Regulated Customer Contract Checker
Every agreement type · Channel and partner

Distribution agreement

A distributor buys and resells in a territory; the regimes of that territory's end customers reach the supplier through it.

How the register reads it

Also calleddistributor agreement
FamilyChannel and partner
Normally carriesAn audit right, a liability cap, auto-renewal.
ICT service arrangementNo: the DORA and CPS 230 terms and the security schedule are not expected of it.

What each customer's regimes expect of it

six customers, personal data named

On a register, the regimes are pulled on by the customer's sector and country; the terms are the checklist boxes the row is read against. Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

With an EU bankPulled on: GDPR, DORA, ISO 27001, ISO 27701.
Expected on the row: breach clock.
GDPR Art. 33 · DORA Art. 19 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.3.12
With a UK insurerPulled on: UK GDPR, ISO 27001, ISO 27701.
Expected on the row: breach clock.
UK GDPR Arts. 24 to 43 · GDPR Art. 33 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.3.12
With a US hospitalPulled on: HIPAA, ISO 27001, ISO 27701.
Expected on the row: breach clock.
HIPAA 164.308(a)(6)(ii) · HIPAA 164.314(a)(2)(i) · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.3.12
With a California retailerPulled on: CCPA, ISO 27001, ISO 27701.
Expected on the row: breach clock.
CCPA §1798.150 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.3.12
With an Australian superannuation fundPulled on: CPS 230, CPS 234, ISO 27001, ISO 27701.
Expected on the row: breach clock.
CPS 230 P33 · CPS 230 P42 · CPS 234 para 35 · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.3.12
With an EU energy utilityPulled on: GDPR, NIS2, ISO 27001, ISO 27701.
Expected on the row: breach clock.
GDPR Art. 33 · NIS2 Art. 23(1) · NIS2 Art. 23(4)(a) · NIS2 Art. 23(4)(b) · ISO 27001 A.5.24 · ISO 27001 A.5.31 · ISO 27001 A.5.34 · ISO 27701 A.3.12

The clauses, quoted

16 across the six customers
CCPA §1798.150 Private Right of Action for Data Breaches

A consumer whose nonencrypted and nonredacted PI (or email address with password/security question allowing account access) is subject to unauthorized access and exfiltration, theft, or disclosure as a result of the business's violation of duty to implement and maintain reasonable security may bring a civil action for statutory damages of USD 100 to 750 per consumer per inciden...

Evidence an auditor accepts: Reasonable security program documentation (encryption, access control, monitoring); Incident response plan including 30-day cure handling; Breach notification procedure
Where it usually falls short: Encryption not applied to sensitive elements
CCPA/CPRA and its regulations in The Art of Service standards library
CPS 230 P33 APRA Notification of Operational Risk Incidents within 72 Hours

The entity must notify APRA as soon as possible and no later than 72 hours after becoming aware of an operational risk incident it determines is likely to have a material financial impact or a material impact on its ability to maintain critical operations.

Evidence an auditor accepts: Notification records with awareness and submission timestamps; Materiality determination criteria and decision records; Escalation path from the incident register to the notification decision
Where it usually falls short: Clock started at incident classification rather than awareness
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 230 P42 APRA Notification of Disruption Outside Tolerance within 24 Hours

The entity must notify APRA as soon as possible and no later than 24 hours after suffering a disruption to a critical operation outside tolerance, covering the nature of the disruption, the action taken, the likely impact on business operations and the timeframe for returning to normal operations.

Evidence an auditor accepts: Notification records with disruption and submission timestamps; Evidence the notification covered all four required content elements; Tolerance breach detection records feeding the notification
Where it usually falls short: Tolerance breach detected late so the 24 hour clock is missed
APRA CPS 230 Operational Risk Management in The Art of Service standards library
CPS 234 para 35 APRA Notification of Material Incidents within 72 Hours

APRA must be notified as soon as possible and no later than 72 hours after the entity becomes aware of an incident that materially affected or could have materially affected the entity or its customers, or that has been notified to another regulator in any jurisdiction.

Evidence an auditor accepts: Notification records with awareness and submission timestamps; Materiality assessment criteria and decision records; Register of notifications made to other regulators
Where it usually falls short: Clock started at incident confirmation rather than awareness
APRA CPS 234 Information Security in The Art of Service standards library
DORA Art. 19 Reporting of major ICT-related incidents

Financial entities shall report major ICT-related incidents to the relevant competent authority within the prescribed timelines using initial, intermediate and final notifications, and may notify significant cyber threats on a voluntary basis.

Evidence an auditor accepts: Major-incident reports (initial/intermediate/final) submitted to the competent authority within the deadlines
Where it usually falls short: Late or missing major-incident reporting
DORA (Regulation (EU) 2022/2554) in The Art of Service standards library
GDPR Art. 33 Notification of a personal data breach to the supervisory authority

On becoming aware of a personal data breach, notify it to the competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; a notification made later than 72 hours must be accompanied by the reasons for the delay. A processor ...

Evidence an auditor accepts: The internal breach register covering all breaches including those assessed as not notifiable, with the risk assessment recorded for each; The awareness timestamp per incident and the basis for it, since the 72 hours runs from awareness and not from confirmation or containment; Notifications as submitted, checked against the four content elements Article 33(3) requires
Where it usually falls short: The awareness clock started at the end of the investigation rather than at the point of reasonable certainty that a breach had occurred
GDPR (Regulation (EU) 2016/679) in The Art of Service standards library
HIPAA 164.308(a)(6)(ii) Response and Reporting (Required)

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

Evidence an auditor accepts: Incident ticket log; Post-incident reports; Breach risk assessments per 164.402
Where it usually falls short: Incident closure without root cause
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(i) Business Associate Contract Required Provisions

The contract between a covered entity and a business associate must provide that the business associate will comply with the applicable Security Rule requirements, ensure subcontractors comply, report security incidents including breaches, and authorize termination by the covered entity if the business associate violates a material term.

Evidence an auditor accepts: BAA template with required clauses traceable to 164.314(a)(2)(i); Incident reporting requirements and SLAs; Subcontractor flow-down clause
Where it usually falls short: Incident reporting SLA missing or longer than reasonable
HIPAA Security Rule in The Art of Service standards library
ISO 27001 A.5.24 Information security incident management planning and preparation

Define incident roles, processes and readiness before an incident happens.

Evidence an auditor accepts: Incident response plan; Role assignment matrix; Training and awareness records
Where it usually falls short: roles are defined but not formally assigned or approved
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.31 Legal, statutory, regulatory and contractual requirements

Identify, document and keep current the legal and contractual obligations relevant to security, and your approach to meeting them.

Evidence an auditor accepts: Legal register; Contractual obligations; Regulatory filing records
Where it usually falls short: outdated legal register
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27001 A.5.34 Privacy and protection of personal identifiable information (PII)

Identify and meet privacy and PII-protection requirements from law, regulation and contract.

Evidence an auditor accepts: Privacy policy; Data inventory; Processing agreements
Where it usually falls short: Missing documented consent for all data subjects
ISO/IEC 27001:2022 in The Art of Service standards library
ISO 27701 A.3.12 Response to information security incidents

For a PII controller, an incident that involves PII shall trigger a review to determine whether a breach involving PII requiring a response has occurred, an event alone not necessarily triggering it; when a breach has occurred the response shall include the relevant notifications and records, jurisdictions defining when the supervisory authority and PII principals must be notif...

Evidence an auditor accepts: Breach determination records for incidents involving PII; Breach register carrying every field the standard names; Notifications made to authorities, PII principals or customers with timing against the legal limit
Where it usually falls short: Incidents closed as security events with no PII breach determination
ISO/IEC 27701:2025 in The Art of Service standards library
NIS2 Art. 23(1) Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients

The core reporting duty attaches to any incident with a significant impact on the provision of the entity's services. Article 23(3) fixes the threshold: an incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity, or if it has affected or is capable of affecting other natural or legal person...

Evidence an auditor accepts: The documented significance test, expressed against the Article 23(3) limbs including capable of causing; The determination record for each candidate incident, including reasoned decisions not to report; Notifications as submitted, with timestamps, and the identity of the receiving CSIRT or authority
Where it usually falls short: Threshold applied only to realised impact, so contained incidents capable of severe disruption go unreported
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(4)(a) Submit an early warning within 24 hours of becoming aware of a significant incident

The first stage of the layered reporting regime falls due without undue delay and in any event within 24 hours of becoming aware of the significant incident. The early warning is deliberately light: where applicable it indicates whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact. It is not a full assess...

Evidence an auditor accepts: The definition of becoming aware and the evidence trail that fixes that moment per incident; Submitted early warnings with timestamps, measured against the 24-hour limit; Out-of-hours submission capability, including named authorised submitters and their credentials
Where it usually falls short: Awareness treated as the moment of executive briefing rather than of qualified detection
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(4)(b) Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise

Within 72 hours of becoming aware, the entity updates the early warning and provides an initial assessment of the significant incident covering its severity and impact, together with indicators of compromise where those are available. The 72 hours runs from awareness, not from the early warning, so the two clocks start together. Trust service providers are held to a shorter dea...

Evidence an auditor accepts: Submitted notifications with timestamps measured from the awareness moment; The initial severity and impact assessment as submitted, and the basis for it; Indicators of compromise shared, and the telemetry and tooling they were derived from
Where it usually falls short: 72 hours counted from the early warning rather than from awareness
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
UK GDPR Arts. 24 to 43 Controller and Processor (Articles 24-43)

Per UK GDPR Articles 24-43: controller + processor + DPO + RoPA + DPIA + Privacy by Design + Records + breach notification.

Evidence an auditor accepts: UK GDPR evidence for UKGDPRREG-3
Where it usually falls short: DPO + DPIA + ICO partial
UK GDPR (summary of the articles held) in The Art of Service standards library

Read every agreement on your list

Paste the list of customer agreements and each one comes back with the regimes its customer pulls on, the terms ticked or open, the clock, the audit right and the renewal. Eight agreements free, no account.

Check my contract list

Tender and bid terms · Marketplace listing terms