Back to library

Clause · data_protection_baseline

Data Protection

Data
STANDARD+
medium risk
US-IN
US-GB
US-EU
US-SG
GENERIC

Clause body

Vendor shall implement and maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Client data against unauthorized access, disclosure, alteration, and destruction. Vendor shall restrict access to Client data to personnel with a legitimate need to know in connection with the Services. Vendor shall notify Client of any confirmed unauthorized access to or disclosure of Client data without undue delay and, as a term agreed between the parties in this Statement of Work, in any event within {{BREACH_NOTIFICATION_HOURS}} hours of confirming it. This notification period is a contractual commitment agreed here; it does not state, replace, or measure any notification duty either party may separately owe a regulator or a data subject under applicable law.

Sources

NIST Cybersecurity Framework; ISO 27001

Last verified: Pending review.

Library version: 1.1.0