
A cloud services agreement is the contract between a cloud or SaaS vendor and its customer, and a good one nails down the things a customer cannot afford to leave to chance: who owns the data, what the service level is, and how data comes back when the deal ends. Years ago Gartner published a list it called the “Rights and Responsibilities for Consumers of Cloud Computing Services.” Most of the items still hold up. The real question, the one I get from the SaaS vendors I represent, is which of them belong in the cloud agreement and which are really a policy statement or a communication issue. Here is how I sort them.
I represent lots of SaaS and cloud companies (literally 100s of deals), and the pattern is always the same. The items that allocate legal risk go in the contract, and the items that set expectations go in your policies and your sales conversations. Mixing those up is what creates disputes later, the same way a fuzzy SaaS agreement versus EULA decision does.
What Belongs in the Cloud Agreement.
Three of Gartner’s items are squarely contract material. Data ownership and return comes first. Say plainly that the customer owns its data, and spell out how and when that data is returned or deleted at the end of the term. There is real litigation over who controls hosted data, so get data ownership and a data-return obligation in writing, in the agreement itself, not on a webpage you can change later. The service level belongs in the contract too. An SLA that lives only in a policy statement is an SLA your customer cannot enforce, so put the uptime commitment, the measurement method, and the remedy (usually service credits) in the agreement or an attached exhibit. Software license portability rounds out the list. If you let a customer move an on-premise license into your cloud, document that permission in the agreement or an amendment, because it changes the scope of the license grant.
This is the same instinct behind getting your limitation of liability model right and not letting key terms drift onto customer paper. If a term decides who pays when something goes wrong, it is contract language.
What Is Really Policy or Communication.
The rest of Gartner’s list is about transparency, and transparency is mostly a communication job, not a contract clause. Notice of material changes to the service is something every vendor should do (add the word “material” so you are not on the hook for every minor update), but it usually lives in a policy. Explaining technical limitations and publishing your security process are things you should handle before and after the sale; your SaaS agreement is not the place to teach the customer how the product works, and the FTC’s Six Steps Toward More Secure Cloud Computing is a good baseline for what to communicate about security. Telling customers where their data resides and handling cross-border legal issues is also more policy than clause, with one exception: back it with a short contract warranty that you “will comply with all applicable laws in performing under the agreement.” For the definitions everyone still argues about, the NIST Definition of Cloud Computing (SP 800-145) remains the common reference point.
Cloud Agreement Checklist: Contract vs. Policy.
Here is the quick sort I use:
- Data ownership and return. Contract.
- Service level (SLA). Contract.
- License portability (on-premise to cloud). Contract or amendment.
- Compliance with applicable law. Contract (short warranty).
- Notice of material service changes. Policy or communication.
- Technical limitations. Communication, before and after the sale.
- Security process. Policy statement.
- Where data resides. Policy, plus the compliance warranty above.
Frequently Asked Questions.
Who owns the data in a cloud agreement? The customer should, and the agreement should say so expressly, along with how the data is exported or deleted at termination. Silence here is what ends up in court. The FTC’s Protecting Personal Information guide is a useful reference on handling that data responsibly.
Should the SLA go in the contract or a separate policy? In the contract, or an exhibit to it. An SLA your customer cannot point to and enforce is just marketing.
Does a cloud agreement need to list where data is stored? Not usually as a clause. Handle data location through your policies and a general compliance-with-law warranty, unless a regulated customer needs a specific data-residency commitment.
I hope this helps. These lists keep evolving, but the contract-versus-policy instinct does not. Trust me on this one.
Resources:
- SaaS Agreement vs. EULA: Which Template Do I Need?
- 6 Tips If Your Customer Wants Their Form Agreement.
- RFP Responses Included in SaaS Contracts. WHAT?
Disclaimer:
This post is for informational and educational purposes only, and is not legal advice. You should hire an attorney if you need legal advice, which should be provided only after review of all relevant facts and applicable law.
Discover more from Aber Law Firm
Subscribe to get the latest posts sent to your email.