Data privacy is of increasing urgency for all businesses, including California contractors. While winning bids, managing crews, meeting deadlines, and delivering quality work is of paramount importance, data privacy cannot be sidelined as a mere administrative concern. If your business emails invoices, texts appointment reminders, runs a website, or keeps electronic applicant or employee files, you’re holding the sort of information that hackers target. And the businesses that suffer cyber attacks typically don’t realize the volume of sensitive data they have been collecting until it’s too late. If your business hasn’t reviewed how its data is managed and protected, you probably have cyber-attack vulnerability and related liability exposure. Waiting longer to protect your business from these risks is not a good idea.
The collection and safeguarding of personal information are governed by the California Consumer Privacy Act (“CCPA”) and California Privacy Rights Act (“CPRA”), which impose affirmative duties to implement security procedures, require prompt notification when a breach occurs, and give consumers a private right of action of $100 to $750 per consumer, per incident, for breaches caused by inadequate security. The California Invasion of Privacy Act (“CIPA”) prohibits the unauthorized interception of communications and the use of “trap and trace” or “pen register” tools without consent, and allows an injured person to recover money damages from business that permitted their private data to be stolen. And marketing calls and texts are governed by the federal Telephone Consumer Protection Act (“TCPA”), which permits a private plaintiff to recover actual loss, $500 per unlawful call or text, or up to $1,500 for each willful violation, with no cap. Violations of these expectations expose businesses to civil liability.
“Data privacy and compliance is increasing in both importance to regulators and to plaintiffs’ attorneys,” says Elaine Harwell, Esq., a data privacy litigation attorney at Procopio, Cory, Hargreaves & Savitch LLP. Harwell leads Procopio’s Privacy and Cybersecurity practice and is the firm’s Privacy Officer.
Harwell frames privacy as a competitive issue, not only a legal one: “To be competitive in any industry now,” she says, businesses “have to answer those questions on how data is being shared.” Experienced data privacy attorneys routinely counsel businesses on compliance before a problem becomes a claim. That includes carrying insurance against cyber attacks and data hacks.
Cyber insurance does more than pay for economic loss. As Natalie Sherod, a principal at San Diego-based Cavignac insurance brokerage and a cyber-insurance specialist, explains, the right insurance policy brings affirmative counseling and practical tools that reach well beyond coverage alone. Cybersecurity insurance is a savvy business decision, not an afterthought.
Most Business Collect Data – 5 Areas That Affect Contractors
1. Email accounts. Sherod emphasizes that emailing invoices is the single most common but overlooked routine business practice that creates data privacy risk. When businesses send invoices, there is necessarily electronic data worth safeguarding from criminals. In one incident Sherod encountered for a client, a target had paid over $1 million to someone posing as a project manager before anyone noticed. In another instance, a construction company’s employee clicked a suspicious email link, and the intruder quietly reached the payment system and changed ACH details on a single payment, thereby stealing more than $500,000 before anyone noticed.
2. Employee records. Job applications, W2s, social security numbers, and direct deposit details are valuable information that hackers focus upon. California businesses must now notify affected persons – including people who weren’t hired – after discovering a breach.
3. Your website. The analytics and tracking pixels running in the background of a website often pass website visitor data to third parties without consent. California courts have increasingly treated that as a privacy violation. A compliant cookie banner and a privacy policy that matches what the site does are smart choices. Separately, any form or field that collects a name, email, phone number, or address, such as a contact form, estimate request, or bid inquiry, is itself regulated data collection under the CCPA and CPRA, which require notice at the point of collection and reasonable security for what is gathered. Having your website regularly reviewed by a data privacy consultant has become increasingly important.
4. The apps your crews carry into the field. As Harwell has experience, compliance issues arise from the use of contractors’ job management apps that crews run from a cell phone or tablet for things like project scheduling, on-site assessments, estimates, job photos, or GPS routing. But often these apps capture more data than you might expect. They can log data about the property, the customer, and the crew members themselves, including geolocation and employee-performance metrics. Under the CCPA and CPRA, geolocation is personal information and a person’s precise geolocation is “sensitive personal information.” Business owners need to know what their apps collect and should consult a data privacy professional about the potential risk of exposure.
5. Automated texts. Automated text messages, such as appointment reminders and follow-up texts, fall under the TCPA. Businesses that use automated text messaging should scrub contact lists against the Do Not Call Registry, get documented consent, and honor opt-outs immediately.
Cybersecurity Insurance – What It Is, and Why Your Business Needs It
Cyber insurance is the backstop to protect against the damage caused by cyber attacks. Sherod calls it one of the most valuable and least understood tools a contractor can buy. “I love talking about cyber insurance,” she says, partly because so few clients understand what theirs actually does. Sherod breaks the coverage into three buckets that affect contractors:
1. Data privacy liability. This covers your duty to protect information you hold, the piece that answers website and breach claims. This is where contractors talk themselves out of coverage, insisting “I don’t have private data.” Her answer: “You don’t have to be selling something to collect data.” If you have employees and customers, you have data.
2. First-party costs. This relates to your own breach response: forensics, notification, credit monitoring, lost revenue, ransomware. The numbers are not hypothetical. Ms. Sherod points to a landscape architect whose cloud network was breached and locked with no backup in place. The carrier ultimately paid an $808,000 ransom, and the claim stayed open for hardware and business-interruption costs. In another matter, a mechanical-engineering firm was breached across two locations through a single account that lacked multi-factor authentication and roughly $690,000 in ransom. Ransomware claims, she notes, routinely run in the high six figures once response costs are counted.
3. Cybercrime. This is the bucket that answers invoice and social engineering fraud, and the one impacting contractors the most. Contractors push high volumes of invoices through systems that Ms. Sherod describes as less sophisticated than those in many other industries, and she sees that as a constant source of opportunity for fraud. This coverage is often sold as a supplement with a modest default limit (the typical starting point around $250,000), so it should be sized to what actually moves through the business and built up, not left at the minimum. Ms. Sherod cautions to read the conditions, too, as crime coverage frequently pays only if the insured verified the payment change through a separate, alternate means of communication.
Beyond these concepts, Sherod offers several practical points business owners may overlook when considering the importance of a cybersecurity policy:
A cyber policy is also a proactive resource and response team. Sherod stresses that cybersecurity coverage often brings numerous additional resources that are useful to a business, such as access to breach hotlines, breach and ransomware coaches, and protective tools like multi-factor authentication and backups. Some of these perks are included at no extra cost. Whereas a contractor without a policy is left hiring its own attorney and forensics help in the middle of a crisis. Insured businesses can get far more out of a cyber policy, Sherod says, than a general liability policy.
Outsourcing does not transfer the risk. Many contractors run payroll and other functions through vendor software platforms (ADP is a common example), and assume the vendor owns the risk. That assumption can be dangerous. As Sherod puts it, the business is “responsible for keeping data safe even if you outsource it to a third party.” Often, vendor contracts require the business to indemnify the vendor when claims arise or have a limit on their liability to the business for errors on the vendor’s end. If a breach at your payroll processor exposes your employees’ private data, those limits may cover only a fraction of the exposure, and the affected employees can still look to their employer to make them whole for potentially significant damage.
Understand the scope of your coverage. Cyber risk insurance coverage may turn on where a loss originated. For instance, a breach of your own system may be covered while one that started elsewhere may not. And some policies require proof that payment changes were verified before they’ll pay a fraud claim. Unlike general liability, defense costs come out of the same limit as the damages, so a $1 million policy facing $800,000 in losses plus $500,000 in legal fees still leaves roughly $300,000 out of pocket.
California business owners need to be aware of all the responsibilities and risks that come from data privacy considerations. The tools to do this are out there. It starts with having a dialogue with the consultants who understand the tech, the law, and the risk management tools including cyber insurance. Every business owner need not become a data privacy expert, but they should be aware of the need to address these risks. Ignoring data privacy considerations is simply not an option.
Akylah M. Cooper is an attorney with DDWK. Her practice is focused on the litigation of commercial and employment law disputes as well as advising businesses on privacy and data protection matters.
Dunn DeSantis Walt & Kendrick provides a broad spectrum of legal services to businesses of all sizes, from small, local start-ups and non-profits to large, national companies. DDWK’s real estate development and construction practice includes representing all segments of the development and construction industries on both private and public projects.
You can find additional information and resources related to helping business owners and their businesses on the DDWK website.

