Software as a service (SaaS) has become a popular way for businesses to access technology: from email, accounting and HR management to CRM and e-commerce platforms. Instead of buying software outright and operating their own servers, businesses pay subscription fees to use software running on the vendor’s infrastructure. This model is convenient but creates deep dependence on the vendor and distinct legal risks.
A SaaS contract cannot be drafted like an ordinary sale-of-goods contract. Businesses need to understand the legal nature of the transaction, the key terms on services and data, and the tax issues when the vendor is located abroad.
Quick Summary
| Legal basis | Civil Code 2015; Commercial Law 2005; Article 7 of Decree 356/2025/ND-CP; foreign contractor tax regulations |
|---|---|
| Key point | Measurable SLA; clear data and termination terms; note foreign contractor tax for cross-border SaaS |
| Audience | Businesses purchasing or leasing SaaS software domestically and internationally |
SaaS from a Legal Perspective: Service Subscription or Software Purchase?
In essence, SaaS is a services contract: the vendor allows the business to access and use software running on its own infrastructure via the internet, in exchange for periodic subscription fees. The business does not own the software, receives no source code handover, and generally cannot control the technical infrastructure where its data is stored and processed.
This characterization has important legal consequences. Because it is not a sale of goods, goods-warranty rules do not apply directly; instead, service quality is governed by the service level agreement (SLA) agreed by the parties. Because data resides on the vendor’s systems, the business depends entirely on contractual commitments regarding security, data return and deletion.
What Makes SaaS Contracts Distinct from Traditional Software Purchases
Unlike an outright software purchase, a SaaS contract is an ongoing relationship: the vendor is obliged to keep the service running stably throughout the subscription period, update features and patch security vulnerabilities. The business pays periodic fees and can scale usage up or down. This continuity requires the contract to accommodate changes during performance: increasing or decreasing user numbers, upgrading service tiers, changing features.
The second distinction is technical dependence: the business’s data and business processes “live” on the vendor’s systems. When switching to another vendor, the business faces high switching costs and the risk of data loss. Terms on transition support and data return upon termination should be negotiated from the outset, when the business’s bargaining position is strongest.
Legal Framework for SaaS Contracts in Vietnam
Vietnamese law has no dedicated instrument governing SaaS contracts. These relationships are subject to the general regime of the Civil Code 2015 on services contracts and the Commercial Law 2005 where the parties are traders. Where SaaS processes personal data, the Law on Personal Data Protection 2025 and Decree 356/2025/ND-CP apply, particularly the data processing agreement rules in Article 7 of Decree 356.
Where the SaaS vendor is located abroad, two further issues arise: cross-border transfers of personal data where the business’s data is stored and processed on servers outside Vietnam; and foreign contractor tax obligations on payments to the foreign vendor. Certain specialized sectors such as finance and banking may have their own rules on cloud computing and data storage.
Scope of Services and Service Level Agreement (SLA)
The scope of services should be described specifically in the contract or an appendix: the modules and features used; the number of users; storage capacity; accompanying support services such as training and technical support. For tiered service packages, the conditions and costs of upgrading or downgrading should be stated clearly.
The SLA is the most important quality commitment: uptime ratio, incident response and remediation time, and support request handling time. The SLA needs an objective measurement mechanism and sanctions when the vendor fails to meet commitments, typically a proportional reduction of service fees.
Data Terms in SaaS Contracts
Because the business’s data sits on the vendor’s systems, data terms are indispensable. The contract should clearly establish: the business owns its data; the vendor may only use the data to provide the services under the contract, and may not use it for its own purposes such as aggregated analytics or model training without consent; and the specific data storage location, including whether data is stored abroad.
Where SaaS processes personal data, a data processing agreement consistent with Article 7 of Decree 356/2025/ND-CP is needed, identifying the controller and processor roles and their respective obligations. Data return and deletion terms upon termination must also be detailed: return format, return deadline, the deadline for deleting copies after return, and written confirmation of deletion (see also Technology vendor review and cybersecurity in Vietnam).
Security and Incident Response in SaaS Contracts
SaaS contracts should prescribe the vendor’s specific security obligations rather than generic commitments: data encryption measures; access controls; vulnerability patching procedures; data backup and recovery. For systems processing critical data, businesses may require the vendor to maintain information security certifications and provide periodic audit reports.
On incident response, the contract should set the deadline for the vendor to notify the business upon discovering an incident affecting the business’s data, because the business needs time to fulfill its own notification obligations under personal data protection regulations. Responsibilities for investigation cooperation, remediation and cost allocation should be clearly defined. Businesses should also have the right to inspect and assess the vendor’s system security in defined circumstances.
Pricing, Payment and Tax Issues in SaaS
SaaS pricing typically comprises periodic subscription fees based on user numbers or usage levels, plus initial implementation, training and customization fees. The contract should clearly set the conditions for price adjustments: when the vendor may raise prices, how much advance notice is required, and the business’s rights when it does not accept the new price. There should be a transparent pricing mechanism for scaling up to avoid being overcharged once dependent.
For SaaS from foreign vendors, Vietnamese businesses should note foreign contractor tax obligations on outbound payments. The characterization of SaaS payments may differ depending on the transaction structure, affecting the applicable tax obligations. This is a complex technical issue — businesses should consult tax specialists before signing to avoid later assessments and penalties.
Term, Renewal and Termination of SaaS Contracts
SaaS contracts typically run from one to three years with automatic renewal clauses. Businesses should read the renewal mechanism carefully: the notice period for declining renewal, and the consequences of missing the notice (usually renewal for another term at new prices). An internal tracking system for renewal and termination milestones of all active SaaS contracts is advisable.
Termination terms should cover all cases: expiry, early termination for breach, and termination for convenience. Most important are the vendor’s post-termination obligations: maintaining the service during a reasonable transition period; supporting data export; deleting all copies after completion.
Intellectual Property and Use Restrictions in SaaS Contracts
SaaS contracts should clearly allocate intellectual property rights: the software and platform belong to the vendor, and the business is only licensed to use them within the permitted scope; conversely, data and content created by the business on the system belong to the business. For customizations and configurations performed specifically for the business, post-termination usage rights should be agreed.
The license typically comes with restrictions: user numbers, prohibition on account sharing, prohibition on reverse engineering, and prohibition on using the service to compete with the vendor. Businesses should assess whether these restrictions fit their actual operational needs, particularly for businesses with many shared accounts or deep integration needs with internal systems.
Common Risks When Signing SaaS Contracts
The most common risk is signing the vendor’s template without negotiation: vendor templates are typically drafted in the vendor’s favor with a weak SLA, low liability caps and thin data terms. The second risk is having no exit plan: when switching vendors, the business discovers data cannot be exported in a usable format, or switching fees are prohibitively high.
The third risk concerns unilateral changes: many contracts allow the vendor to change service terms and pricing policies with mere notice on its website. The fourth risk is the vendor ceasing business or being acquired, with the service discontinued or changed adversely. Businesses should negotiate terms on change notifications with reasonable lead time and termination rights when changes are adverse.
How FLAT LAW FIRM Supports Businesses
FLAT LAW FIRM supports businesses throughout the SaaS contract lifecycle: reviewing and negotiating contracts with domestic and foreign vendors; drafting terms on SLA, data, security, termination and transition; building data processing agreement templates for technology contracts; advising on tax obligations for payments to foreign vendors.
When disputes with SaaS vendors arise, we support negotiation, mediation and dispute resolution. We work in Vietnamese, Chinese and English. See also Contracts and risk governance when using AI and Data and technology compliance checklist.
Frequently Asked Questions
How does a SaaS contract differ from a software purchase contract?
SaaS is an ongoing services contract: the business pays subscription fees to use software on the vendor’s infrastructure, owning neither the software nor the source code. Quality is governed by the SLA agreed by the parties, and data and termination terms are of special importance.
Which terms matter most in a SaaS contract?
An SLA with measurable indicators and sanctions for breach; terms on data ownership, use, return and deletion; security and incident notification obligations; termination and transition support terms. Do not sign the vendor’s template without negotiating these.
Who owns data on a SaaS system?
Data created by the business belongs to the business. The contract must state this clearly, prohibit the vendor from using data for its own purposes without consent, and provide for data return and deletion upon termination.
What should I note when buying SaaS from a foreign vendor?
Assess cross-border data transfer obligations where data is stored on servers abroad, data hosting location terms, and foreign contractor tax on outbound payments. Consult tax specialists before signing.
How do I switch to another SaaS vendor?
Transition support terms should be in the original contract: post-termination service duration, data export format, switching fees and copy deletion obligations. Back up data regularly to reduce dependence.
Talk to FLAT LAW FIRM
If your business is negotiating a SaaS contract or needs to review existing technology contracts, FLAT LAW FIRM is ready to assist in Vietnamese, Chinese and English.
