Author
No results available
Every business in Finland that procures cloud software or IT services will, sooner or later, face a vendor’s standard agreement that heavily favours the supplier. Knowing how to negotiate and draft SaaS and IT contracts in Finland is the single most effective way to protect Your organisation from service failures, data-protection exposure, and vendor lock-in. At Hedman Partners, I regularly advise Finnish and international buyers through this process, from early procurement planning through to executed redlines, and the patterns of risk are remarkably consistent. This guide sets out the practical playbook I share with clients: an eight-step negotiation framework, clause-by-clause drafting guidance with sample redlines, and Finland-specific statutory pointers that every in-house team should know before signing.
Key takeaways at a glance:
A disciplined, step-by-step approach to SaaS procurement in Finland will consistently produce better outcomes than ad-hoc redlining. Below is the framework I use with clients.
Before opening the vendor’s PDF, define the organisation’s risk appetite in three categories: operational criticality (what happens if the service goes down?), data sensitivity (personal data, special categories, trade secrets), and commercial value. This triage determines which clauses deserve full negotiation and which may be accepted as-is.
Identify every variable the vendor cares about: contract term, number of users or seats, payment terms, auto-renewal mechanics, and volume commitments. In my experience, extending a term from one year to three can unlock meaningful concessions on SLA credits and liability caps, use that leverage deliberately.
Map the personal data flows before negotiating the DPA. Determine the roles (controller or joint controller), identify every subprocessor and its location, and confirm the legal basis for each transfer outside the EEA. Finland’s Data Protection Act (1050/2018) supplements the GDPR with national enforcement powers exercised by the Data Protection Ombudsman (Tietosuojavaltuutettu / Tietosuojavaltuutetun toimisto), so compliance carries real teeth locally.
Insist on measurable uptime commitments (e.g., 99.9 % monthly availability), clearly defined measurement methodology, and a tiered credit schedule. Vague “commercially reasonable efforts” language is not an SLA, it is an aspiration. Tie repeated SLA failures to a termination right; otherwise, credits alone will never compensate for operational disruption. See the SLA credit table below for a practical framework.
Require that the DPA accurately reflects controller–processor responsibilities under Articles 28 and 32 of the GDPR. Pay particular attention to breach-notification timelines (the vendor should notify the buyer without undue delay and in any event within a fixed number of hours, I recommend 24 to 36 hours operationally, well inside the 72-hour window the buyer face as controller).
Confirm who owns any configurations, integrations, or bespoke code developed during the engagement. Default vendor terms almost always vest ownership in the supplier. If the buyer’s organisation funds custom development, negotiate for an assignment or at minimum an irrevocable, perpetual licence.
Negotiate a contractual right to receive all data in a standard, machine-readable format within a defined period after termination (30 days is typical), followed by certified deletion. Without this clause, the buyer could face vendor lock-in and potentially unrecoverable data.
Choose the forum deliberately. For purely domestic Finnish SaaS contracts, litigation in a district court is the usual route to dispute resolution, however arbitration terms ensure lightly faster and flexible option to dispute resolution. For cross-border deals or high-value engagements, arbitration under the Finland Chamber of Commerce Arbitration Institute rules offers confidentiality and enforceability under the New York Convention.
In Finland, IT contracts are heavily influenced or governed by the IT2022 terms. The clauses below represent the highest-risk areas in any SaaS contract when the IT2022 are not applied. For each, I provide the negotiation rationale and a suggested redline.
Vendors prefer vague scope descriptions because they preserve flexibility to modify the service. Buyers need a precise service description annexed to the agreement, with a formal change-control mechanism for any modifications. Every material change, whether to features, integrations, or system requirements, should require the buyer’s written approval and, where it increases cost, a separate work order.
Suggested redline: “Any material change to the Service Description shall require the Buyer’s prior written approval and, if it results in additional cost or reduced functionality, a signed Change Order specifying the scope, timeline, and price adjustment.”
Well-drafted definitions are essential here: terms such as “Service,” “Availability,” and “Authorised Users” must be unambiguous from the outset.
Service levels are only meaningful if they are measurable, independently verifiable, and linked to financial consequences. I advise buyers to negotiate a tiered SLA credit structure tied to monthly uptime, with a termination trigger for chronic underperformance.
| Monthly uptime | SLA credit (% of monthly fee) | Additional remedy |
|---|---|---|
| ≥ 99.9 % | None | , |
| 99.5 % – 99.89 % | 5 % | Root-cause report within 5 business days |
| 99.0 % – 99.49 % | 10 % | Remediation plan within 10 business days |
| 95.0 % – 98.99 % | 25 % | Customer may terminate for cause if repeated in 2 of any 3 consecutive months |
| < 95.0 % | 50 % | Immediate termination right; no early-termination fee |
Suggested redline: “Uptime shall be measured by the Supplier’s monitoring system, with raw data accessible to the Customer in real time via a dashboard or API. Scheduled maintenance windows shall not exceed [X] hours per month and shall be excluded from availability calculations only if notified at least 5 business days in advance.”
Negotiate pre-agreed maintenance windows (preferably outside the buyer’s business hours), maximum permitted downtime per window, and tiered incident-response times (P1 critical: response within 15 minutes, resolution target within 4 hours). Ensure the contract specifies the support channels (phone, ticket, dedicated account manager) are preferably available 24/7 and escalation matrix.
Under the GDPR, any SaaS vendor processing personal data on the buyer’s behalf acts as a data processor. Article 28 of Regulation (EU) 2016/679 mandates a written contract, the DPA, that specifies the subject matter, duration, nature and purpose of processing, data categories, and the controller’s obligations.
In Finland, the Data Protection Ombudsman actively enforces these requirements. A SaaS contract that lacks a compliant DPA, or that shifts processor obligations back to the controller through indemnities, will not survive regulatory scrutiny.
What to negotiate in the DPA:
Suggested redline: “The Processor shall notify the Controller of any Personal Data Breach without undue delay becoming aware of it, however not later than 24 hours, providing sufficient detail for the Controller to comply with its notification obligations under Article 33 (2) of the GDPR.”
Require a complete list of subprocessors at signing and a contractual obligation to notify the buyer at least 30 days before any addition or replacement. Insist on a right to object with cause, and if the vendor proceeds despite the buyer’s objection, there should be the right to terminate the contract without penalty.
The default position in most SaaS agreements is that the vendor retains all IP and grants the buyer a limited, revocable licence. This is generally acceptable for the core platform, but becomes problematic when the buyer commissions bespoke modules, integrations, or data models.
Negotiate a clear IP indemnity: the vendor should defend the buyer against third-party IP infringement claims arising from authorised use of the service, at the vendor’s cost and with an obligation to procure a licence, modify the service, or refund fees if the claim succeeds.
Suggested redline: “Supplier shall indemnify, defend and hold harmless the Customer against any third-party claim that the Customer’s use of the Service in accordance with this Agreement infringes any patent, copyright, trade mark or trade secret of a third party.”
Standard mutual confidentiality provisions are usually acceptable, but ensure they survive termination for a reasonable period (typically three to five years, or indefinitely for trade secrets). Under Finnish law, the Trade Secrets Act (liikesalaisuuslaki, 595/2018) provides additional statutory protection, but contractual obligations remain the first line of defence.
Liability allocation is often the most heavily contested area when businesses negotiate and draft SaaS IT contracts in Finland. Vendors want low caps and broad exclusions; buyers need protection proportionate to the risk.
Under Finnish law, parties enjoy broad freedom of contract, but Section 36 of the Contracts Act (228/1929) permits a court to adjust a contract term, or disregard it entirely, if enforcing it would be unreasonable. In practice, this means that an extremely low liability cap in a high-value, high-risk SaaS engagement could be challenged, though it is far better to negotiate a reasonable cap than to rely on judicial intervention.
| Typical vendor position | Buyer negotiation target | Rationale / when to accept |
|---|---|---|
| Cap = fees paid in prior 12 months | Cap = 12–24 months’ fees, or uninsured-loss carveouts | Use the higher cap where the service is operationally critical or data-breach risk is material |
| Blanket exclusion of indirect / consequential damages | Carve out GDPR fines, IP indemnity claims, and personal injury from the exclusion | Regulatory fines and IP losses should never be subject to a low general cap |
| Unlimited liability for gross negligence / willful misconduct | Keep unlimited for willful misconduct; negotiate objective definitions | Finnish courts read in reasonableness, but keep exceptions narrow and well-defined |
Suggested redline: “The aggregate liability of each Party under this Agreement shall not exceed [X] times the total Fees paid and payable in the twelve (12) months preceding the event giving rise to liability; provided that the foregoing cap shall not apply to (a) breaches of data protection obligations, (b) IP infringement indemnities, (c) willful misconduct or gross negligence, or (d) death or personal injury.”
Finland’s Data Protection Act (1050/2018) supplements the GDPR and designates the Data Protection Ombudsman as the national supervisory authority. In practice, this means the buyer’s SaaS DPA must satisfy both EU-wide and Finnish national requirements.
Any transfer of personal data to a country outside the EEA that lacks an adequacy decision must rely on an approved transfer mechanism. The European Commission’s Standard Contractual Clauses (SCCs), adopted under Implementing Decision (EU) 2021/914, remain the most widely used safeguard. In my contracts, I require the following clause:
Suggested redline: “Where the Processor or any Subprocessor transfers Personal Data outside the EEA, it shall ensure that such transfer is subject to (a) an adequacy decision pursuant to Article 45 of the GDPR, or (b) Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914, supplemented by a documented transfer impact assessment.”
Buyers should also request disclosure of the vendor’s transfer impact assessment and verify that supplementary technical measures (encryption in transit and at rest, pseudonymisation) are in place.
Article 33 of the GDPR requires controllers to notify the Data Protection Ombudsman within 72 hours of becoming aware of a personal data breach. To meet this obligation, the buyer needs the vendor to notify well in advance. I recommend a contractual requirement of 24 hours for initial notification, with a full written report (categories of data affected, estimated number of data subjects, remediation steps) within 48 hours.
Under Article 28(3)(e) of the GDPR, the processor must assist the controller in responding to data-subject access, rectification, and erasure requests. Require the vendor to respond the cooperation requests within a defined time frame (five business days is standard) and at no additional cost, many vendor templates attempt to charge hourly fees for this statutory obligation.
A well-drafted exit clause is as important as the service levels. Without one, the cost of switching providers can exceed the value of the original contract.
What to negotiate:
Audit rights are an essential tool for verifying that the vendor, and its subprocessors, are meeting their contractual and regulatory obligations. Under Article 28(3)(h) of the GDPR, the processor must make available all information necessary to demonstrate compliance and allow audits, including inspections.
What to negotiate:
Vendors legitimately push back on unlimited audit rights, they create operational disruption and confidentiality risks. The practical compromise is to limit audits to once per year (unless triggered by a suspected breach), require auditors to sign NDAs, and agree that the audit will be conducted during business hours with minimal disruption. Remote audits or document reviews should be the default, with on-site inspection reserved for serious concerns.
Choosing the right forum is a critical part of IT contract drafting in Finland. My recommendation depends on the nature of the counterparty and the contract value.
For domestic SaaS contracts between Finnish entities, district courts provide a traditional forum for dispute resolution. Proceedings can be conducted in Finnish or Swedish.
For cross-border SaaS contracts or high-value IT engagements, I typically recommend arbitration under the Arbitration Rules of the Finland Chamber of Commerce, seated in Helsinki, with proceedings in English. Arbitration offers confidentiality (important for trade-secret-heavy disputes), speed, and global enforceability under the New York Convention.
Regardless of forum, insist on a clause preserving each party’s right to seek interim relief (injunctions, freezing orders) from any court of competent jurisdiction, arbitration clauses that prohibit court-ordered interim measures leave the buyer exposed during the weeks before an arbitral tribunal is constituted.
Below are twelve sample redline clauses that cover the highest-risk areas when negotiating and draft SaaS IT contracts in Finland. I use variations of these in virtually every procurement engagement.
The ability to negotiate and draft SaaS IT contracts in Finland effectively comes down to preparation, prioritisation, and precision. Finnish contract law grants parties broad freedom to agree terms, but it also empowers courts to intervene when those terms are unreasonable. The practical implication is clear: invest in the negotiation and drafting phase rather than relying on after-the-fact judicial correction. From SLA credits and liability caps to GDPR-compliant DPAs and exit provisions, every clause discussed in this guide represents a real risk I have seen materialise in client engagements. The checklist and redlines above are designed to give Your team a head start, but for complex or high-value procurements, Finland-specific legal review remains essential.
For specialist advice on this topic, contact Mikko Junno at Hedman Partners.
posted 4 hours ago
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
posted 6 hours ago
posted 6 hours ago
posted 7 hours ago
posted 8 hours ago
posted 8 hours ago
posted 9 hours ago
posted 11 hours ago
posted 12 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message