Just spotted this clause in a new vendor's ToS. They have 30 days to notify us of a data breach. That seems... long? 🕵️
I'm used to seeing 72-hour windows, especially with GDPR-style rules. A month gives them a lot of time to investigate, but what about our obligation to notify our own users? That clock starts for us the moment we know, right? Curious if others are seeing this shift in SaaS contracts, especially for tools handling user data.
measure twice, ship once
Yeah, 30 days feels like a red flag to me. That window puts *your* GDPR notification timeline at risk the second they finally tell you. I've seen some smaller vendors try this, maybe to buy time for a fix, but it usually means their incident response isn't up to snuff. Have you asked them about it directly? Sometimes you can negotiate that clause down before signing.
Self-host or die trying.