Vendor Suffers Data Breach Affecting Your Customers: Processor Incident and Notification File
By Ravi Sisodia · Reviewed by CA Divyanshu Sengar · Updated 5 October 2026
India-first finance and compliance workflow with primary-source anchors.
2-minute summary
- A vendor breach involving your customers does not become “the vendor’s problem.” The organisation needs enough contractual and technical information to determine which records were affected, when access occurred, whether data was exfiltrated, which safeguards failed and what containment has been completed. The vendor must be able to support the organisation’s own notification and customer-response duties.
- Incident clauses should specify prompt notice, preservation of logs, forensic cooperation, sub-processor flow-down, root-cause report, deletion/containment evidence and allocation of communication responsibilities. A clause that says only “notify without undue delay” can be operationally inadequate if Indian reporting clocks are shorter.
- CERT-In’s six-hour direction can apply to reportable data breaches/cyber incidents, including where data was stored on a third party’s system. DPDP breach rules are notified but, as of 5 October 2026, relevant rules remain in the phased transition schedule.
Current position
Control and decision map
| # | Control / decision step |
|---|---|
| 1 | Open one joint incident chronology with first detection, vendor notice, containment and customer-impact timestamps. |
| 2 | Demand affected dataset/user list, log scope, attack vector, exfiltration evidence and sub-processor impact. |
| 3 | Independently map affected customers/data categories to your own data inventory. |
| 4 | Assess CERT-In and sector/client reporting clocks from your detection/notification facts. |
| 5 | Prepare customer communication that states known facts, protective steps and contact route without speculation. |
| 6 | Track vendor root cause, control remediation and contract/SLA lessons before closing the incident. |
Evidence pack
- Vendor incident notice
- Affected-record list and logs
- Forensic/root-cause report
- Notification decision memo
- Customer communications and remediation evidence
Worked example
A SaaS payroll vendor reports that an attacker accessed a support database containing employee names, bank details and tickets for several customers. The client company should not wait for the vendor’s final forensic report before starting its own impact map and reporting-clock analysis; it can report available facts where required and supplement later.
Common mistakes
- Assuming only the vendor must report the breach.
- Waiting for perfect forensic certainty before assessing a short statutory reporting deadline.
- Sending customers a generic breach email without identifying the affected data or protective steps.
- Closing the incident when service resumes rather than after root-cause remediation.
Frequently asked questions
Does CERT-In apply when the breach is at a vendor?
CERT-In FAQ states reporting obligations can still apply when an entity’s data is affected in a third party’s systems.
Can later information be added?
Yes. CERT-In FAQ allows available information first and additional information later.
What contract term matters most?
Operationally prompt incident notice plus evidence/log cooperation, not just liability language.
Official sources
- Indian Computer Emergency Response Team (CERT-In) - Directions under section 70B on cyber security practices and incident reporting (No. 20(3)/2022-CERT-In; 28 Apr 2022; current direction)
- Indian Computer Emergency Response Team (CERT-In) - FAQs on Cyber Security Directions of 28.04.2022 (CERT-In FAQ; May 2022)
- Ministry of Electronics and Information Technology - Digital Personal Data Protection Rules, 2025 (G.S.R. 846(E); published 13/14 Nov 2025; phased commencement)
- Press Information Bureau / MeitY - DPDP phased implementation and transition guidance (PIB release; 12 Dec 2025)
Disclaimer
Educational and professional reference only; confirm the current law, rates and the facts of your case before relying on this page.