Data Breach Notification Clause

A clause requiring a party to notify the other of a security breach affecting its data within a defined window, with defined content, so the other can meet its own legal obligations.

Reviewed by

GC AI Solutions Team

Updated

September 2026

Definition

A data breach notification clause requires one party, usually the vendor or processor handling the other's data, to tell the other about a security breach within a set time, with enough detail for the recipient to respond. GDPR Article 33 requires processors to notify controllers without undue delay after awareness. Controllers must notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to risk individuals' rights and freedoms. The contractual clause is how a customer makes sure it learns of a breach in time to meet those deadlines.

What It Does

For in-house counsel, the notice clause should give your response team usable information while the vendor investigates. A practical test: work through an incident with your security lead and identify when the vendor must notify you, who receives the notice, what the first update must contain, and how follow-up information reaches your team.

  • Requires notice of a security breach within a defined window

  • Specifies the content the notice must include

  • Sets the trigger, such as becoming aware of an actual or suspected incident

  • Adds duties to cooperate with investigation and regulator or individual notice

  • Often allocates the cost of notification, credit monitoring, and remediation

The clause supplements applicable duties under GDPR Article 33, US state breach laws, and HIPAA. Set its notice trigger and deadline to support those duties, including any requirement for earlier notice.

When You'll See It

Data breach notification appears in data processing addenda, SaaS and cloud agreements, security exhibits, HIPAA business associate agreements, and outsourcing and claims-services agreements, in any contract where a vendor stores or processes your data. It sits near the security, confidentiality, and data-protection provisions. The flavor shifts with the regime: a GDPR DPA tracks the processor-to-controller duty, a US commercial agreement sets a fixed hour-based window, and a BAA tracks HIPAA's timelines.

It matters most where a vendor holds personal data whose breach would trigger your own legal duties: customer records, employee data, health or financial information. The more regulated the data and the tighter your own deadlines, the more the vendor's notice window decides whether you can comply.

Examples

CoreWeave, Inc. / Meta

Master Services Agreement

Customer notifies provider, promptly, plus cooperation

One-Sided

2025

"Notification by Customer of Security Incidents. Customer will notify CoreWeave promptly after becoming aware of a Security Incident, including unauthorized access to Customer’s account or account credentials, and shall aid in any investigation or legal action that is taken by authorities and/or CoreWeave to investigate and cure the Security Incident or breach to the extent caused by the Customer’s account or Customer’s or its End Users’ use of the Services."

Source

Relativity ODA LLC / KLDiscovery Ontrack, LLC

Data Processing Agreement (UK SCCs)

Processor notifies controller, without undue delay, with required content

One-Sided

2023

"...in the event of a personal data breach concerning data processed by the processor, the processor shall notify the controller without undue delay after the processor having become aware of the breach. Such notification shall contain, at least: (a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects...)."

Source

SageSure Capital Holdings, Inc. / Interboro Insurance Company

Claims Services Agreement

Mutual, 24-hour window, defined method

Mutual

2024

"...ii) notify the other Party of a Security Breach as soon as practicable, but no later than twenty-four (24) hours after the Party becomes aware of it; and iii) notify the other Party of any Security Breaches by emailing the other Party at an address provided by the other Party, with a copy by email to the Party’s primary business contact within the other Party."

Source

Affirm, Inc. / Shopify Inc.

Amended and Restated Customer Installment Program Agreement

Affirm bears its breach costs; Shopify's corresponding duty has stated limits

One-Sided

2024

"Affirm shall be responsible for all Security Breach Costs associated with its Security Breach."

Source

Negotiate

Customer or Controller Positions:

Customer or Controller Positions:

Seek early notice and enough information to assess your own reporting duties.

  • Require notice within a short, fixed window, such as 24 to 72 hours, of the vendor becoming aware of, rather than merely confirming, an incident.

  • Specify the content the notice must include, so you receive what you need to notify regulators and affected individuals on time.

  • Require cooperation with the investigation, and make the vendor bear the cost of notification, credit monitoring, and remediation for breaches it caused.

Vendor or Processor Positions:

Vendor or Processor Positions:

Make the response process workable while preserving your statutory notification duties.

  • Define the incident trigger clearly and allow phased updates as facts emerge. Preserve any duty to notify without undue delay after awareness of a personal data breach.

  • Limit the content obligation to information reasonably available at the time, with updates to follow.

  • Cap cost-bearing to breaches caused by your fault, and exclude incidents originating in the customer's own environment.

Negotiate the notice trigger, deadline, required content, and follow-up process together. A contractual outer limit must preserve any duty to notify sooner under applicable law.

Red Flags

  • A vague "prompt" or "reasonable" notice obligation with no fixed window, which can leave you unable to meet your own 72-hour or state-law deadlines.

  • No requirement that the notice contain the information you need to notify regulators and affected individuals.

  • Silence on who pays for breach notification, credit monitoring, and remediation.

  • A trigger tied only to "confirmed" breaches, which lets a vendor delay while it investigates.

  • No cooperation obligation, leaving you to investigate a breach that happened on someone else's systems.

FAQs

It is a clause requiring a party, usually the one handling the other's data, to notify the other of a security breach within a defined time and with defined content, so the recipient can meet its own legal and regulatory obligations.

It is a clause requiring a party, usually the one handling the other's data, to notify the other of a security breach within a defined time and with defined content, so the recipient can meet its own legal and regulatory obligations.

Check the applicable law and the contract separately. GDPR Article 33 requires processor notice without undue delay after awareness. Controllers must notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to risk individuals' rights and freedoms. A contractual deadline does not extend a statutory one.

Check the applicable law and the contract separately. GDPR Article 33 requires processor notice without undue delay after awareness. Controllers must notify the supervisory authority without undue delay and, where feasible, within 72 hours of awareness, unless the breach is unlikely to risk individuals' rights and freedoms. A contractual deadline does not extend a statutory one.

Specify the information needed for the applicable reporting regime. For a GDPR Article 33 supervisory-authority notice, include the nature of the breach; affected categories and approximate numbers of individuals and records where possible; the data protection officer's or another contact point's details; likely consequences; and measures taken or proposed, including mitigation. Allow phased updates without undue further delay when the information cannot be provided together, and require enough detail to support any separate notice to individuals.

Specify the information needed for the applicable reporting regime. For a GDPR Article 33 supervisory-authority notice, include the nature of the breach; affected categories and approximate numbers of individuals and records where possible; the data protection officer's or another contact point's details; likely consequences; and measures taken or proposed, including mitigation. Allow phased updates without undue further delay when the information cannot be provided together, and require enough detail to support any separate notice to individuals.

That depends on the contract. Customers can seek vendor responsibility for notification, credit monitoring, and remediation for vendor-caused breaches; vendors can negotiate cost limits and exclusions for incidents originating in the customer's environment. In the Affirm/Shopify agreement, §2.40 includes claims, investigations, litigation, arbitration, and mediation costs; fines and penalties; Merchant or Customer Losses; notification expenses; and mitigation and remediation, including protective monitoring services reasonably required by the non-breached party. Section 15.6.3 makes Affirm responsible for its Security Breach Costs. Section 16 applies the corresponding duty to Shopify only as required by a Regulatory Authority or in relation to the SHOP Portal, SHOP App, or GLBA NPI.

That depends on the contract. Customers can seek vendor responsibility for notification, credit monitoring, and remediation for vendor-caused breaches; vendors can negotiate cost limits and exclusions for incidents originating in the customer's environment. In the Affirm/Shopify agreement, §2.40 includes claims, investigations, litigation, arbitration, and mediation costs; fines and penalties; Merchant or Customer Losses; notification expenses; and mitigation and remediation, including protective monitoring services reasonably required by the non-breached party. Section 15.6.3 makes Affirm responsible for its Security Breach Costs. Section 16 applies the corresponding duty to Shopify only as required by a Regulatory Authority or in relation to the SHOP Portal, SHOP App, or GLBA NPI.

The clause supplements applicable breach-notification laws. Set the vendor's notice trigger and deadline to support your reporting duties, which may run from awareness or discovery under the applicable regime. A shorter contractual window can help your response, but it does not extend a statutory deadline or establish compliance by itself.

The clause supplements applicable breach-notification laws. Set the vendor's notice trigger and deadline to support your reporting duties, which may run from awareness or discovery under the applicable regime. A shorter contractual window can help your response, but it does not extend a statutory deadline or establish compliance by itself.

This content is for informational purposes only and does not constitute legal advice.

Try GC AI Free

Find Every Gap in Your Data Breach Notification Clause

Trusted by 2,100+ in-house teams

Upload your contract. In 60 seconds, see every missing trigger, weak notice window, and one-sided fee provision, quoted exactly where it appears.

14-day free · No credit card required

SOC 2

Type II Certified

SOC 3

Certified

GDPR

Compliant

Book a personalized demo call

The AI platform built for in-house legal teams. SOC 2 certified. Zero data retention. See it for yourself.

What to expect:

A walkthrough of the GC AI platform, tailored to your team's use cases.

Answers to your questions about security, integrations, and onboarding.

A 14-day free trial if the platform looks like a fit for your team.

Related Clauses

Data Protection (DPA)

A provision, often a standalone data processing agreement, that governs how a vendor processes personal data on a customer's behalf and meets privacy-law requirements.

Sub-Processor

A clause in a data processing addendum that governs when and how a vendor may hand the customer's personal data to a downstream provider, and on what conditions.

Confidentiality

A contractual provision requiring one or both parties to keep specified information secret and use it only for an agreed purpose.

Indemnification

A contractual provision in which one party agrees to cover specified losses or third-party claims that the other party incurs.