Data Indemnity from the Provider

Provider shall defend and indemnify Customer and Customer’s Indemnified Associates against any “Indemnified Claim,” meaning any third party claim, suit, or proceeding arising out of a Data Incident (as defined below) resulting primarily from Provider’s breach of Section __ (Data Management & Security) or Provider’s violation of Privacy/Security Law (as defined below), including without limitation breaches and violations committed by or through Provider’s agents or subcontractors. Indemnified Claims include, without limitation, government enforcement actions. (A “Data Incident” is any unauthorized disclosure of, access to, or use of Customer Data processed or otherwise stored on computers or other media operated or otherwise controlled by Provider or its agents or subcontractors. “Privacy/Security Law” means applicable law governing the protection, security, or management of personal information, including without limitation the following statutes: _________.)

• • •

Provider shall defend and indemnify Customer and Customer’s Indemnified Associates against any third party claim, suit, or proceeding arising out of or related to a Data Incident (as defined below) caused by the act or omission of Provider or any of its agents, subcontractors, or employees (an “Indemnified Claim”). Indemnified Claims include, without limitation, government enforcement actions. (A “Data Incident” is any unauthorized disclosure of, access to, or use of Customer Data.)