β οΈ YOU MAY BE RESPONSIBLE FOR NOTIFICATION
Even though the breach happened at your vendor, you may be legally required to notify YOUR customers if their data was exposed. Many data protection laws place the notification obligation on the data controller (you), not the data processor (your vendor).
Step 1: Confirm the Breach and Get Details
When a vendor notifies you of a breach, do not accept a vague statement. Demand specific answers:
- β’ What exactly happened? Unauthorized access? Data exfiltration? Ransomware? Insider threat?
- β’ What data of yours was affected? Which customers? What data types (names, emails, SSNs, payment info, PHI)?
- β’ When did it happen and when was it discovered? These dates determine your notification deadlines.
- β’ What have they done to contain it? Has the vulnerability been closed? Can it happen again?
- β’ Are they notifying affected individuals? If not, you need to β and the clock is already running.
Review your contract/Data Processing Agreement (DPA) with this vendor. Most DPAs require the vendor to notify you "without undue delay" after discovering a breach. If weeks passed between their discovery and their notification to you, they may be in breach of contract.
Step 2: Determine Your Exposure
Map the breached data to your regulatory obligations. The same breach may trigger multiple laws:
- β’ PII (names, emails, phone numbers): State breach notification laws in every state where affected customers reside
- β’ Financial data / SSNs: State laws + possible FTC Safeguards Rule implications + credit monitoring requirements
- β’ EU customer data: GDPR (72-hour notification to DPA)
- β’ California residents' data: CCPA/CPRA
- β’ Health information: HIPAA Breach Notification Rule
If you are unsure which laws apply, consult with your legal counsel or cyber insurance provider's breach coach. Getting this wrong can multiply your liability.
Data Breach Response Guide
Complete guide to notifying customers, reporting to regulators, and managing the aftermath of a data breach.
Read Data Breach Response βStep 3: Notify YOUR Customers (If Required)
In many jurisdictions, the data controller (you) β not the data processor (vendor) β is responsible for notifying affected individuals. Even if your vendor offers to handle notification, you remain legally responsible for ensuring it happens correctly and on time. Send your own notification to affected customers. Be transparent that the breach occurred at a vendor, but take responsibility for the impact on your customers. Blaming the vendor damages your credibility.
Step 4: Activate Contractual Protections
- Request indemnification: Your contract or DPA may require the vendor to cover breach-related costs β notification expenses, credit monitoring, legal fees, regulatory fines. Request these in writing.
- Request a forensic report: You need the vendor's incident investigation findings for your own compliance documentation and possible regulatory inquiries.
- Request a remediation plan: What has the vendor changed to prevent recurrence? You need to document this for your own risk assessment.
- Review your cyber insurance: Your policy may cover vendor-caused breaches. Contact your insurer to open a claim and access breach coach services.
Step 5: Decide β Continue or Terminate the Vendor Relationship
Not every breach requires firing the vendor β but some do. Evaluate:
- β’ Was this negligence or an advanced attack? A vendor that left an AWS bucket open for 6 months is different from one hit by a sophisticated nation-state actor.
- β’ How did they respond? Transparent, fast, and accountable? Or evasive, slow, and dismissive? The response tells you everything about their security culture.
- β’ What have they changed? Concrete remediation (enabled MFA, encrypted data, hired a CISO) or vague promises ("we take security seriously")?
- β’ Is there a viable alternative? Some vendors are hard to replace. If you stay, increase your monitoring and consider contractual audit rights.
Step 6: Prevent the Next Vendor Breach
- 1. Inventory your vendors. List every company that stores, processes, or transmits your customer data. You cannot manage what you do not track.
- 2. Require DPAs with all data processors. A signed Data Processing Agreement should be mandatory before sharing any customer data with a vendor.
- 3. Add security requirements to vendor contracts. Require MFA, encryption, breach notification within 24-72 hours, and annual security assessments.
- 4. Audit critical vendors annually. Send a security questionnaire. Follow up on gaps. Document their responses.
- 5. Limit data sharing to what is necessary. Do not send vendors more customer data than they actually need. Every extra field is extra exposure.
- 6. Have an offboarding process. When a vendor relationship ends, ensure they delete your data and provide written confirmation of deletion.