Cyberattack on Your SaaS Vendor: Who Is Liable Between Controller and Processor After a GDPR Breach?
The Renault Commercial Roumanie case shows that a breach coming from the vendor stack does not end with “the supplier made a mistake”. The Romanian DPA looked at both the actual security of the processing and the choice of the processor. In this guide, I explain who is liable, what obligations arise before the incident, how to manage the first 24–72 hours, when to notify the Romanian DPA, when to inform data subjects, and what the SaaS vendor contract must contain.
