IT Contracts, Data & Cybersecurity Lawyer | Withlaw
  • Our firm
  • About us
  • Our areas of expertise
  • What our clients say
  • Insights
  • Contact us
  • FR

Selling SaaS and Cloud Services to the French Public Sector: What International Providers Need to Know

The French public sector represents a significant market for SaaS, cloud and technology providers.

For international providers, however, selling to a French public-sector customer may raise issues that do not typically arise — or do not arise in the same way — in private-sector negotiations.

Public procurement rules are only part of the picture. The contractual framework, cybersecurity requirements, data protection, hosting arrangements and, in some cases, digital sovereignty requirements can all affect whether and how a service can be offered.

The key is to identify these constraints before committing to contractual or technical requirements that the provider may not be able to meet.

The French public sector is not a single market

The first point is an important one: there is no single set of technology requirements applicable to every French public-sector customer.

The relevant framework may differ depending on whether the customer is:

  • a central government department;
  • a State agency or other public body;
  • a local authority;
  • a public healthcare organisation;
  • or another entity subject to specific sectoral requirements.

The nature of the service and the sensitivity of the data processed are equally important.

Requirements applicable to a cloud service handling sensitive government or health data may therefore be very different from those applicable to a standard SaaS solution used for non-sensitive administrative functions.

International providers should avoid assuming either that all French public-sector projects require a sovereign cloud solution — or that a standard commercial cloud architecture will always be acceptable.

Public procurement affects the negotiation process

Public-sector contracts are generally awarded within a regulated procurement framework.

For a SaaS or technology provider, this has practical consequences.

Unlike a private customer negotiation, the provider may have limited ability to renegotiate contractual requirements once the procurement procedure is underway.

Tender documentation may include:

  • administrative and technical specifications;
  • contractual terms;
  • security requirements;
  • data protection provisions;
  • service levels;
  • reversibility requirements;
  • pricing structures;
  • evaluation criteria.

Potential legal or operational difficulties should therefore be identified during the procurement process rather than after award.

This is particularly important for international providers using global contractual templates. The customer's procurement documents may become the primary contractual framework, leaving less room to rely on the provider's standard SaaS agreement.

Understanding the contractual framework

French public contracts may incorporate contractual mechanisms and standard documents that are unfamiliar to an international provider.

The terminology and risk allocation may also differ from those used in a global MSA or SaaS agreement.

Particular attention may be required in relation to:

  • contract duration and renewal;
  • termination;
  • financial penalties;
  • service levels;
  • liability;
  • intellectual property;
  • audit and control rights;
  • subcontracting;
  • reversibility and exit;
  • data protection;
  • cybersecurity.

The objective is not merely to translate the tender documents.

The provider needs to understand which provisions are imposed by the procurement framework, which derive from the customer's specific requirements and which may still be clarified or negotiated.

Cloud requirements depend on the customer, service and data

France has developed specific policies governing the use of cloud services by the State.

Under the French government's “Cloud at the Centre” policy, cloud is the default approach for new State digital projects and significant application redesigns.

This does not mean that every cloud service sold to a French public-sector customer must hold the same security qualification.

The applicable requirements depend in particular on the entity concerned and the nature and sensitivity of the data and services.

Where particularly sensitive data is involved within the scope of the State cloud policy, commercial cloud services may be required to meet SecNumCloud — or an equivalent European qualification — and to provide protection against unauthorised access by third-country public authorities.

International providers should therefore determine the applicable requirements for the particular project before assuming that their existing hosting model is either compliant or excluded.

Digital sovereignty can become a legal and technical issue

For non-EU technology providers, digital sovereignty deserves particular attention.

The issue is not simply where servers are physically located.

The customer's requirements may also concern:

  • the law applicable to the provider or its group;
  • potential access by third-country public authorities;
  • the provider's cloud infrastructure;
  • subcontractors and subprocessors;
  • control over encryption or security mechanisms;
  • the location and conditions of support services.

A service hosted in the European Union is therefore not necessarily sufficient, by itself, to satisfy every public-sector sovereignty requirement.

Conversely, sovereignty requirements should not automatically be assumed to apply to every public-sector SaaS procurement.

The assessment needs to be made in the context of the particular customer, data and service.

For a detailed analysis of third-country governmental access to EU-held data, see Third-Country Government Access under the EU Data Act: What International SaaS and Cloud Providers Need to Know.

GDPR and data hosting remain separate issues

Public-sector procurement may also involve personal data.

Where the provider acts as a processor, the contract will need to address the requirements of Article 28 GDPR, including processing instructions, security, subprocessors, assistance, deletion or return of data and audit arrangements.

International transfers may require separate consideration.

Additional sector-specific hosting requirements may also apply. For example, services involving health data may be subject to French health-data hosting requirements.

These questions should be distinguished from cloud sovereignty requirements: they may overlap, but they do not have the same legal basis or scope.

Cybersecurity requirements may exceed the provider's standard framework

Public-sector customers may impose detailed cybersecurity requirements through tender specifications, security schedules or contractual annexes.

These may concern:

  • security governance;
  • access control;
  • vulnerability management;
  • encryption;
  • logging;
  • incident response;
  • business continuity and disaster recovery;
  • security audits;
  • notification obligations;
  • subcontractor security.

Before accepting these commitments, the provider should verify that they correspond to its actual technical and organisational framework.

This is particularly important for global SaaS providers operating a standardised multi-tenant service: customer-specific security commitments can be difficult to implement if they are inconsistent with the architecture used for the rest of the customer base.

Reversibility needs to be considered from the outset

Public-sector technology contracts commonly include detailed reversibility and exit requirements.

For SaaS and cloud providers, these requirements now need to be considered alongside the EU Data Act where that regulation applies.

The contract may need to address:

  • data export;
  • formats;
  • migration assistance;
  • transition periods;
  • cooperation with an incoming provider;
  • deletion of remaining data;
  • service continuity during transition.

International providers should ensure that contractual commitments remain consistent with the technical capabilities of the service and with their wider EU switching framework.

See SaaS Switching under the EU Data Act: Protecting Contractual Commitments and the Subscription Model.

Anticipating requirements before bidding

For international providers, the most effective approach is to review the legal and technical requirements before submitting a binding tender.

This makes it possible to identify:

  • requirements the provider already meets;
  • requirements that can be addressed contractually;
  • requirements requiring a technical or organisational adaptation;

and, where necessary,

  • requirements that make the existing service model unsuitable for the procurement.

This analysis can also prevent commercial teams from committing to customer requirements that cannot subsequently be implemented by product, security or infrastructure teams.

For providers entering the French market more broadly, see Doing Business in France: A Legal Guide for International SaaS and Technology Providers.

How Withlaw can help

Withlaw assists international SaaS, cloud and technology providers seeking to contract with French public-sector customers, including by:

  • reviewing tender and contractual documentation;
  • identifying French public procurement and contractual requirements affecting the proposed service;
  • analysing data protection, cybersecurity, cloud and digital sovereignty requirements;
  • assessing contractual requirements against the provider's existing global model;
  • reviewing liability, penalties, service levels, subcontracting and reversibility provisions;
  • supporting responses to legal and contractual questions during procurement procedures;
  • reviewing Data Act implications for SaaS and cloud services;
  • coordinating with the provider's legal, sales, security and technical teams.

The objective is to identify the requirements that genuinely affect the service early enough for the provider to make informed legal, commercial and technical decisions when approaching the French public-sector market.

© Withlaw 2015 – 2026 – All rights reserved

Legal information / Privacy Policy / Credits / Contact us / Share / Follow us on LinkedIn