This clause requires you to notify the other party (and sometimes regulators and affected individuals) quickly if personal data is stolen, lost, or accessed without permission. UK GDPR requires notification to regulators within 72 hours of discovering a breach; US law varies by state but often requires notification within 30-60 days. For example, if hackers steal customer email addresses, you must tell the customer and the regulator. This clause typically specifies the timeframe for notification, what information you must include, and who pays for the notification process (like sending letters or credit monitoring). Fast notification limits damage because people can protect themselves (like changing passwords).
Accept this clause—it's legally required anyway, so negotiating against it looks suspicious. However, clarify the definition of "breach" (does it include minor incidents?) and negotiate a reasonable timeframe for *internal* notification to the other party (e.g., 24-48 hours) before public notification. Confirm who pays for notification costs, especially for large breaches affecting thousands of people, as this can be expensive.
Frequently Asked Questions
What does this clause mean in simple terms?
This clause requires you to notify the other party (and sometimes regulators and affected individuals) quickly if personal data is stolen, lost, or accessed without permission.
Why should I care about this clause?
UK GDPR requires notification to regulators within 72 hours of discovering a breach; US law varies by state but often requires notification within 30-60 days.
What are my options?
For example, if hackers steal customer email addresses, you must tell the customer and the regulator.
How does this affect small businesses?
This clause typically specifies the timeframe for notification, what information you must include, and who pays for the notification process (like sending letters or credit monitoring).
