Establish what of yours was involved, assess whether it creates real risk of harm, and decide about notifying people. Accountability stays with you even though the failure was theirs.

Accountability does not transfer

The point that surprises people during the incident rather than before it.

When you give customer information to a service to process on your behalf, the responsibility for that information generally remains yours.

Your customers gave their details to you. They have not heard of the booking platform, the mailing service, or the invoicing tool, and it is not their job to.

Which means the response is yours to run, the communication is yours to make, and the argument with the supplier happens separately and afterwards.

This is a general description rather than legal advice. Breach obligations, thresholds, and reporting timeframes differ by jurisdiction and sector, and a serious incident is the point to get proper advice quickly.

Establish what of yours was in it

Before doing anything else, and it is harder than it sounds.

Supplier notifications are frequently vague, describing an incident affecting some customers without saying whether you are one.

Ask directly, in writing: was our account affected, which of our records were involved, which fields, over what period, and what is your evidence.

Then check your own side: what did you actually store there, which is often more than anybody remembers, particularly in free-text notes fields.

Until you know which people and which fields, you cannot assess anything, and acting on an assumption in either direction is how this goes wrong.

What to ask them

Ask in writing and keep the replies, because your own assessment has to be based on something and their initial account frequently changes.

Assess the actual risk

The judgement that drives everything else.

Email addresses and names exposed together is unpleasant and rarely creates significant risk of harm on its own.

Addresses combined with dates of birth, financial details, health information, or passwords are a different matter.

The questions worth asking are what somebody could do with this combination, who is likely to be affected, and how badly.

Most jurisdictions frame the notification threshold around real risk of significant harm, so this assessment is the thing that determines whether you tell people and whether you report it.

Write down your reasoning at the time, whichever way you decide, because a documented assessment is what you would rely on later.

Telling your customers

If the assessment says you should, do it properly rather than minimally.

Say what happened in plain terms, what information of theirs was involved, what the practical risk is, what you have done, and what they should do.

Do not lead with the supplier's name as an explanation of why it was not your fault, because the customer's relationship is with you and that framing reads badly.

Give them something actionable: change a password if one was involved, watch for messages claiming to be from you, and a route to ask questions.

Send it directly rather than posting a notice and hoping, and expect a small number of replies, most of which will be reasonable.

A worked example

A firm was told by a booking provider that a subset of accounts had been exposed.

The notice did not say whether theirs was one, so they asked in writing and received confirmation two days later that it was, covering names, email addresses, phone numbers, and appointment dates over an eleven-month period.

No financial information and no passwords.

They assessed the risk as low but not negligible, mainly because appointment dates combined with names could support a convincing impersonation of their business.

They emailed everyone affected, explained what was involved, and warned specifically that anybody contacting them claiming to be the firm and asking for payment should be treated with suspicion.

Two customers replied to say they had received exactly such a message the following week, which the warning had caused them to ignore.

The warning had been the useful part of the whole response.

Expect the follow-on attempt

Worth planning for, because it is the most likely actual harm.

Information from a breach is frequently used to make contact look legitimate: a message referencing a real appointment, a real invoice number, or a real job.

Your customers are the target and your business name is the disguise.

Which is why the customer notice should say plainly how you will and will not contact them, particularly regarding payment, and should repeat that in the following weeks.

Telling your own staff to expect it matters too, since the same information supports convincing messages in the other direction.

Afterwards, with the supplier

The commercial half, handled separately from the incident.

Read what your agreement says about security obligations, breach notification timeframes, and liability, which is frequently the first time anybody has looked.

Assess how they behaved: how quickly they told you, how straight the account was, and whether it changed.

That behaviour is better evidence about the relationship than the breach itself, since any provider can be compromised and not all of them handle it honestly.

Decide whether to continue, and if you do, tighten what you store there and what the agreement says. If you leave, take your data out properly rather than abandoning the account.

The counter-case

Over-reacting has costs too.

Notifying every customer about every incident, including those creating no realistic risk, produces alarm, damages confidence, and makes the notice that genuinely matters less likely to be read.

The threshold exists for a reason, and a documented decision not to notify is a legitimate outcome when the assessment supports it.

There is also a limit to what a small business can demand of a large provider, whose terms are not negotiable and who will not answer detailed questions from a small account.

In that situation, do what you can: establish what you stored, assess it, act on your own judgement, and document that you did.

What to do

  1. Ask in writing whether your data specifically was involved.
  2. Check what you actually stored there.
  3. Assess the risk of real harm, and write down why.
  4. Decide about notifying, people and any regulator.
  5. Warn about impersonation specifically.
  6. Say how you will never contact them about payment.
  7. Review the agreement and their conduct afterwards.

Step five is the item that prevents the actual harm, and it is the one most notices leave out.

Messages that impersonate a supplier are covered in the email that looks like your supplier.


Frequently asked questions

Whose responsibility is it if my supplier is breached?

Generally yours. Your customers gave their details to you and have not heard of the booking platform. The response and the communication are yours; the argument with the supplier happens afterwards.

What should I ask the supplier?

In writing: whether your account specifically was affected, which fields and how many records, over what period, whether data was accessed or only exposed, and what they have told regulators.

How do I decide whether to notify customers?

Assess whether the combination of information creates real risk of significant harm. Names and email addresses alone rarely do; add dates of birth, financial details, or passwords and it changes.

What should a customer notice say?

What happened, what of theirs was involved, the practical risk, what you have done, and what they should do. Do not lead with the supplier's name as an excuse.

What is the most likely actual harm?

Impersonation. Breached information makes contact look legitimate by referencing a real appointment or invoice. Say plainly how you will and will not contact people about payment.

Should I notify about every incident?

No. Notifying about incidents creating no realistic risk causes alarm and makes the notice that matters less likely to be read. Document the decision either way.

West Coast Media Solutions Inc. provides web design, web development, hosting, digital marketing, and business consulting to organisations across Canada, drawing on more than twenty-five years in the field.

Supplier notice that does not say if you are affected?

Ask in writing which of your records and which fields. You cannot assess anything until you know.

Start a Conversation