Nonpublic Information
Nonpublic information is any information that has not been made available to the general public. Depending on the context, it can mean confidential facts about a company that could move its stock price if released, or personal details about an individual, such as a Social Security number, that are not meant to be publicly accessible. The exact meaning varies by field, and it is important to note that the securities-law concept (material nonpublic information) and the personal-data concept are distinct usages.
Nonpublic information refers to information that has not been broadly disseminated to, or otherwise become available to, the general public. The term is used differently across contexts. In securities and insider-trading contexts, information is considered nonpublic if it has not been disseminated broadly to the marketplace (for example, via a press release or analyst report) and has not yet permeated the market; when such information would also have a definite or material impact on a security's price, it is characterized as material nonpublic information (MNPI). In a data-protection or privacy context, nonpublic information typically relates to the personal information of an individual that is not and should not be available to the public, such as a Social Security number. In a public-sector ethics context, it can also mean information received because of one's employment that the recipient knows or reasonably should know has not been made public. These usages should not be conflated; the applicable definition depends on the governing regime, and this entry does not resolve how any specific insurance policy, statute, or regulator defines the term.
Why it matters
The term "nonpublic information" carries materially different meanings across the fields that intersect in cyber insurance and organizational resilience, and conflating them can lead to serious errors in coverage analysis, compliance, and incident response. In securities and insider-trading contexts, the concern is material nonpublic information (MNPI), facts about a company not yet disseminated broadly to the marketplace that would have a definite or material impact on a security's price if released. In a data-protection or privacy context, the same phrase points instead to personal details about an individual, such as a Social Security number, that are not and should not be available to the public. A public-sector ethics regime adds yet another usage: information an employee receives because of their federal employment that they know or reasonably should know has not been made public.
For practitioners, the risk is treating these usages as interchangeable. A privacy breach exposing individuals' personal nonpublic information raises questions that may implicate third-party privacy liability and regulatory exposure, and those questions turn on how the governing statute, regulator, or insurance form defines the protected data category. Whether any specific loss connected to nonpublic information is covered depends on the policy wording, applicable exclusions and conditions, and the jurisdiction, this entry does not resolve those questions. The securities-law concept of MNPI, by contrast, is primarily an insider-trading and market-integrity concern and does not describe the same universe of data that privacy-focused definitions address.
Because the applicable meaning is determined by the governing regime rather than by the label alone, risk managers, underwriters, and compliance professionals should confirm which definition a given contract, statute, or regulator is using before drawing conclusions. Assuming a single, uniform meaning across the securities, privacy, and ethics contexts is a common and consequential mistake.
Who it's relevant to
Inside NPI
Common questions
Answers to the questions practitioners most commonly ask about NPI.
