SaaS · 9 min read

My SaaS Vendor Was Breached. What Does the Contract Actually Cover?

Check the security, breach notification, data processing and liability sections. Most contracts require the vendor to notify you and cooperate, but liability caps and exclusions often limit what you can recover. Some contracts have a higher cap for data breaches. Your own legal notification duties may apply regardless.

A vendor emails to say it has had a security incident, and your data may be involved. You need to know what the vendor must do, what you must do, and whether you can recover costs. The answers are spread across several parts of the contract: the security commitments, the data processing addendum, breach notification terms, indemnities and the limitation of liability. This guide shows where to look and what each part usually means.

Have the contract in front of you? You can check your software contract for this clause in a few minutes.

Key takeaways

  • Check security commitments, notification timelines and cooperation duties.
  • Your own breach notification duties apply regardless of the vendor.
  • Liability caps often limit recovery, but a data breach super cap may apply.
  • Preserve records and follow the contract's claim procedures.

Security commitments

Most SaaS contracts describe the vendor's security obligations, sometimes referring to certifications like SOC 2 or ISO 27001, or a security schedule. Check whether the vendor promised specific measures, such as encryption, access controls or regular testing. If the breach resulted from failing to meet those commitments, that can be a breach of contract.

Breach notification

Contracts and data processing addendums usually require the vendor to notify you of a security incident affecting your data, often "without undue delay" or within a set period such as 48 or 72 hours. They may also require the vendor to share details: what happened, what data was affected and what it is doing. Check whether the vendor met these obligations.

Cooperation and your legal duties

If personal data was involved, you may have legal duties as the data owner or controller, such as notifying affected individuals or regulators under state breach notification laws or privacy laws. Contracts often require the vendor to cooperate and provide information you need. Your duties apply whether or not the vendor cooperates, so start your own assessment immediately. Our guide to data processing addendums explains these roles.

Liability caps

The limitation of liability clause often caps the vendor's liability at the fees paid in the previous 12 months, and excludes indirect or consequential losses such as lost profits. Many contracts include a separate, higher cap for data breaches or confidentiality breaches, sometimes called a super cap, such as two or three times annual fees. Some exclude gross negligence or willful misconduct from the cap. Our guide to fair liability caps explains typical structures.

Costs you may try to recover

Contracts vary on which of these are covered. Some expressly include breach response costs within a data breach cap.

  • Notification costs, such as letters and call centers.
  • Credit monitoring for affected individuals.
  • Forensic investigation costs.
  • Regulatory fines, where recoverable and allowed by law.
  • Legal fees and third-party claims.

Indemnities

Some contracts include an indemnity for claims arising from the vendor's breach of data protection obligations. An indemnity can be more valuable than a general damages claim because it covers third-party claims against you, but it is often subject to the cap.

Termination rights

A material security breach may give you a right to terminate for cause, particularly if the vendor fails to cure or the breach violates specific commitments. Check the termination clause and whether you are entitled to a refund of prepaid fees.

A worked example

A clinic uses a scheduling platform that suffers a breach exposing patient contact details. The contract caps liability at 12 months' fees, $18,000, but includes a data breach super cap of $100,000 covering notification and credit monitoring costs. The vendor notified within 48 hours as required. The clinic handles its own notification duties and recovers $62,000 of costs under the super cap.

Sample email to the vendor

"Thank you for notifying us of the incident. Under our agreement, please provide: the categories and volume of our data affected, the timeline, root cause, containment steps, and any information we need to meet our notification obligations. Please confirm your point of contact and preserve all relevant records. We reserve our rights under the agreement."

Common mistakes

  • Waiting for the vendor before assessing your own duties.
  • Assuming the general liability cap is the only limit.
  • Missing notice or claim procedures in the contract.
  • Not preserving records.
  • Admitting responsibility to affected people before understanding the facts.

Quick checklist

  • What security commitments did the vendor make?
  • Did the vendor notify you on time?
  • What data was affected, and do you have notification duties?
  • Is there a data breach super cap?
  • Which costs does the contract cover?
  • Is there an indemnity or termination right?

Key terms explained

These terms matter after a vendor breach.

  • Security incident: an event that compromises data or systems.
  • Data processing addendum: the contract terms for how a vendor handles personal data.
  • Super cap: a higher liability cap for specific risks such as data breaches.
  • Consequential losses: indirect losses like lost profits, often excluded.
  • Indemnity: a promise to cover losses from certain claims.

Immediate steps for your team

  • Assemble a small response team: IT or security, legal, communications and the business owner of the system.
  • Identify exactly what data you stored in the vendor's system and whose it is.
  • Rotate credentials and API keys connected to the vendor.
  • Review access logs available to you.
  • Document every step and decision with dates and times.
  • Check your cyber insurance policy and notify the insurer if required.

Your customers' contracts

If you process data for your own customers, your contracts with them may require you to notify them of incidents affecting their data within a set period, sometimes shorter than the vendor's notice to you. Check those obligations immediately. A vendor breach can quickly become your obligation to your customers.

State notification laws

Every US state has a data breach notification law requiring notice to affected residents when certain personal information is compromised, often names combined with Social Security numbers, financial account numbers or other sensitive data. Some require notice to the state attorney general. Deadlines and triggers vary. Get advice promptly if personal information may be involved.

Negotiating better breach terms next time

At signing, ask for: specific security commitments and certifications, notification within a set number of hours, a duty to cooperate and provide information, a data breach super cap covering notification and response costs, an indemnity for claims arising from the vendor's security failures, and a right to terminate for a material security breach. Vendors that handle sensitive data should also carry cyber insurance and name it in the contract.

When the vendor's subprocessor was breached

Breaches often occur at a vendor's own suppliers, such as hosting or support providers. Check whether the contract makes the vendor responsible for its subprocessors. Most data processing addendums do. If the vendor says the breach was not its fault because a subprocessor caused it, that usually does not remove its contractual obligations to you.

Questions to ask the vendor

Ask when the incident started and was discovered, whether it is contained, which of your records were affected, whether data was encrypted, and what the vendor is changing to prevent a repeat.

Communication with affected people

Coordinate messages to customers or employees with the vendor so facts are consistent. Do not speculate about causes before the investigation is complete.

Review the relationship afterwards

After the incident, decide whether to continue with the vendor. Ask for its post-incident report and remediation plan, and consider stronger contract terms at renewal.

Keep a claims file

Keep invoices for every cost you incur responding to the incident, such as forensic work, notification letters, credit monitoring and legal advice. You will need them to claim under the contract or your insurance.

Review before the next incident

The time to negotiate breach terms is before signing. Upload your SaaS agreement to see its security, notification and liability terms explained, including any data breach cap.

Check what your contract covers after a breach

Upload your SaaS contract and we will flag security, notification and liability terms, plus every other risky clause, in plain English, tuned to your state, with a downloadable report and redline.

Frequently asked questions

Is my SaaS vendor liable for a data breach?

Possibly, if it breached the contract, but liability caps and exclusions often limit recovery.

How quickly must a vendor tell me about a breach?

Whatever the contract says, often without undue delay or within 48 to 72 hours.

What is a data breach super cap?

A higher liability cap that applies specifically to data or confidentiality breaches.

Related guides

This guide is general information from ClauseAudit, not legal advice. Laws vary by state and change, consult a qualified attorney for your situation. Published 2026-05-01; last reviewed 2026-09-25.