Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

SaaS and Tech Contracts6 min read

SaaS contract: essential clauses to protect your online software

In 2026, a robust SaaS contract needs clauses on scope, SLAs, security, GDPR, Data Act (portability/termination) and intellectual property. Practical guide and negotiation points.

The SaaS contract is the safety belt for your online software. Hybrid by nature, it combines a right to use software with ongoing services (hosting, maintenance, support). In 2026, it must incorporate GDPR requirements, the Data Act (applicable since 12 September 2025) and a regulatory environment strengthened by the SREN law (May 2024). The aim: prevent disputes, secure data and enable frictionless provider switching.

- The contract is interpreted under general obligations law (binding force, good faith, essential clauses), including the prohibition on depriving the essential obligation of substance (art. 1103 and 1170 C. civ., Legifrance) and compensation for foreseeable damage (art. 1231-3 C. civ., Legifrance).

- Software is protected by copyright; the customer generally receives a limited, non-exclusive right of use (CPI, particularly art. L.122-6 et seq., INPI).

- Personal data compliance rests on the GDPR (Regulation 2016/679) and the controller/processor relationship (Article 28) (EUR-Lex; CNIL).

- The Data Act (Regulation (EU) 2023/2854) strengthens portability, interoperability and freedom to terminate/switch, prohibiting excessive charges and technical obstacles to changing provider (EUR-Lex).

- The SREN law (21 May 2024) forms part of the drive for secure and transparent digital services in France (Legifrance).

Essential clauses in a SaaS contract in 2026

1) Subject matter and service scope

Precisely describe features, included/excluded modules, environments (production, sandbox), usage limits (user numbers, data volume, API calls), technical prerequisites and any third-party dependencies.

  • Include: module list, indicative non-contractual roadmap, quantitative limits, supported environments, exclusions (e.g. business consulting).
  • Good practice: align this scope with your SaaS terms of sale and commercial communications.

2) Right of use and intellectual property

Grant a non-exclusive, non-assignable (except within a group or on a business transfer), non-transferable right of use for the contract term and specified territory. Prohibit reproduction, decompilation and reverse engineering outside statutory exceptions (CPI, Legifrance).

  • Add an escrow clause for critical SaaS: conditional source-code access in the event of liquidation, prolonged service cessation or material breach.
  • Specify the treatment of bespoke developments (ownership/assignment, license, reuse by the provider).

3) Acceptable use policy (AUP)

Define permitted and prohibited uses: abnormal load, unauthorized penetration testing, unlawful content, bulk messaging, bypassing security measures, account sharing. Provide a graduated suspension right for serious security risks.

4) Service levels (SLA) and maintenance

Set an availability rate (e.g. 99.9%), response and restoration times (GTR), maintenance windows and SLA credits for failures (without excluding all statutory compensation). Industry practices confirm these standards (FIDAL).

  • Avoid making SLA credits the sole and exclusive remedy for gross negligence or repeated failures (art. 1170 C. civ., Legifrance).

5) Information security

Describe technical and organizational measures: encryption at rest/in transit, access management and MFA, logging, vulnerability testing, backup/restoration plan (RPO/RTO), incident notification and, where relevant, a standard (ISO 27001, SecNumCloud as applicable). The regulatory environment raises security expectations (SREN law).

6) Personal data (GDPR DPA)

If the provider acts as processor, incorporate a data processing agreement compliant with GDPR Article 28: subject matter, duration, nature and purposes, data and data-subject categories, confidentiality obligations, security measures, compliance assistance, audits and list of subprocessors (CNIL; EUR-Lex (GDPR)).

7) International transfers and cloud

For hosting or support outside the EEA: provide transfer mechanisms (SCCs 2021/914), a transfer impact assessment (TIA) and supplementary measures (encryption, pseudonymization) in line with post-Schrems II recommendations (CNIL). For operational detail, see our guide to data transfers outside the EU.

8) Portability, exit and interoperability (Data Act)

The Data Act requires effective exit arrangements: open export formats, API documentation, transfer assistance within reasonable periods, and prohibition of excessive charges or technical barriers to changing provider from 12/09/2025 (EUR-Lex – Data Act). Sector summaries outline these new obligations for SaaS contracts (Sidely).

  • Provide an annexed exit plan: data scope, formats, APIs, timetable, responsibilities, reasonable costs, technical support, purging/deletion at the end of the contract.

9) Liability, warranties and insurance

Calibrate a compensation cap (e.g. 12 to 24 months of fees), standard exclusions (indirect losses), and carve-outs for critical breaches: privacy infringements, IP rights violations, willful misconduct/gross negligence, security failures. Respect public policy and art. 1170 C. civ. (Legifrance). For drafting technique, see our focus on the limitation of liability clause.

  • Require professional indemnity/cyber insurance with coverage levels and an annual certificate.

10) Pricing, indexation and revisions

Make costs transparent (license, additional users, storage, APIs, premium support, professional services, exit assistance). Control indexation (clear index, notice) and price changes, with a termination right for substantial increases. Transparency of terms in B2B relationships is good practice supported by the authorities (Service Public Pro; Economie.gouv.fr).

11) Term, termination and suspension

Provide termination for breach, serious security failures and convenience with reasonable notice, consistent with the Data Act’s support for freedom to switch without excessive charges (EUR-Lex – Data Act). Describe data purging/deletion and residual statutory retention.

12) Subcontractors and contractual chain

List critical subcontractors (IaaS, email, support), give information/advance notice of significant changes, and impose equivalent obligations (flow-down), particularly for GDPR and security (CNIL). For method, our advice on the subcontracting agreement will help secure the chain.

13) Applicable law, jurisdiction and dispute resolution

In B2B, a jurisdiction clause is valid; consider prior mediation and digital evidence (logs, timestamps). For signature, ensure the solutions used meet eIDAS validity requirements (Regulation 910/2014, EUR-Lex) and see our good practice on electronic signatures.

Sample clauses (practical examples)

Extract — Right of use

“The Provider grants the Customer, for the term of the Agreement and territory [•], a personal, non-exclusive and non-transferable right to access and use the Service, limited to [•] Users and [•] GB of storage. All decompilation, reverse engineering or attempted source-code access is prohibited, except for mandatory statutory exceptions.”

Extract — SLA

“The Provider commits to monthly Availability of 99.9%, excluding Maintenance Windows announced [•]. In the event of failure, the Customer receives SLA Credits under the SLA Annex. These credits do not affect the right to compensation for gross negligence, willful misconduct or a Personal Data breach.”

Extract — Exit (Data Act)

“On termination of the Agreement, the Customer may require, without excessive charges, export of all its Data in open formats [•] and provision of the documented APIs needed to transfer to another provider, within [•] days. The Provider shall supply reasonable assistance charged according to the schedule in Annex [•].”

Quick negotiation checklist

  • Scope: modules/features, usage limits, clearly listed exclusions.
  • IP: license to use, prohibitions, bespoke developments, possible escrow.
  • Security: encryption, backups, logging, incident notification, audits.
  • GDPR: Article 28 DPA, listed subprocessors, safeguarded transfers outside the EU (SCCs/TIA).
  • Data Act: exit plan, interoperability/APIs, freedom to terminate without excessive charges.
  • SLA: availability rate, restoration times, SLA credits without depriving the essential obligation of substance.
  • Liability: cap, exclusions, carve-outs (IP, GDPR, security, willful misconduct/gross negligence).
  • Pricing: transparency, controlled indexation, price changes with a termination right.

Risks of omissions

Absence of GDPR-compliant clauses exposes you to administrative penalties of up to €20 million or 4% of worldwide revenue (CNIL; EUR-Lex — GDPR). Data Act failures (portability, prohibition of excessive charges, interoperability) weaken the contract and can lead to litigation, termination and reputational harm (EUR-Lex – Data Act; FIDAL).

Quick FAQ

Does the Data Act require me to offer exit assistance free of charge?

It prohibits excessive charges and technical obstacles to switching. Reasonable assistance may be charged for if transparent and proportionate (Data Act).

Can SLA credits be the sole remedy?

Avoid making them the only remedy, especially for gross negligence, GDPR or security breaches, or the clause risks being deemed unwritten (art. 1170 C. civ., Legifrance).

Is a dedicated GDPR annex needed?

Yes. A GDPR Article 28-compliant DPA is essential, listing subprocessors, security measures and audit arrangements (CNIL).

Is there a mandatory data export format?

The Data Act requires interoperable, documented formats without prescribing a single format. Provide open formats and detailed APIs (EUR-Lex).

For more on contractual architecture (terms of use/sale, ancillary policies) and document automation, consult our dedicated guides, particularly on SaaS terms of sale.

Further reading

Related resources

Frequently asked questions

FAQ

What is a SaaS contract and why is it called hybrid?

It combines a limited right to use software (intellectual property) with ongoing services (hosting, maintenance, support), hence mixed IP/service clauses.

What clauses does the Data Act require in 2026?

Effective portability and exit, interoperability (APIs/documentation), prohibition of excessive charges and removal of technical obstacles to changing provider.

Is a GDPR DPA mandatory in a B2B SaaS contract?

Yes, where the provider processes personal data for the customer, a GDPR Article 28 agreement is required (purposes, security measures, subprocessors, audits).

How can liability be limited without invalidating the clause?

Set a proportionate cap and exclude indirect losses, but include carve-outs (IP, GDPR breach, willful misconduct/gross negligence) so as not to deprive the essential obligation of substance.

What should exit arrangements cover?

Data scope, open formats, APIs, timetable, migration support, post-contract purging/deletion and reasonable costs compliant with the Data Act.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles