If a vendor is breached, who has to notify the affected individuals?
The company that owns or licenses the data, not the vendor holding it. Three state breach-notification statutes were checked for this piece — California, New York and Texas — and each is built on that distinction. California Civil Code section 1798.82(a)(1) requires “[a]n individual or business that conducts business in California, and that owns or licenses computerized data that includes personal information” to disclose a breach to affected California residents; section 1798.82(b) requires “[a]n individual or business that maintains computerized data that includes personal information that the individual or business does not own” to notify the owner or licensee of the information “immediately following discovery” instead.
New York and Texas draw the same line in the same terms. New York General Business Law section 899-aa(2) requires “[a]ny person or business which owns or licenses computerized data which includes private information” to disclose a breach to affected New York residents; section 899-aa(3) requires “[a]ny person or business which maintains computerized data which includes private information which such person or business does not own” to notify the owner or licensee “immediately,” with notification in both cases to be made within thirty days of discovery. Texas Business and Commerce Code section 521.053(b) requires the owner or license holder to notify individuals “without unreasonable delay and in each case not later than the 60th day after the date on which the person determines that the breach occurred,” while section 521.053(c) requires a person who maintains computerized data that includes sensitive personal information not owned by that person to notify the owner or license holder “immediately after discovering the breach.”
The practical consequence is the one that surprises boards. When a service provider is compromised, the customer whose data it held is the entity whose name appears on the notification letters, on the attorney general filings and in the press coverage, even where the customer’s own network was never touched. The vendor’s statutory obligation, in the three states checked here, runs to the customer rather than to the public — which also means the customer cannot start its own clock until the vendor tells it something, and what the vendor says first is usually not enough to scope the notice.
What does the contract between a company and its vendor actually decide?
Money and control between the two companies, not the duty owed to regulators or to affected individuals. A master services agreement and its security exhibit typically allocate who pays for notification and credit monitoring, who controls the forensic investigation and selects the firm, how quickly the vendor must report a security event, what audit and certification rights the customer holds, and where liability is capped or carved out of the cap. Those terms decide who bears the cost of a breach as between the parties, and they are frequently the first document each side reads after one.
Several of those terms are not merely negotiated but required. The Federal Trade Commission’s Safeguards Rule, 16 CFR 314.4(f)(2), requires covered financial institutions to “requir[e] your service providers by contract to implement and maintain such safeguards.” Massachusetts 201 CMR 17.03(2)(f)2. requires covered persons to “[r]equir[e] such third-party service providers by contract to implement and maintain such appropriate security measures for personal information.” California Civil Code section 1798.81.5(c) requires a business that discloses personal information about a California resident under a contract with a nonaffiliated third party not itself subject to subdivision (b) to “require by contract that the third party implement and maintain reasonable security procedures and practices appropriate to the nature of the information.” Under HIPAA, 45 CFR 164.308(b)(1) permits a covered entity to let a business associate handle electronic protected health information “only if the covered entity obtains satisfactory assurances, in accordance with § 164.314(a), that the business associate will appropriately safeguard the information.”
What no contract does is move the statutory notification duty. An indemnity can make the vendor pay for the notice; it cannot make the vendor the notifier where the statute assigns that role to the data owner. The agreement and the statute answer different questions — allocation on one side, duty on the other — and in these matters they do not line up.
What have regulators said about a company’s duty to oversee its service providers?
That the duty is continuous and belongs to the company that hands over the data. The Federal Trade Commission’s Safeguards Rule, 16 CFR 314.4(f), states the obligation in three parts: taking reasonable steps to select and retain service providers capable of maintaining appropriate safeguards; requiring them by contract to implement and maintain such safeguards; and “periodically assessing your service providers based on the risk they present and the continued adequacy of their safeguards.” Massachusetts 201 CMR 17.03(2)(f) frames the obligation under the same heading — “Oversee service providers, by:” — but in two parts rather than three: selecting and retaining capable third-party service providers, and requiring them by contract to implement and maintain appropriate security measures. It contains no periodic-assessment clause.
The New York Department of Financial Services regulation is the most detailed. 23 NYCRR 500.11(a) requires each covered entity to implement written policies and procedures designed to ensure the security of information systems and nonpublic information accessible to or held by third-party service providers, based on its own risk assessment, addressing the identification and risk assessment of those providers, the minimum cybersecurity practices they must meet, the due diligence used to evaluate their practices, and periodic assessment based on the risk they present. Section 500.11(b) requires guidelines for due diligence and contractual protections covering access controls including multi-factor authentication as required by section 500.12, encryption as required by section 500.15, notice to the covered entity in the event of a cybersecurity event, and representations and warranties about the provider’s cybersecurity practices. The section reads as amended effective November 1, 2023.
The Securities and Exchange Commission reaches the same subject through disclosure rather than prescription. Item 106(b)(1)(iii) of Regulation S-K, 17 CFR 229.106, requires a registrant to describe, as applicable, “Whether the registrant has processes to oversee and identify such risks from cybersecurity threats associated with its use of any third-party service provider.” That annual statement is dated, discoverable, and comparable against what the company actually did — the same evidentiary dynamic that makes a stated benchmark cut both ways, discussed in frameworks and benchmarking.
Can the vendor itself be held liable, or does everything land on the customer?
The vendor carries its own exposure, and in some regimes it is regulated directly. Under the HIPAA rules a business associate is not merely a contract counterparty: 45 CFR 164.410 requires it, “following the discovery of a breach of unsecured protected health information,” to notify the covered entity “without unreasonable delay and in no case later than 60 calendar days after discovery of a breach,” identifying to the extent possible the individuals whose information was involved and supplying the other information the covered entity needs for its own notifications.
General consumer-protection authority reaches providers too. On February 1, 2024 the Federal Trade Commission announced a proposed order against Blackbaud, Inc., which it described as a company that “provides data services and financial, fundraising, and administrative software services to companies, nonprofits, healthcare organizations, and others.” The Commission charged that Blackbaud failed to implement appropriate safeguards for the personal data it maintained as part of those services, and that after learning by late July 2020 that a hacker had obtained sensitive data, the company “waited another two months before it told its customers about the full scope of the breach.” The Commission gave the order final approval on May 20, 2024. It requires a comprehensive information security program, deletion of personal data no longer needed, a data retention schedule stating why data is kept and when it is deleted, a prohibition on misrepresenting its data security and retention practices, and notice to the Commission of future breaches Blackbaud must report to other agencies.
Liability can also run through the customer to the vendor’s conduct. 45 CFR 160.402(c)(1) provides that a covered entity “is liable, in accordance with the Federal common law of agency, for a civil money penalty for a violation based on the act or omission of any agent of the covered entity, including a workforce member or business associate, acting within the scope of the agency,” and section 160.402(c)(2) applies the same rule to a business associate and its subcontractors. Whether a given provider is an agent for those purposes is a fact question, and it turns substantially on how much control the customer retained.
What does the enforcement record show about blaming the vendor?
That the customer’s own oversight is examined on its own terms, and that pointing at the vendor has not answered the question. The clearest illustration remains the Federal Trade Commission’s settlement with GMR Transcription Services, Inc.: the proposed settlement was announced January 31, 2014, and the Commission approved the final order in August 2014. GMR hired contractors to transcribe audio files; according to the complaint, transcripts prepared between March 2011 and October 2011 by Fedtrans, GMR’s service provider, were indexed by a major internet search engine and were publicly available to anyone using it.
What the Commission charged GMR with is the part worth noting. The press release states that GMR “never required the individual typists it hired as contractors to implement security measures, such as installing anti-virus software,” and that an independent service provider it hired to transcribe medical files “stored and transmitted the files in clear and readable text on a server that was configured so that they could be accessed online by anyone without authentication.” These are the Commission’s allegations as stated in its own release; the matter resolved by settlement rather than by any adjudicated finding. The resulting order, in force for twenty years, required GMR to establish a comprehensive information security program protecting sensitive personal information “including information the company provided to independent service providers,” evaluated initially and every two years by a certified third party.
Read alongside Blackbaud, the pattern is that each party answers for what it controlled. The provider answers for the security of the systems it ran and for what it told its customers and when; the customer answers for how it selected the provider, what it required of it in writing, and whether it ever verified any of it. Neither posture is improved by the existence of the other party, and neither company’s security is graded here — that opinion is the expert’s, and what the analysis examines is set out in reasonable security in breach litigation.
In a dispute between a company and its breached vendor, what actually decides it?
Evidence held by somebody else, which is the structural problem in every one of these matters. The forensic record of a vendor-side intrusion — the logs, the images, the endpoint telemetry, the internal chat about what was known and when — sits inside the vendor’s environment, under the vendor’s retention settings, and often under the vendor’s own privilege assertions. The customer’s ability to establish what happened depends on contractual audit and cooperation rights it negotiated before anyone knew it would need them, and on how quickly it invoked them.
That is why the preservation question is sharper here than in a single-party incident. A hold issued inside the customer’s organization does nothing to stop log rotation inside the vendor’s, and by the time a demand letter is drafted the window may be closed. The timescales are set out in what disappears first after a breach, and the separate problem of connecting a particular control failure to a particular intrusion is treated in proving a control failure caused the breach.
The rest is allocation. Which entity owed which duty under which statute, what the agreement said about liability caps and indemnity, what the vendor represented in its security questionnaire and certifications, and whether the customer’s oversight met the standard applicable to it. Quantifying what the breach cost either party is a damages question and belongs to the Economic Damages Institute at economicdamagesinstitute.com, which covers the measures of loss; this Institute deals with the evidence underneath them.