6 August 2026

Your CRM Provider Has Had a Data Breach. What Should Museums Do Next?


By Jess Pembroke, Director of Information Law Services

Many people working in the museum and heritage sector will have seen the recent cyber security incident affecting Client Relationship Manager (CRM) provider Beacon[1]. When a supplier experiences a security incident, the immediate reaction is often uncertainty. Museums and other cultural heritage institutions will want to know whether they need to report the incident to the Information Commissioners Office (ICO), whether they need to inform service users, and ultimately what consequences they may now face.

When a third-party supplier suffers a breach, the legal and regulatory responsibilities do not sit with the supplier alone. While every incident will differ depending on the facts, there are three areas that every museum and heritage organisation should be considering right now: understanding your role, reviewing your supplier governance, and making sure your incident response arrangements are fit for purpose.

Understand Your Role

A misconception can be that where a supplier breach is responsible for a breach, that responsibility rests solely with the supplier. In most cases, museums and heritage organisations will be acting as the data controller, while the CRM provider acts as the data processor. That distinction is important because data controllers remain responsible for the personal data they collect and use, even when it is processed by a third party on their behalf.

This means museums and other heritage organisations need to assess the risks arising from the incident and determine whether any action is required. In practice, that assessment should include whether:

  • the incident poses a risk to the rights and freedoms of individuals;
  • the threshold for reporting to the ICO has been met;
  • affected individuals need to be informed; and
  • the organisation can evidence how each decision was reached.

Importantly, those decisions need to be documented. Even if an organisation concludes that notification is not required, it should still be able to demonstrate how it reached that decision.

One of the first questions senior leaders often ask is whether their organisation could be fined. The answer is that it depends. Regulators will typically look at the whole picture and will want to understand what due diligence was undertaken before appointing the supplier, whether appropriate contractual arrangements were in place, what security assurances were obtained, and how the organisation responded once it became aware of the incident.

Another concern is whether affected individuals could bring claims against their organisation. Again, the answer is potentially yes. Data subjects may seek compensation if they believe they have suffered financial loss, distress or other harm because of their personal data being compromised. Whether those claims ultimately succeed will depend on the specific circumstances, but museums should recognise that this may be a consequence even where a third-party is the subject of a breach. Reputational damage, complaints, media attention and civil claims can all form part of the wider impact.

For that reason, each organisation should ensure that they retain evidence of supplier selection processes, security reviews, contract negotiations, data processing agreements and decisions made during the breach response. Good record keeping can become one of the strongest forms of protection when questions are asked later.

Look Beyond This Incident

While it is easy to focus on the breach itself, incidents like this often expose weaknesses in wider supplier management arrangements.

A useful starting point is asking how you found out about the incident. Were you informed directly by the supplier? Did you learn about it through sector networks, social media or industry contacts? The answer can reveal a great deal about how effectively communication arrangements are working.

This is also an opportunity to review your organisation’s understanding of its supply chain. Many organisations have an incomplete picture of the third parties processing personal data on their behalf. Over time, systems are procured by different teams, contracts are renewed automatically, and records become outdated. When a significant breach occurs, organisations sometimes discover they cannot easily identify what data was shared with a supplier, who approved its use, or what contractual protections are in place.

As part of any supplier review, organisations should check whether they have:

  • an accurate and up-to-date record of suppliers;
  • a clear understanding of what categories of personal data each supplier processes;
  • regular due diligence checks in place;
  • current contracts and data processing agreements;
  • clear security requirements, audit rights and breach notification obligations; and
  • agreed responsibilities for what happens after an incident.

Make Sure Leadership Is Engaged

A supplier breach should not be treated as a purely technical issue. Where personal data is involved, it can create legal, regulatory, financial and reputational risks.

Senior leaders should be informed early, even before all the facts are known, so they understand the potential impact, the decisions needed and the actions being taken.

As part of the response, leadership should be clear on:

  • the likely impact on the organisation and affected individuals;
  • the reasons for key decisions, especially where notification is not required; and
  • how the organisation will respond if trustees, staff, donors, members, regulators or the media ask questions.

Prepare for the Next Incident

No organisation can eliminate cyber risk entirely. Even suppliers with sophisticated security programmes and substantial investment in cyber security can experience incidents. What organisations can control is how prepared they are when something goes wrong.

An effective incident response plan should clearly identify who needs to be involved, who is responsible for making decisions, how incidents will be assessed, how communications will be managed and how actions will be documented. It should also consider external support requirements, including legal, privacy and cyber security expertise.

Further Support

The recent Beacon incident is a reminder that outsourcing data processing does not outsource accountability. Organisations remain responsible for understanding the risks associated with their suppliers, ensuring appropriate safeguards are in place and responding effectively when incidents occur.

Rather than asking whether this is the supplier’s problem or the organisation’s problem, leaders should recognise that the answer is often both. The more important question is whether the organisation can demonstrate that it selected its suppliers carefully, governed them appropriately and responded responsibly when things went wrong.

If your organisation would like practical support in reviewing its breach response arrangements, strengthening supplier oversight or accessing expert advice when incidents arise, our Outsourced DPO or Consultancy services can provide ongoing, responsive support.

We also offer CPD UK accredited Data Breach training to help teams understand what to do when an incident occurs, how to assess risk, when to escalate, and how to keep clear records of the decisions made. Join our next Information Security & Data Breach Management course on 15 October, 9:30am-1pm. Book your place now via the link or contact our Operations Manager at info@naomikorn.com.


[1] Incident FAQs

Recent News

Back to News

Discover more from Naomi Korn Associates

Subscribe now to keep reading and get access to the full archive.

Continue reading