Summary
This post explains the vendor-breach notification chain under the Alabama Data Breach Notification Act of 2018 and the Florida Information Protection Act, then walks through four common gaps in vendor contracts (notice deadlines, information-sharing requirements, cost allocation, and multi-state compliance) that determine how prepared a business actually is when a vendor reports a breach.
By: Jordan Gerheim, CEO – Outside Chief Legal LLC
When a vendor experiences a data breach, the company that needs to communicate with your customers is often not the vendor. It is your business.
That is the practical reality under both the Alabama Data Breach Notification Act of 2018 and the Florida Information Protection Act. A third-party agent that experiences a breach generally must notify the business it serves. The business, often called the covered entity, may then have the responsibility to assess the incident, notify affected individuals, and, when required, notify the appropriate state agency.
You may have outsourced payment processing, customer relationship management, email marketing, payroll, scheduling, bookkeeping, cloud storage, or another business function. You have not necessarily outsourced the responsibility to respond when customer information is compromised.
The issue is not whether the vendor has a breach-response plan. The issue is whether your business has enough information, enough time, and the right contract terms to meet its own obligations when the vendor calls.
Who must notify whom?
The basic structure in Alabama and Florida is similar.
When a third-party agent experiences a breach involving information it maintains on behalf of a business, the third-party agent must notify the covered entity. In Alabama, the notice must be given as expeditiously as possible and without unreasonable delay, and no later than 10 days after the vendor determines that a breach occurred or has reason to believe that one occurred. Alabama also requires the vendor to cooperate with the covered entity and provide information in its possession that will help the covered entity meet its notification obligations.
Florida imposes a similar requirement. A third-party agent must notify the covered entity as expeditiously as practicable and no later than 10 days after determining that a breach occurred or that there is reason to believe a breach occurred.
Neither statute automatically places the vendor in front of your customers. The business that owns the customer relationship must be prepared to take the lead in determining the scope of the incident and whether notice is required.
In Alabama, a covered entity must notify affected individuals when it determines that a breach is reasonably likely to cause substantial harm to the individuals whose sensitive personally identifying information was involved. The notice must be provided as expeditiously as possible and without unreasonable delay, generally within 45 days after the entity receives notice from a third-party agent or makes its own qualifying determination. If more than 1,000 individuals must be notified, the Alabama Attorney General must also receive written notice within the same 45-day period.
In Florida, a covered entity must generally provide notice to affected individuals as expeditiously as practicable and no later than 30 days after determining that a breach occurred or that there is reason to believe one occurred. If 500 or more Florida residents are affected, the business must also notify the Florida Department of Legal Affairs within the same 30-day period.
For a business with customers in both Alabama and Florida, a single vendor incident can create multiple compliance obligations at once. Florida’s 30-day deadline may become the practical response deadline, but the business still needs to assess each state’s requirements separately.
Florida also has meaningful consequences for failing to provide required notice. The statute provides for escalating civil penalties, with a maximum penalty of $500,000 for a violation related to a single breach.
Gap 1: The contract does not set a workable notice deadline
Many standard vendor agreements are vague about breach notification. Some say nothing at all. Others require notice “promptly” or “within a reasonable time,” which may sound protective but does not give the business a clear timeline to rely on during an incident.
A vendor may have up to 10 days under Alabama or Florida law before it must notify the business. That period can consume a substantial portion of the time available for a coordinated response, particularly if Florida residents are affected.
A better vendor agreement sets a specific, short notification deadline that gives the business meaningful working time to investigate, make decisions, and prepare any required notices. It should also define the event that triggers the vendor’s duty to report. A contract that allows the vendor to wait until it completes an internal investigation may leave the business without the information it needs until valuable time has passed.
The contract should require notice when the vendor discovers, suspects, or reasonably believes that a security incident may have occurred. It can also recognize that preliminary facts may change as the investigation develops. The business does not need every answer immediately, but it does need to know there is a potential problem.
Gap 2: The contract does not require the information you need
Receiving notice that a vendor had “an incident” is not enough.
To evaluate whether notification is required, a business may need to know which individuals were affected, what categories of information were involved, when the incident occurred, how the information was accessed, whether the information was acquired, and what steps the vendor has taken to contain the issue.
That information often sits with the vendor.
Alabama recognizes this practical problem. The statute requires a third-party agent, in cooperation with the covered entity, to provide information in its possession so the covered entity can comply with its notice obligations.
That statutory obligation is helpful, but it is not a substitute for a detailed contract provision. A business should know what information the vendor must provide, how quickly it must be delivered, who will serve as the vendor’s point of contact, and how updates will be communicated while the investigation is ongoing.
Without those details, the business may be trying to determine who was affected and what to tell them while negotiating with the vendor about access to its own incident information.
Gap 3: No one has agreed who pays
Data-breach response can be expensive.
Depending on the incident, costs may include forensic investigation, legal counsel, notification printing and mailing, call-center services, credit or identity monitoring, public-relations support, customer communications, and internal time spent responding to the event.
Many vendor agreements do not address those costs directly. Others include a liability cap tied to the fees paid under the agreement. For a low-cost software provider or service vendor, that cap may be substantially lower than the cost of responding to a significant breach.
An indemnity provision may appear helpful, but its value depends on the exact language of the agreement, the scope of the indemnity, the applicable liability cap, available insurance coverage, and the facts of the incident. Those provisions should be reviewed before a breach occurs, not after the business is already facing a notification deadline.
Gap 4: The agreement does not address multi-state compliance
For Gulf Coast businesses, this is not an academic concern.
A business based in Alabama may serve Florida customers. A Florida business may have customers, employees, or vendors in Alabama. A single incident involving one vendor can therefore trigger obligations in more than one state.
The notification rules generally follow the location of the affected individuals, not simply the location of the business or the vendor. That means a company may need to work through different deadlines, notice requirements, regulatory notifications, and exceptions at the same time.
A well-drafted vendor agreement should require the vendor to cooperate with the business’s notification obligations in each state where affected individuals reside. It should require timely information, regular updates, appropriate documentation, and support for the business’s response on the shortest applicable timeline.
That does not replace a legal analysis after an incident. It does reduce the likelihood that the business and the vendor will spend the first week of a breach arguing about who has to do what.
Cybersecurity Awareness Month is a good time to review vendor contracts
October often brings reminders about passwords, phishing awareness, and employee training. Those are important subjects, and an IT provider may be best positioned to lead that part of the conversation.
There is also a legal and business exercise that can be completed without turning the month into a major project.
Review the agreements for vendors that maintain, store, or process customer information. Consider your payment processor, CRM platform, email provider, payroll company, bookkeeping service, scheduling platform, cloud-storage provider, and other technology vendors.
For each agreement, ask four questions.
How quickly must the vendor notify your business of a suspected or confirmed breach? What information must the vendor provide, in what format, and on what timeline? Who is responsible for the costs associated with the incident and any required notifications? Does the agreement require the vendor to support the business’s compliance obligations wherever affected individuals live?
If the agreement does not answer one of those questions, that is useful information. You do not have to renegotiate every agreement immediately. You do need to understand the gap before the vendor calls.
Frequently asked questions
If my vendor is breached, will the vendor notify my customers?
Generally, the vendor’s initial notification obligation runs to the business it serves, not directly to that business’s customers. Under Alabama and Florida law, a third-party agent that experiences a breach must notify the covered entity. The covered entity then evaluates the incident and determines whether notice to affected individuals and state authorities is required.
How long does a vendor have to notify my business?
Alabama and Florida both require a third-party agent to notify the covered entity as quickly as possible and no later than 10 days after the vendor determines that a breach occurred or has reason to believe that one occurred.
How long does my business have to notify affected individuals?
In Alabama, a covered entity generally has up to 45 days after receiving notice from a third-party agent or making its own qualifying determination. Notice is required when the business determines that the breach is reasonably likely to cause substantial harm to the affected individuals.
In Florida, a covered entity generally has up to 30 days after determining that a breach occurred or that there is reason to believe a breach occurred.
Can the vendor handle customer notifications for my business?
Alabama expressly permits a covered entity and third-party agent to enter into a contract under which the agent agrees to handle notifications required under the Act.
That can be a useful arrangement, but it should be addressed carefully in the contract. The business still needs to manage the customer relationship, understand the incident, confirm that notifications are accurate and timely, and protect its own legal and business interests.
Does this apply to small businesses?
Potentially, yes. Alabama’s definition of a covered entity is broad and includes individuals, sole proprietorships, partnerships, corporations, nonprofits, and other business entities that acquire or use sensitive personally identifying information. The analysis generally depends on the type of information involved, the individuals affected, and the circumstances of the breach, not simply on the number of employees.
Review the agreement before the incident
If you are not sure what your vendor contracts say about a data breach, that is a finite issue to identify now. It is much easier to review the notice, cooperation, indemnity, and multi-state compliance provisions before a vendor calls with an incident.
Schedule a Risk-Free Strategy Session with Outside Chief Legal to discuss the agreements that involve your customer information and the practical steps that can help your business prepare.
This article provides general information only and is not legal advice.
Our Corporate/Business Counsel Services
Outside Chief Legal LLC is a modern, forward-thinking law firm serving as fractional chief legal officers and outside general counsel for businesses and their owners. With over 200 years of combined litigation, in-house, general counsel, and administrative legal experience, the firm delivers approachable, comprehensive counsel that blends legal expertise with practical business insight to help clients navigate ownership complexities with confidence. OCL is a trusted partner for founders, business owners, and leadership teams nationwide. Learn more about our firm, meet our team, or schedule a Risk-Free Strategy Session to talk with an attorney about how we can help your company.