Data Rooms Providers Find a data room
VDR glossary · Compliance and privacy

What is breach notification?

Definition

Breach notification: The legal duty to inform regulators, affected people or customers when personal data or confidential information has been exposed, within deadlines set by law or contract.

How it works in a data room

If a room is compromised, for example through a stolen password or a misconfigured permission, the provider must alert its customer under the terms of their contract. The customer, as the party responsible for the data, then decides whether the incident meets a legal threshold for reporting. Under the GDPR, a notifiable breach goes to the supervisory authority within 72 hours of becoming aware of it, and to affected individuals where the risk is high. US state laws set their own triggers and timelines. The audit trail is the main evidence for working out what was exposed and to whom.

Why it matters in a deal

A breach during a sale process can delay signing, change the price or end the deal, and the reporting clock keeps running regardless of deal timetables. Sellers should know before launch who at the provider notifies them, how fast, and what logs they can export. Limiting the amount of personal data in the room in the first place reduces both the risk and the size of any notification. Our methodology looks at incident response terms when rating security.

Example

A bidder’s analyst in Singapore downloads a payroll file by mistake after a folder was set to the wrong rights. The administrator sees it in the activity report within an hour, revokes access, and asks the bidder to confirm deletion. Counsel reviews the incident against Singapore and EU rules, documents the assessment, and decides on notification based on the risk to the employees involved.

Related terms