Let’s talk about your firm · A free 15-minute discovery call. No commitment.Prepare for my call

SaaS and Tech Contracts6 min read

Warranties and liability exclusions in a SaaS contract: drafting guide

SaaS clauses: warranties (SLAs, GDPR/NIS2 security), liability limits (caps, indirect losses), legal exceptions and templates ready to adapt.

Why these clauses are central to SaaS

In a SaaS contract, most value lies in service availability, data security and exit arrangements. Warranties and liability exclusions govern these issues, allocate risk and often determine price. Poor drafting can make them unenforceable or, worse, undermine the contract's economic balance.

Under French law, a clause cannot deprive the debtor's essential obligation of its substance (Article 1170 of the Civil Code). Liability also cannot be limited for intentional misconduct or gross negligence (Article 1231‑3 of the Civil Code). Reference: Legifrance – Civil Code. In practice, a total liability exclusion for data loss where the SaaS service's purpose is to host that data is highly likely to be deemed unwritten.

GDPR – processing agreement (Article 28)

If the provider processes personal data for the client, a Data Processing Agreement (DPA) compliant with GDPR Article 28 is mandatory. It must detail technical and organisational measures, govern subprocessing, audit cooperation and security-incident alerts so the client can notify the authority within 72 hours (GDPR Article 33). See CNIL recommendations: CNIL and the specific Cloud guide (CNIL – Cloud recommendations).

Cybersecurity – NIS2 and financial sectors (DORA)

Depending on your position, you may be directly or indirectly affected by:

  • The NIS2 Directive (EU) 2022/2555, requiring risk management measures and incident notifications for essential/important entities (digital service providers, cloud, MSPs…).
  • The DORA Regulation (EU) 2022/2554, covering financial entities and their critical ICT providers (risk governance, resilience testing, major incidents).

Transparency, exit routes and SREN

Act no. 2024‑449, known as SREN, strengthens the fight against unfair practices (particularly dark patterns) and promotes transparent contractual terms, especially for digital services. Reference: Legifrance – SREN Act 2024‑449. In B2B practice, translate this into clear information about costs, limitations, exit arrangements and data-export times.

B2C: statutory conformity warranties

For consumer (B2C) offerings, statutory conformity warranties for digital content and services are mandatory. See Decree no. 2022‑946 and explanations on Economie.gouv.fr. Liability limitation clauses are strictly regulated; avoid copying B2B terms into B2C terms without adaptation.

Warranties to include (and draft unambiguously)

1) Availability and performance (SLA)

Define scope (“core” service, add-ons, environments), excluded periods (announced maintenance windows), metrics (uptime, RTO/RPO), calculation method and evidence. Specify remedies: automatic service credits, escalating remedies (patch within X hours). For more on SLA structure, consult our dedicated guide to drafting an enforceable SLA.

2) Security and data protection

Describe technical and organisational measures (encryption at rest/in transit, key management, hardening, logging, segmentation, penetration testing, disaster recovery/business continuity plans), certifications (ISO 27001, SOC 2) and incident-alert commitments. Include a compliant DPA: our GDPR DPA guide provides a ready-to-use checklist.

3) Support, maintenance and roadmap

Specify support levels (hours, languages, channels), first-response and resolution times by severity, update policy (security vs functionality) and conditions for ending support for a feature (notice, fallback solution).

Valid liability exclusions and limitations

Reasonable indemnification caps

Common B2B arrangements include:

  • A general cap: aggregate amounts paid over a rolling 12 months (or 6/24 months depending on risk and annual contract value).
  • “Super-caps” for critical risks: personal data (GDPR), confidentiality breaches, IP infringement, financial transactions. Example: 2 to 3 times the general cap for a data breach.

Align these with professional indemnity and cyber insurance. Specify each party's obligation to maintain appropriate insurance (and provide evidence on request).

Excluding indirect losses (and what that covers)

Define “indirect losses” (lost turnover, customers, opportunities, reputational harm, non-material damage). Include an exception if they result from a GDPR breach, confidentiality breach, IP infringement or breach of an expressly stipulated obligation to achieve a result.

Mandatory exceptions

Expressly state that limitations do not apply to intentional misconduct, gross negligence, personal injury, death or inalienable consumer rights (for B2C). Legal reminder: Legifrance – Civil Code.

Essential obligation and Article 1170

Avoid clauses negating the essence of SaaS: for example, a general liability exclusion for downtime exceeding the SLA or data loss/corruption without alternatives (backups, export). Such a clause risks being set aside under Civil Code Article 1170.

Portability, exit arrangements and dependencies

Exit arrangements and data export

Draft a clear clause: export formats, API/documentation, deadlines, paid assistance, post-termination retention, erasure/deletion. Avoid opaque vendor lock‑in: the CNIL recommends anticipating exit arrangements in cloud contracts. For technical hosting issues, see our guidance on negotiating the data-hosting clause.

Critical subcontractors and the liability chain

List essential subcontractors (cloud, email, payments), notify changes with a reasonable right to object, and impose equivalent security levels (flow-down). NIS2/DORA require robust critical-provider governance: NIS2 and DORA.

Model clauses ready to adapt

Service warranty and SLA (extract)

The Provider warrants monthly Service availability of 99.9% (excluding scheduled Maintenance Windows notified 72 h in advance). In the event of non-compliance, the Client receives automatic Service Credits under the SLA Schedule, constituting the exclusive remedy for downtime, subject to the exceptions in the Limitation of Liability article.

Limitation of liability (extract)

Except for intentional misconduct or gross negligence, the Provider's aggregate liability under the Contract is limited to amounts actually paid by the Client during the last twelve (12) months. This limit increases to three (3) times that amount for (i) a personal data breach attributable to the Provider, (ii) an established confidentiality breach, (iii) infringement of a third party's intellectual property rights by the Service.

The Parties agree to exclude indirect losses (including lost turnover, customers, opportunities or reputational harm), except those arising from cases (i) to (iii) above.

Exit arrangements and portability (extract)

On expiry or termination, and upon a request made within thirty (30) days, the Provider will make an export of Client Data available in the open formats specified in the Technical Schedule, through a documented API. It will provide migration assistance under an accepted quote. After ninety (90) days, Client Data will be deleted from active systems and backups in accordance with the Retention Policy.

Incident notification (DPA extract)

The Provider will inform the Client without undue delay of any security incident affecting Personal Data, specifying the incident's nature, data categories and volumes concerned, corrective measures implemented and proposed remediation, enabling the Client to meet its notification duties within 72 hours.

Negotiation process and evidence

  • Map the Client's business risks (availability, data integrity, continuity) and align SLAs/limitations.
  • Require/produce evidence: audit reports, ISO 27001/SOC 2 certificates, load-testing and disaster recovery/business continuity test results.
  • Check caps against insurance (professional indemnity/cyber); produce certificates.
  • Provide automatic service credits for minor deviations and enhanced remedies for major incidents.
  • Document portability: export test datasets, measured times, estimated costs.

For an overview of other key provisions to coordinate with these clauses, see our essential SaaS contract clauses and, for terms of sale/commercial contracts, our guide to limitation-of-liability clauses.

Common mistakes (and how to avoid them)

  • Excluding all liability for data loss when the service hosts the data: unenforceability risk (art. 1170 CCiv.).
  • Omitting the GDPR DPA and incident notification: non-compliance (GDPR art. 28) and NIS2/DORA exposure.
  • A “1 month subscription” cap without a GDPR super-cap: manifest imbalance given the risk.
  • SLA without a verifiable calculation method or automatic remedy: unusable in practice.
  • No exit clause or specified export formats: extra costs and disputes on exit.

Need a complete annotated template? Our guides to SLA structure and the GDPR DPA will save you valuable time.

Further reading

Related resources

Frequently asked questions

FAQ

Can a SaaS provider exclude all liability for downtime?

No. A total exclusion could deprive the essential obligation of its substance (art. 1170 CCiv.). Instead, provide an enforceable SLA with remedies (credits, patches) and a reasonable indemnification cap.

Is a DPA required if my SaaS processes only business data?

If it includes personal data (even B2B), a GDPR Article 28-compliant DPA is required. Describe security measures, subprocessors, audits and incident notification without undue delay.

Which losses can lawfully be excluded in B2B contracts?

Typically indirect losses (lost turnover, customers, reputation). Retain exceptions for GDPR, confidentiality, IP and breaches of an obligation to achieve a result. Exclusions for intentional misconduct and gross negligence remain unenforceable.

What indemnification cap is usual in SaaS?

Generally amounts paid over a rolling 12 months, with 2–3x super-caps for GDPR, confidentiality, IP or payments. Align with professional indemnity/cyber insurance.

How should data portability be organised on exit?

Specify open export formats, deadlines, APIs, paid assistance, retention and deletion. Test the procedure and document realistic times/costs from signing.

References

Sources used

Training · Audit · Support

Put what you read into practice

Initial helps law firms define AI usage, train teams, deploy the right tools and oversee adoption.

Explore the auditBook an introductory call
← Back to all articles