forumNew topic

Customer data breached and site hacked — legally and contractually, who's responsible?

PPınar G***MemberCommunity member
Joined
Jul 2024
Message
37
#1

We run a Germany-based e-commerce site doing wholesale and retail. Last week our site was breached in a cyberattack and names, addresses, and email details of roughly 4,500 customers were stolen from the database. We had a digital agency build the site two years ago, and we've been paying them 350 EUR a month for server hosting and general technical support.

Once things blew up, we contacted the agency but they're blaming the hosting company and an outdated plugin on the site. Our maintenance contract has a vague clause like "security patches included," but no detailed SLA is laid out. Now customer complaints are rolling in, and a potential fine is looming.

In a breach like this who is legally considered responsible in the eyes of the data protection authority? Can we seek recourse from the agency or does the entire bill fall squarely on us as the site owner?

OOrhan K***MemberCommunity member
Joined
May 2023
Message
83
Most Helpful#2

Short answer: In the eyes of the data protection authority and your customers, your company is the sole direct legal point of contact; since you are the data controller (Verantwortlicher), any administrative fines will be levied on you first. The agency's liability can only be pursued later through a recourse claim, depending on the Data Processing Agreement (AVV) between you and the specific obligations in your maintenance contract.

Under DSGVO Article 24, the site owner is responsible for putting technical and organizational security measures in place. You must officially notify the competent state data protection authority (Landesdatenschutzbeauftragter) within 72 hours of becoming aware of the incident, and notify the affected customers if the risk is high based on the scope of the stolen data. Missing this deadline will only multiply the fine.

Your legal dispute with the agency falls under BGB (German Civil Code) contract law. If security patches were explicitly promised in the maintenance agreement and the breach happened because the system wasn't updated against a known vulnerability, the agency could be liable for damages due to defective performance. However, agency terms and conditions (AGB) usually cap their liability. If your company carries cyber insurance, open a claim immediately, and make sure to secure all digital forensics evidence before rebuilding the server.

HHavva E***Member
Job title
Finance Manager
Sector
Electrical-electronics
Organization type
medium-sized business
Joined
Aug 2024
Message
150
#3

Instead of pointing fingers right now, take these three steps immediately: 1) If the 72-hour official notification window hasn't closed, file a preliminary breach notification with the state data protection authority. 2) Take a full server snapshot to freeze the evidence; do not do a clean reinstall just yet. 3) Consult an attorney who specializes in IT law.

KKoray C***MemberCommunity member
Joined
Oct 2022
Message
180
#4

Standard agency contracts almost always include a clause stating "the agency cannot be held liable for security vulnerabilities arising from third-party plugins." For a low fee like 350 EUR a month, there's no way they provided comprehensive vulnerability and pentesting coverage. Legal fees will likely end up higher than whatever payout you'd squeeze out of them anyway.

EEsra A***Member
Job title
Technical service technician
Sector
Healthcare services
Organization type
120-person company
Joined
Dec 2025
Message
9
#5

We went through a similar incident two years ago. We paid 4,800 EUR for incident response and a digital forensics report, and 3,200 EUR for a specialized lawyer. Because we notified on time and kept the whole process transparent, the data protection office didn't fine us, just issued a formal warning. The lawsuit we filed against the agency dragged on for 14 months and ended in a partial settlement.

CCaner G***Expert
Job title
Store associate
Sector
Livestock
Organization type
chain store
Joined
Feb 2023
Message
105
#6

You need to understand the legal distinction: In external relations (the authorities and affected individuals), you alone are responsible. In internal relations, the contract between you and the agency comes into play. If you never signed an AVV (Auftragsverarbeitungsvertrag) with them, the regulatory authority could also penalize you simply for having data processed without a contract.

FFiliz Ö***Member
Job title
System support specialist
Sector
Furniture manufacturing
Organization type
cooperative
Joined
Jan 2026
Message
88
#7

When this happened to us, the agency claimed "the server was hit with a brute force attack, our code is clean." We brought in an independent expert to investigate; turned out two-factor authentication wasn't enforced on the admin panel and a well-known form exploit had been left unpatched for 6 months. Once we dropped that report on the table, the agency's professional liability insurance covered half our damages.

TTülay K***MemberCommunity member
Joined
Mar 2023
Message
216
#8

Does your contract specify an update frequency? Like a clause saying "critical patches applied within 48 hours"? Also, were passwords and customer data in the database hashed and salted, or sitting in plain text?

HHatice Ç***MemberCommunity member
Joined
Sep 2025
Message
2
#9

claassic triangle: The agency blames the hosting provider the host blames the plugin developer and the plugin developer is nowhere to be found and meanwhile the bill always lands on the domain owner... anyway call your lawyer now, imo.

Edit: asked below, I wrote the answer in the second message.

İİbrahim T***ExpertCommunity member
Joined
Mar 2025
Message
22
#10

I agree with this. Trying to do this alone is the most expensive way.

If 2FA is on a stolen password alone is useless. Of course, it varies if your situation is different.

HHakan U***Member
Job title
Regional Manager
Sector
Sports and fitness
Organization type
40-person manufacturing company
Joined
Aug 2022
Message
13

Doki · Server maintenance contract · 2025

#11

Following.

TTuğçe E***MemberCommunity member
Joined
Sep 2022
Message
343
#12

The opposite happened to me, that's why I'm writing. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

This is my opinion, I'm not claiming it's absolute truth.

VVildan Ö***Member
Job title
Secretary
Sector
Retail
Organization type
family business
Joined
Dec 2024
Message
66
#13

looking at it as a process, the picture changes. i mean don't hesitate to ask; those who don't ask always pay more.

if you post the result here, it will help others too.

AAhmet Ç***Member
Job title
Warehouse Manager
Sector
Jewelry
Organization type
workshop
Joined
Jan 2026
Message
399
#14

i didn't know that.

FFadimeNew member
Job title
Food manufacturer
Organization type
a company within a holding
Joined
Sep 2024
Message
42
#15

Correct in theory but it doesn't work that way in practice. honestly any unwritten clause becomes a point of disagreement later, as both sides remember it differently.

Processes without records never improve because you dont know what to fix. I mean hope this helps.

LLale K***MemberCommunity member
Joined
Oct 2024
Message
253
#16

The discussion got scattered let me summarize. Security isn't absolute; it's about making attacks not worth the effort.

Hope this helps.

GGizem Y***Expert
Job title
Marketing manager
Organization type
a company within a holding
Joined
Sep 2023
Message
168
#17

Three different views emerged, they all complement each other. The answer varies greatly by industry; there is no one-size-fits-all rule.

Of course, it varies if your situation is different.

ZZehra A***ExpertCommunity member
Joined
Feb 2023
Message
5
#18

Thanks for writing this, that's the right way. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

Just leaving this note, it might be useful.

ŞŞerife Ç***MemberCommunity member
Joined
Apr 2022
Message
2
#19

I agree. Dont hesitate to ask; those who dont ask always pay more.

NNeslihan E***Member
Job title
Board member
Sector
Security services
Organization type
8-person team
Joined
Apr 2025
Message
35

Doki · Corporate website · 2023

#20

Following.

Reply