[codicts-css-switcher id=”346″]

Global Law Experts Logo
negotiate saas agreement under romanian law

How to Negotiate a Saas Agreement Under Romanian Law

By Razvan Alexandru Olaru
– posted 1 week ago

  1. Whether you are a buyer procuring a cloud platform for Romanian operations or a vendor selling into the Romanian market, knowing how to negotiate a SaaS agreement with a Romanian nexus is one of the most important steps you can take before signing. Romania sits at the intersection of directly applicable EU frameworks—principally the GDPR—and its own Civil Code contract rules, creating a negotiation landscape that rewards preparation and exposes vague drafting. At Olawru, I routinely advise both sides of the table on SaaS contracts governed by Romanian law or otherwise connected to Romania, and this guide distils the clause-by-clause playbook I use in practice.

    Below I set out the six pillars every negotiator should address, complete with sample language, buyer and vendor positions, and Romanian-specific legal considerations that generic guides may not cover.

    SaaS negotiation checklist for Romania, at a glance

    • Scope and service definition. Pin down what the SaaS service includes, who may use it, and how changes are controlled.

    • Service levels and remedies. Set measurable SLAs with clearly drafted credits and escalation triggers.

    • Data protection. Include the terms required by Article 28 GDPR where the vendor acts as a processor, map restricted international transfers, and align with applicable EDPB guidance, Romanian data protection legislation and, where relevant, ANSPDCP practice.

    • Security and audit rights. Define technical and organisational measures, audit arrangements, and proportionate protections for vendor confidentiality and third-party data.

    • Liability, indemnities and insurance. Agree on liability caps, appropriate carve-outs, and insurance levels calibrated to the contract and risk profile.

    • Exit assistance and data portability. Guarantee data return in a usable format, transition support, and deletion or return obligations at contract end.

    Understanding the Commercial Scope and Parties

    The foundation of any SaaS contract in Romania is a precise definition of the service. A poorly drafted scope clause is a common source of disputes because it creates ambiguity about what the vendor is obliged to deliver and what the buyer is entitled to receive.

    Defining the service

    A SaaS agreement may combine access or licence elements with hosting, maintenance, support and other service obligations; its legal treatment under the Romanian Civil Code depends on its actual content, rather than its label alone. Clarify whether the vendor is providing access to a standard multi-tenant platform, a single-tenant hosted instance, or a managed service with customisation. Each model should be reflected in different contractual commitments regarding uptime, data isolation, update management, support and responsibility allocation.

    Licensed users vs named users

    Specify whether licences are per named user, per concurrent user, or based on consumption metrics such as API calls, storage or transactions. Include a mechanism for overage billing, reporting frequency and reconciliation. In my experience, disputes about user counts often escalate when the contract fails to define “active user” versus “provisioned user.”

    Change control procedure

    Romanian contract law recognises freedom of contract, but material changes to the agreed service scope should flow through a documented change control procedure. At minimum, the contract should require:

    • written change requests with an impact assessment covering cost, timeline and scope;

    • mutual written approval before a change to the agreed scope takes effect, except for updates expressly permitted by the contract; and

    • a versioning mechanism for the service description annex.

    Sample clause, buyer-lean: “No amendment to the Service Description shall take effect unless approved in writing by both parties. Except for changes expressly permitted under this Agreement, the Vendor shall provide at least 30 days’ prior notice of any material change to functionality, including an impact assessment.”

    Sample clause, vendor-lean: “The Vendor may update the Service in its discretion, provided that such updates do not materially reduce the core functionality purchased by the Customer. The Vendor shall notify the Customer of material changes through the agreed notice channel.”

    Negotiating Service Levels, Monitoring and Remedies

    Service level agreements are the commercial backbone of a SaaS contract. Under Romanian law, a service credit may operate as a price adjustment or, depending on its substance and drafting, may be characterised as a penalty clause (clauză penală) governed by Articles 1538–1543 of the Romanian Civil Code. If it is a penalty clause, a court may reduce it only in the circumstances set out in Article 1541, including where it is manifestly excessive in relation to the loss the parties could have foreseen when concluding the contract. Getting the structure right matters.

    SLA measurement and reporting

    Define uptime as a percentage of available minutes during a stated measurement period, commonly a calendar month, and specify the agreed exclusions, including scheduled maintenance and customer-caused downtime. Identify the measurement tool, the applicable time zone, the hierarchy between vendor and independent monitoring data, and the procedure and time limit for disputing availability calculations. Buyers may also seek a status dashboard and periodic availability reports.

    Remedies and limitations

    Service credits are a common contractual remedy, but Romanian law does not prescribe a statutory uptime target, credit percentage or claim window. The agreement should state whether credits are automatic or claim-based, whether they are a price adjustment or agreed compensation, how they interact with damages and termination rights, and whether they are the exclusive remedy for the relevant SLA failure. Calling a credit a “pre-estimate of loss” does not, by itself, determine its legal character or prevent judicial review where the clause operates in substance as a penalty clause.

    The following matrix is illustrative only; it is neither a statutory rule nor a verified Romanian market benchmark:

    Illustrative availability tier Possible remedy Illustrative negotiation positions (Buyer / Vendor)
    ≥ 99.95% Pro rata service credits, capped for the measurement period Buyer: automatic credits plus reporting. Vendor: cap credits at an agreed percentage of the affected recurring fee and require claims within a defined period.
    99.9% Tiered service credit plus a limited additional remedy Buyer: partial termination right after repeated failures. Vendor: tiered credits without an immediate termination trigger.
    < 99.9% Enhanced remedies, potentially including termination for repeated or material failure Buyer: a short cure period followed by termination for cause. Vendor: written notice, a reasonable cure window and a materiality threshold.

    Escalation matrix

    Beyond credits, include an escalation matrix that maps severity levels to response, update and target resolution times. For illustration, a Severity 1 incident involving unavailability of a critical service might require a response within one hour and regular status updates until resolution; the appropriate times depend on service criticality, support coverage and price. Operationally, escalation is clearer when it identifies roles or escalation contacts on both sides rather than relying solely on generic support queues.

    Sample clause, buyer-lean: “If Availability falls below 99.9% for any two consecutive calendar months, the Customer may terminate the affected Service Order on 15 days’ written notice and receive a pro rata refund of prepaid fees for the period after termination.”

    Sample clause, vendor-lean: “Subject to any termination right expressly set out in this Agreement, Service Credits shall be the Customer’s sole and exclusive monetary remedy for failure to meet the SLA. Credits shall not exceed 15% of the monthly recurring fee for the affected Service.”

    Data Protection and Restricted International Transfers

    The GDPR applies directly in Romania and is supplemented by Romanian legislation, including Law No. 190/2018, as well as sector-specific rules where applicable. ANSPDCP is the Romanian supervisory authority, subject to the GDPR’s competence and one-stop-shop framework.

    Article 28 terms

    Where the customer is a controller and the vendor processes personal data on its behalf, Article 28 GDPR requires a binding contract or other legal act. This may be a standalone Data Processing Addendum or appropriately integrated provisions in the main agreement. The terms should, at a minimum, cover:

    • the subject matter and duration of processing;

    • the nature and purpose of processing;

    • the types of personal data and categories of data subjects;

    • the controller’s obligations and rights;

    • processing only on documented controller instructions, including the processor’s duty to inform the controller if an instruction infringes applicable data protection law, unless prohibited from doing so by law;

    • confidentiality, security, assistance, return or deletion, information and audit obligations; and

    • sub-processor requirements.

    Article 28(2) permits specific or general prior written authorisation for sub-processors. A buyer may therefore seek an up-to-date sub-processor list, advance notice of proposed changes and a reasonable objection procedure. A 30-day objection period is a negotiable drafting option, not a statutory period.

    Cross-border transfer options

    When a disclosure or remote access constitutes a transfer of personal data to a third country or international organisation, Chapter V GDPR requires an applicable transfer basis. Relevant options include:

    • Adequacy decisions. Transfers covered by a valid European Commission adequacy decision do not require an additional Chapter V transfer tool, although the other GDPR obligations continue to apply.

    • Standard Contractual Clauses. The European Commission’s SCCs remain a widely used transfer tool. Their use may require a transfer impact assessment and supplementary measures, depending on the law and practices of the destination country and the circumstances of the transfer.

    • Binding Corporate Rules. BCRs may be suitable for intra-group transfers once approved through the applicable supervisory process.

    • Other Chapter V mechanisms and derogations. These may be available in the circumstances specified by the GDPR but should not be treated as interchangeable or automatically suitable.

    For Romanian customers, map the location and role of each processor and sub-processor, identify the data flows and determine the transfer mechanism for each restricted transfer. ANSPDCP may exercise GDPR corrective powers within its competence, including ordering a suspension of data flows to a recipient in a third country or international organisation.

    Breach notification and cooperation

    Under Article 33 GDPR, the controller must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to individuals’ rights and freedoms. The processor must notify the controller without undue delay after becoming aware of a personal data breach. A contractual outer limit, such as 24 or 48 hours, is a negotiated risk allocation and not the statutory GDPR deadline applicable to processors.

    Sample clause, buyer-lean: “The Processor shall notify the Controller of any Personal Data Breach without undue delay and in any event within 24 hours after becoming aware of it. The initial notification shall contain the information then reasonably available, and the Processor shall provide further information in phases without undue delay, as necessary to enable the Controller to comply with Articles 33 and 34 GDPR.”

    Sample clause, vendor-lean: “The Processor shall notify the Controller of any Personal Data Breach without undue delay and in any event within 48 hours after becoming aware of it, providing the information then reasonably available and supplementing that information without undue delay as the investigation progresses.”

    Security Obligations, Audits and Vendor Protections

    Article 32 GDPR requires controllers and processors to implement technical and organisational measures appropriate to the risk. What is appropriate depends on the context, nature, scope and purposes of processing, the state of the art, implementation costs and the risks to individuals. Sector-specific cybersecurity and operational-resilience rules may impose additional obligations.

    Acceptable audit scope and process

    Where Article 28 applies, the processor must make available the information necessary to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by the controller or an auditor mandated by it. The agreement may organise this right proportionately but should not extinguish the statutory right. A balanced framework may address:

    • Frequency: one routine audit per 12-month period, with additional audits following a personal data breach, material compliance concern or supervisory request.

    • Scope: systems, processes and locations relevant to processing the customer’s personal data, while protecting unrelated customer data, security and confidential information.

    • Confidentiality and competence: auditors should be independent, suitably qualified and subject to appropriate confidentiality and security obligations.

    • Evidence-first process: current independent reports or certifications may be supplied first, but they should not automatically replace a further audit where the evidence is insufficient for a specific, documented concern or a competent authority requires more.

    Security commitments and incident response

    Beyond general references to technical and organisational measures, specify risk-appropriate encryption, access controls, key management, backup and recovery objectives, vulnerability management, security testing, logging, incident response and business continuity. If particular protocols are named—for example, AES-256 or an equivalent current standard for data at rest and TLS 1.2 or later for data in transit—the contract should include a mechanism for updating obsolete standards; TLS 1.3 should be preferred where technically supported and appropriate.

    Certifications and assurance reports

    Romanian law does not impose ISO/IEC 27001 certification or a SOC 2 Type II report as a general condition for every SaaS vendor. Such evidence is, however, commonly requested in enterprise transactions and may reduce the need for duplicative assurance work. It does not, by itself, prove compliance with every contractual or legal obligation. Regulated sectors and particular services may be subject to additional requirements, which must be assessed separately.

    Sample audit clause, balanced: “The Customer may, at its own cost, audit the Vendor’s compliance with this Agreement and applicable data protection law once per calendar year on 30 days’ written notice, subject to additional audits following a Personal Data Breach, a material documented compliance concern or a competent authority request. The Vendor may initially respond by providing relevant, current independent audit reports or certifications. If those materials do not reasonably address the identified concern, the Vendor shall permit a proportionate further audit or inspection, subject to appropriate confidentiality, security and non-disruption safeguards.”

    IP, Licensing and Escrow Considerations

    Intellectual property allocation should be explicit. Under Law No. 8/1996, copyright initially vests in the author, subject to statutory rules and exceptions; notably, in the absence of a contrary clause, the economic rights in computer programs created by employees in the course of their duties or following the employer’s instructions belong to the employer. Any assignment or licence should identify the relevant rights, scope, modes of use, duration, territory and remuneration where required, and should comply with the statutory evidentiary and content requirements.

    Customer data vs metadata

    The agreement should state that, as between the parties, the customer retains all rights and interests it has in Customer Data and grants the vendor only the rights necessary to provide the service and perform other specifically agreed purposes. Data—particularly personal data—should not be presented as a single, undifferentiated object of “ownership”; intellectual property, confidentiality, database rights and data protection roles must be addressed separately. Vendor use of Customer Data for model training, benchmarking or analytics should be separately and specifically authorised where intended and must have an applicable legal basis where personal data is involved. The vendor may use aggregated data only within the agreed limits; data described as anonymised must in fact meet the applicable anonymisation standard, while pseudonymised data remains personal data under the GDPR.

    Escrow triggers and mechanics

    A Romanian buyer has no statutory right to compel source-code escrow. The parties may nevertheless agree an escrow arrangement, which may be enforceable subject to ordinary contract, intellectual property and insolvency rules. The clause should define the deposited materials, update and verification obligations, the escrow agent, release triggers, licence rights after release, permitted use and the effect of insolvency. Typical negotiated triggers may include vendor insolvency, prolonged failure to maintain a mission-critical service or a material unremedied breach.

    Liability, Indemnities and Insurance

    Liability clauses under Romanian law must take account of the Civil Code rules on damages and contractual liability, including Articles 1530–1537, together with mandatory limits on exclusions and caps. In particular, Article 1355 prevents the exclusion or limitation of liability for material damage caused intentionally or through gross negligence and restricts limitations concerning physical or mental integrity or health.

    Limitation of liability drafting

    An aggregate cap expressed by reference to fees paid or payable over a defined period is a common negotiating structure, but Romanian law does not prescribe a statutory “market” multiple for SaaS contracts. Carve-outs and sub-caps should therefore be calibrated to the contract value, foreseeable loss, service criticality, data sensitivity, insurance and mandatory law.

    The following figures are illustrative negotiating positions only; they are neither statutory limits nor verified Romanian market benchmarks:

    Liability category Illustrative position Negotiation considerations
    General aggregate cap 6–12 months’ recurring fees Buyer: seek a higher cap where the service is critical or prepaid. Vendor: align the cap with recurring revenue and insurable exposure.
    Data protection or security Enhanced sub-cap, or uncapped for narrowly defined risks Contractual allocation does not remove either party’s regulatory responsibility toward authorities or data subjects. Define the covered losses and interaction with insurance.
    Third-party IP infringement Enhanced sub-cap or uncapped indemnity Include control of defence, settlement consent, exclusions for customer materials or modifications, and mitigation rights such as modifying, replacing or terminating the affected service.
    Intentional fault or gross negligence Outside the cap to the extent required by mandatory law The agreement should expressly preserve liability that cannot legally be excluded or limited, including the Article 1355 restrictions.

    Insurance

    Require professional indemnity and cyber insurance only at levels proportionate to the contract value, service criticality, categories and volume of data, plausible loss scenarios and available market coverage. Avoid presenting a fixed EUR amount as a Romanian legal requirement or universal market standard. Any additional-insured or loss-payee requirement should be checked against the actual policy wording and insurer practice.

    Pricing, Termination and Exit Assistance

    SaaS exit assistance is often neglected during negotiation, even though it becomes critical when the relationship ends. Whether termination is for cause or convenience, the buyer needs a defined transition pathway and the vendor needs clear limits on duration, scope, dependencies and charges.

    Exit assistance

    Define an exit-assistance period appropriate to migration complexity; three to six months may be a negotiating starting point for some services, not a legal or universal market standard. Specify the export format—such as CSV, JSON, API-based extraction or database dump—together with data dictionaries, frequency of exports, support obligations, migration testing, security and charges. State whether continued service during transition is included or billed separately.

    Data handover checklist

    An exit schedule may include:

    • export of Customer Data in the agreed format within a defined period after termination;

    • return or deletion of Customer Data in accordance with the agreed retention schedule, applicable law and the documented backup cycle, together with a written certification where appropriate;

    • return or destruction of confidential information, subject to lawful archival and legal-hold exceptions; and

    • proportionate cooperation with a replacement vendor, subject to confidentiality, security and agreed fees.

    Sample clause, buyer-lean: “Upon termination or expiry, the Vendor shall provide Exit Assistance Services for a period of six months at no additional charge. During this period, the Vendor shall export all Customer Data in the agreed documented format and reasonably cooperate with a replacement service provider designated by the Customer, subject to appropriate confidentiality and security safeguards.”

    Sample clause, vendor-lean: “Exit Assistance Services shall be available for up to three months following termination at the Vendor’s then-current professional services rates. Data export shall be limited to the documented formats supported by the platform at the date of termination, and the Customer shall remain responsible for timely migration and third-party costs.”

    Dispute Resolution and Enforcement

    Governing law and jurisdiction are distinct questions. Choosing Romanian law does not, by itself, confer jurisdiction on Romanian courts. Jurisdiction in cross-border civil and commercial matters must be determined under the applicable jurisdiction rules, including Regulation (EU) No. 1215/2012 where it applies, and any valid choice-of-court agreement. Arbitration may be agreed for arbitrable disputes, subject to applicable formal, consumer-protection and public-policy limits.

    Enforceability considerations and interim relief

    For some cross-border, higher-value or confidentiality-sensitive deals, arbitration under the rules of the Court of International Commercial Arbitration attached to the Chamber of Commerce and Industry of Romania, with Bucharest as the seat, may be appropriate. The decision should also consider likely claim value, cost, urgency, technical complexity, confidentiality and enforcement geography. Romania is a party to the New York Convention, but recognition and enforcement remain subject to the Convention and the applicable Romanian procedural rules; enforcement should not be described as automatic.

    For urgent matters, such as measures intended to preserve evidence, prevent data destruction or restrain misuse of intellectual property, the clause should preserve access to interim or protective measures from a competent court to the extent permitted by applicable law and the chosen arbitration rules.

    Sample clause, balanced: “This Agreement shall be governed by and construed in accordance with the laws of Romania. Any dispute arising out of or in connection with this Agreement shall be finally settled by arbitration administered by the Court of International Commercial Arbitration attached to the Chamber of Commerce and Industry of Romania in accordance with its Rules. The seat of arbitration shall be Bucharest, Romania. Nothing in this clause shall prevent either party from seeking interim or protective relief from a court of competent jurisdiction, to the extent permitted by applicable law.”

    Conclusion: Your SaaS Contract Negotiation Playbook

    To negotiate a SaaS agreement under Romanian law, treat the contract as six interconnected negotiations: scope, SLAs, data protection, security, liability and exit. Each must be calibrated to the actual service and aligned with applicable Civil Code rules, GDPR obligations and any sector-specific requirements. In my practice, contracts tend to work best where both sides use a structured term sheet, identify non-negotiables early, and treat sample language as a starting point rather than a substitute for transaction-specific drafting.

    If you are entering a SaaS negotiation with a Romanian dimension, whether as buyer or vendor, consider engaging specialist technology counsel early; correcting an unclear contract after implementation or during a dispute may cost more than addressing the issues during negotiation. Technology-law specialists for Romania can be identified through relevant professional directories, including the GLE lawyer directory.

    Need Legal Advice?

    For specialist advice on this topic, contact Razvan Alexandru Olaru at Olawru.

    Sources and legal materials consulted

    • Romanian Civil Code, Law No. 287/2009, including Articles 1169, 1355 and 1530–1543.

    • Law No. 8/1996 on Copyright and Related Rights, including Articles 41–42 and 75.

    • Regulation (EU) 2016/679 (GDPR), including Articles 28, 32, 33, 44–49 and 58.

    • Romanian Law No. 190/2018 on measures implementing the GDPR.

    • EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR.

    • EDPB Opinion 22/2024 on obligations arising from reliance on processors and sub-processors.

    • EDPB Recommendations 01/2020 on supplementary measures for international transfers.

    • European Commission Decision (EU) 2021/914 on Standard Contractual Clauses for transfers to third countries.

    • Regulation (EU) No. 1215/2012 (Brussels I bis) on jurisdiction and the recognition and enforcement of judgments in civil and commercial matters.

    • Regulation (EC) No. 593/2008 (Rome I) on the law applicable to contractual obligations.

    • Romanian Code of Civil Procedure provisions on arbitration and recognition and enforcement of foreign arbitral awards.

    • New York Convention on the Recognition and Enforcement of Foreign Arbitral Awards (1958).

FAQs

What clauses are most important when negotiating a SaaS agreement in Romania?
The core provisions are: a precise service description; authorised users and usage metrics; change control; measurable SLAs and remedies; fees and indexation; data protection roles and Article 28 terms; international-transfer arrangements; security and incident response; audit rights; IP and permitted data use; confidentiality; liability and indemnities; insurance where justified; suspension and termination; exit assistance and data return or deletion; and separate governing-law and dispute-resolution clauses. Regulated customers should also identify sector-specific cybersecurity, outsourcing and operational-resilience requirements.
Define the measurement period, formula, time zone, exclusions, monitoring source, severity levels, response and update times, reporting and dispute procedure. State whether service credits are automatic, how they are calculated, whether they are a price adjustment or agreed compensation, and whether they are exclusive. Romanian law sets no general statutory uptime percentage or credit cap. If a credit functions as a penalty clause, Articles 1538–1543 of the Civil Code, including the limited reduction power in Article 1541, may apply.
First determine the parties’ roles for each processing activity. Where the vendor is a processor, include all Article 28 GDPR elements: documented instructions, confidentiality, risk-appropriate security, sub-processor authorisation, assistance with rights requests and GDPR compliance, breach notification without undue delay, return or deletion, provision of compliance information and proportionate audits. Map restricted transfers under Chapter V and specify the transfer tool and supplementary measures where needed. Remember that the controller’s 72-hour authority-notification rule is subject to the statutory risk exception, while the processor’s statutory duty is to notify the controller without undue delay.
A customer may request and negotiate escrow, but it has no general statutory right to impose it unilaterally. A workable clause should identify the materials, update and verification duties, agent, fees, release triggers, post-release licence and use rights, confidentiality and insolvency effects. Escrow is most useful where the service is mission-critical and substitution would be difficult; for standard multi-tenant SaaS, operational continuity and data-portability commitments may sometimes be more practical.
There is no statutory SaaS cap or universally reliable Romanian market percentage. The cap should reflect fees, foreseeable loss, criticality, data risk and insurance. Article 1355 of the Civil Code prevents exclusion or limitation of liability for material damage caused intentionally or through gross negligence and restricts limitations for harm to physical or mental integrity or health. Data-protection caps cannot eliminate regulatory responsibility toward authorities or data subjects. Carve-outs and enhanced sub-caps should therefore be drafted by reference to defined risks rather than copied mechanically from a template.
Romanian law may be sensible where a party, substantial performance, regulated activity or expected enforcement assets are in Romania, or where both sides want a familiar Civil Code framework. Arbitration may suit higher-value, cross-border, confidential or technically complex disputes, but its costs and likely claim values should be assessed. The governing-law clause must be kept separate from the jurisdiction or arbitration clause: choosing Romanian law does not automatically give Romanian courts jurisdiction. Consumer contracts and other protected relationships require additional mandatory-law analysis.
corporate lawyer netherlands
By Global Law Experts

posted 36 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Negotiate a Saas Agreement Under Romanian Law

Send welcome message

Custom Message