SaaS Contracts

Legal risks in a SaaS contract: what to look for

SaaS agreements cover more legal ground than most people realise before they sign. Understanding where the risk actually sits, and what the standard terms mean in practice, is how you avoid discovering the problem when the contract is already running.

Eliga Consultancy Services 16 June 2026 7 min read

The biggest legal risk in a SaaS contract is not the clause with the most words. It is the clause nobody questioned because it looked standard. Liability cap. Data terms. Auto-renewal. IP ownership. Each one can run in the wrong direction for years before anyone notices.

1

Why standard templates create real exposure

Most SaaS agreements start as templates. The vendor’s template, drafted to protect the vendor, reviewed when the company was smaller, signed because the deal needed to close. The problem is not that templates exist. It is that they accumulate.

A SaaS contract that was reasonable at seed stage may create significant exposure when the product has grown, when data volumes have increased, when enterprise customers are asking harder questions, or when the regulatory environment has shifted. The contract does not update itself. The business does.

2

Data protection and UK GDPR obligations

Where a SaaS provider processes personal data on behalf of a customer, UK GDPR Article 28 requires a written data processing agreement between them. The DPA must specify the subject matter, duration, nature and purpose of processing, the types of personal data, and the obligations and rights of both parties.

Most SaaS agreements include data processing terms. Far fewer include terms that accurately reflect the actual processing taking place. The mismatch is where the compliance gap sits, and it creates exposure for both the vendor and the customer.

Sector Signal

The UK government’s investment in AI for NHS services is generating new SaaS contracts for health tech vendors at pace. New data-sharing arrangements, AI output liability, and compliance obligations are being negotiated under time pressure. The risk of signing standard templates into fast-moving arrangements applies across the sector, not just health tech.

3

Liability caps, indemnities, and one-way exposure

Liability caps are standard in SaaS agreements. The question is where they are set, and whether they run both ways. A cap set at one month’s fees is a very different commercial outcome than a cap set at twelve months of contract value when a significant incident occurs.

Indemnity clauses deserve the same scrutiny. An indemnity that runs from the customer to the vendor for IP infringement, but does not run the other way if the vendor’s platform infringes a third party’s rights, is a one-sided arrangement that is worth understanding before signing. These provisions are not always obvious on a first read because they are often buried in definitions and cross-references.

  • Check the cap level against the value and risk of the contract
  • Identify which indemnities run which way and what triggers them
  • Note what is excluded from the cap entirely, these are often the highest-risk events

When the product changes but the contract does not

A common pattern in fast-moving SaaS businesses: the product ships AI features, the data volumes grow, the customer base shifts from SMB to enterprise. The contracts stay the same. The exposure accumulates quietly until a customer makes a claim, a regulator asks a question, or an enterprise procurement team reviews the terms and declines to proceed. Reviewing contracts when the business changes is not a legal formality. It is risk management.

4

IP ownership and what you are actually licensing

SaaS agreements should be clear about what the customer is getting. A licence to use the software, not ownership of it. What that licence includes matters: how many users, which jurisdictions, whether it can be sublicensed, and what happens to it if the agreement ends.

IP provisions also need to address customer data. Who owns the data the customer puts into the platform. Whether the vendor can use it for model training, benchmarking, or product improvement. Whether it can be shared with third parties. These provisions have become more significant as AI features are built on top of customer data, and they are worth reading carefully before signing.

5

Exit, auto-renewal and what the contract costs to leave

Auto-renewal provisions are one of the most commonly overlooked terms in SaaS agreements. A contract that auto-renews on 90 days notice effectively locks in the customer for another full term unless they act well in advance of a date they may not have logged.

Exit provisions should also address what happens to customer data at the end of the agreement. How long the vendor retains it, in what format the customer can export it, and what the deletion timeline looks like. These terms matter when switching vendors or terminating a relationship, and they are much harder to negotiate after the agreement is signed.

Frequently asked questions

What are the legal risks in a SaaS contract?

The main legal risks cluster around five areas: liability caps and indemnities that only run one way, data protection obligations that do not match how the product processes personal data, IP ownership provisions that are ambiguous or unfavourable, auto-renewal and exit terms that make the agreement hard to leave, and service level commitments that do not reflect what the product actually delivers.

What should a SaaS contract include to protect my business?

A SaaS contract should include a mutual liability cap set at an appropriate level, data processing terms that match your actual data flows and UK GDPR obligations, clear IP ownership provisions, a service level agreement with meaningful remedies, transparent pricing with controls on increases, and exit terms that include data return and deletion obligations.

How does UK GDPR affect SaaS contracts?

Where a SaaS provider processes personal data on behalf of a customer, UK GDPR Article 28 requires a written data processing agreement between them. The agreement must specify the subject matter, duration, nature and purpose of processing, the type of personal data and categories of data subjects, and the obligations and rights of the controller. Signing a SaaS agreement without the correct DPA terms in place creates a compliance gap for both parties.

What is the difference between a SaaS agreement and a software licence?

A software licence gives you permission to use software that is installed locally. A SaaS agreement governs access to software delivered over the internet, where the provider hosts and maintains the product. SaaS agreements typically include service level obligations, data handling terms, subscription pricing, and ongoing compliance obligations that a traditional software licence does not cover.

When should a SaaS business get its contracts reviewed by a lawyer?

A SaaS business should get its contracts reviewed when it is first drafting its standard terms, when it is signing a high-value enterprise agreement, when a customer proposes significant changes, when the product has changed materially, or when data processing obligations have grown. For businesses signing contracts regularly, ongoing fractional legal support is usually more practical than reviewing each one in isolation.

Have a SaaS contract that needs reviewing?

We review SaaS and commercial contracts for scaling tech businesses, quickly and in plain English. We flag where the exposure sits and what to do about it before you sign.

Book a call with us: calendly.com/dhruve-eligaconsultancy

Want updates like this first? Subscribe to Tech Counsel Insight, our newsletter for scaling SaaS and tech businesses.