
SaaS and Cloud Services
Structuring SaaS agreements for vendors and regulated customers
Every SaaS agreement that handles personal data is a data protection arrangement, whether the customer operates in a regulated sector or not. We act for SaaS vendors and regulated customers in equal measure. For vendors, the challenge is structuring standard terms, data protection addenda and security schedules that satisfy the regulatory requirements of customers in telecoms, payments and financial services, without creating unmanageable operational obligations. For customers, the challenge is ensuring that the vendor’s terms meet UK GDPR controller and processor obligations, international transfer mechanisms and sector-specific requirements under the Communications Act 2003 as amended by the Telecommunications (Security) Act 2021 and, for payments and financial services customers, the FCA’s operational resilience rules. Both sides need the contract to work commercially and comply with the law.
Why SaaS regulatory compliance matters now
A payment institution, an electronic money institution or a bank must set an impact tolerance for each of its important business services, map and test its ability to stay within it, and be able to show the FCA it has done so (SYSC 15A; FCA PS21/3, March 2021). Designation as a critical third party is a separate question, and it is not the FCA’s to make: HM Treasury designates under section 312L of the Financial Services and Markets Act 2000, inserted by section 18(3) of the Financial Services and Markets Act 2023, and the first designations took effect on 13 July 2026 for Amazon Web Services EMEA SARL, Google Cloud EMEA Limited, Microsoft Ireland Operations Limited and Oracle Corporation UK Limited. A SaaS vendor outside that list is an ordinary outsourcing. Ofcom has begun to test the telecoms security duties case by case, opening an own-initiative investigation on 15 December 2025 into BT’s compliance with sections 105A and 105C of the Communications Act 2003 and the Electronic Communications (Security Measures) Regulations 2022. The Information Commissioner rewrote the international transfers guidance on 15 January 2026 around a three step test, with further guidance on the IDTA and cloud services to follow.
Exit terms commonly set a deletion window of 30 to 90 days after termination, and that window can cut across a retention duty the customer owes elsewhere. An authorised payment institution or small payment institution must keep records relevant to its compliance with Parts 2 to 5 for at least five years from the date the record was created (regulation 31 of the Payment Services Regulations 2017). A telecoms operator given a retention notice under section 87 of the Investigatory Powers Act 2016 must retain the relevant communications data for the period the notice specifies, which cannot exceed 12 months. An automatic deletion clause that fires on termination will put the customer in breach of those duties unless the contract carves them out.
Common SaaS agreement failures
A SaaS agreement that touches personal data is not standard procurement. The data protection addendum has to identify which party is the controller and which the processor, and it has to say how the processor will assist. Under UK GDPR Article 28(3)(e) a processor must, taking into account the nature of the processing, assist the controller by appropriate technical and organisational measures in responding to requests from data subjects. A contract that recites the duty without setting out the mechanism leaves the controller unable to discharge it.
International transfer risk needs separate attention in the contract. Many SaaS vendors use tiered architecture: data is processed in the nominated region but may be backed up, analysed or logged elsewhere. The contract should explicitly prohibit transfers outside approved jurisdictions and require notification if the vendor plans to change its infrastructure.
Exit mechanics have to be written rather than assumed. Where the contract is silent on format, timeline and conditions, the vendor may charge for extended retention, export in a proprietary format, or apply its standard deletion clause on the day the agreement ends. For a payment institution or a telecoms operator that means an interrupted service and, where a statutory retention duty applies, a breach of it.
| Common issue | Better approach |
|---|---|
| Standard procurement without controller/processor analysis | Precise roles defined under UK GDPR Article 28 |
| International transfers not investigated | Transfer mechanisms verified for backup, analytics and logging locations |
| Data portability at exit not addressed in the contract | Format, timeline and conditions for data return specified contractually |
| Sector-specific retention obligations not addressed in the contract | Retention aligned with telecoms, financial services or payments requirements |
| Vendor and customer risks not balanced | Terms satisfying regulated customers without unreasonable vendor exposure |
Regulated customers carry outsourcing requirements that standard SaaS terms do not address. An authorised payment institution must notify the FCA before it outsources any operational function, and where that function is an important operational function the outsourcing must not impair the quality of its internal control or the FCA’s ability to monitor and retrace its compliance (regulation 25 of the Payment Services Regulations 2017). An authorised electronic money institution is subject to the same conditions under regulation 26 of the Electronic Money Regulations 2011, and both are within the FCA’s operational resilience rules at SYSC 15A. In practice the SaaS agreement has to give the customer and its regulator audit rights, set business continuity provisions and allocate responsibility for regulatory reporting. For a SaaS vendor selling into regulated sectors, building those provisions into standard terms takes them out of every deal negotiation.
Telecoms operators using SaaS for network management, billing or customer data face an additional layer. The Telecommunications (Security) Act 2021 rewrote the security provisions of the Communications Act 2003. Sections 105A to 105D had been inserted in 2011; the 2021 Act substituted sections 105A and 105B, replaced sections 105C and 105D and added the sections that follow, with the principal duties in force from 1 October 2022. They impose security duties on providers of public electronic communications networks and services. These duties reach the supply chain: a provider must take appropriate and proportionate measures to identify and reduce the risks of a security compromise arising from what a third party supplier does or fails to do, and must secure by contract that the supplier discloses and reduces those risks, lets the provider monitor its activity, and co-operates in resolving incidents (regulation 7 of the Electronic Communications (Security Measures) Regulations 2022). The Secretary of State, not Ofcom, issues the Telecommunications Security Code of Practice under section 105E of the Communications Act 2003; Ofcom monitors and enforces. For SaaS vendors, this means customers in the telecoms sector will require contractual commitments on penetration testing, vulnerability disclosure and incident notification that go beyond standard information security schedules.
The sub-processing chain needs to be traced before signature. UK GDPR Article 28 requires the same data protection obligations as are set out in the controller’s contract with the processor to be imposed on any sub-processor (Article 28(4)), and a processor may engage one only with the controller’s prior specific or general written authorisation; where the authorisation is general, the processor must tell the controller of intended changes and give it the opportunity to object (Article 28(2)). In practice, most SaaS vendors sub-process through cloud infrastructure providers such as AWS, Azure or Google Cloud, each of which may store or process data in multiple jurisdictions. The vendor’s standard terms typically permit sub-processing with general authorisation and a notification mechanism; the customer’s regulatory obligations may require specific authorisation or the right to terminate if an unacceptable sub-processor is appointed. For vendors, building a workable sub-processing framework into standard terms reduces friction; for customers, verifying the sub-processing chain against international transfer requirements is essential before signing.
Firms with operations in the EEA must also consider the EU Data Act, which entered into force on 11 January 2024 with Chapter VI (cloud switching) obligations applying from 12 September 2025. Articles 23 to 31 require cloud service providers to enable customers to switch to a competing provider or port data back to their own infrastructure, with a notice period of up to two months followed by a mandatory maximum transitional period of 30 calendar days, which the provider may replace with an alternative period of no more than seven months where the 30 days is technically unfeasible (Article 25(2) and (4)). From 12 January 2027, switching charges must be zero. The Data Act does not apply directly in the UK, but vendors serving EEA customers and UK customers using EEA-based infrastructure will need to comply. For SaaS vendors, this means exit provisions in standard terms must now meet EU switching requirements as well as UK contractual expectations. For customers, the Data Act provides a regulatory floor for data portability that can be used in commercial negotiations.
The terms a SaaS agreement should cover
A well-drafted SaaS agreement works for both parties. For the vendor, standard terms must be strong enough to satisfy regulated customers without creating customer-specific obligations for every deal. For the customer, the agreement must address the lawful basis for processing, define controller/processor roles with precision, handle international transfers, address data subject requests, set out deletion and data portability at termination, and meet sector-specific security requirements.
Bratby Law advises on both sides of SaaS transactions. For vendors, we structure standard terms and regulatory schedules that a regulated customer’s procurement and compliance teams can accept without amendment. For customers, we identify the specific regulatory requirements that apply and negotiate amendments to vendor terms that meet those requirements. On both sides, we build in exit mechanics that work commercially and comply with retention obligations.
How Bratby Law helps
- SaaS agreement review and negotiation: for customers, reviewing vendor master service agreements, data protection addenda and security schedules against sector-specific regulatory obligations, identifying gaps and negotiating amendments; for vendors, reviewing customer markup and advising on which amendments are commercially acceptable
- Data protection addendum drafting: drafting or negotiating DPAs that meet UK GDPR Article 28 requirements, covering the subject matter, duration, nature and purpose of the processing, the types of personal data and categories of data subject, controller and processor roles, data subject request assistance, sub-processor management and breach notification
- International transfer mechanisms: advising on the legal basis for cross-border data transfers, including adequacy decisions, the UK International Data Transfer Agreement (IDTA) and UK Addendum (or the EU Standard Contractual Clauses where the EU GDPR applies), and transfer impact assessments for vendors with multi-country infrastructure
- Security schedules for regulated customers: drafting security schedules that reflect the supply chain duties in the Communications Act 2003 as amended by the Telecommunications (Security) Act 2021 and regulation 7 of the Electronic Communications (Security Measures) Regulations 2022 for telecoms operators, and the FCA’s operational resilience rules at SYSC 15A for payments and financial services customers
- Exit mechanics and data portability: negotiating data export terms (format, timeline, conditions), retention obligations that align with sector-specific statutory requirements, and transition support provisions that protect the customer during migration
- Vendor-side terms structuring: for SaaS providers, structuring standard terms, DPAs and security schedules that satisfy the regulatory requirements of customers in telecoms, payments and financial services from the outset, so that one set of terms serves each regulated customer rather than being negotiated again on every deal
Rob Bratby advises SaaS vendors and regulated customers in equal measure on data protection and regulatory compliance for cloud services agreements, bringing experience from General Counsel roles at regulated telecoms and payments businesses. Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection.
Frequently asked questions
Should we negotiate the vendor’s standard terms or draft our own?
It depends on which side you are on. For customers, negotiating amendments to the vendor’s standard terms is usually more practical than drafting customer-specific agreements. Focus negotiation effort on the data protection addendum, security schedule, exit mechanics and sector-specific regulatory requirements. For vendors selling into regulated sectors, investing in standard terms that already address telecoms, payments and financial services requirements avoids protracted negotiation on every deal. For high-value or high-risk procurements, a customer-specific agreement may be justified on either side.
Does a SaaS agreement need a separate data protection addendum?
Yes. UK GDPR Article 28 requires processor obligations to be set out in a contract. The DPA should specify scope, nature, purpose and duration of processing, types of personal data, categories of data subjects, and the parties’ obligations. A vendor that does not offer a processing addendum as standard has not built for regulated customers.
What if the SaaS vendor is US-based?
US-based vendors can comply with UK GDPR. The key is ensuring transfers outside the UK are covered by an adequacy decision, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses; the EU Standard Contractual Clauses on their own are an EU GDPR mechanism and do not satisfy the UK GDPR for UK restricted transfers. If the vendor uses sub-processors in multiple countries, require confirmation of the legal basis for each transfer. Many US vendors now offer UK data residency options.
Can we rely on anonymisation to avoid GDPR obligations?
Only where re-identification is not reasonably possible. Where a key or other information can restore identity, the data is pseudonymised and remains personal data under UK GDPR. If in doubt, assume the data is personal and apply GDPR controls. The ICO provides guidance on anonymisation.
What happens if the SaaS vendor suffers a data breach?
A processor must notify the controller without undue delay after becoming aware of a personal data breach (UK GDPR Article 33(2)). The controller must then notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals; a notification made later must give reasons for the delay (Article 33(1)). That is a deadline to notify, not a period in which to decide. The contract should require the vendor to co-operate with the customer’s breach response, preserve evidence and assist with regulator notification.
How do we ensure data is available for migration at termination?
Specify that data must be exported in a standard, machine-readable format (CSV, JSON, XML) within 30 days. Do not accept proprietary formats. Require a test export during procurement. If you have large data volumes, negotiate a 60-day export window.
What outsourcing rules apply to regulated customers using SaaS?
An authorised payment institution must meet the outsourcing conditions in regulation 25 of the Payment Services Regulations 2017, and an authorised electronic money institution the same conditions in regulation 26 of the Electronic Money Regulations 2011; both are also within the FCA’s operational resilience rules at SYSC 15A. SYSC 8.1 applies to FSMA-authorised firms and does not reach either. Telecoms operators must comply with the security duties in sections 105A to 105D of the Communications Act 2003 (as substituted and extended by the Telecommunications (Security) Act 2021), which reach supply chain risk, and must inform Ofcom as soon as reasonably practicable of any security compromise that has a significant effect on the operation of the network or service (section 105K). That last duty is what drives the incident notification clause a regulated customer needs from its SaaS vendor. Both regimes require the SaaS agreement to include regulator audit rights, business continuity provisions and incident notification obligations that go beyond standard commercial terms.
Does the EU Data Act affect UK SaaS agreements?
The EU Data Act does not apply directly in the UK. However, SaaS vendors serving EEA customers or using EEA-based infrastructure must comply with the Data Act’s cloud switching requirements under Articles 23 to 31, including a 30-day switching completion obligation and zero switching charges from January 2027. UK customers can use the Data Act as a benchmark in commercial negotiations for data portability and exit provisions, even where the Act does not apply directly.
Related transactions pages
See also our other transactions pages:
- Mergers and Acquisitions (M&A)
- Private equity
- Subsea cables
- MVNOs and MVNEs
- Interconnection, peering and access agreements
- Network sharing and co-location agreements
- Digital Infrastructure Projects
- Data Commercialisation and Licensing
- NSIA Clearances
Independent directory rankings
Our specialist expertise is recognised in major independent legal directories:
- Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
- The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
- Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology



See our TelXL case study for an example of how we advise on SaaS and CCaaS platform agreements.
