Every modern SaaS relies on a chain of technical subcontractors (cloud hosting, CDN, email, monitoring, support, backups). Managed well, these dependencies accelerate innovation. Poorly defined, they expose the business to service outages, non-compliance and costly disputes. This practical guide explains how to secure your contracts in 2026 by combining GDPR (Article 28), the Data Act and contractual good practice.
1) Why subcontractors are your SaaS’s Achilles’ heel
Hosting incidents, unilateral termination by an API provider, changes in data location, insolvency of a critical provider: each link can trigger legal risks (confidentiality, availability, compliance) and business risks (SLAs, penalties, churn). Control requires clear mapping, flow-down clauses and a testable exit plan.
For an overview of cross-cutting software contract clauses, also see our summary of the essential clauses of a SaaS contract, and the dedicated focus on the data hosting clause.
2) The applicable legal framework in 2026
- GDPR — Article 28: every provider processing personal data on the customer’s behalf must be bound by a data processing agreement (DPA) containing the 8 minimum clauses (documented instructions, confidentiality, security, subprocessing, assistance with rights, DPIA assistance, breach notification, audits). Official reference: GDPR, Article 28.
- Data Act — Regulation (EU) 2023/2854: largely applicable from 12/09/2025, it provides for portability, interoperability and exit arrangements for cloud/SaaS services and regulates obstacles and switching charges. Reference: Data Act. General overview on economie.gouv.fr.
- CNIL Cloud recommendations: provider selection, data-flow analysis, allocation of responsibilities, audit clauses, location, encryption and key management: CNIL guide and resources from CNIL.
- SREN law (21 May 2024): strengthens regulation of digital businesses and user information in France; it works alongside the Data Act to secure the cloud/SaaS ecosystem. Text on Legifrance.
- Practical resources: contractual matters and business obligations on Service Public Pro and the EUR‑Lex collection.
Need a practical reminder of DPAs and their clauses? Browse our complete DPA guide.
3) Organizing the subcontracting chain: mapping and responsibility matrix
3.1 Map your dependencies
- Hosting/IaaS (region, zones, backups, encryption, KMS, HSM).
- Critical data (database, logs, analytics, email, support, backups, DRaaS).
- Sensitive functions (authentication/SSO, payment, image processing/AI, moderation, anti-fraud).
Produce a subcontractor annex to the SaaS contract listing: provider name, service, location, data categories, security measures, certifications, GDPR status (subprocessor), incident contact.
3.2 RACI matrix (who does what?)
- Responsible (operations): SaaS provider.
- Accountable (compliance): SaaS provider toward the customer.
- Consulted: DPO, CISO, architect, customer (for a major subcontractor change).
- Informed: customer for any addition/replacement of a critical subcontractor.
4) Essential clauses in your SaaS contract and DPA
4.1 Subcontractor transparency and notification
- Up-to-date subcontractor annex, accessible online (with versioning) + advance change notification (15–30 days) with a reasoned objection right.
- Flow‑down: the provider imposes equivalent obligations on every subprocessor (GDPR Article 28, security, confidentiality, incidents).
For the information/objection mechanism, draw on our recommendations in GDPR processing in SaaS.
4.2 Audit rights and alternatives
- Audit that is reasonable (15–30 days’ notice, business hours, confidentiality, no unnecessary source-code access).
- Alternatives that are proportionate: SOC 2, ISO/IEC 27001 reports, penetration-testing certificates, independent assurance letters — as recommended by CNIL.
4.3 Security and confidentiality
- Encryption at rest/in transit, key management (KMS/HSM), logging, logical data separation, hardening, least-privilege principles.
- An incident detection and notification plan (timing, minimum content, contact point, cooperation), consistent with the GDPR (Article 28 and incident notification obligations).
4.4 SLAs extending across the chain
- Availability and performance end‑to‑end (include critical third-party components), service credits, targeted exclusions.
- Recovery commitments (RTO/RPO), DRP testing, proactive communication during major incidents.
To structure realistic and enforceable commitments, follow our method in the guide SLA: legal obligations and drafting.
4.5 Exit, portability and interoperability (Data Act)
- Detailed exit plan: documented open formats, export APIs, technical assistance, timelines and responsibilities.
- Exit charges that are transparent, reasonable and non-deterrent; gradual removal of switching obstacles in accordance with the Data Act.
- Interoperability and data-schema mapping; documentation of the interop layer.
4.6 Transfers outside the EU and global chains
- Identify all exfiltration (support, logs, backups, monitoring) to third countries; establish appropriate safeguards (SCCs, encryption, transfer impact assessment).
- Inform the customer and document transfers in the DPA (see CNIL and EUR‑Lex for the applicable legal framework).
4.7 Non-blocking clause
Provide that one customer’s objection to a subcontractor does not prevent technical development of the service for all customers. Offer options: a reasonable alternative, or partial/penalty-free termination if the objection is objectively justified (a major GDPR risk that cannot be remedied).
5) Subcontractor governance and due diligence
- Approval process (security, legal, financial) with risk scoring.
- Annual review of critical providers (certifications, changes of control, incidents, location, roadmap).
- KPIs: availability measured by component, MTTR, rate of incidents attributable to third parties, notification times, compliance with the exit plan.
- Contingency plan by category (hosting, email, payment), with backup/standby providers and ready-to-use access/API sets.
6) Ready-to-use contractual checklists
6.1 Subcontractor annex (to insert in the contract)
- Role and service provided; data categories; processing regions/countries; security measures and certificates; retention period; incident contact.
- Versioned update mechanism + 15–30 days’ advance notification; objection right; possible fallback.
6.2 Audit right (balanced)
- Notice; scope limits; non-disruption; enhanced confidentiality; sharing third-party reports (SOC 2, ISO 27001); periodic testing.
6.3 Exit arrangements
- Exports in open formats; documentation; reasonable assistance; timetable; verifiable purging/deletion.
7) Sample wording (extracts)
Subcontractor notification.
The Provider shall maintain an up-to-date Annex listing its subprocessors.
Any material change shall be notified 30 (thirty) days in advance.
The Customer may raise a reasoned objection where there is a serious and established risk of GDPR non-compliance.
The Provider shall propose a reasonable alternative; failing this, the Customer may terminate only the affected functionality without penalty.
GDPR flow-down.
The Provider undertakes to impose on its subprocessors obligations equivalent to those provided
in this Agreement and the DPA compliant with GDPR Article 28, including security, confidentiality
and incident notification, and remains responsible toward the Customer.
Exit and switching (Data Act).
On termination of the Agreement, the Provider shall assist the Customer for 60 (sixty) days in exporting
the Data in open, documented formats and shall cooperate in good faith to facilitate migration, without technical obstacles
or deterrent charges, in accordance with Regulation (EU) 2023/2854.
Audit right.
Subject to 20 (twenty) business days’ notice, the Customer may audit relevant security measures once a year.
Alternatively, the Provider may supply independent audit reports (SOC 2 Type II, ISO/IEC 27001) and associated action plans.
8) Risks and responsibilities
- No DPA compliant with GDPR Article 28: exposure to administrative penalties of up to 4% of worldwide revenue.
- Strong dependency risk (vendor lock-in): high exit costs and delays if exit arrangements are not provided in accordance with the Data Act.
To secure the contractual package (terms of sale/license agreement, DPA, SLA), avoid generic templates and adopt a context-specific approach: see our advice in why to avoid a generic template.
Quick FAQ
Is the provider responsible for its subcontractors’ failures?
Yes, toward the customer, the provider remains responsible for contractual performance and its subprocessors’ GDPR compliance, except where an unlawful provision states otherwise.
Can a new subcontractor be refused?
Provide advance notification (15–30 days) + reasoned objection right. If refusal is justified, the solution is a reasonable alternative or targeted termination without penalty.
How can audit rights be reconciled with cloud providers’ confidentiality?
Draft a proportionate audit right and accept alternatives (ISO 27001, SOC 2, certificates), as recommended by CNIL.
What does the Data Act change for my SaaS?
Concrete obligations for portability, exit and removal of switching obstacles from 12/09/2025, with fee transparency and migration assistance.
Is a specific policy needed for transfers outside the EU?
Yes: flow inventory, SCCs where applicable, encryption and transfer impact assessment. Document this in your DPA and records of processing activities.
For more on B2B and B2C SaaS obligations, also consult this reminder of legal obligations.
Further reading
Related resources
- SaaS contract: essential clauses to protect your online software
- Data hosting clause in a SaaS contract: what to negotiate
- SLA (Service Level Agreement): legal obligations and how to draft it
- DPA (Data Processing Agreement): complete guide for SaaS startups
- GDPR processing in SaaS: how to draft a compliant DPA
Frequently asked questions
FAQ
Which minimum GDPR clauses must appear in a DPA with my subprocessors?
The 8 clauses of GDPR Article 28: documented instructions, confidentiality, security, subprocessing (flow-down), assistance with rights, DPIAs, breach notification, audits.
How should replacement of a critical subcontractor during the contract be governed?
Provide a versioned subcontractor annex + 15–30 days’ notification + reasoned objection right + alternative or targeted termination without penalty if a serious risk is established.
Does the Data Act apply to all SaaS by 2026?
Its main provisions (portability, exit arrangements, removal of switching obstacles) apply from 12 September 2025 to data processing services (cloud/SaaS).
Is an on-site audit of every cloud provider necessary?
No: a proportionate audit right is sufficient. Independent reports (ISO 27001, SOC 2) and third-party penetration tests can provide effective alternatives under CNIL recommendations.
What should be provided for transfers outside the EU involving a subprocessor?
Map flows, establish SCCs if necessary, encrypt and carry out a transfer impact assessment. Inform the customer and document everything in the DPA.
References
Sources used
- SREN Law no. 2024-422 of 21 May 2024
- Legifrance — official legal database
- Economie.gouv.fr — official economy ministry website
- Regulation (EU) 2016/679 (GDPR) — Article 28
- Regulation (EU) 2023/2854 (Data Act)
- EUR-Lex — European Union law portal
- Recommendations for businesses considering cloud services (CNIL)
- CNIL — official website
- Service Public Pro — official business information portal
- INPI — official industrial property institute website
- AMF — official financial markets authority website
- BPI France — official public investment bank website
Training · Audit · Support
Put what you read into practice
Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.