Below is a summary of the following online platform laws, the EU Digital Services Act, the European Accessibility Directive and the UK Online Safety Act, the UK Digital Markets Competition and Consumers Act and the EU Revised Product Liability Directive, that will impact SaaS suppliers and SaaS customers in 2026. Some of these laws apply extra-territorially, meaning the laws apply even when a SaaS supplier is not located in the UK or the EU (respectively). It is important to be aware of these new laws in order to assess whether
Continue readingYear: 2025
SaaS Agreements – New EU and UK Data Security Laws
Below is a summary of the following data security laws, the EU Network and Information Systems Directive 2, the EU Digital Operational Resilience Act, the EU Cyber Resilience Act, the EU Critical Entities Resilience Directive and the UK Product Security and Telecommunications Infrastructure Act that will impact SaaS suppliers and SaaS customers in 2025. Some of these laws apply extra-territorially, meaning the laws apply even when a SaaS supplier is not located in the UK or the EU (respectively).
It is important to be aware of these new laws in order to assess whether or not they apply to your particular SaaS business, products and services.
Continue readingSaaS Agreements – New EU and UK Data Laws
Below is a summary of the EU Artificial Intelligence Act, the EU Data Act and the UK Data Use and Access Act that will impact SaaS suppliers and SaaS customers in 2025. These laws will apply extra-territorially, meaning the laws apply even when a SaaS supplier is not located in the UK or the EU (respectively). It is important to be aware of these new laws in order to assess whether or not they apply to your particular SaaS business, products and services. The EU AI Act applies to AI systems and AI models and categorises AI systems into different risk categories.
Continue readingFAQs – Sub-Processor Lists – Transfer Mechanisms
SaaS suppliers and SaaS customers can only lawfully transfer personal data to sub-processors located outside of the UK, Switzerland or the EEA, (make a restricted transfer) if a recognized transfer mechanism is in place to protect the personal data being transferred.
Continue readingSaaS Agreements – DORA – ICT Supplier Obligations
SaaS suppliers obligations under the Digital Operational Resilience Act,(“DORA”), (Regulation (EU) 2022/2554 on digital operational resilience for the EU financial sector), are effective from the 17th of January 2025. From this date DORA provisions must be included in contracts entered into between financial services entities subject to DORA and their third party providers of ICT Services. As SaaS suppliers are third party providers of digital and data services on an ongoing basis they will be third party providers of ICT services if their SaaS customers are regulated by DORA. Both
Continue reading