A supplier may suffer the breach, but its customer still needs to know what data was exposed and decide what action its own obligations require. A first-person account by Serguey Shinder shows how a supplier register full of contract and renewal details can fail at the moment that matters if it does not record what the supplier actually holds.
What happened in Serguey Shinder’s account
Shinder describes being told that a supplier’s environment had been accessed. The urgent question was what of the customer’s data the supplier held. According to his account, it took the organization twelve days to establish that. The account is an individual report, not an independently verified incident or a measure of how common these problems are. The article’s result shows “Posted on Sep 19” but no year, and it does not identify the jurisdiction or regulator involved. Read Shinder’s account.
The organization had a supplier register with 214 entries. It recorded contract value, an owner, renewal date, service description, and whether an assurance questionnaire was on file. It did not record the categories or approximate volume of data processed, retention, or processing location. Those omissions left the customer trying to reconstruct its exposure after the supplier’s incident.
Contract language did not describe practice
Shinder says the contract referred to “claim documentation.” In practice, operational staff attached scanned identity documents through a general portal field. The contracted retention period was two years, while the supplier reportedly held the data for nine. A subprocessor appeared only in an annex. These details are the author’s account and have not been independently corroborated.
#1 Best Overall
The response exposed a supplier-lifecycle problem
Shinder says notification to affected people was delayed because the organization could not describe its own exposure, not simply because the breach occurred. Afterward, the team expanded its supplier records to include data categories, approximate volume, retention, subprocessors, and processing locations, and reviewed suppliers in order of sensitivity. He reports that the work took a contractor four months and found six suppliers still holding data for services that had ended, including one since 2021. These are figures from this account alone.
Why a supplier breach still creates work for the customer
The supplier may control the affected systems and initial forensic evidence, but the customer needs to map those findings to its own people, data, services, and responsibilities. That is difficult if procurement records describe a vendor commercially but not the processing relationship operationally.
A useful supplier record should help answer, quickly and with a named owner:
- What categories of personal or business data does the supplier receive or generate?
- Whose data is involved, and roughly how much is processed?
- For what service and purpose is it used, and where is it processed or stored?
- How long is it retained, and how is deletion or return confirmed when the service ends?
- Which subprocessors can access it, and where do they process it?
- Who must be contacted after an incident, through which channel, and within what agreed time?
- What incident information, records, or audit access can the customer obtain?
These are practical inventory questions, not a universal statutory field list. Their value is that they connect the contract to how the service is actually used. Shinder’s example of identity documents entered in a general portal field illustrates why a short service description may not reveal the data involved.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #3
What UK GDPR guidance says about breach timing
The article does not say which law applied. The following timing rules are specifically from UK ICO guidance for UK GDPR-covered processing, not a conclusion about Shinder’s incident or a universal rule for every jurisdiction.
- A processor must notify the controller without undue delay after becoming aware of a personal data breach.
- A controller must notify the ICO without undue delay and no later than 72 hours after becoming aware if the breach is notifiable.
- The ICO says notification is not required when a breach is unlikely to result in a risk to people’s rights and freedoms. The controller should be able to justify and document that decision.
The 72-hour period is tied to the controller’s awareness and applies to notifiable breaches; it is not a blanket deadline for every incident or a deadline established for the unidentified incident in Shinder’s account. See the ICO personal data breach guide and its processor guidance.
Rank #4
What to put in supplier contracts and response arrangements
For UK GDPR-covered processing, ICO contract guidance says a processor contract should identify the subject matter and duration of processing, its nature and purpose, the types of personal data, and categories of data subjects. It also requires provisions covering documented instructions, confidentiality, security, authorised subprocessors under written contracts, assistance with breach obligations, deletion or return of data at contract end, and audit or inspection. The ICO contracts guidance sets out these requirements.
Contract language needs an operational counterpart. The ICO’s third-party arrangements guidance recommends specifying breach-reporting timescales, communication channels, and nominated contacts. In practice, the customer should know how to reach the right person at any hour relevant to the service and what information the supplier can provide as an investigation develops. The guidance page says it is under review following the Data (Use and Access) Act; check current ICO material and the applicable law before relying on it.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsBest Value
How to make the supplier inventory useful before an incident
- Start at procurement. Record the data and processing purpose before signing, not only the commercial owner, cost, renewal date, and service label. Ask operational teams what they will actually upload, enter, or expose through the service.
- Map suppliers by sensitivity. Identify which vendors handle the most sensitive categories or largest volumes, then prioritize review accordingly. This is the order Shinder says his organization used; it is a practical approach, not a statutory ranking method.
- Reconcile contract terms with use. Check whether actual data types, retention, locations, and subprocessors match the documented arrangement. Resolve broad descriptions such as “claim documentation” into meaningful categories.
- Track the full lifecycle. Give someone responsibility for checking retention and confirming return or deletion when a service ends. Shinder’s account of data remaining with suppliers after services ceased shows why contract-end controls need follow-through.
- Rehearse the evidence gap. Run a scenario in which the supplier controls the affected environment and the customer has no direct logs or forensic access. Test whether the team can identify affected data, reach contacts, obtain incident information, and make decisions on the required timeline.
What the account does—and does not—establish
The article is useful as a concrete example of a mismatch between supplier oversight records and the information needed for incident response. It does not independently establish that the described incident, figures, or unnamed organization have been verified; nor does it identify the applicable regulator or law. Its numbers should be read as Shinder’s account, not as prevalence statistics. The UK ICO material provides a separate regulatory reference point, with jurisdictional and currency limits of its own.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

