The same software, two legal regimes. For SaaS, terms of use and terms of sale must be tailored according to whether you sell to businesses (B2B) or consumers (B2C). In B2C, the Code de la consommation requires a high level of protection (pre-contractual information, withdrawal rights, unfair terms), whereas in B2B contractual freedom prevails, subject to specific rules in the Code de commerce. From 2025, the European Data Act further strengthens portability and switching for cloud/SaaS services.
This guide summarizes the differences and clauses to adapt, and provides actionable checklists with official references (Legifrance, EUR‑Lex, CNIL).
B2B vs B2C: overview of the legal framework
B2C: enhanced protections (France/EU)
- Pre-contractual information that is complete, clear and understandable before the order (seller identity, essential characteristics, VAT-inclusive price, termination conditions, compatibility, etc.), in accordance with the EU framework for distance selling and e-commerce (official Youreurope website).
- 14-day right of withdrawal for distance contracts, subject to an exception where digital content/services are supplied immediately following express consent and waiver of the withdrawal period: see the Code de la consommation (right of withdrawal) and Directive 2011/83/EU.
- Statutory conformity guarantees for digital services and the obligation to provide updates needed to maintain conformity (EU law on digital content and services, available on EUR‑Lex).
- Unfair terms are prohibited, with DGCCRF oversight: see resources from économie.gouv.fr and Service-Public Pro.
B2B: contractual freedom, transparency and negotiation
- Terms of sale provided to any business buyer who requests them: sale conditions, price schedules, discounts and payment terms (Article L441‑1 of the Code de commerce).
- Negotiable clauses (liability, SLA, security, support, exit/portability), provided they do not create a significant imbalance or contravene public policy. B2C rules on withdrawal and unfair terms do not apply to business customers.
Clauses that must be adapted between B2B and B2C
1) Pre-contractual information and contract formation
- B2C: display all key information before payment (VAT-inclusive price, term, renewal, termination arrangements, technical compatibility), with a clear checkout process and double-click confirmation. Refer to the EU distance-selling framework (Youreurope).
- B2B: formalize offers in an order form + Master SaaS Agreement. Your legal obligations for SaaS terms of sale remain central (prices, discounts, payment).
2) Right of withdrawal (B2C only) and immediate commencement
For consumer SaaS, provide:
- A checkbox stating “I request immediate performance and waive my right of withdrawal”, with confirmation on a durable medium (email). Legal basis: Code de la consommation and Directive 2011/83/EU.
- A process for pro-rata calculations/refunds if performance has not begun.
In B2B, there is no right of withdrawal. Provide a trial period and a clear contractual cancellation policy.
3) Limitation of liability and warranties
- B2C: consumers must not be deprived of their statutory guarantees; take particular care with blanket exclusions of liability (risk of unfair terms; see économie.gouv.fr).
- B2B: caps (e.g. total fees for the previous 12 months), exclusions of indirect loss, and carve‑outs typically covering bodily injury, gross negligence/willful misconduct, infringement, confidentiality/data. See the practices described in our SaaS license agreement guide.
4) Personal data (GDPR) and DPA
- Roles: the customer is often the controller and the SaaS provider the processor. A detailed DPA is essential (purposes, security, subprocessors, transfers outside the EU). References: CNIL. For practical implementation, follow our method for a GDPR-compliant DPA.
- B2C: granular lawful basis and consent for marketing/trackers, clear notices and opt‑in settings (see CNIL recommendations).
- B2B: focus on security (encryption, logging), audit rights and incident notification.
5) Non-personal data, portability and the Data Act (EU 2023/2854)
The Data Act requires providers of data processing services (cloud/SaaS) to facilitate switching: removing contractual/technical obstacles, documented export formats and a progressive reduction in exit charges, according to the timetable in the regulation (see EUR‑Lex — Regulation (EU) 2023/2854). Plan now for:
- An exit/portability policy (scope, timelines, assistance, transitional costs, open formats/APIs).
- Data mapping (personal vs non-personal) and tested export procedures.
- Switching clauses consistent with your SLAs and security.
6) SLA, support and maintenance
- B2B: define measurable SLAs (uptime, RTO/RPO, response times), service credits and planned exclusions. See our guide to drafting suitable SLAs.
- B2C: simpler commitments (best efforts), without depriving consumers of statutory rights. Avoid service credits that a consumer cannot understand.
7) Security, access and accessibility
- B2B: SSO/SAML, MFA, environment segmentation, administrator policies and audit logs.
- B2C: accessibility requirements for public-facing interfaces under the European Accessibility Act (applicable from 2025, see EUR‑Lex). Document your by design measures.
8) Pricing, billing and renewal
- B2C: prices including VAT and the total amount payable before confirmation, clear statements on renewal and duration (Youreurope). Enhanced transparency (see économie.gouv.fr).
- B2B: payment terms and discounts in the terms of sale (Article L441‑1), early-payment discounts, late-payment penalties, recovery charges.
9) Termination and exit/portability
- B2C: a simple, accessible termination process, with confirmation on a durable medium (reference: Service‑Public Pro).
- B2B: termination for convenience with notice, termination grounds (breach, insolvency), exit assistance, consistent with the Data Act’s switching policy (EUR‑Lex). For contractual practice, see what to check before signing a B2B SaaS contract.
Common borderline cases (and mistakes to avoid)
- Consumer-facing freemium: if individuals can subscribe, provide a B2C journey (information, withdrawal, accessibility). Identify status (business/consumer) at signup and display the appropriate terms of use.
- SaaS with third-party content/publishing: if you host and moderate public content, assess the scope of the Digital Services Act (transparency and moderation; consult EUR‑Lex). Many purely collaborative B2B SaaS services remain outside the DSA definition of an “online platform”.
- Data transfers outside the EU: put SCCs in place and assess risks; official resources on cnil.fr. Avoid stating “mandatory EU location” if it is not legally required; instead specify your hosting regions and transfer mechanisms.
2026 update action plan
- Classify user journeys: map your channels (public website, trial, self‑serve, assisted sales). If a journey is open to individuals, automatically activate B2C terms of use/sale.
- Revise the documentation: separate B2B and B2C terms of use/sale, a clear SaaS license agreement, DPA, SLA, privacy policy, cookies (see CNIL).
- Prepare for the Data Act: add a switching clause (export formats, APIs, timetable, transitional costs), a tested exit/portability procedure, and continuity indicators during migration (EUR‑Lex – Data Act).
- Security and accessibility: MFA/SSO (B2B), role-based access control, EAA accessibility for public-facing B2C (EUR‑Lex).
- Internal training: sales, support, product and legal teams; B2B/B2C clause matrices, compliant sales scripts, termination and withdrawal playbooks.
- Annual review: monitor CNIL, Legifrance and EU updates (Legifrance, EUR‑Lex).
Recommended contractual architecture
- B2B journey: Order Form + MSA/B2B terms of sale + SLA + DPA + Security Policy + Exit/Portability Policy (Data Act).
- B2C journey: B2C terms of use/sale readable before payment + withdrawal/waiver module + legal notices + privacy/cookie policy compliant with CNIL.
Risks of non-compliance
- B2C: DGCCRF inspections, fines and clauses deemed unwritten (see économie.gouv.fr and Service‑Public Pro).
- Data Act: obligations applicable from 2025; non-compliance = unlawful practices (references: EUR‑Lex).
- GDPR: CNIL sanctions for failures in transparency/consent/security (CNIL).
Further reading
Related resources
- Terms of sale for a SaaS startup: what the law requires in 2026
- SaaS license agreement: 2026 template and legal points to watch
- SLA (Service Level Agreement): legal obligations and how to draft it
- DPA (Data Processing Agreement): complete guide for SaaS startups
- B2B SaaS contract: what you absolutely must check before signing
Frequently asked questions
FAQ
What are the 3 priority adaptations for B2C?
1) Clear, complete pre-contractual information before payment. 2) A 14-day withdrawal module with the possibility of an explicit waiver for immediate performance. 3) No unfair terms and respect for statutory guarantees.
Does the right of withdrawal apply in B2B?
No. The 14-day right of withdrawal is a consumer right for distance contracts. In B2B, provide a contractual trial period and cancellation arrangements instead.
How should I prepare my SaaS for the Data Act?
Draft a switching and exit/portability policy (export formats, APIs, timelines, assistance), reduce contractual lock-in and test exports under real conditions. Align your terms of use/sale with these commitments.
How does liability differ between B2B and B2C?
B2C: no removal of statutory guarantees, and care over unfair blanket exclusions. B2B: liability caps and exclusions of indirect loss are permitted if reasonable and negotiated.
Does the GDPR differ between B2B and B2C?
GDPR principles apply in both cases. In B2C, strengthen transparency and consent management. In B2B, focus on the DPA, security (MFA/SSO) and audit rights.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.