, and any endorsements. Definitions can be narrowed or expanded by endorsement, so the schedule and endorsement pages matter. Where the scope is ambiguous, raise the question with your broker or coverage counsel before binding, since the same term can be defined differently across insurer forms.
Why does it matter whether an incident involves nonpublic information versus other data?
The classification can affect which coverage parts respond and how. Incidents involving nonpublic information may implicate third-party liability coverage for privacy claims and regulatory defense, as well as first-party costs such as notification and data restoration, subject to the specific wording. Data that falls outside the policy's definition may be treated differently. Understanding the classification helps you anticipate potential notification obligations and how retentions, sublimits, and waiting periods might apply to a given event.
How should I inventory nonpublic information to align with my coverage?
Map the categories of data your organization holds against the categories captured in your policy's definition of nonpublic information. This helps identify gaps where data you consider sensitive may not match the policy's defined scope, or where the policy's scope is broader than your internal classification. This data mapping is a risk mitigation and governance exercise; it does not by itself alter coverage, but it informs both your resilience planning and your discussions with your broker about whether the definition and limits fit your exposure.
Does definitions of nonpublic information vary between regulators and insurers, and how do I reconcile them?
Yes, the concept can be defined differently across regulatory regimes and across insurer forms, so a data set treated as nonpublic under one regime may be scoped differently under another or under your policy. To reconcile them, treat the regulatory definitions as drivers of your compliance and notification obligations and the policy definition as the driver of coverage scope, then work with compliance staff, coverage counsel, and your broker to identify where the two diverge. Where a precise reconciliation is unclear, document the differences and seek clarification rather than assuming alignment.

Common misconceptions

Nonpublic information means the same thing under every law and in every insurance policy.
The term is defined differently across data protection regimes, regulatory frameworks, and individual insurer forms. Practitioners should not assume a single universal definition; the operative meaning depends on the applicable regulation and the specific policy or endorsement wording.
Any incident involving nonpublic information is automatically covered by a cyber policy.
Coverage is conditional. Whether a loss involving nonpublic information triggers first-party or third-party coverage depends on policy definitions, endorsements, exclusions, conditions precedent, and jurisdiction. The mere involvement of nonpublic information does not guarantee a payable claim.
Protecting nonpublic information through insurance makes the organization resilient to breaches.
Insurance is a risk-transfer mechanism, not a resilience or mitigation control. It does not reduce the likelihood of a breach or by itself protect the data; it may finance certain losses subject to the policy terms. Safeguarding nonpublic information requires distinct security and resilience measures.

Best practices

Map which categories of nonpublic information (PII, PHI, confidential corporate or third-party data) the organization holds, and identify the specific regulatory regimes that define and govern each category.
Compare your policy's definition of nonpublic or covered information against the definitions used by the laws you are subject to, since these can differ across regimes and insurer forms.
Review policy wording, endorsements, exclusions, and conditions precedent to understand whether a given information-related loss would fall under first-party coverage, third-party coverage, both, or neither.
Do not rely on insurance as a substitute for data protection controls; maintain distinct security and resilience measures because risk transfer does not reduce the likelihood of a breach.
Confirm how breach-notification obligations tied to nonpublic information interact with any policy conditions or timelines, and coordinate legal, compliance, and claims stakeholders before an incident.
Where a term's scope is ambiguous, seek clarification from your broker, underwriter, or counsel rather than assuming coverage, and document the interpretation relied upon.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide