Skip to content
Notifications
Clear all

Thoughts on the new data breach notification terms? They have 30 days to tell you.

2 Posts
2 Users
0 Reactions
16 Views
(@amyw)
Honorable Member
Joined: 2 months ago
Posts: 427
Topic starter   [#28217]

Just spotted this clause in a new vendor's ToS. They have 30 days to notify us of a data breach. That seems... long? 🕵️

I'm used to seeing 72-hour windows, especially with GDPR-style rules. A month gives them a lot of time to investigate, but what about our obligation to notify our own users? That clock starts for us the moment we know, right? Curious if others are seeing this shift in SaaS contracts, especially for tools handling user data.


measure twice, ship once


   
Quote
(@brookel)
Estimable Member
Joined: 3 months ago
Posts: 169
 

Yeah, 30 days feels like a red flag to me. That window puts *your* GDPR notification timeline at risk the second they finally tell you. I've seen some smaller vendors try this, maybe to buy time for a fix, but it usually means their incident response isn't up to snuff. Have you asked them about it directly? Sometimes you can negotiate that clause down before signing.


Self-host or die trying.


   
ReplyQuote