IT Contracts, Data & Cybersecurity Lawyer | Withlaw
  • Our firm
  • About us
  • Our areas of expertise
  • What our clients say
  • Insights
  • Contact us
  • FR

Negotiating SaaS Agreements with French Enterprise Customers: What International Providers Should Expect

For an international SaaS provider, securing a French enterprise customer often means negotiating beyond the provider’s standard global agreement.

French customers — particularly large organisations — may submit their own contractual templates or require significant amendments to the provider’s terms. Procurement, legal, data protection and cybersecurity teams may all become involved, sometimes resulting in requirements that go well beyond what French or EU law actually requires.

The challenge for the provider is therefore not simply to make its agreement “compliant with French law”. It is to identify what genuinely needs to be adapted, what can be negotiated and what should be resisted in order to preserve the provider’s contractual and business model.

Starting from the provider’s global agreement

Entering the French market does not generally require replacing a provider’s global SaaS agreement with an entirely French contract.

The existing MSA, SaaS agreement or standard terms can usually remain the starting point.

A French-law review should instead identify provisions that require adaptation and areas likely to become negotiation points with French customers.

This approach also helps international providers maintain consistency across jurisdictions rather than creating a separate contractual model for each country.

For a broader overview, see Doing Business in France: A Legal Guide for International SaaS and Technology Providers.

Customer template or provider template?

One of the first issues may simply be whose paper is used.

Large French customers may seek to impose their own purchasing terms, IT agreement or SaaS template. Accepting customer paper can significantly change the allocation of risk compared with negotiating amendments to the provider’s global terms.

The choice is not merely formal.

Customer templates are generally drafted around the customer’s procurement policies and risk allocation. They may contain obligations that do not reflect the provider’s service architecture, operating model or standard commitments to its other customers.

Where customer paper cannot be avoided, it should therefore be reviewed not only for legal compliance but also for operational feasibility.

Liability: a central negotiation point

Liability is frequently one of the most heavily negotiated provisions in enterprise SaaS agreements.

Customers may request:

  • a higher general liability cap;
  • uncapped liability for certain categories of loss;
  • specific indemnification obligations;
  • broad exclusions from the agreed cap;
  • liability linked to cybersecurity incidents or personal data breaches;
  • commitments extending beyond the provider’s actual control.

For the provider, the issue is not simply the amount of the cap. The interaction between the cap, exclusions, indemnities, warranties and insurance coverage needs to be considered as a whole.

Particular care is also required when customer templates import concepts developed under common-law contracts that do not necessarily operate in the same way under French law.

Term, termination and the economics of the SaaS model

Contract duration is another area where legal and commercial issues intersect.

A provider may offer preferential pricing in exchange for a fixed subscription term, while the customer seeks broad termination rights — sometimes including termination for convenience.

These provisions need to be assessed against the commercial structure of the agreement.

EU regulation can add another layer. In particular, the Data Act introduces switching rights for customers of data processing services, but those requirements should not automatically be treated as eliminating all contractual or economic consequences associated with a committed subscription term.

See SaaS Switching under the EU Data Act: Protecting Contractual Commitments and the Subscription Model.

Service levels and contractual remedies

French enterprise customers frequently seek detailed service levels covering availability, support, incident response and recovery.

The main points of negotiation may include:

  • how availability is calculated;
  • exclusions and scheduled maintenance;
  • incident severity levels;
  • response and resolution targets;
  • service credits;
  • whether service credits constitute the exclusive contractual remedy;
  • repeated SLA failures and termination rights.

The contract should remain aligned with the service the provider can actually deliver.

Accepting bespoke commitments negotiated by legal or procurement teams without checking them against operational capabilities can create contractual exposure that was never reflected in the technical service itself.

GDPR and data processing agreements

Where personal data is processed on behalf of the customer, GDPR requirements will generally form part of the negotiation.

International providers often already use a global DPA. The question is therefore usually whether that document satisfies EU requirements and whether customer-requested amendments are legally necessary.

Negotiations may concern:

  • controller and processor roles;
  • subprocessors and notification mechanisms;
  • international transfers;
  • security measures;
  • assistance obligations;
  • audit rights;
  • breach notification;
  • deletion and return of data.

Here again, a distinction should be made between GDPR requirements and additional contractual protections requested by the customer.

The latter may be negotiable even when presented as “GDPR requirements”.

Cybersecurity requirements increasingly drive the contract

Cybersecurity has become a major component of enterprise technology negotiations.

Customers may provide detailed security schedules, questionnaires or internal policies and ask the provider to incorporate them contractually.

Some requirements may reflect regulatory obligations applicable to the customer, particularly in regulated sectors. Others may simply reflect its internal security policy.

The provider needs to determine whether the requested commitments:

  • are legally required;
  • are technically achievable;
  • correspond to its existing security framework and certifications;
  • create customer-specific obligations that cannot realistically be maintained at scale;
  • or transfer risks that should remain with the customer.

This distinction is increasingly important as EU cybersecurity legislation develops and regulated customers seek to pass requirements through their supply chain.

Audit rights: keeping them proportionate

Audit clauses are another common source of negotiation.

Customers may seek broad rights to inspect systems, premises, security arrangements, subcontractors or compliance documentation.

Providers operating multi-tenant SaaS environments need to ensure that such rights remain compatible with security, confidentiality and obligations owed to other customers.

Existing certifications, independent audit reports and structured assurance mechanisms can often provide a more appropriate solution than unrestricted customer audits.

Knowing what to accept — and what to negotiate

A customer request should not be accepted merely because it is described as a “French legal requirement”.

Conversely, rejecting a provision simply because it does not appear in the provider’s global template may make a negotiation unnecessarily difficult.

For international providers, effective negotiation requires separating three different questions:

What is required by French or EU law?

What reflects established market practice?

What is simply the customer’s preferred contractual position?

The answer determines the negotiation strategy.

It also allows the provider’s legal and sales teams to focus concessions where they are commercially justified while preserving the provisions that protect the scalability and economics of the SaaS model.

How Withlaw can help

Withlaw assists international SaaS and technology providers in negotiating agreements with French customers, including large enterprise customers.

Our work may include:

  • reviewing international SaaS agreements and global templates against French and EU requirements;
  • negotiating directly with customers’ legal and procurement teams;
  • reviewing customer paper and identifying provisions that materially depart from the provider’s standard risk allocation;
  • negotiating liability, warranties, indemnities, term and termination provisions;
  • reviewing DPAs, security schedules, SLAs and audit provisions;
  • coordinating contractual negotiations with the provider’s in-house legal, sales, security and compliance teams;
  • helping distinguish mandatory legal requirements from market practice and negotiable customer requirements.

The objective is not to replace the provider’s global contractual model with a French one, but to make that model work effectively in the French market while preserving its legal, operational and economic consistency.

© Withlaw 2015 – 2026 – All rights reserved

Legal information / Privacy Policy / Credits / Contact us / Share / Follow us on LinkedIn