What It Does
For in-house counsel, the notice clause should give your response team usable information while the vendor investigates. A practical test: work through an incident with your security lead and identify when the vendor must notify you, who receives the notice, what the first update must contain, and how follow-up information reaches your team.
Requires notice of a security breach within a defined window
Specifies the content the notice must include
Sets the trigger, such as becoming aware of an actual or suspected incident
Adds duties to cooperate with investigation and regulator or individual notice
Often allocates the cost of notification, credit monitoring, and remediation
The clause supplements applicable duties under GDPR Article 33, US state breach laws, and HIPAA. Set its notice trigger and deadline to support those duties, including any requirement for earlier notice.
When You'll See It
Data breach notification appears in data processing addenda, SaaS and cloud agreements, security exhibits, HIPAA business associate agreements, and outsourcing and claims-services agreements, in any contract where a vendor stores or processes your data. It sits near the security, confidentiality, and data-protection provisions. The flavor shifts with the regime: a GDPR DPA tracks the processor-to-controller duty, a US commercial agreement sets a fixed hour-based window, and a BAA tracks HIPAA's timelines.
It matters most where a vendor holds personal data whose breach would trigger your own legal duties: customer records, employee data, health or financial information. The more regulated the data and the tighter your own deadlines, the more the vendor's notice window decides whether you can comply.
Examples
CoreWeave, Inc. / Meta
Master Services Agreement
Customer notifies provider, promptly, plus cooperation
One-Sided
2025
"Notification by Customer of Security Incidents. Customer will notify CoreWeave promptly after becoming aware of a Security Incident, including unauthorized access to Customer’s account or account credentials, and shall aid in any investigation or legal action that is taken by authorities and/or CoreWeave to investigate and cure the Security Incident or breach to the extent caused by the Customer’s account or Customer’s or its End Users’ use of the Services."
Relativity ODA LLC / KLDiscovery Ontrack, LLC
Data Processing Agreement (UK SCCs)
Processor notifies controller, without undue delay, with required content
One-Sided
2023
"...in the event of a personal data breach concerning data processed by the processor, the processor shall notify the controller without undue delay after the processor having become aware of the breach. Such notification shall contain, at least: (a) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects...)."
SageSure Capital Holdings, Inc. / Interboro Insurance Company
Claims Services Agreement
Mutual, 24-hour window, defined method
Mutual
2024
"...ii) notify the other Party of a Security Breach as soon as practicable, but no later than twenty-four (24) hours after the Party becomes aware of it; and iii) notify the other Party of any Security Breaches by emailing the other Party at an address provided by the other Party, with a copy by email to the Party’s primary business contact within the other Party."
Affirm, Inc. / Shopify Inc.
Amended and Restated Customer Installment Program Agreement
Affirm bears its breach costs; Shopify's corresponding duty has stated limits
One-Sided
2024
"Affirm shall be responsible for all Security Breach Costs associated with its Security Breach."
Negotiate
Seek early notice and enough information to assess your own reporting duties.
Require notice within a short, fixed window, such as 24 to 72 hours, of the vendor becoming aware of, rather than merely confirming, an incident.
Specify the content the notice must include, so you receive what you need to notify regulators and affected individuals on time.
Require cooperation with the investigation, and make the vendor bear the cost of notification, credit monitoring, and remediation for breaches it caused.
Make the response process workable while preserving your statutory notification duties.
Define the incident trigger clearly and allow phased updates as facts emerge. Preserve any duty to notify without undue delay after awareness of a personal data breach.
Limit the content obligation to information reasonably available at the time, with updates to follow.
Cap cost-bearing to breaches caused by your fault, and exclude incidents originating in the customer's own environment.
Negotiate the notice trigger, deadline, required content, and follow-up process together. A contractual outer limit must preserve any duty to notify sooner under applicable law.
Red Flags
A vague "prompt" or "reasonable" notice obligation with no fixed window, which can leave you unable to meet your own 72-hour or state-law deadlines.
No requirement that the notice contain the information you need to notify regulators and affected individuals.
Silence on who pays for breach notification, credit monitoring, and remediation.
A trigger tied only to "confirmed" breaches, which lets a vendor delay while it investigates.
No cooperation obligation, leaving you to investigate a breach that happened on someone else's systems.
FAQs
This content is for informational purposes only and does not constitute legal advice.



