⚠️
Risk Consideration

This clause fails to clearly state who owns customer data, how it will be protected, or what happens to it when the contract ends. This is high-risk because UK GDPR and US state privacy laws (like CCPA in California) impose strict legal duties on anyone handling personal data—and you can face fines up to £20 million or 4% of revenue in the UK, or $7,500 per violation in California. If the contract doesn't specify these rules, you could be held liable for the other party's data mishandling. For example, if a vendor loses customer email addresses and the contract doesn't say who's responsible, you might be legally liable even though you didn't cause the breach.

💡
Key Recommendation

Insist the contract clearly state: (1) what data will be shared, (2) who is responsible for protecting it, (3) how long it's kept, and (4) what happens to it after the contract ends (usually deletion or return). If you're not a data expert, ask your IT or compliance person to review this section before signing. ---

Frequently Asked Questions

What does this clause mean in simple terms?

This clause fails to clearly state who owns customer data, how it will be protected, or what happens to it when the contract ends.

Why should I care about this clause?

This is high-risk because UK GDPR and US state privacy laws (like CCPA in California) impose strict legal duties on anyone handling personal data—and you can face fines up to £20 million or 4% of revenue in the UK, or $7,500 per violation in California.

What are my options?

If the contract doesn't specify these rules, you could be held liable for the other party's data mishandling.

How does this affect small businesses?

For example, if a vendor loses customer email addresses and the contract doesn't say who's responsible, you might be legally liable even though you didn't cause the breach.

✅ Action Checklist