It is 8.30am on a Monday when your MSP reports unusual cloud account activity. Customer records may have been accessed. Staff cannot log in. Your first question is simple: are you still on the hook if the provider caused it?
When SMEs use MSPs, breach liability is rarely automatic. Your business may still answer to customers and the ICO. The MSP may also owe contractual and UK GDPR duties. Who pays depends on roles, technical evidence, contract wording and insurance cover.
Your SME usually remains liable as controller
Your SME will usually remain the data controller. This applies if it decides why customer or staff data is used. It still applies when an MSP runs the systems that hold the data.
Controller, processor and joint controller
A processor handles personal data under the controller's instructions. An MSP may reset passwords, apply patches and host backups. That MSP is often a processor. The contract label alone does not decide the role.
| Incident fact | Likely regulatory position | Who may bear costs |
|---|
| MSP leaves an admin account exposed | SME remains controller; MSP may breach processor duties | Both, subject to the contract and insurance |
| Employee gives a password to a fake caller | SME may face a training and access-control question | Usually SME and its cyber insurer first |
| Cloud sub-processor suffers an outage | Roles depend on contracts and system control | Potential claims through MSP and cloud terms |
| MSP ignores written security instructions | Processor may be directly exposed under UK GDPR | MSP may face an indemnity or recovery claim |
Liability is not automatically joint
Joint liability with an MSP is not automatic under UK GDPR. Article 82 can make a controller liable for damage from unlawful processing. It can also make a processor liable for breaking its own duties. A processor may also be liable when acting outside lawful instructions.
The controller normally decides whether it must report a personal-data breach to the ICO within 72 hours. The 72 hours start when it becomes aware. A processor must tell the controller without undue delay. A sensible MSP contract sets a faster target, often between 2 and 4 hours.
An MSP is not always a processor simply because it manages technology. Your SME is the controller when it decides the purposes and essential means of processing. The MSP is often a processor when it follows documented instructions only.
Joint control needs a real shared decision about purposes or essential means. Routine technical choices by the MSP do not usually create joint control. This distinction can decide who must lead the ICO response.
The most common error is trusting the contract label without checking how the work actually happens.
The position becomes harder when the MSP appoints a cloud sub-processor. The DPA should name approved sub-processors. It should require advance notice of changes. It should also pass down equivalent processor duties, security measures, audit support and breach notices.
Contracts decide how MSP breach costs are shared
UK GDPR sets regulatory duties. The MSA, SLA and data processing agreement set much of the financial split. These documents decide how your SME and MSP share breach costs.
A cap does not remove ICO duties
A liability cap limits what one contract party can recover from another. It cannot stop an ICO investigation. It cannot erase a customer claim. It cannot make a reportable breach disappear.
Contract points to check before renewal
After an MSP incident: who does what?
0-4 hours
SME preserves evidence and calls insurer.
4-24 hours
MSP contains systems and exports logs.
24-72 hours
Controller assesses ICO report and affected people.
Keep one written incident record: time detected, systems affected, actions taken, advice received and decisions made.
Read MSP terms as a package. Do not rely on the MSA liability cap alone. Check the MSA, SLA incident schedule and data processing agreement together.
They should say who owns logs and who can export them. They should state who pays for forensics. They should set deadlines for preserving incident evidence. They should require help with regulator, customer and insurance enquiries.
Check whether a processor indemnity covers losses from the MSP's data protection breach. Check whether confidentiality and data protection claims sit inside the cap. Check exclusions for ransomware, supplier failure and lost profits.
These clauses shape recovery and cash flow after a breach. They do not remove regulatory duties, but they can affect recovery, cash flow and reputational harm after an SME data breach.
Within 72 hours, preserve evidence and notify
During the first 72 hours, protect evidence and contain the incident. Involve your cyber insurer before agreeing that the MSP was at fault.
The first 24 hours
Record when you found the issue and who knew about it. Isolate affected accounts or devices without wiping them. Ask the MSP to identify affected systems, privileged accounts and data stores. Ask whether an attacker still has access.
A wiped laptop can remove the clues needed to prove fault. Preserve logs before changing passwords or rebuilding systems, where it is safe to do so.
ICO reports and customer notices
The controller normally reports a notifiable breach to the ICO within 72 hours of awareness. A report is needed when the breach is likely to risk people's rights and freedoms. Risks include identity fraud, financial loss, discrimination or serious distress.
This approach does not replace legal, regulatory or insurance advice for a live incident. It may matter less when the supplier processes no personal data. It may also matter less when the supplier runs no critical systems. Contract and business-continuity duties may still apply. Escalate at once to advisers, your insurer and suitable specialists if fraud, extortion, high risk or an active breach exists.
Beyond immediate notification, prevention affects both liability and insurance cover. Cyber Essentials-aligned basics reduce the chance that an MSP setup error becomes a major incident. These basics include multi-factor authentication for administrator accounts, prompt patching and secure backups. They also include least-privilege access and tested endpoint protection.
Your SME should train staff to spot phishing and fake helpdesk calls. A stolen customer-side password can defeat well-managed infrastructure. Agree and test an SLA incident response process at least once each year.
Confirm emergency contacts and isolate a sample account. Check that logs can be kept and exported. Rehearse the decision path for a 72-hour breach report. Insurers may ask for proof of these controls during underwriting or claims.
This works well in theory, but an untested contact list often fails at 8.30am.
Questions & answers
Is my SME liable if our MSP is breached?
Yes, often. If your SME is the UK GDPR controller, it must assess the breach and protect people. It must report to the ICO within 72 hours when the risk test is met.
Can an MSP contract shift all breach liability?
No. A liability cap or indemnity can move contract costs between parties. It cannot remove the controller's UK GDPR duties or stop ICO action.
Does the MSP have to tell us about a breach?
Yes. A processor must notify its controller without undue delay under UK GDPR. Your DPA should set a clear target, such as between 2 and 4 hours after suspicion or detection.
Are ICO fines the only cost after a breach?
No. Forensics, legal advice, business interruption, customer messages and recovery work often create the larger early bill. UK GDPR fines can reach £17.5 million or 4% of annual worldwide turnover.
What cyber cover should an SME using an MSP buy?
Look for incident response, ransomware, business interruption, data recovery, third-party liability and supplier incident cover. Check whether the policy requires approved forensic firms. Check exclusions for unpatched systems or weak access controls.
Who pays first, our insurer or the MSP?
Your cyber insurer may pay covered urgent costs first, subject to policy terms and excess. Liability is then investigated. The insurer may pursue the MSP if evidence and contract terms support recovery.