We run a Germany-based e-commerce site doing wholesale and retail. Last week our site was breached in a cyberattack and names, addresses, and email details of roughly 4,500 customers were stolen from the database. We had a digital agency build the site two years ago, and we've been paying them 350 EUR a month for server hosting and general technical support.
Once things blew up, we contacted the agency but they're blaming the hosting company and an outdated plugin on the site. Our maintenance contract has a vague clause like "security patches included," but no detailed SLA is laid out. Now customer complaints are rolling in, and a potential fine is looming.
In a breach like this who is legally considered responsible in the eyes of the data protection authority? Can we seek recourse from the agency or does the entire bill fall squarely on us as the site owner?