Get a Quote
Fill out a form and a team member will reach out within one business day.
In most cases, yes. If a vendor you hired, such as a payroll processor, cloud storage provider, or point-of-sale company, loses control of your customers' personal information, your business can still be the one legally required to notify those customers and answer for the fallout. Handing data to a third party doesn't hand off the responsibility that comes with it.
That surprises a lot of business owners, who assume the company that actually got hacked is the one on the hook. Under California law, and in most vendor contracts, it doesn't usually work that way.
California's data breach notification statute draws a clear line between the business that owns or licenses customer data and a vendor that merely maintains it on that business's behalf. The business that owns the data has the primary duty to notify affected California residents. A vendor that discovers a breach in its own systems is required to notify the data owner right away, but the vendor generally isn't the one who has to contact your customers. You are.
In practical terms, if your point-of-sale vendor, marketing platform, or billing service gets breached and your customers' names, emails, or payment details are exposed, your business is typically still the party the law (and your customers) will hold accountable, even though the actual intrusion happened somewhere else entirely.
Under California Civil Code Section 1798.82, a business that owns or licenses computerized personal information must notify affected California residents "in the most expedient time possible and without unreasonable delay," and no later than 30 calendar days after discovering the breach. If a single breach affects more than 500 California residents, a sample notice must also be submitted electronically to the California Attorney General's office.
A vendor holding data on your behalf has a narrower duty: notify you, the data owner, immediately upon discovering a breach. From there, the consumer-facing notification obligation, and the legal exposure that comes with it, generally falls back on your business.
A solid vendor contract with indemnification language can help you recover some costs after a vendor-caused breach, and it's worth having one. But contracts have real limits. An indemnification clause is only as good as the vendor's ability, or willingness, to pay. If the vendor is underinsured, disputes fault, or goes out of business, a paper promise doesn't cover your breach response costs, regulatory notifications, or the customers who show up asking what happened.
Contractual protection and insurance protection does different jobs. One allocates blame after the fact. The other actually pays the bills while that dispute plays out.
This depends on your specific policy, but a properly structured cyber liability policy is built to respond to exactly this scenario in several ways:
Because coverage details and exclusions vary by carrier, it's worth reviewing your policy language with your agent to confirm how vendor-related incidents are handled before you need to file a claim, not after.
The Cybersecurity and Infrastructure Security Agency (CISA) recommends that businesses treat vendor and supply chain risk as part of their own cybersecurity program, not someone else's problem. A few practical steps:
None of this eliminates the risk entirely, but it does reduce the odds of a breach and puts you in a stronger position if one happens anyway.
Fuller Insurance Agency helps California businesses evaluate their cyber and network security liability exposure, including risk tied to vendors and third-party service providers. Call (800) 640-4238, email contact@fullerins.com, or request a quote at fullerins.com.
Read Also: Data Privacy Impact Cyber Insurance
Fill out a form and a team member will reach out within one business day.Get a Quote
In most cases, yes. Under California law, the business that owns or licenses the data generally carries the duty to notify affected customers, even when the actual breach happened inside a vendor's systems.
Typically, not. Standard general liability policies are built around bodily injury and property damage, not data compromise. Data breaches, including those caused by a vendor, are usually addressed under a dedicated cyber liability or network security liability policy.
Cost varies based on factors like how much sensitive data you handle, your industry, annual revenue, and the security controls you already have in place. An agent can walk through your specific risk profile and give you an accurate quote rather than a generic number.
Fuller Insurance Agency works with multiple carriers to help California businesses find cyber liability coverage that fits their size and risk, including protection tied to vendor and third-party incidents. Call (800) 640-4238 or request a quote through fullerins.com to get started.