A SaaS contract is more than a straightforward services agreement. It involves technical issues (SLAs, interoperability, exit and migration), regulation (GDPR, Data Act, NIS2/DORA) and business terms (pricing, indexation, liability) that standard templates do not address. The result: unenforceable clauses, penalties, disputes… Here, point by point, is why a SaaS lawyer drafts a tailored agreement—and what you should require in your contracts.
7 legal reasons to abandon generic templates
1) GDPR: a detailed data processing agreement is mandatory
When your SaaS processes personal data on clients’ behalf, you are generally a processor. The GDPR requires a written contract between controller and processor, precisely governing the subject matter, duration, nature of processing, security measures, assistance, audits, management of subprocessors, etc. (art. 28 of Regulation (EU) 2016/679; CNIL guide Processor obligations). Generic templates often omit:
- the prior-authorisation procedure for subprocessors and an up-to-date list,
- a realistic audit right (scope, notice, frequency, costs),
- assistance with breach notification and DPIAs,
- mechanisms for transfers outside the EU (SCCs, TIAs),
- verifiable security levels proportionate to risk.
Without these clauses, you risk non-compliance and administrative penalties (CNIL) of up to €20 million or 4% of worldwide turnover.
2) Data Act: exit, interoperability and switching charges
The Data Act (Regulation (EU) 2023/2854) requires, from 2025, effective portability of data and switching between data processing services (including cloud/SaaS), with a progressive prohibition on abusive switching charges and technical barriers. Your contracts must provide for:
- an exit plan (open formats, documented APIs, assistance, timelines),
- reasonable interoperability commitments,
- transparency and caps on transfer-assistance costs.
The Commission describes these portability and interoperability requirements in its explanatory factsheet (Data Act explained). Generic templates include neither the timetable milestones nor the operational exit plan buyers require.
3) Security and resilience: NIS2 and DORA affect your clauses
Depending on your clients and your role in the value chain, cybersecurity obligations may fall under NIS2 (Directive (EU) 2022/2555: EUR‑Lex) or DORA for the financial sector (Regulation (EU) 2022/2554: EUR‑Lex). In practice, your contracts must specify:
- security SLAs (vulnerability management, logging, encryption),
- incident-notification deadlines and communication channels,
- audit rights and resilience-testing rights required by regulators,
- supply-chain requirements (critical suppliers, back‑to‑back clauses).
Standard templates do not anticipate these cascading regulatory requirements and prove unusable during clients’ vendor due diligence.
4) Code civil and Code de commerce: “magic” clauses are often ineffective
Under French law, a clause that deprives the debtor’s essential obligation of its substance is deemed unwritten (art. 1170 Code civil). Many templates contain a limitation of liability disconnected from the service (e.g. a derisory cap despite a 99.9% availability obligation) that does not hold up in litigation. In B2B, certain practices are also penalised for creating a significant imbalance (art. L442‑1, I, 2° Code de commerce). A lawyer aligns liability with the SLAs and price.
On these issues, also see our guide to drafting a valid limitation of liability.
5) Intellectual property and open source: clarify use and avoid licence contamination
SaaS grants a right to access and use the service, without transfer of source code or economic rights. Vague templates create ambiguity about the rights granted, IP in deliverables (connectors, scripts), or open-source compliance. Refer to INPI good practice on software protection (INPI) and contractually govern third-party components, internal/external use, restrictions and compliance audits. For an overview, read our summary of the distinction between software licensing, SaaS and open source.
6) International data transfers: SCCs and risk assessments
Any transfer outside the EU requires an appropriate mechanism (SCCs, BCRs) and an assessment of the level of protection (post-Schrems II). Your contract must provide for these obligations to flow down, appropriate Standard Contractual Clauses and provider cooperation (CNIL: transfers outside the EU). We detail the implementation of post-Schrems II standard contractual clauses and their interaction with your technical schedules.
7) Pre-contractual information, terms of sale and French compliance
In B2B, you must provide your terms of sale on request and include mandatory particulars (prices, discounts, payment terms, penalties: Service-Public Pro). The contract must remain consistent with the terms of sale/use, privacy policy and security policy. France’s recent digital-space law (SREN) strengthens transparency and regulation of digital services; for cloud services and portability, it interacts with the European Data Act. To explore local requirements, consult our legal obligations for SaaS terms of sale and the essential clauses of a SaaS contract.
Practical consequences of a generic template
- CNIL inspection: missing GDPR art. 28 clauses → formal notice, urgent corrections, penalty risk (CNIL).
- Blocked exit: client invokes the Data Act → export impossible/closed format → penalties and loss of the client (European Commission).
- Unenforceable SLAs: vague indicators, no measurement method → uncompensated outages, dispute.
- Financial-sector client: DORA requires audit and testing rights → template silent → supplier approval refused (EUR‑Lex).
- Liability clause invalidated: derisory cap versus essential obligation (art. 1170 Code civil) → uncapped liability award.
How a SaaS lawyer safeguards your contract (8-step method)
- Mapping: data processed, GDPR roles, processors, locations.
- Scope: functional description, limits, deliverables, exclusions.
- Measurable SLAs: availability, support, RTO/RPO, maintenance, service credits (metrics and evidence).
- Data Act‑ready: contractual exit plan (formats, API, deadlines, assistance, non-abusive costs), export tests.
- Security: technical/organisational measures, incident management, audits, back‑to‑back supplier terms (NIS2/DORA where applicable).
- Liability: proportionate cap, targeted exclusions, specific data/confidentiality regime; compatibility with art. 1170.
- GDPR compliance: art. 28 clauses, records, processors, transfers, SCCs and TIAs.
- Pricing and changes: indexation, fair use, excess usage, package changes; consistency with terms of sale/use.
Digital-law practitioners detail this approach (e.g. Fidal’s analysis of essential clauses and B2B obligations).
Quick checklist (adapt to your SaaS)
- Define the subject matter/duration/purposes of processing (GDPR art. 28) and security measures.
- List and govern processors (information/authorisation, replacements).
- Provide for exit and migration and interoperability (open formats, API, deadlines, assistance, costs) compliant with the Data Act.
- Draft verifiable SLAs (calculation method, evidence, remedies).
- Include incident notification, audits and NIS2/DORA requirements if your market demands them.
- Safeguard transfers outside the EU (SCCs, TIAs, cooperation).
- Adopt a defensible limitation of liability (price/SLAs/risks) compatible with art. 1170.
- Document IP and licences (use, restrictions, OSS, deliverables, audit).
- Align terms of sale/use and the contract; include mandatory B2B information (Service‑Public Pro).
- Provide for price increases (index, notice, grounds) and termination (breach, change of control, compliance).
- Organise contractual governance (committees, roadmap, service developments).
- Test exit on a data sample before signature.
Further resources from the firm
For further reading:
- Our guide to the essential clauses of a SaaS contract.
- The specific obligations for SaaS terms of sale.
- How to build a limitation of liability that stands up in court.
- Practical implementation of post-Schrems II SCCs.
- Mapping rights in software, SaaS and open source.
Quick FAQ
Can a template suffice if I am just starting out?
No, because GDPR art. 28 obligations and Data Act switching requirements apply regardless of size. Adapt at least the critical points (roles, SLAs, security, exit).
Must I always sign a DPA?
Yes, if you are a processor or your client processes data through your SaaS. The DPA (GDPR art. 28) can be a schedule to the main contract.
How should a credible liability cap be set?
It must be proportionate to price, risk and SLAs, with specific regimes (data, IP, breach of law). Avoid derisory caps.
Does the Data Act require open APIs?
It requires effective portability and “reasonable” interoperability. Specify formats, documentation and assistance; prohibit abusive switching charges.
Do NIS2/DORA concern me?
Yes, if you serve covered entities (essential/financial sectors) or clients require it contractually. Anticipate audit and incident clauses.
Useful references: GDPR · Data Act · NIS2 · DORA · CNIL: processor · B2B terms of sale.
Further reading
Related resources
- SaaS contract: essential clauses to safeguard your online software
- SaaS startup terms of sale: what the law requires in 2026
- Limitation-of-liability clause: drafting and validity
- Data transfers outside the EU: applying post-Schrems II SCCs (2026 guide)
- Software licence agreement: SaaS, open source and proprietary
Frequently asked questions
FAQ
Why is a SaaS contract template risky in France?
It often ignores GDPR requirements (art. 28), Data Act switching, NIS2/DORA constraints and results in ineffective clauses (art. 1170 C. civ., L442‑1 C. com.).
What must a Data Act-compliant exit clause contain?
Open export formats, documented APIs, extraction deadlines, reasonable assistance, cost transparency and no abusive switching charges.
How should terms of sale, terms of use and the SaaS contract fit together?
Terms of sale cover price and payment (B2B), terms of use govern service use; the main contract and its schedules (DPA, security, SLA) must remain consistent.
When am I responsible for subprocessors?
Always under the GDPR: you must govern them in writing, ensure equivalent standards and inform the client/obtain authorisation for changes.
Which legal references should be checked before signature?
GDPR (art. 28), Data Act, NIS2/DORA according to sector, Code civil (art. 1170), Code de commerce (L442‑1), transfers outside the EU (SCCs, TIAs, CNIL guidance).
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.