Legal & CompliancePublished on · 3 min read· Author: WSV Redaktion· Reviewed on

Who Is Liable for Data Loss in a Business?

Who bears responsibility when company data is lost - the business itself, the IT service provider, or an employee? An overview of the key liability questions.

Cover image: Who Is Liable for Data Loss in a Business?

When a business loses data, the first question is rarely technical - it's legal: who is responsible? The answer doesn't depend on who "clicked last," but on the cause, the contractual arrangements, the protective measures in place, and the type of data affected.

The basic rule: the business is responsible

First and foremost, the business itself is obligated. Anyone processing and storing data must implement appropriate technical and organizational measures - including working backups, clear responsibilities, access controls, current security updates, and a documented emergency plan. How far this duty of care extends for management depends on the size of the business and the sensitivity of the data processed - a trade business is held to different standards than a company processing health or financial data.

When is the IT service provider liable?

An external IT service provider is liable when they breach contractually agreed obligations or clearly deviate from recognized security standards - for example, if contractually promised backups didn't actually run or were grossly misconfigured. What matters is always proof of a specific breach of duty that actually caused the damage: not every technical fault automatically triggers liability. Clear contractual service descriptions (what gets backed up? how often? how is restoration tested?) are therefore in both parties' interest.

Employee liability

For simple mistakes made during normal work duties - an accidentally deleted folder, a misconfigured backup target - employees generally aren't liable for the full amount. The business usually bears the cost as an operational risk. In cases of gross negligence, a partial cost contribution may apply; full personal liability is realistically only expected for intentional misconduct. That's an argument for securing responsibility structurally (permissions, a four-eyes principle for critical actions) rather than relying on individuals after the fact.

Special case: personal data

If personal data is lost - such as customer or HR records - additional GDPR obligations apply. A notifiable incident must generally be reported to the competent supervisory authority within 72 hours of becoming aware of it (Art. 33 GDPR), and to the affected individuals themselves if there is a high risk to them (Art. 34 GDPR). Affected individuals may also claim compensation. These deadlines apply regardless of whether the data loss occurred internally or at a contracted service provider - the business remains the responsible party for reporting.

Reducing risk in practice

The most effective way to avoid liability is to prevent the incident in the first place:

  • Automated, regularly tested backups instead of manual one-off actions (see our 3-2-1 backup strategy).
  • Clear roles and access rights, so it's traceable what happened if something goes wrong.
  • Current security updates, to avoid technical causes of data loss in the first place.
  • Documented emergency processes, so everyone involved knows what to do if it counts.
  • Clearly worded contracts with IT service providers that clearly define scope and responsibilities.

Checklist

  • Is the backup demonstrably working - verified through real restore tests?
  • Are responsibilities for backup and recovery clearly defined?
  • Are contracts with IT service providers clear on scope and liability?
  • Is there a documented process for reporting incidents involving personal data?
  • Is an emergency plan in place and known to those responsible?

Conclusion

Liability for data loss is rarely a matter of chance - it's a matter of preparation: working backups, clear responsibilities, and solid contracts significantly reduce the risk, and are the best evidence in an emergency that a business met its duty of care. Our Online Backup and an IT Emergency Plan provide the technical foundation for that. This overview doesn't replace legal advice for specific liability questions - but get in touch via our contact page for the technical side.

Sources

WhatsApp (External link)Request adviceGet support

Get in touch

Privacy settings

We use cookies and other technologies on our website. Some of them are essential, while others help us improve this website and your experience. Personal data may be processed (e.g. IP addresses), for example for personalized ads and content or ad and content measurement.

There is no obligation to consent to the processing of your data in order to use this offer. You can withdraw or adjust your selection at any time under settings. Please note that due to individual settings, not all functions of the website may be available.

We use technically necessary storage for operating this website. Optional services (statistics, marketing, external media) are only loaded after your consent.

Privacy settings