One of the most important legal issues in SaaS services is clearly determining who owns the data uploaded to the system and to what extent it may be used.
Cloud-based software services (Software as a Service — SaaS) have today become an integral part of business operations for many companies. Yet when SaaS agreements are drafted, attention is often focused on pricing, service levels (SLAs) or technical support provisions, while data ownership and usage rights are frequently left under-addressed.
Yet questions such as who owns the data the customer uploads to the system, for what purposes the service provider may use that data, and what happens to the data once the contract ends, can carry significant legal and commercial consequences for both parties. For that reason, the provisions governing data management should be regarded as among the most critical sections of the contract.
Why Should Data Ownership Be Expressly Addressed?
In a SaaS service, the software provider supplies the infrastructure, while the customer typically enters its own commercial data into the system. This data may include high-value information such as:
- customer information,
- employee data,
- financial records,
- project files,
- commercial documents,
- operational data.
If the contract does not clearly address data ownership, disputes can arise between the parties over what rights each holds in the data. Standard practice is to expressly state that data uploaded by the customer remains the customer's property, with the service provider holding only the processing or access rights necessary to deliver the service.
How Should the Service Provider's Data-Use Authority Be Defined?
Data ownership and the right to use data are not the same concept. A customer owning the data does not mean the service provider can never access it. It is important for the contract to expressly address, in particular:
- for what purposes the data may be accessed,
- the limits of access authority in the context of technical support,
- the scope of data use during maintenance and update processes,
- whether anonymised data may be used for performance analysis or product development,
- whether sub-processors will be involved in data processing activities.
Vague wording can lead to differing interpretations between the parties down the line.
Use of Anonymised Data
Many SaaS providers wish to make use of anonymised data to improve service quality or develop their product. This should be expressly addressed in the contract, clearly setting out:
- the scope of anonymisation,
- which data may be used,
- the purpose of use,
- limits on sharing with third parties.
Acting in compliance with applicable data protection law is particularly important for systems containing personal data.
What Happens to the Data When the Contract Ends?
This is one of the areas most prone to dispute in practice. The contract should clearly answer the following questions:
- In what format will the customer be able to retrieve its data?
- How long will the data be retained?
- When will the service provider delete the data?
- What will happen to backup copies?
- How will deletion be documented?
Failing to address these matters can lead to serious disputes between the parties once the contract ends.
Data Protection Obligations
In SaaS agreements, provisions on data security and the protection of personal data are just as important as data ownership provisions and should be clearly set out. In particular, the following should be included in the contract:
- technical and administrative security measures,
- confidentiality obligations,
- data breach notification processes,
- international data transfers,
- use of sub-processors,
- compliance with applicable data protection law.
These provisions matter not only for reducing legal risk but also for maintaining the trust relationship between the parties.
Common Mistakes in SaaS Agreements
Some of the most frequent mistakes seen in practice include:
- failing to clearly state data ownership,
- granting the service provider excessively broad usage rights,
- failing to address the data-return process at the end of the contract,
- uncertainty regarding the use of anonymised data,
- leaving data security provisions as vague, general statements,
- inadequately addressing obligations under applicable data protection law.
These gaps can create significant legal risk, particularly in cross-border service relationships.
Conclusion
SaaS agreements are not merely documents defining the scope of a software service. They are also core legal texts that govern the parties' rights over data, the limits of its use, and their respective responsibilities.
Setting out data ownership, usage rights and data protection obligations clearly, in a balanced way and suited to the specific transaction, helps ensure legal certainty for both the service provider and the customer. These provisions preserve the customer's control over its data while giving the provider a predictable framework of responsibility.
Frequently Asked Questions
Who owns the data uploaded in a SaaS service?
This is primarily determined by the contract between the parties. Standard practice is to expressly provide that data uploaded by the customer to the system remains the customer's property.
Can the service provider use customer data for product development?
This depends on the usage provisions in the contract and applicable data protection law. It is particularly important that provisions on the use of anonymised data are clearly drafted.
What happens to the data when a SaaS agreement ends?
Setting out in detail how data will be returned, retained or deleted helps prevent disputes between the parties down the line.