In 2026, SaaS terms of sale are no longer optional: the essential legal framework
Since the Data Act became applicable in September 2025 and the loi SREN entered into force in 2024, a SaaS startup’s terms of sale must incorporate stronger requirements on data portability, pricing transparency and security, in addition to the GDPR and, where applicable, the AI Regulation (AI Act). Otherwise, you face administrative penalties (DGCCRF) and litigation over unfair terms.
- Data Act (applicable since 09/2025): data portability, prohibition of abusive contractual lock-in, easier cloud switching, capping and then phasing out certain switching charges (EUR-Lex; implementation analysis for SaaS: MDP Data).
- Loi SREN (21 May 2024): pricing transparency obligations and measures promoting interoperability and cloud-provider switching (economie.gouv.fr).
- GDPR: if you process personal data, your terms of sale (or a DPA schedule) must specify roles, purposes, data types, security measures and processing arrangements (CNIL).
- AI Act: if your SaaS incorporates AI, transparency and documentation obligations apply according to the risk level (EUR-Lex).
- Pre-contractual information and online terms of sale: mandatory particulars for selling digital services, consumer withdrawal rights and rules for concluding contracts remotely (Service Public Pro).
In B2B, communicating your terms of sale is also governed by the Code de commerce (art. L441-1) (Legifrance).
Particulars and clauses now essential in your SaaS terms of sale
1) Purpose, scope and conditions of use
- Define the service precisely (modules, API, storage, volume/user limits).
- Specify exclusions (beta versions, sandbox environments and third-party integrations).
- Regulate permitted use (licence, compliance with laws, technical prohibitions and fair use).
For more on drafting functional clauses in practice, see our guide to the SaaS contract and essential clauses.
2) Price, billing, indexation and changes
- Clearly display the price (excluding/including VAT according to the audience), billing frequency and additional charges (e.g. excess usage, migrations and premium support).
- Terms for indexation and adjustment of prices (reference index and notice).
- In B2C, stronger transparency and information on the right of withdrawal (or its exception for digital services begun with express agreement), according to Service Public Pro.
3) Service levels (SLA), maintenance and support
- Targets for availability (% uptime per month), maintenance windows and service credits.
- Support (hours, channels and response times) and incident handling.
4) Security, confidentiality and GDPR
Beyond a general clause, provide a Security Schedule describing technical and organisational measures (encryption at rest/in transit, access management, logging, backups, disaster recovery/business continuity plans and penetration tests). The CNIL sets out security and processor-governance requirements (CNIL).
If you act as a processor under the GDPR, your data processing agreement (DPA) must comply with art. 28 (roles, purposes, categories of data and individuals, duration, security measures, use of sub-processors, assistance and breach notification, data return/deletion). Attach it to the terms of sale. For transfers outside the EU, mention the use of SCCs and your safeguards (see our guide to data transfers outside the EU and post-Schrems II SCCs).
5) Portability, exit arrangements and Data Act
- Provide a documented exit process: structured, commonly used and interoperable export formats, deadlines, assistance and deletion afterwards.
- Prohibit any clause blocking extraction or provider switching. The Data Act prohibits contractual/technical obstacles to switching and provides for a phased reduction and then elimination of certain switching charges (EUR-Lex; also see the analysis by MDP Data).
The loi SREN complements this approach by strengthening pricing transparency and interoperability in cloud services in France (economie.gouv.fr).
6) Intellectual property and content
- Reaffirm the publisher’s ownership of code and trademarks, and the licence granted to the customer.
- Regulate the licence for content uploaded by users (hosting and processing), and restrictions (unlawful content, third-party rights).
7) Liability and insurance
- Limitation of liability: reasonable caps and targeted exclusions, without depriving an essential obligation of its substance or excluding fraud/gross negligence. See our good practices for the limitation-of-liability clause.
- Usual exclusions (indirect loss of profit), force majeure, and a warranty that the service conforms to its documentation.
8) Term, termination and renewal
- Commitment periods, notice, termination for breach and effects (exit arrangements, data deletion and pro-rata billing).
- Automation and clear information on subscription renewals (enhanced B2C requirements according to Service Public Pro).
9) Changes to the service and terms of sale
- An update process with notice, rights to refuse/terminate without abusive charges for material changes.
- Traceability of acceptance (clickwrap), retention of logs and evidential value.
For an overview of product-side operational clauses, also read our focus on essential SaaS terms-of-sale clauses.
If your SaaS incorporates AI: specific particulars in 2026
The AI Regulation imposes transparency and documentation obligations (particularly for systems presenting risks). In your terms of sale/schedules:
- Inform users of AI use in certain features, its limitations (possible errors), the datasets used and the user’s rights.
- Specify logs, risk assessments and user-feedback mechanisms.
- Regulate liability for AI-generated suggestions and appropriate exclusions.
To guide your teams, see our AI Act guide for startups and, for GDPR, our summary of GDPR and artificial intelligence. For the text and legislative monitoring, refer to EUR-Lex.
2026 SaaS terms-of-sale outline: recommended structure
- Contract purpose and definitions
- Service description (scope, SLA and support)
- Conditions of use and restrictions
- Price, billing, indexation and additional charges
- Term, renewal, termination (effects and exit arrangements)
- Intellectual property and licences
- Confidentiality, security (Security Schedule)
- Data protection (GDPR DPA Schedule)
- Portability and exit arrangements (Data Act compliant)
- Liability and warranties, insurance
- Changes to the service and terms of sale (notice and notification)
- Governing law, dispute resolution (jurisdiction clause where appropriate)
On disputes and procedural planning, see our guide to the jurisdiction clause.
A 30-day compliance method
- Map features, processed data and third-party integrations.
- Align your DPA (art. 28 GDPR) with a detailed Security Schedule (TOMs, logging and disaster recovery/business continuity plans).
- Write a exit/portability clause compliant with the Data Act (formats, deadlines, assistance and capped charges).
- Clarify prices, indexation and exit/migration charges, with SREN transparency.
- Update SLA and incident management (notification, timeframes and credits).
- Regulate AI (transparency, limitations and logs) where applicable.
- Strengthen the liability clause within legal limits and check exclusions.
- Evidence of acceptance (clickwrap), retained versions and up-to-date GDPR records.
Common mistakes and risks
- No operational exit arrangements: contrary to the Data Act and a source of exit disputes (EUR-Lex).
- Opaque switching charges or disproportionate charges: risk under the Data Act and SREN transparency requirements (economie.gouv.fr).
- Incomplete DPA (art. 28 GDPR): non-compliance and risk of supervisory authority penalties (CNIL).
- Incomplete e-commerce terms of sale (B2C): breach of information rules, withdrawal rights, etc. (Service Public Pro).
- Failure to communicate B2B terms of sale: risk of an administrative fine (art. L441‑1 C. com., Legifrance; DGCCRF enforcement on economie.gouv.fr).
For an in-depth overview of publishers’ contractual issues, also see the firm’s analysis of essential SaaS contract clauses.
Quick FAQ
Are terms of sale mandatory in B2B?
Yes: you must be able to communicate your terms of sale to any professional buyer who requests them (C. com., L441‑1). Online, publish them and obtain acceptance.
How do you draft a portability clause?
Provide for export formats, deadlines, assistance, deletion at contract end and transparent, capped charges, in compliance with the Data Act.
Can all liability be excluded?
No. Avoid clauses that empty an essential obligation of substance. Instead, provide a cap and targeted exclusions, without covering fraud or gross negligence.
To systematise compliance (versions, signatures and evidence), see our practical advice on electronic signatures and legal validity and our contract automation guide.
Further reading
Related resources
- SaaS terms of sale: essential clauses for online software
- SaaS contract: essential clauses to secure your online software
- Data transfers outside the EU: applying post-Schrems II SCCs (2026 guide)
- Limitation-of-liability clause: drafting and validity
- GDPR and artificial intelligence: legal obligations for businesses
Frequently asked questions
FAQ
Are terms of sale mandatory for B2B and B2C SaaS?
Yes. In B2B, you must communicate your terms of sale on request (C. com., L441‑1). In B2C, online selling requires published and accepted terms of sale, with pre-contractual information and properly addressed withdrawal rights.
What must a portability clause cover under the Data Act?
Structured, interoperable export formats, timetable, provider-switching assistance, deletion at contract end, and transparent/regulated switching charges compliant with the Data Act.
Is a separate data processing agreement (DPA) recommended?
Yes. The DPA (art. 28 GDPR) can be attached to the terms of sale and detail purposes, data categories, security measures, sub-processors, transfers outside the EU, breaches and exit arrangements.
Can liability be capped?
Yes, with a reasonable cap and targeted exclusions, without covering fraud/gross negligence or emptying an essential obligation of substance. Caps may be linked to amounts billed over a given period.
What particulars should I add if my SaaS incorporates AI?
Explain AI use, its limitations, documentation and risk management under the AI Act. Provide logs and reporting channels, and contractually regulate liability for AI outputs.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.