A well-drafted SaaS license agreement combines a right to use the software with ongoing services (hosting, support, maintenance, security). In 2026, the agreement must incorporate the French IP framework, GDPR compliance, the new portability and interoperability obligations under the Data Act, and the transparency requirements of the SREN law.
What is a SaaS license agreement in 2026?
A SaaS license agreement grants a non-exclusive, non-transferable and limited right to use the software, while governing associated services (SLA, support, updates). Legally:
- Copyright protects the software and governs exceptions (particularly for interoperability) under the Code de la propriété intellectuelle (CPI).
- Personal data processing requires an agreement compliant with the GDPR (particularly Article 28 governing processors).
- The Data Act (EU 2023/2854), applicable from 12 September 2025, requires data portability, cloud-service interoperability and the reduction of contractual and technical obstacles to switching providers.
- The SREN Law no. 2024‑449 strengthens cost transparency and regulates lock-in practices for digital services in France.
SaaS license agreement template: recommended structure
This framework covers 95% of B2B needs, to be adapted to your product, GDPR exposure and cloud architecture.
1) Parties, definitions and contractual documents
- Full identification of the parties, document hierarchy (main agreement, technical/SLA/pricing/DPA annexes, order forms).
- Precise glossary (authorized user, Customer Data, Personal Data, Service Data, Availability, Critical Incident…).
2) Subject matter and right of use (license)
- Non-exclusive, non-assignable right of use, limited to the scope (modules, environment, user volume, territory, purposes).
- Restrictions (no reverse engineering or unauthorized access), subject to statutory interoperability exceptions under the CPI.
Reference: Code de la propriété intellectuelle.
3) Services, support and SLA
- Service levels (e.g. monthly availability, maintenance windows, restoration times), penalties or service credits.
- Support (business hours, channels, response times by severity), updates and functional enhancements.
4) Security, hosting and compliance
- Technical and organizational measures, logging, encryption, vulnerability management, recovery plan (RTO/RPO).
- Data location, list of subprocessors, security incident and personal data breach notification.
References: GDPR and recommendations from CNIL.
5) Data protection (DPA annex — GDPR Article 28)
- Roles (Controller/Processor), documented instructions, confidentiality, security, audits, subprocessors and transfers outside the EU.
- Transfer mechanisms (Standard Contractual Clauses where applicable) and records of processing activities.
References: GDPR; guidance from CNIL.
6) Data, portability and exit arrangements
- Export on first request in open, machine-readable formats, with API documentation and field mapping.
- Exit plan (duration, milestones, technical assistance), caps on and transparency of switching charges in accordance with the Data Act and SREN law.
References: Data Act ; SREN law.
7) Interoperability and APIs
- Interoperability commitments (open standards, SDK), reasonable compatibility with target solutions and stable documentation.
- Versioning policy and notice of breaking changes.
Reference: Data Act.
8) Financial terms
- Pricing model (users, consumption, tiers), indexation, revisions, billing arrangements, late-payment penalties.
- Cost transparency (storage, egress, exit assistance) in accordance with SREN.
References: SREN law; practical information from Service Public Pro and économie.gouv.fr.
9) Intellectual property and warranties
- Supplier’s retention of ownership, Customer’s license to use, rights over Customer content, and clauses on open-source components.
- IP infringement warranty for the SaaS, with workarounds or cessation-of-use mechanisms.
References: CPI; resources from INPI.
10) Confidentiality
- Definition of Confidential Information, exceptions, confidentiality period, reasonable security, return/destruction.
11) Liability and insurance
- Limitations and exclusions (indirect loss), caps (e.g. subscription amount), professional indemnity/cyber insurance obligations.
- Specific clauses for availability/SLAs and data damage (separate regime).
12) Term, termination and end of agreement
- Initial term, renewal, termination for material breach, force majeure, change of control.
- Exit procedure: timetable, assistance, post-contract deletion/security.
References: Data Act (no contractual/technical obstacles to switching).
Major legal points to watch
- Scope of the right of use: specify modules, environments, license metrics and restrictions in light of the CPI interoperability exceptions.
- Exit/portability: deliverables, open formats, timelines, assistance, API documentation and capped/transparent fees (Data Act, SREN).
- Effective interoperability: versioning policies, compatibility tests, notice of breaking changes (Data Act).
- GDPR: Article 28 DPA, subprocessor mapping, transfers outside the EU, breach notification and proportionate audits (CNIL).
- Realistic SLAs: guaranteed availability, controlled exclusions, credits/penalties and alignment with technical redundancy.
- Intellectual property: IP infringement warranty and management of open-source components; consider targeted escrow if a critical on-premises component is needed for continuity.
- Pricing changes: reasonable indexation mechanisms, caps on increases and termination rights for material changes.
- Embedded AI features: transparency on third-party model use, data flows, output rights and GDPR compliance.
For an overview of the core clauses in a SaaS agreement, see our guide to the essential clauses of a SaaS contract. If your solution uses AI models, incorporate a dedicated contractual clause on AI use.
Negotiation checklist (practical)
- GDPR roles, attached DPA and safeguards for transfers outside the EU (see our DPA guide for SaaS and guide to transfers outside the EU).
- Portability: complete export, open formats, timelines and capped fees; documented API and trial extraction tests.
- SLA: measured availability, automatic penalties, escalation process, RTO/RPO aligned with your business needs.
- IP: license to use, IP infringement warranty, open-source policy and, if required, escrow or a continuity mechanism.
- Pricing: indexation, variations, ancillary costs (storage, egress, assistance), exit rights for abnormal increases.
- Interoperability: standards, breaking-change notice, sandbox and SDK provided.
- Termination: grounds, notice, exit plan, data deletion/security and deletion certificate.
Sample clauses (template to adapt)
License to use
The Supplier grants the Customer, for the Term, a non-exclusive, non-transferable and non-sublicensable right to use the Software, strictly limited to the authorized Modules and Users, solely for the Customer’s internal requirements and in the agreed Territory. All reverse engineering, decompilation or attempted unauthorized access is prohibited, subject to mandatory interoperability exceptions under the Code de la propriété intellectuelle.
Reference: CPI.
SLA — availability and penalties
The Service targets monthly availability of 99.9%, excluding scheduled maintenance windows (notice ≥ 72 hours) and agreed grounds for exemption. If this target is not met, the Customer automatically receives a service credit under the schedule in the SLA Annex. Incidents are handled according to target times by severity (P1, P2, P3).
Exit and portability
On any expiry or termination, the Supplier shall make the Customer Data Export available within 15 business days in open, machine-readable formats, accompanied by API documentation. Migration assistance (scope and costs) is defined in the Exit Annex, in compliance with interoperability requirements and limits on obstacles to switching.
Data protection (DPA — GDPR Article 28)
The Supplier acts as Processor and processes Personal Data only on documented instructions from the Customer, as Controller. It implements appropriate security measures, notifies any breach as soon as possible and engages no Subprocessor without authorization. Transfers outside the EU rely on a valid mechanism.
Reference: GDPR.
IP and infringement warranty
The Supplier warrants that the Software, as supplied, does not infringe third-party intellectual property rights in the specified territories. In the event of a claim, it shall conduct the defense and bear any awards against the Customer, provided the Customer notifies it promptly. The Supplier may, at its option, (i) modify the Software, (ii) obtain a right of use, or (iii) terminate the license for the affected functionality with a pro-rata refund.
For more on the differences between licensing models and open-source implications, consult our dedicated article on the software license agreement (SaaS, open source, proprietary).
Penalties and risks of non-compliance
- GDPR: risk of formal notices and financial penalties from CNIL for non-compliance (e.g. no DPA, transfers without safeguards).
- Data Act: contractual disputes, injunctions and administrative penalties from the competent authorities for obstacles to switching and interoperability failures.
- SREN: oversight of lock-in practices and cost transparency, with risk of penalties for non-compliance.
Further reading
Related resources
- SaaS contract: essential clauses to protect your online software
- DPA (Data Processing Agreement): complete guide for SaaS startups
- Data transfers outside the EU: applying post-Schrems II SCCs (2026 guide)
- Software license agreements: SaaS, open source and proprietary software
- Contractual clause on AI use: template and good practice
Frequently asked questions
FAQ
Which clauses are essential in a SaaS license agreement?
Right of use, service description, SLA, security, GDPR DPA, portability/exit arrangements (Data Act), interoperability, IP/infringement warranty, confidentiality, liability, term/termination.
Does the Data Act apply to all SaaS contracts?
From 12/09/2025, it applies to many data processing services (cloud/SaaS), requiring portability, interoperability and removal of obstacles to switching providers.
How can GDPR risks in SaaS be limited?
Attach a DPA (Article 28), map subprocessors, safeguard transfers outside the EU, define security measures, provide for proportionate audits and breach notification.
Can exit assistance be charged for?
Yes, for technical assistance, if costs are transparent and proportionate and do not create lock-in contrary to the Data Act and SREN.
Is source-code escrow needed?
Optional in SaaS; useful only if an on-premises component is critical. Favor a tested continuity and exit plan.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.