Cloud and SaaS (Software as a Service) contracts have become the most common type of IT procurement in recent years. Detailed contract analysis is essential to manage legal risks.
Checklist
1. Data Ownership
- Who owns the customer data?
- Provider's right to use the data
- Permission to use anonymous/accumulated data
2. Data Residency
- In which country is it stored?
- KVKK art.9 restrictions on transfer abroad
- EU GDPR Standard Contractual Clauses
3. SLA (Service Level Agreement)
- Uptime guarantee (99.9% = 43 minutes downtime per month)
- Response times
- Penalty/credit for SLA violation
4. Security
- Certificates (ISO 27001, SOC 2)
- Penetration tests
- Data breach notification period
5. Exit Strategy
- Data format at the end of the contract
- Data deletion/return process
- Transition support (transition period)
6. Limitations of Liability
- Supplier's upper limit of liability
- Intention/grave fault exception (TBK art. 115)
- Insurance obligation
IT and contract law lawyer support is recommended.