Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

SaaS and Tech Contracts6 min read

Data hosting clause in a SaaS contract: what to negotiate

EU location, GDPR DPA, security, sub-processors, transfers, SLA and exit arrangements (Data Act). The 2026 guide to negotiating a SaaS hosting clause.

In a SaaS contract, the data hosting clause is one of the few tools that lets you address compliance (GDPR), sovereignty (data residency), operational security (backups and disaster recovery/business continuity) and service exit (exit arrangements/portability) together. In 2026, it must incorporate the GDPR, the Data Act (EU 2023/2854) and, in France, take account of the national framework strengthened by the loi SREN n° 2024‑449. Here is a practical method for negotiating without blind spots.

1) Why the hosting clause is strategic in 2026

  • Extraterritoriality risk: hosting outside the EU may expose your data to foreign laws (such as the CLOUD Act), complicating compliance with articles 44 to 50 GDPR on international transfers (GDPR).
  • Exit and portability: the Data Act requires genuine switching capabilities between cloud/SaaS services and limits undue switching charges (EU 2023/2854).
  • Security requirements: encryption, backups, traceability and audits. The CNIL has published useful recommendations for purchasing cloud services (CNIL — Cloud recommendations).
  • Legal responsibilities: precise classification of roles (controller/processor) and a GDPR data processing agreement compliant with art. 28.

GDPR: art. 28 (processing) and 44‑50 (transfers)

The GDPR requires a Data Processing Agreement (DPA) detailing documented instructions, security measures and processor management, together with safeguards for any transfer outside the EU (GDPR). The CNIL also sets out good practices for selecting and monitoring cloud providers (CNIL).

Data Act (EU 2023/2854)

Applicable to data processing services (cloud/SaaS), it requires the absence of obstacles to switching, transfer assistance, open formats and proportionate, non-abusive switching charges, with a reduction path provided by the Regulation (EUR‑Lex).

Loi SREN (France)

Loi n° 2024‑449 du 21 mai 2024 strengthens France’s digital security and regulation framework. Without replacing the GDPR or Data Act, it complements the national ecosystem and may affect hosting and cloud providers’ obligations. Refer to the text on Legifrance.

Useful guides and guidance

3) The 10 points to negotiate in the hosting clause

1. Data location, residency and sovereignty

  • 100% EU location: production, backups and disaster recovery in the EU/EEA. No replication outside the EU without prior written agreement.
  • Change of location: prior notification (60 days) and a right to terminate without charges if hosting moves outside the EU.
  • Access by foreign authorities: commitment to inform and challenge any illegitimate request, to the extent permitted by law.

2. Role classification and art. 28 GDPR DPA

  • Controller/Processor: specify roles and attach a complete DPA (instructions, confidentiality, security, assistance with GDPR rights and deletion). See our DPA guide for SaaS.
  • Assistance: provider support deadline for rights requests (e.g. 5 working days).

3. Sub-processors and the hosting chain

  • Named list of sub-processors (IaaS/PaaS, support, emailing and monitoring) and prior customer authorisation for any significant addition/replacement.
  • Back‑to‑back: impose equivalent obligations on sub-processors (security, location, audit and incident notification).

4. Technical and organisational security

  • Encryption in transit (TLS 1.2+) and at rest (AES‑256), key management (EU KMS, BYOK option).
  • Multi-tenant segmentation, IAM access control, MFA, timestamped logging and log retention.
  • Hardening, security patches, vulnerability scans and regular penetration tests by an independent third party.
  • Certifications/audits: ISO 27001/SOC 2 and, for health data, HDS (health data hosting) in France. Refer to CNIL recommendations (CNIL – Cloud).

5. Backups and disaster recovery/business continuity

  • Backups: frequency (e.g. daily), encrypted, tested (quarterly restores), retention (e.g. 30/90 days), always in the EU.
  • Disaster recovery/business continuity: define RTO/RPO (e.g. RTO 4 h, RPO 15 min) and an EU recovery site. Annual recovery-test reports.

6. Transfers outside the EU: if unavoidable

  • Legal basis compliant with GDPR art. 44‑50 and Standard Contractual Clauses where applicable. See our guide to applying post-Schrems II SCCs.
  • Transfer Impact Assessment documented and updated, with supplementary measures (encryption and minimisation).

7. Breach notification and incident management

  • Deadlines: notification to the customer without undue delay and no later than 24 business hours after discovery, to enable GDPR notification to the authority within 72 h (CNIL).
  • Content: nature of the incident, affected data, measures taken, action plan and contact point.

8. Audit rights and compliance evidence

  • Third-party reports (ISO/SOC), summaries of pen‑tests, evidence of disaster-recovery tests and security board reports.
  • On-site/remote audit 1×/year with reasonable notice, without access to other customers’ secrets.

9. Traceability, support access and confidentiality

  • Administrator/support access logs, justified, temporary access (break‑glass), retained traceability (e.g. 12 months).
  • No use of customer data for AI training without express consent.

10. Exit arrangements, portability and deletion (Data Act)

  • Full export of data and metadata in open formats (e.g. CSV/JSON/Parquet + schemas), with documentation.
  • Assistance with transfer to another service, without abusive charges, in accordance with the Data Act (EUR‑Lex).
  • Execution deadline (e.g. ≤ 30 days) and a deletion certificate at the end of the exit process.

4) Contract wording: examples to adapt

Location and transfers
“Customer Data (including backups and disaster recovery) is hosted exclusively within the European Union.
No transfer outside the EU/EEA will take place without the Customer’s prior written agreement and the implementation of safeguards
compliant with art. 44 to 50 GDPR. Any location change is notified 60 days in advance; the Customer may terminate
without charges if hosting moves outside the EU.”

Sub-processors
“The Provider maintains an up-to-date named list of its sub-processors. Any significant addition, replacement or removal
is notified 30 days in advance and subject to the Customer’s prior written authorisation. The Provider contractually imposes
obligations equivalent to these provisions on its sub-processors.”

Security and disaster recovery/business continuity
“The Provider applies state-of-the-art security measures (ISO 27001 or equivalent), encryption in transit
and at rest, daily backups tested quarterly, and a disaster recovery plan guaranteeing RTO 4 h / RPO 15 min.
Recovery-test reports are provided annually.”

Exit arrangements (Data Act)
“On first request or at contract end, the Provider supplies, without abusive charges, a complete export of Customer Data
and metadata in documented open formats and reasonable assistance with transfer to the service designated by the
Customer, within a maximum of 30 days, and then provides a deletion certificate.”

Pair the hosting clause with measurable SLAs: availability (e.g. ≥ 99.9%), correction times (P1/P2), RTO/RPO, incident-notification deadlines and support-access activation times. To frame the whole arrangement, see our guide to SLAs for cloud/SaaS services.

6) Sensitive sectors: health, critical data and public sector

  • Health: require HDS for any health data hosting in France, and enhanced traceability (healthcare professional access, consultations).
  • Critical data: stronger requirements (BYOK/EU KMS, dual access control and long-term logging).
  • Public tenders: specify EU residency and Data Act-compliant exit arrangements from the tender stage.

7) Due diligence: evidence to require before signing

  • Map sub-processors, data flow and locations (production / backups / disaster recovery).
  • ISO/SOC audit extracts, pen‑tests, incident-response plan and disaster-recovery test reports.
  • Example of a complete export (data + schemas) and documented exit procedure.
  • DPA template and clauses for transfers outside the EU. For an overview, revisit our B2B SaaS contract review checklist.

8) Common pitfalls and negotiating points

  • Unclear location: lock production + backups + disaster recovery into the EU, with an exit right if this changes.
  • Illusory portability: test the export before signing, list formats, require assistance and a deadline.
  • Disproportionate switching charges: invoke the Data Act and negotiate a capped time & material fee schedule.
  • Ineffective audit: provide standardised evidence (ISO/SOC and summaries) + annual audit on notice.
  • Limitation of liability: exclude/qualify the cap for data breaches and unlawful transfers.

In the event of persistent disagreement or a need to exit, organise contract termination in line with our advice on terminating a SaaS contract.

Useful cited references

Further reading

Related resources

Frequently asked questions

FAQ

Should I require 100% EU hosting?

Yes, this is the best option to avoid GDPR transfers (art. 44‑50) and reduce exposure to extraterritorial laws. Include production, backups and disaster recovery, plus an exit right if this changes.

The provider uses a US hyperscaler: is that a deal-breaker?

No, if hosting is in the EU and transfers outside the EU are avoided. Otherwise, require SCCs, a TIA, strong encryption with EU KMS and a robust DPA. Watch for support access from outside the EU.

Who pays for exit arrangements at contract end?

The Data Act requires switching assistance and prohibits abusive charges. Negotiate a capped time-based fee schedule, open formats and an execution deadline (e.g. 30 days).

Should HDS certification be required for all health data?

Yes, whenever health data is hosted in France. Also ask for enhanced traceability, restricted access and regular recovery tests.

Can the customer’s audit right be limited?

Yes, by structuring it through ISO/SOC reports, penetration-test summaries and reasonable audits on notice. Avoid removing it: it is a standard expected under GDPR art. 28.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles