My SaaS Vendor Was Breached. What Does the Contract Actually Cover?
Check the security, breach notification, data processing and liability sections. Most contracts require the vendor to notify you and cooperate, but liability caps and exclusions often limit what you can recover. Some contracts have a higher cap for data breaches. Your own legal notification duties may apply regardless.
A vendor emails to say it has had a security incident, and your data may be involved. You need to know what the vendor must do, what you must do, and whether you can recover costs. The answers are spread across several parts of the contract: the security commitments, the data processing addendum, breach notification terms, indemnities and the limitation of liability. This guide shows where to look and what each part usually means.
Have the contract in front of you? You can check your software contract for this clause in a few minutes.
Key takeaways
- Check security commitments, notification timelines and cooperation duties.
- Your own breach notification duties apply regardless of the vendor.
- Liability caps often limit recovery, but a data breach super cap may apply.
- Preserve records and follow the contract's claim procedures.
Security commitments
Most SaaS contracts describe the vendor's security obligations, sometimes referring to certifications like SOC 2 or ISO 27001, or a security schedule. Check whether the vendor promised specific measures, such as encryption, access controls or regular testing. If the breach resulted from failing to meet those commitments, that can be a breach of contract.
Breach notification
Contracts and data processing addendums usually require the vendor to notify you of a security incident affecting your data, often "without undue delay" or within a set period such as 48 or 72 hours. They may also require the vendor to share details: what happened, what data was affected and what it is doing. Check whether the vendor met these obligations.
Cooperation and your legal duties
If personal data was involved, you may have legal duties as the data owner or controller, such as notifying affected individuals or regulators under state breach notification laws or privacy laws. Contracts often require the vendor to cooperate and provide information you need. Your duties apply whether or not the vendor cooperates, so start your own assessment immediately. Our guide to data processing addendums explains these roles.
Liability caps
The limitation of liability clause often caps the vendor's liability at the fees paid in the previous 12 months, and excludes indirect or consequential losses such as lost profits. Many contracts include a separate, higher cap for data breaches or confidentiality breaches, sometimes called a super cap, such as two or three times annual fees. Some exclude gross negligence or willful misconduct from the cap. Our guide to fair liability caps explains typical structures.
Costs you may try to recover
Contracts vary on which of these are covered. Some expressly include breach response costs within a data breach cap.
- Notification costs, such as letters and call centers.
- Credit monitoring for affected individuals.
- Forensic investigation costs.
- Regulatory fines, where recoverable and allowed by law.
- Legal fees and third-party claims.
Indemnities
Some contracts include an indemnity for claims arising from the vendor's breach of data protection obligations. An indemnity can be more valuable than a general damages claim because it covers third-party claims against you, but it is often subject to the cap.
Termination rights
A material security breach may give you a right to terminate for cause, particularly if the vendor fails to cure or the breach violates specific commitments. Check the termination clause and whether you are entitled to a refund of prepaid fees.
A worked example
A clinic uses a scheduling platform that suffers a breach exposing patient contact details. The contract caps liability at 12 months' fees, $18,000, but includes a data breach super cap of $100,000 covering notification and credit monitoring costs. The vendor notified within 48 hours as required. The clinic handles its own notification duties and recovers $62,000 of costs under the super cap.
Sample email to the vendor
"Thank you for notifying us of the incident. Under our agreement, please provide: the categories and volume of our data affected, the timeline, root cause, containment steps, and any information we need to meet our notification obligations. Please confirm your point of contact and preserve all relevant records. We reserve our rights under the agreement."
Common mistakes
- Waiting for the vendor before assessing your own duties.
- Assuming the general liability cap is the only limit.
- Missing notice or claim procedures in the contract.
- Not preserving records.
- Admitting responsibility to affected people before understanding the facts.
Quick checklist
- What security commitments did the vendor make?
- Did the vendor notify you on time?
- What data was affected, and do you have notification duties?
- Is there a data breach super cap?
- Which costs does the contract cover?
- Is there an indemnity or termination right?
Key terms explained
These terms matter after a vendor breach.
- Security incident: an event that compromises data or systems.
- Data processing addendum: the contract terms for how a vendor handles personal data.
- Super cap: a higher liability cap for specific risks such as data breaches.
- Consequential losses: indirect losses like lost profits, often excluded.
- Indemnity: a promise to cover losses from certain claims.
Immediate steps for your team
- Assemble a small response team: IT or security, legal, communications and the business owner of the system.
- Identify exactly what data you stored in the vendor's system and whose it is.
- Rotate credentials and API keys connected to the vendor.
- Review access logs available to you.
- Document every step and decision with dates and times.
- Check your cyber insurance policy and notify the insurer if required.
Your customers' contracts
If you process data for your own customers, your contracts with them may require you to notify them of incidents affecting their data within a set period, sometimes shorter than the vendor's notice to you. Check those obligations immediately. A vendor breach can quickly become your obligation to your customers.
State notification laws
Every US state has a data breach notification law requiring notice to affected residents when certain personal information is compromised, often names combined with Social Security numbers, financial account numbers or other sensitive data. Some require notice to the state attorney general. Deadlines and triggers vary. Get advice promptly if personal information may be involved.
Negotiating better breach terms next time
At signing, ask for: specific security commitments and certifications, notification within a set number of hours, a duty to cooperate and provide information, a data breach super cap covering notification and response costs, an indemnity for claims arising from the vendor's security failures, and a right to terminate for a material security breach. Vendors that handle sensitive data should also carry cyber insurance and name it in the contract.
When the vendor's subprocessor was breached
Breaches often occur at a vendor's own suppliers, such as hosting or support providers. Check whether the contract makes the vendor responsible for its subprocessors. Most data processing addendums do. If the vendor says the breach was not its fault because a subprocessor caused it, that usually does not remove its contractual obligations to you.
Questions to ask the vendor
Ask when the incident started and was discovered, whether it is contained, which of your records were affected, whether data was encrypted, and what the vendor is changing to prevent a repeat.
Communication with affected people
Coordinate messages to customers or employees with the vendor so facts are consistent. Do not speculate about causes before the investigation is complete.
Review the relationship afterwards
After the incident, decide whether to continue with the vendor. Ask for its post-incident report and remediation plan, and consider stronger contract terms at renewal.
Keep a claims file
Keep invoices for every cost you incur responding to the incident, such as forensic work, notification letters, credit monitoring and legal advice. You will need them to claim under the contract or your insurance.
Review before the next incident
The time to negotiate breach terms is before signing. Upload your SaaS agreement to see its security, notification and liability terms explained, including any data breach cap.
Check what your contract covers after a breach
Upload your SaaS contract and we will flag security, notification and liability terms, plus every other risky clause, in plain English, tuned to your state, with a downloadable report and redline.
Frequently asked questions
Is my SaaS vendor liable for a data breach?
Possibly, if it breached the contract, but liability caps and exclusions often limit recovery.
How quickly must a vendor tell me about a breach?
Whatever the contract says, often without undue delay or within 48 to 72 hours.
What is a data breach super cap?
A higher liability cap that applies specifically to data or confidentiality breaches.
Related guides
- Getting Your Data Out When You Cancel a SaaS ContractWhen a software subscription ends, access to your data can end with it. Here is how to check export rights, deletion timelines and formats before you cancel.
- Who Owns Your Data in a SaaS Agreement? How to Read the Fine PrintA clear data-ownership clause is one of the most important things in any software contract. Here is how ownership, licenses, and what happens when you cancel actually work, and what to negotiate.
- Small Business Buying Software: A 10-Minute Contract CheckA fast, practical checklist for small businesses signing software and SaaS contracts, covering price, renewal, data, liability and exit terms.
- How to Read a SaaS Contract Before You SignSaaS terms are some of the most one-sided contracts businesses sign. Here’s what to check first.
- What Is a Data Processing Addendum (DPA), and Do You Need One?A DPA sets the rules for how a SaaS vendor handles the personal data you send it, required under GDPR and central to CCPA compliance. Here are the terms that actually protect you.
- My SaaS Contract Auto-Renewed and They Won't Let Me Cancel. What Now?A software subscription renewed for another year because you missed a notice window. Here is how to check the contract, which laws may help and how to negotiate an exit.
This guide is general information from ClauseAudit, not legal advice. Laws vary by state and change, consult a qualified attorney for your situation. Published 2026-05-01; last reviewed 2026-09-25.