Your obligations as data controller continue; recourse against the provider depends on the security and indemnity clauses in your contract. We strengthen supplier contracts based on incident scenarios.
In data-protection terms the provider is your processor, so a compliant data processing agreement is the real control: it should carry prompt breach-notification timelines, audit rights, sub-processor limits and security commitments. Recourse is only as strong as those clauses — we pressure-test them against concrete incident scenarios before signature.
Shall we apply this matter to your situation?
Tell us your specific situation in a few sentences; we'll assess it with the right team.