💡
Best Practice

This clause sets deadlines for what happens if your data is stolen, leaked, or corrupted—who gets told, how fast, and what the other company must do to fix it. It matters because delays in reporting breaches can make the damage worse (criminals have more time to use stolen data) and can violate legal requirements. Under UK GDPR, you must report breaches to regulators within 72 hours; under US state laws like California's, timelines vary but are typically 30-60 days. The clause should specify: the company tells you within 24-48 hours of discovering a breach, they investigate and tell you what happened, and they take steps to stop ongoing damage.

💡
Key Recommendation

Push for notification within 24 hours of discovery (not 72 hours), and require them to provide daily updates while investigating. Specify that "discovery" means when they first realize something is wrong, not when they've confirmed it—otherwise they can delay by claiming they're still investigating. Include a penalty (like contract termination) if they miss the deadline, so they take it seriously. ---

Frequently Asked Questions

What does this clause mean in simple terms?

This clause sets deadlines for what happens if your data is stolen, leaked, or corrupted—who gets told, how fast, and what the other company must do to fix it.

Why should I care about this clause?

It matters because delays in reporting breaches can make the damage worse (criminals have more time to use stolen data) and can violate legal requirements.

What are my options?

Under UK GDPR, you must report breaches to regulators within 72 hours; under US state laws like California's, timelines vary but are typically 30-60 days.

How does this affect small businesses?

The clause should specify: the company tells you within 24-48 hours of discovering a breach, they investigate and tell you what happened, and they take steps to stop ongoing damage.

✅ Action Checklist