[codicts-css-switcher id=”346″]

Global Law Experts Logo
negotiate draft saas it contracts finland

How to Negotiate and Draft SaaS & IT Contracts in Finland

By Mikko Junno
– posted 2 hours ago

Every business in Finland that procures cloud software or IT services will, sooner or later, face a vendor’s standard agreement that heavily favours the supplier. Knowing how to negotiate and draft SaaS and IT contracts in Finland is the single most effective way to protect Your organisation from service failures, data-protection exposure, and vendor lock-in. At Hedman Partners, I regularly advise Finnish and international buyers through this process, from early procurement planning through to executed redlines, and the patterns of risk are remarkably consistent. This guide sets out the practical playbook I share with clients: an eight-step negotiation framework, clause-by-clause drafting guidance with sample redlines, and Finland-specific statutory pointers that every in-house team should know before signing.

Key takeaways at a glance:

  • Yes, SaaS contracts can be negotiated. Most vendors will move on price, SLAs, liability caps, and data-protection terms when the buyer makes a risk-based case.
  • Finnish contract law, particularly Section 36 of the Contracts Act (228/1929), gives courts the power to adjust unreasonable terms, but it is far better to negotiate those terms out before signing.
  • GDPR obligations under Regulation (EU) 2016/679 require specific data processing agreement (DPA) clauses, including transfer safeguards, that cannot simply be accepted in a vendor’s boilerplate.
  • A structured exit and data-return clause is non-negotiable: without one, switching providers becomes prohibitively expensive.

Quick Negotiation Playbook: 8 Steps to Win Better SaaS Terms in Finland

A disciplined, step-by-step approach to SaaS procurement in Finland will consistently produce better outcomes than ad-hoc redlining. Below is the framework I use with clients.

Step 1, Prioritise Business Needs and Risk Appetite

Before opening the vendor’s PDF, define the organisation’s risk appetite in three categories: operational criticality (what happens if the service goes down?), data sensitivity (personal data, special categories, trade secrets), and commercial value. This triage determines which clauses deserve full negotiation and which may be accepted as-is.

Step 2, Define the Commercial Levers

Identify every variable the vendor cares about: contract term, number of users or seats, payment terms, auto-renewal mechanics, and volume commitments. In my experience, extending a term from one year to three can unlock meaningful concessions on SLA credits and liability caps, use that leverage deliberately.

Step 3, Data and Compliance Due Diligence

Map the personal data flows before negotiating the DPA. Determine the roles (controller or joint controller), identify every subprocessor and its location, and confirm the legal basis for each transfer outside the EEA. Finland’s Data Protection Act (1050/2018) supplements the GDPR with national enforcement powers exercised by the Data Protection Ombudsman (Tietosuojavaltuutettu / Tietosuojavaltuutetun toimisto), so compliance carries real teeth locally.

Step 4, Negotiate SLA and Remedies

Insist on measurable uptime commitments (e.g., 99.9 % monthly availability), clearly defined measurement methodology, and a tiered credit schedule. Vague “commercially reasonable efforts” language is not an SLA, it is an aspiration. Tie repeated SLA failures to a termination right; otherwise, credits alone will never compensate for operational disruption. See the SLA credit table below for a practical framework.

Step 5, Redline the Vendor’s Standard DPA

Require that the DPA accurately reflects controller–processor responsibilities under Articles 28 and 32 of the GDPR. Pay particular attention to breach-notification timelines (the vendor should notify the buyer without undue delay and in any event within a fixed number of hours, I recommend 24 to 36 hours operationally, well inside the 72-hour window the buyer face as controller).

Step 6, IP, Licensing and Deliverables

Confirm who owns any configurations, integrations, or bespoke code developed during the engagement. Default vendor terms almost always vest ownership in the supplier. If the buyer’s organisation funds custom development, negotiate for an assignment or at minimum an irrevocable, perpetual licence. 

Step 7, Exit, Data Return and Migration Plan

Negotiate a contractual right to receive all data in a standard, machine-readable format within a defined period after termination (30 days is typical), followed by certified deletion. Without this clause, the buyer could face vendor lock-in and potentially unrecoverable data.

Step 8, Align Dispute Resolution to Risk

Choose the forum deliberately. For purely domestic Finnish SaaS contracts, litigation in a district court is the usual route to dispute resolution, however arbitration terms ensure lightly faster and flexible option to dispute resolution. For cross-border deals or high-value engagements, arbitration under the Finland Chamber of Commerce Arbitration Institute rules offers confidentiality and enforceability under the New York Convention.

Key Contract Clauses: How to Negotiate and Draft SaaS & IT Contracts in Finland

In Finland, IT contracts are heavily influenced or governed by the IT2022 terms. The clauses below represent the highest-risk areas in any SaaS contract when the IT2022 are not applied. For each, I provide the negotiation rationale and a suggested redline. 

Scope of Services and Acceptance

Vendors prefer vague scope descriptions because they preserve flexibility to modify the service. Buyers need a precise service description annexed to the agreement, with a formal change-control mechanism for any modifications. Every material change, whether to features, integrations, or system requirements, should require the buyer’s written approval and, where it increases cost, a separate work order.

Suggested redline: “Any material change to the Service Description shall require the Buyer’s prior written approval and, if it results in additional cost or reduced functionality, a signed Change Order specifying the scope, timeline, and price adjustment.”

Well-drafted definitions are essential here: terms such as “Service,” “Availability,” and “Authorised Users” must be unambiguous from the outset.

Service Levels and Measurement, SLA Credits

Service levels are only meaningful if they are measurable, independently verifiable, and linked to financial consequences. I advise buyers to negotiate a tiered SLA credit structure tied to monthly uptime, with a termination trigger for chronic underperformance.

Monthly uptime SLA credit (% of monthly fee) Additional remedy
≥ 99.9 % None ,
99.5 % – 99.89 % 5 % Root-cause report within 5 business days
99.0 % – 99.49 % 10 % Remediation plan within 10 business days
95.0 % – 98.99 % 25 % Customer may terminate for cause if repeated in 2 of any 3 consecutive months
< 95.0 % 50 % Immediate termination right; no early-termination fee

Suggested redline: “Uptime shall be measured by the Supplier’s monitoring system, with raw data accessible to the Customer in real time via a dashboard or API. Scheduled maintenance windows shall not exceed [X] hours per month and shall be excluded from availability calculations only if notified at least 5 business days in advance.”

Availability, Maintenance Windows, Support and Incident Response

Negotiate pre-agreed maintenance windows (preferably outside the buyer’s business hours), maximum permitted downtime per window, and tiered incident-response times (P1 critical: response within 15 minutes, resolution target within 4 hours). Ensure the contract specifies the support channels (phone, ticket, dedicated account manager) are preferably available 24/7 and escalation matrix.

Data Protection and Processing (GDPR)

Under the GDPR, any SaaS vendor processing personal data on the buyer’s behalf acts as a data processor. Article 28 of Regulation (EU) 2016/679 mandates a written contract, the DPA, that specifies the subject matter, duration, nature and purpose of processing, data categories, and the controller’s obligations.

In Finland, the Data Protection Ombudsman actively enforces these requirements. A SaaS contract that lacks a compliant DPA, or that shifts processor obligations back to the controller through indemnities, will not survive regulatory scrutiny.

What to negotiate in the DPA:

  • Roles and purpose limitation: Confirm the vendor is a processor (not a controller) and restrict processing to documented instructions.
  • Subprocessor controls: Require prior specific or general written authorisation before any subprocessor change.
  • Transfer safeguards: For transfers outside the EEA, require Standard Contractual Clauses (SCCs) adopted under Commission Implementing Decision (EU) 2021/914, supplemented by a transfer impact assessment.
  • Security measures: Annex the vendor’s technical and organisational measures (TOMs) and require annual review.
  • Breach notification: Require vendor notification without undue delay since becoming aware of a breach, however not later than 24 hours. the term “without undue delay” is a vague expression. 

Suggested redline: “The Processor shall notify the Controller of any Personal Data Breach without undue delay becoming aware of it, however not later than 24 hours, providing sufficient detail for the Controller to comply with its notification obligations under Article 33 (2) of the GDPR.”

Subcontracting and Subprocessors, Right to Approve

Require a complete list of subprocessors at signing and a contractual obligation to notify the buyer at least 30 days before any addition or replacement. Insist on a right to object with cause, and if the vendor proceeds despite the buyer’s objection, there should be the right to terminate the contract without penalty. 

IP Ownership, Licences, and Third-Party IP Indemnities

The default position in most SaaS agreements is that the vendor retains all IP and grants the buyer a limited, revocable licence. This is generally acceptable for the core platform, but becomes problematic when the buyer commissions bespoke modules, integrations, or data models.

Negotiate a clear IP indemnity: the vendor should defend the buyer against third-party IP infringement claims arising from authorised use of the service, at the vendor’s cost and with an obligation to procure a licence, modify the service, or refund fees if the claim succeeds.

Suggested redline: “Supplier shall indemnify, defend and hold harmless the Customer against any third-party claim that the Customer’s use of the Service in accordance with this Agreement infringes any patent, copyright, trade mark or trade secret of a third party.”

Confidentiality and Trade Secrets

Standard mutual confidentiality provisions are usually acceptable, but ensure they survive termination for a reasonable period (typically three to five years, or indefinitely for trade secrets). Under Finnish law, the Trade Secrets Act (liikesalaisuuslaki, 595/2018) provides additional statutory protection, but contractual obligations remain the first line of defence.

Liability Caps, Indemnities and Insurance in Finland

Liability allocation is often the most heavily contested area when businesses negotiate and draft SaaS IT contracts in Finland. Vendors want low caps and broad exclusions; buyers need protection proportionate to the risk.

Under Finnish law, parties enjoy broad freedom of contract, but Section 36 of the Contracts Act (228/1929) permits a court to adjust a contract term, or disregard it entirely, if enforcing it would be unreasonable. In practice, this means that an extremely low liability cap in a high-value, high-risk SaaS engagement could be challenged, though it is far better to negotiate a reasonable cap than to rely on judicial intervention.

Typical vendor position Buyer negotiation target Rationale / when to accept
Cap = fees paid in prior 12 months Cap = 12–24 months’ fees, or uninsured-loss carveouts Use the higher cap where the service is operationally critical or data-breach risk is material
Blanket exclusion of indirect / consequential damages Carve out GDPR fines, IP indemnity claims, and personal injury from the exclusion Regulatory fines and IP losses should never be subject to a low general cap
Unlimited liability for gross negligence / willful misconduct Keep unlimited for willful misconduct; negotiate objective definitions Finnish courts read in reasonableness, but keep exceptions narrow and well-defined

Suggested redline: “The aggregate liability of each Party under this Agreement shall not exceed [X] times the total Fees paid and payable in the twelve (12) months preceding the event giving rise to liability; provided that the foregoing cap shall not apply to (a) breaches of data protection obligations, (b) IP infringement indemnities, (c) willful misconduct or gross negligence, or (d) death or personal injury.”

Data Handling and Transfers, GDPR and Finland-Specific Obligations

Finland’s Data Protection Act (1050/2018) supplements the GDPR and designates the Data Protection Ombudsman as the national supervisory authority. In practice, this means the buyer’s SaaS DPA must satisfy both EU-wide and Finnish national requirements.

Cross-Border Transfers and Standard Contractual Clauses

Any transfer of personal data to a country outside the EEA that lacks an adequacy decision must rely on an approved transfer mechanism. The European Commission’s Standard Contractual Clauses (SCCs), adopted under Implementing Decision (EU) 2021/914, remain the most widely used safeguard. In my contracts, I require the following clause:

Suggested redline: “Where the Processor or any Subprocessor transfers Personal Data outside the EEA, it shall ensure that such transfer is subject to (a) an adequacy decision pursuant to Article 45 of the GDPR, or (b) Standard Contractual Clauses adopted pursuant to Commission Implementing Decision (EU) 2021/914, supplemented by a documented transfer impact assessment.”

Buyers should also request disclosure of the vendor’s transfer impact assessment and verify that supplementary technical measures (encryption in transit and at rest, pseudonymisation) are in place.

Breach Reporting Timelines and Practical Vendor SLAs

Article 33 of the GDPR requires controllers to notify the Data Protection Ombudsman within 72 hours of becoming aware of a personal data breach. To meet this obligation, the buyer needs the vendor to notify well in advance. I recommend a contractual requirement of 24 hours for initial notification, with a full written report (categories of data affected, estimated number of data subjects, remediation steps) within 48 hours.

Data Subject Requests and Cooperation Obligations

Under Article 28(3)(e) of the GDPR, the processor must assist the controller in responding to data-subject access, rectification, and erasure requests. Require the vendor to respond the cooperation requests within a defined time frame (five business days is standard) and at no additional cost, many vendor templates attempt to charge hourly fees for this statutory obligation.

Termination Rights, Exit, Data Return and Transition Assistance

A well-drafted exit clause is as important as the service levels. Without one, the cost of switching providers can exceed the value of the original contract.

What to negotiate:

  • Termination for convenience: The buyer should have the right to terminate on 90 days’ notice, without paying an early-termination fee beyond committed minimums.
  • Termination for cause: Material breach not cured within 30 days, insolvency events, repeated SLA failures, and change of control should all trigger immediate termination rights in SaaS contracts in Finland.
  • Survival clauses: Confidentiality, IP indemnities, data-return obligations, and limitation of liability must survive termination.

Practical Exit Playbook

  • Data export: Require delivery of all customer data in a standard, machine-readable format (CSV, JSON, or API-accessible) within 30 days of termination.
  • Verification period: Allow 15 business days after export to verify completeness and integrity before the vendor deletes any data.
  • Certified deletion: Require a written certificate confirming deletion of all customer data (including backups) within 60 days of termination.
  • Transition assistance: Negotiate a defined number of hours of transition support at pre-agreed rates, available for up to 90 days post-termination.

Subprocessors, Audits and Security Warranties

Audit rights are an essential tool for verifying that the vendor, and its subprocessors, are meeting their contractual and regulatory obligations. Under Article 28(3)(h) of the GDPR, the processor must make available all information necessary to demonstrate compliance and allow audits, including inspections.

What to negotiate:

  • Right to audit: A contractual right to conduct or commission an independent audit, subject to reasonable notice (30 days), confidentiality obligations, and scope limitations.
  • Vendor reports in lieu: Accept SOC 2 Type II or ISO 27001 audit reports as a primary assurance mechanism, but preserve the right to conduct a direct audit if a material concern arises.
  • Penetration testing: Require the vendor to conduct annual penetration testing and share the results (redacted for other-customer data).
  • Subprocessor notification: Minimum 30 days’ advance notice before engaging or replacing any subprocessor, with a right to object.

Practical Audit Clauses and Limitations

Vendors legitimately push back on unlimited audit rights, they create operational disruption and confidentiality risks. The practical compromise is to limit audits to once per year (unless triggered by a suspected breach), require auditors to sign NDAs, and agree that the audit will be conducted during business hours with minimal disruption. Remote audits or document reviews should be the default, with on-site inspection reserved for serious concerns.

Dispute Resolution and Governing Law

Choosing the right forum is a critical part of IT contract drafting in Finland. My recommendation depends on the nature of the counterparty and the contract value.

For domestic SaaS contracts between Finnish entities, district courts provide a traditional forum for dispute resolution. Proceedings can be conducted in Finnish or Swedish. 

Arbitration: Seat, Language, and Enforcement

For cross-border SaaS contracts or high-value IT engagements, I typically recommend arbitration under the Arbitration Rules of the Finland Chamber of Commerce, seated in Helsinki, with proceedings in English. Arbitration offers confidentiality (important for trade-secret-heavy disputes), speed, and global enforceability under the New York Convention. 

Regardless of forum, insist on a clause preserving each party’s right to seek interim relief (injunctions, freezing orders) from any court of competent jurisdiction, arbitration clauses that prohibit court-ordered interim measures leave the buyer exposed during the weeks before an arbitral tribunal is constituted.

Negotiation Checklist and Sample Clause Bank

Below are twelve sample redline clauses that cover the highest-risk areas when negotiating and draft SaaS IT contracts in Finland. I use variations of these in virtually every procurement engagement.

  1. Scope: “The Service shall conform to the Service Description in Annex [X]. Any deviation requires a signed Change Order.”
  2. SLA measurement: “Uptime is measured monthly using the Supplier’s monitoring platform, accessible to the Customer in real time.”
  3. SLA credits: “If monthly uptime falls below 99.9 %, the Customer is entitled to service credits calculated per the SLA Credit Table in Annex [Y].”
  4. Breach notification: “The Processor shall notify the Controller of a Personal Data Breach within [24] hours of awareness.”
  5. Transfer safeguards: “Transfers outside the EEA shall be subject to SCCs (Commission Decision 2021/914) with a documented transfer impact assessment.”
  6. Subprocessor approval: “The Processor shall provide 30 days’ prior written notice before engaging any new Subprocessor. The Controller may object with cause.”
  7. IP indemnity: “Supplier shall indemnify Customer against third-party IP infringement claims arising from authorised use of the Service.”
  8. Liability cap carveouts: “The aggregate liability cap shall not apply to breaches of data-protection obligations, IP indemnities, or wilful misconduct.”
  9. Termination for convenience: “Customer may terminate on 90 days’ written notice without early-termination fee beyond committed minimums.”
  10. Data export: “Within 30 days of termination, Supplier shall deliver all Customer Data in [CSV/JSON/API] format.”
  11. Audit right: “Customer may audit Supplier’s compliance once per year on 30 days’ notice, or immediately upon a suspected breach.”
  12. Governing law: “This Agreement is governed by the laws of Finland. Disputes shall be resolved by [ e.g., the District Court of Helsinki / arbitration under the FAI Rules].”

Conclusion

The ability to negotiate and draft SaaS IT contracts in Finland effectively comes down to preparation, prioritisation, and precision. Finnish contract law grants parties broad freedom to agree terms, but it also empowers courts to intervene when those terms are unreasonable. The practical implication is clear: invest in the negotiation and drafting phase rather than relying on after-the-fact judicial correction. From SLA credits and liability caps to GDPR-compliant DPAs and exit provisions, every clause discussed in this guide represents a real risk I have seen materialise in client engagements. The checklist and redlines above are designed to give Your team a head start, but for complex or high-value procurements, Finland-specific legal review remains essential.

Need Legal Advice?

For specialist advice on this topic, contact Mikko Junno at Hedman Partners.

Sources

  1. Regulation (EU) 2016/679 (GDPR), EUR-Lex
  2. Contracts Act (228/1929), Finlex
  3. European Commission, Standard Contractual Clauses (SCCs)

FAQs

Can I negotiate a vendor's standard SaaS contract?
Yes. Most SaaS vendors will negotiate on price, contract term, user counts, SLAs, and key liability and data-protection clauses, particularly for enterprise or mid-market deals. The key is to prioritise your redlines based on risk rather than attempting to rewrite every provision.
Under Article 28 of the GDPR, the DPA must define the roles of controller and processor, the subject matter and purpose of processing, categories of data subjects and personal data, subprocessor authorisation rules, international transfer safeguards (such as SCCs), technical and organisational security measures, breach-notification obligations, and cooperation duties for data-subject requests.
A common vendor starting position is a cap equal to fees paid in the prior twelve months. Buyers should negotiate for a cap of twelve to twenty-four months’ fees, with carveouts that exclude GDPR breaches, IP indemnity claims, wilful misconduct, and personal injury from the cap entirely.
Define measurable metrics (e.g., monthly uptime percentage), a clear measurement methodology, a tiered credit schedule linked to severity, and a termination right triggered by repeated failures. Credits alone are rarely sufficient compensation, tie them to a remediation obligation and escalation path.
Yes, especially for high-risk data processing. The GDPR requires processors to allow audits. In practice, accept SOC 2 Type II or ISO 27001 reports as primary assurance, but preserve a contractual right to commission an independent audit if a material concern or suspected breach arises.
For domestic agreements, the District Court of Helsinki is efficient and cost-effective. For cross-border or high-value contracts, arbitration under the Finland Chamber of Commerce rules, seated in Helsinki and conducted in English, offers confidentiality and global enforceability.
Lim Tat: Singapore's Premier Dispute Resolution Expert Renewed by Global Law Experts | GLE News
By Global Law Experts

posted 5 hours ago

debt recovery enforcement judgment work malaysia
By Sanjiv Naddan

posted 7 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Negotiate and Draft SaaS & IT Contracts in Finland

Send welcome message

Custom Message