A B2B SaaS contract is not a simple software license: it is a hybrid license + service relationship governed by French/EU law and recent legislation (Data Act, SREN law). Before signing, secure your usage, data, budgets and remedies.
This 2026 guide summarizes the clauses and safeguards to require, with official references (Legifrance, EUR‑Lex, CNIL) and practical negotiation advice.
1) Precisely define the subject matter and scope of use
Internal-use, non-exclusive and non-transferable license
The contract must grant clear usage rights: non-exclusive, non-assignable, limited to your internal requirements and desired territory. Prohibit sublicensing and resale unless agreed in writing. Specify API access, environments (production/sandbox) and use by subsidiaries.
Features, modules, limitations and exclusions
Detail the included modules, limitations (named users, storage capacity, API call volume, bandwidth) and expressly excluded features. Require a versioned scope matrix as an annex to avoid scope creep or retroactive billing.
Changes and non-regression
Set boundaries for updates: an indicative roadmap, maintenance of an equivalent functional level, and a non-regression commitment for essential features used in production. Provide reasonable notice of API breaking changes.
2) SLA and support: quantified, enforceable commitments
Measured, verifiable availability
A serious SLA includes monthly/annual availability (e.g. 99.9%), scheduled downtime windows, limited exclusions, UTC timestamps and an independent measurement method. Penalties must be automatic (SLA credits), with termination rights for repeated failures.
Support, response and escalation times
Document hours (24/7 or business hours), channels (ticketing, telephone), response/resolution times by severity (S1 to S4), escalation levels (N1‑N3), languages and handling of security incidents.
SLA credits: sole remedy?
Reject SLA credits as the sole remedy in all circumstances. Retain the possibility of compensation for proven damage under the Code civil (foreseeability and limits, see Code civil on Legifrance, Article 1231‑3: exception for gross negligence/willful misconduct).
3) Security, compliance and GDPR: non-negotiable
DPA (GDPR Article 28): what it must contain
If the provider processes personal data on your behalf, a DPA compliant with GDPR Article 28 is mandatory: subject matter/duration, nature/purposes, data types, categories of people, security obligations, assistance with rights requests, handling of data at the end of the contract, and subprocessor arrangements. Refer to the GDPR on EUR‑Lex and guidance from CNIL.
For more on DPA structure and technical annexes, see our dedicated guide: DPA (Data Processing Agreement): complete guide for SaaS startups.
Technical and organizational measures
Require a security annex detailing encryption at rest/in transit, key management, MFA/SSO, logging and log retention, network segmentation, backups with RPO/RTO, penetration testing, vulnerability management, secure SDLC, and an incident response plan (with notification under the GDPR and any sector-specific obligations; also see Service‑Public Pro).
Subprocessors and transfers outside the EU
Require a list of subprocessors (with advance information/objection mechanism) and safeguard all transfers outside the EEA using lawful bases and standard clauses where necessary (SCCs). See CNIL guidance and the GDPR on cnil.fr and EUR‑Lex. For transfers, our practical recommendations: Data transfers outside the EU: applying post-Schrems II SCCs.
NIS2 and DORA: are you in scope?
The cloud computing service providers and managed services fall within the scope of the NIS2 Directive (EU 2022/2555), with risk-management and incident-reporting requirements; consult the text on EUR‑Lex. If you serve financial institutions, assess DORA (EU 2022/2554) for digital operational resilience and testing, also available through EUR‑Lex.
4) Data and intellectual property
Who owns what?
The provider retains rights over the software and its documentation. The customer retains ownership of its inputs and generated data directly identifying it (reports, exports). Include a clear clause prohibiting commercial use of customer data beyond providing the service.
AI training and customer data
If the provider wants to train models on your data, require explicit opt-in, prior anonymization and an audit right. To incorporate contractual safeguards, see our template and good practice: contractual clauses on AI use. CNIL publishes useful guidance on data reuse: cnil.fr.
Portability and exit: Data Act and SREN law
Provide exit arrangements: timelines (e.g. 30–60 days), open formats (CSV, JSON, XML), integrity, migration assistance, read-only environment. The Data Act (EU Regulation 2023/2854) governs switching between data processing services (including cloud/SaaS) and the gradual reduction of exit charges until their abolition; see EUR‑Lex. In France, SREN Law no. 2024‑449 strengthens transparency and portability; text available on Legifrance and additional information on economie.gouv.fr.
5) Liability, warranties and insurance
Balanced caps and exclusions
A reasonable cap is often linked to amounts paid over 12 months (or a multiple), with certain indirect losses excluded. But the contract cannot exclude compensation for willful misconduct or gross negligence (see Code civil Article 1231‑3, Legifrance). Also check the limitation clause’s validity under Article 1170 (no undermining the essential obligation).
For more on drafting and validity, read: limitation of liability clause: drafting and validity.
IP infringement warranty
Request a warranty for third-party infringement claims, covering defense costs and remedies (license, workaround, replacement) without substantial performance degradation.
Insurance
Require a current certificate: Professional/Tech Liability and Cyber (amounts, key exclusions, maintenance of cover). A right to be informed of changes/termination is prudent.
6) Pricing, indexation and “hidden” fees
Pricing transparency and exit charges
Indexation (index, cap), installation, overage (API/storage overconsumption), training and assistance fees must be listed. switching and exit charges must follow the Data Act’s capping/abolition pathway and the enhanced transparency under SREN; see EUR‑Lex and Legifrance. Industry resources explain these issues: FIDAL, Mirabile Avocat, Village Justice.
Renewal and price changes
Define renewal (automatic or not), notice of non-renewal and conditions for price changes (notice, termination right for significant increases).
7) End of contract and operational exit
Plan your exit from the outset: annexed exit plan, timetable, contacts, migration runbook, dry runs and the right to use the service in “read-only” mode during transition. Require post-export deletion/security (traceability) and return of encryption keys.
8) “Black box” clauses to open before signing
- Audit right (security, GDPR): frequency, scope, confidentiality, remediation.
- Suspension right: strictly limited (established non-payment, serious security risks), with notice and continued access to data.
- Legal changes: a controlled contractual update mechanism.
- Improvements and feedback: ownership of suggestions, no implied assignment of customer IP.
- Customer references and logos: prior written authorization.
- Jurisdiction and applicable law: clear court jurisdiction; see our advice on the jurisdiction clause.
9) Quick pre-signature checklist
- Subject matter, modules, limitations and exclusions listed in a versioned annex.
- Usage rights: internal, non-exclusive, non-transferable, APIs included.
- Quantified SLA: availability, planned maintenance, automatic credits, termination for repeated failures.
- Support: response/resolution times by severity and escalation.
- Continuity plan: backups, RPO/RTO, tested disaster recovery plan.
- Signed GDPR Article 28 DPA, with TOMs, subprocessors and safeguarded transfers outside the EU.
- Security annex: encryption, MFA/SSO, logs, penetration tests, vulnerabilities.
- Breach notification: timing, content, contacts.
- Customer data ownership confirmed; no AI training without opt-in.
- Exit/portability: open formats, timelines, assistance, capped costs (Data Act/SREN).
- Balanced liability cap; no exclusion for willful misconduct/gross negligence.
- IP warranty and defense costs covered.
- Professional/Tech Liability and Cyber insurance: current certificates.
- Pricing: controlled indexation, listed ancillary fees, price‑hold on renewal.
- Audit and compliance (NIS2/DORA if applicable): reciprocal rights and obligations.
- Termination: grounds, notice, effects, read-only access during transition.
- Confidentiality and trade secrets: scope and duration.
- Jurisdiction/applicable law consistent with your risk exposure.
10) Useful resources for further reading
For an overview of clauses to include on the provider side, see: the essential clauses of a SaaS contract and, for commercialization, the essential clauses of SaaS terms of sale. If you are preparing a contract audit, our legal audit checklist will help organize documents and annexes.
Official legislation cited: GDPR and EU regulations available through EUR‑Lex; French framework and SREN law on Legifrance; compliance recommendations on cnil.fr and economie.gouv.fr; practical guidance on Service‑Public Pro, along with law-firm analyses: FIDAL, Mirabile Avocat, Village Justice.
Frequently asked questions
FAQ
Which clauses should be checked first in a B2B SaaS contract?
Subject matter/scope, SLA and support, security and GDPR DPA, liability/insurance, exit/portability (Data Act, SREN law), pricing/indexation and renewal.
Can a provider completely limit its liability?
No. A cap is allowed, but not an exclusion for willful misconduct/gross negligence or a clause depriving the essential obligation of substance (Code civil Articles 1231-3 and 1170).
Is a DPA mandatory for every SaaS?
As soon as it processes personal data for the customer, a DPA (GDPR Article 28) is required, with safeguards for security, subprocessors and end-of-contract handling.
How can the end of the contract and exit be secured?
An exit annex with timelines, open formats (CSV/JSON/XML), assistance, testing, capped costs and post-export deletion/security.
Are exit charges capped in 2026?
The Data Act provides for reduction and then abolition of switching charges; the SREN law strengthens transparency and portability in France.
References
Sources used
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.