13/9/26

Cyberattack: who pays when your company falls victim to a breach at one of its suppliers?

An IT service provider is hacked. A supplier’s servers are compromised. A payroll subcontractor suffers a database breach. In each of these scenarios, it is not your information system that has been breached — it is that of a third party you work with. Yet it is your company that bears the consequences: production downtime, loss of customer data, or the obligation to notify the Data Protection Authority of a personal data breach.

The question is therefore no longer merely technical. It is a legal one, and it arises in very concrete terms: who bears the cost of the incident, who may be held liable, and what should have been negotiated before the crisis in order to avoid suffering the consequences twice — operationally and then financially.

The contractual foundation

The first point of reference is the contract. If the supplier has breached a security obligation set out in the contract (a security clause, an obligation to apply updates, or a commitment to comply with an ISO standard or a framework issued by the Belgian Centre for Cybersecurity, its contractual liability may be engaged on the basis of Book 5 of the Belgian Civil Code (“Obligations”), which has been in force since 1 January 2023.

Two points deserve particular attention:

  • Limitation or exclusion of liability clauses: these are common in IT and cloud contracts and are generally valid between professionals — but they do not apply in cases of fraud, gross negligence, or where they deprive an essential contractual obligation of its substance. A supplier that has manifestly failed to apply known critical security patches, or that has misrepresented its level of compliance, will generally not be able to rely on a derisory liability cap.
  • Proving the breach: in practice, the difficulty is not legal but evidentiary. Without a contractual audit right, an incident reporting obligation, and traceability requirements imposed on the supplier, the victim company may find itself having to prove a breach that it does not have the technical means to identify itself.

The end of the “no cumulation” rule under Book 6

Until 31 December 2024, a well-established case-law principle — prohibiting the concurrent application of contractual and non-contractual liability — generally prevented a party, subject to limited exceptions, from bringing a claim against its contractual counterparty on a legal basis other than the contract itself. The new Book 6 of the Civil Code on non-contractual liability, which entered into force on 1 January 2025, puts an end to this rule for events occurring from that date onwards.

In practical terms, this opens an additional avenue in two situations frequently encountered in cyberattacks:

  • When the supplier’s breach constitutes both a contractual failure and an independent tort (for example, serious negligence in securing data that the contract did not explicitly cover);
  • Above all, when the vulnerability originates from a subcontractor of the supplier with whom your company has no direct contractual relationship. In this situation, a non-contractual claim remains, as before, the usual route for seeking liability from this more remote link in the chain, provided that its fault and the causal link with your loss can be established.

This is an important point to incorporate into your litigation strategy: the question is no longer simply “what does my contract with my direct supplier say?”, but rather “who, anywhere in the chain, committed a fault that caused me harm?”

GDPR: liability does not stop with the processor

If the supplier’s breach involves personal data, the GDPR adds a distinct layer of liability, independent of the contractual analysis.

Your company remains the data controller. Outsourcing hosting, payroll or CRM management to a service provider does not discharge you from your security obligation (Article 32), nor from your obligation to notify the Data Protection Authority within 72 hours (Article 33) and, where applicable, the affected individuals (Article 34). These obligations remain yours vis-à-vis the regulator and the affected individuals — even where the technical breach is entirely attributable to your processor.

The processor is not, however, off the hook. Article 82 GDPR establishes a system of joint and several liability: the injured party may bring a claim against the controller, the processor, or both, without having to determine precisely which party in the chain was at fault. The processor may only be exempted from liability if it proves that the event giving rise to the damage is in no way attributable to it — a narrow exemption, as recalled by the Court of Justice of the European Union in its NAP judgment of 14 December 2023 (C-340/21).

In practice, this means that your data processing agreement (Article 28 GDPR) is the central instrument for organizing, internally, the final allocation of the cost between you and your supplier. The joint and several liability towards affected individuals and the Authority, however, cannot be contractually altered.

NIS2: the security of your suppliers becomes a legal obligation, not merely a contractual one

Since the entry into force of the Belgian law of 26 April 2024 transposing the NIS2 Directive (18 October 2024), entities classified as “essential” or “important” by the Belgian Centre for Cybersecurity can no longer limit their security management to their own perimeter: the law expressly requires them to assess cybersecurity risks and pass on cybersecurity requirements throughout their supply chain, under threat of administrative sanctions. It also makes management bodies responsible for overseeing this risk management.

Two practical consequences arise for a customer company, whether or not it is itself subject to NIS2:

  • If your company falls within the scope of NIS2, the absence of security and audit clauses imposed on your suppliers is no longer merely a poorly negotiated contractual risk — it may constitute a regulatory breach of your own, separate from your supplier’s liability;
  • If your supplier is subject to NIS2, it must be able to demonstrate its compliance — an element that should be required contractually and that strengthens your position in the event of subsequent litigation.

In summary

A cyberattack at a supplier does not dilute your liability — it shifts and multiplies it: contractual liability towards your supplier, GDPR liability towards affected individuals and the Data Protection Authority, potential liability under NIS2 if your company or its supplier falls within its scope, and, since 2025, a broader non-contractual avenue for bringing claims against links in the chain with which you have no direct contractual relationship.

Given the complexity of these chains of liability, the Vanbelle Law Boutique team assists companies on a daily basis with the audit and renegotiation of their IT contracts, as well as with the strategic management of post-incident litigation. Do not hesitate to contact us to secure your digital ecosystem.
REach out

Since you are unique, you deserve a personal and tailor-made approach

Let's work together
Contact