Contract clause
Data breach notification clause
A data breach notification clause fixes when and how a supplier must tell its customer that personal information may have been lost, accessed or disclosed without authority. It sets the clock, the contents of each report, and who assesses and notifies regulators and affected people, so the customer can meet its own legal deadlines.
When an incident happens inside a supplier's systems, the customer cannot start its own legal response until someone tells it. A notification clause is what shortens the gap between the supplier finding out and the customer being able to act.
Nuwan Madhusanka · Co-founder
4 min read · Published
Sample clause
a hosted booking platform agreement between Redgum Analytics and Ashgrove Events, a fictional conference organiser in Adelaide holding attendee records
12. Security Incidents 12.1 A Security Incident means any actual or suspected unauthorised access to, disclosure of, or loss of Customer Personal Information held by Redgum Analytics or its subcontractors. 12.2 Redgum Analytics must notify Ashgrove Events of a suspected Security Incident within 24 hours of becoming aware of it, by phone to the contact in Schedule 1 and by email. 12.3 Within 72 hours of becoming aware of a Security Incident, Redgum Analytics must give Ashgrove Events a written report describing what happened, when it was discovered, the kinds of information and approximate number of individuals involved, the containment steps taken, and a named contact. 12.4 Redgum Analytics must update the report as material facts become known and must give Ashgrove Events the information it reasonably needs to assess whether an eligible data breach has occurred. 12.5 Ashgrove Events decides whether to notify the Office of the Australian Information Commissioner and affected individuals, and Redgum Analytics must not do so without its consent unless the law requires it.
Sample wording, not legal advice.
Variants
Strict hours for every incident
The customer is regulated or holds sensitive records and wants a hard deadline with no argument about suspicion.
The Supplier must notify the Customer in writing within 12 hours after the Supplier first detects any event that affects, or may affect, the confidentiality, integrity or availability of Customer Data, whether or not the Supplier has concluded that personal information was involved. A notice given within that time is not an admission of liability. Failure to give notice within that time is a material breach of this agreement.
Without undue delay
A UK or EU arrangement, or a supplier that will not accept a fixed number of hours.
The Processor must notify the Controller without undue delay after becoming aware of a Personal Data Breach, and must provide, at the time of notification or as soon as it becomes available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it and to mitigate its possible adverse effects.
Customer led notification
Both parties hold the same information and want one of them to run the assessment and speak to regulators.
Where a Security Incident involves personal information held by both parties, the Customer is responsible for assessing whether it is an eligible data breach and for any notification to the regulator or to individuals. The Supplier must provide all information and cooperation the Customer reasonably requests within the times the Customer specifies, and must not make any public statement about the Security Incident without the Customer's prior written approval.
What to negotiate
What starts the clock
Customers want the clock to start when the incident is suspected. Suppliers want it to start when they are aware of a confirmed breach involving personal information, which can be days later. A two stage clause, a short notice on suspicion followed by a fuller report within a set period, gives the customer early warning without forcing the supplier to report conclusions it has not reached.
Who talks to the regulator
A supplier that notifies the regulator or customers on its own can damage the customer's response and relationships. Customers insist on controlling notification. Suppliers accept that but carve out disclosures they are legally required to make themselves. Both sides usually agree that neither makes a public statement without consulting the other first.
Costs of the response
Forensic investigation, notification letters, call centres and credit monitoring can cost more than the contract is worth. Customers want the supplier to pay where its breach caused the incident. Suppliers push these costs under the liability cap or ask for a separate, higher sub cap for data incidents, which is now a common compromise.
The risk of leaving it out
Without the clause a supplier may take weeks to mention an incident, or never mention one it decides was minor. By the time the customer learns of it, affected people may already have suffered harm it could have helped them avoid, and the customer has no contractual basis to demand faster information next time.
Timing across three regimes
In Australia, an entity covered by the Privacy Act that suspects an eligible data breach must take reasonable steps to complete an assessment within 30 calendar days of becoming aware of the grounds for suspicion, and must notify the Office of the Australian Information Commissioner and affected individuals when a breach is likely to result in serious harm. Under the UK GDPR a controller notifies the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware, while a processor tells the controller without undue delay. In California, a business that owns the data notifies affected residents within 30 calendar days of discovery, subject to law enforcement and scoping delays, and a business holding data it does not own must tell the owner immediately following discovery.
One assessment, not two
Where personal information is held jointly by more than one entity, the Notifiable Data Breaches scheme guidance says only one of them needs to assess a suspected breach, rather than each running its own assessment in parallel. The contract is the natural place to decide which party that is. Usually it is the customer, because the individuals are its customers or staff and it has the relationship with them. The supplier's job is then to feed facts into that assessment quickly, which is what the timed reports in the clause are for.
Where it sits in a generated document
A generated platform agreement can number the notification duty as its own clause next to security, with the 24 hour and 72 hour steps as separate sub clauses so a reader can find the deadline fast. The document chat edits text only, so changing 24 hours to 12 is a quick instruction. Research runs only when no file is attached and nothing is cited, so check every statutory period before signing.
Documents that carry this clause
UK data processing agreement template with sub-processorsA data processing agreement is what a UK controller has to have in writing before a processor touches personal data. This one covers a hosted order management platform for a UK retailer, with the processing annex, a table of five named sub-processors and their transfer safeguards, eight security measures, and a breach notice of 48 hours rather than 72.
IT support services agreement with response times by priorityManaged support is sold on a monthly fee and judged on how fast the phone gets answered when nobody can work. This agreement grades every ticket into four priorities with a published response and resolution target, credits the fee when the target is missed, and writes down exactly what the provider hands back on the way out.
Software development agreement with sprints and an acceptance testCustom software goes wrong in the space between delivered and accepted, where one side thinks a sprint is finished and the other is still writing a list. This agreement fixes a ten business day acceptance window against criteria written before the sprint started, and assigns the intellectual property sprint by sprint as each invoice is paid.
Privacy policy template written to the Australian Privacy PrinciplesA privacy policy is a list of true statements about what a business does with information, and copying a US template produces a list of false ones. This policy is written for an Australian online store to the thirteen privacy principles, with a table of every service that receives customer data and where it is, which is the part most policies skip.Questions people ask
How quickly should a supplier report a data breach?
Contracts commonly require an initial notice within 24 to 48 hours of the supplier becoming aware, followed by a fuller written report a few days later. The right number depends on the customer's own deadlines. A UK controller has 72 hours to report to the regulator where feasible, so its processors are usually given less.
Is the 30 day period in Australia a deadline to notify?
It is a deadline to assess. An entity that suspects an eligible data breach must take reasonable steps to complete its assessment within 30 calendar days. If the assessment finds a breach likely to cause serious harm, it must then notify the Office of the Australian Information Commissioner and the affected individuals.
What should the first notice contain?
Enough for the customer to start acting: what is known about the incident, when it was detected, the systems and kinds of information that may be involved, what has been done to contain it, and who to contact. Later reports add numbers of individuals, root cause and remediation. Requiring a named contact avoids the first day being lost to phone tag.
Should a supplier report incidents that turn out not to involve personal information?
Customers usually want early notice of any incident that might, because the supplier's early view is often wrong. Suppliers worry about reporting every blocked attack. Defining a Security Incident as actual or suspected unauthorised access to customer data, rather than any attempted intrusion, keeps the obligation meaningful without flooding the customer.
Is telling the customer an admission of liability?
Not unless the contract makes it one, and most clauses say expressly that it is not. Suppliers value that sentence because it removes a reason to delay. Customers lose nothing by agreeing to it, since liability is decided by what actually happened, not by the fact that a notice was sent.
Can a supplier notify affected individuals directly?
It can if the contract allows it or the law requires it, but most customers prefer to control that communication because the individuals are their customers or staff. Clauses usually require the supplier to obtain the customer's approval before contacting individuals or the media, with a carve out for any notification the supplier is legally obliged to make.
Put the clause in a finished document
The button opens the document generator with a starting description already filled in. Change it to match your own agreement before you run it.
Create a document with OneCraftRelated clauses
- Cyber security clause: the controls a supplier must keepA cyber security clause sets the technical and organisational measures a supplier must keep. Sample naming the Essential Eight, a controls list, three variants.
- Data protection clauseA data protection clause sets how a supplier handles personal information under the contract. Australian Privacy Act sample, UK GDPR and US variants.
- Data processing clause under UK GDPR Article 28A UK data processing clause gives the controller to processor terms UK GDPR Article 28 requires. Sample for a marketing agency, the mandatory points, variants.
For everything the document generator can do, see the document maker.
Step by step in the builder: Create a document with AI, then Document builder components.
Written and checked by the OneCraft team. Last checked .