Jessica Ingrid Law

Intellectual Property & Contract Lawyer

← Back to Blog

What Your International SaaS Licensing Agreement Needs

What Your International SaaS Licensing Agreement

A SaaS founder closes a deal with a German enterprise customer. The contract is signed, onboarding is scheduled, and then the customer’s legal team reviews the agreement. There’s no data processing agreement. The price clause says nothing about VAT. The governing law is Delaware, with no provision for cross-border enforcement. The deal stalls for six weeks while both sides renegotiate from scratch.

At Jessica Ingrid, this scenario is one of the most common situations we encounter with fast-growing SaaS companies: solid products, outpaced legal infrastructure. What a SaaS licensing agreement should include for international customers is a question every cross-border vendor needs to answer before a deal lands on a foreign legal desk, not after.

A domestic SaaS contract, even a well-drafted one, develops material gaps when it travels outside the US.

This article walks through the essential clauses, organized by category, so you can audit an existing agreement or build a new one with confidence.

License Grant and IP Ownership

Usage rights and IP ownership: getting the foundation right.

The license grant is where most SaaS agreements start, and it’s where vague drafting creates the first problem in cross-border deals. A SaaS agreement isn’t granting ownership of software; it’s granting access to a service.

The license grant clause should define scope precisely:

  • number of authorized users,
  • permitted use cases, territory, and
  • whether sublicensing or API access by third parties is allowed.

These are standard elements in well-drafted international SaaS contracts, and legal teams in many jurisdictions, including those in Korea and Germany, commonly push back on undefined license scope, using that ambiguity as a negotiation lever.

Ownership allocation needs its own section in the agreement, not just a passing reference. The vendor owns the platform, the underlying software, and all improvements. The customer owns their data and any configurations they build inside the platform.

What happens To That Customer Data At Termination? The contract should specify a defined retrieval window, the format data is made available in, and what happens after that window closes. Ambiguity here creates real problems at the end of relationships, especially when a customer is headquartered in a jurisdiction with data sovereignty expectations.

Jurisdiction-specific IP carve-outs are worth including when your customer base spans multiple legal systems. An IP ownership clause that holds up under US law may not carry the same effect in all jurisdictions, this is particularly relevant for anything involving joint development, customization, or derivative works built on your platform.

Where EU or Korean commercial law governs, explicit language addressing these scenarios protects both parties and reduces renegotiation risk.

What your SaaS Licensing Agreement Must Include For International Customers: Data Protection and Cross-border Transfers

Where a SaaS vendor acts as a data processor for EU or UK enterprise controllers, a GDPR-compliant Data Processing Agreement is a legal requirement under Article 28, not a commercial nicety. Without a properly executed DPA in that scenario, you cannot lawfully onboard EU enterprise customers. The DPA needs to cover processing scope and instructions, security measures, subprocessor governance, breach notification timelines, data subject rights assistance, and deletion or return terms at contract end.

EU Standard Contractual Clauses and UK transfer documentation are separate instruments, and both may be required if you’re processing data from both jurisdictions. For most SaaS vendors acting as processors for EU enterprise customers, the correct SCC module is Module 2 (controller-to-processor), where the enterprise customer is the controller and you are the processor.

Incomplete or unsigned SCCs are legally invalid, a drafting error that appears consistently in agreements assembled quickly from templates without specialist review.

For official guidance, see the EU Commission Q&A on the new SCCs, a definitive guide to the new SCCs, and tailored commentary on how the clauses interact with SaaS arrangements in this SaaS-focused SCC guidance.

If you’ve made a commitment to host data in the EU, define exactly what that covers: production data, backups, logs, support tooling, and any subprocessors with access. Vague language like “we store data in Europe” is not a contractual commitment; it’s a marketing claim. Include a current subprocessor list, a change notification mechanism, and a customer objection right for material subprocessor changes.

Enterprise procurement teams in the EU will check every one of these provisions before they approve a vendor. For practical data-residency considerations see resources on GDPR data residency requirements and vendor-focused guidance on GDPR data residency.



Payment Terms, Pricing, and Cross-border Tax Compliance

The billing currency should be stated explicitly in the contract, along with whether prices are fixed in that currency or subject to foreign exchange conversion on a stated reference date. Define invoicing frequency, accepted payment methods, grace periods before late payment interest accrues, and how usage-based overages are calculated and invoiced. For annual contracts, also address what happens mid-term if a customer expands their user count.

The tax clause is where many international SaaS contracts leave both parties exposed. For B2B sales to EU customers with valid VAT numbers, the reverse charge mechanism typically applies: the customer self-accounts for VAT in their country and you don’t charge it.

See a practical overview of whether SaaS is subject to VAT and more on VAT and SaaS. The contract still needs to state clearly whether listed prices are exclusive or inclusive of taxes, and which party is responsible for VAT, GST, withholding tax, or digital services tax in each relevant market. Prices listed as “exclusive of tax” with no further detail create disputes when selling into the EU, UK, Australia, or South Korea, where digital services tax obligations vary considerably by market. Include a clause giving the vendor the right to collect and remit taxes where required by local law, and require customers to provide valid VAT or tax identification numbers as a condition of being invoiced under reverse charge. Also beware the common commercial traps documented in vendor guides to legal pitfalls in SaaS pricing terms and conditions.

Governing Law, Jurisdiction, and Dispute Resolution

Commonly chosen governing law options in international SaaS agreements include English law, prominent US choices such as Delaware or New York law, and sometimes the customer’s home EU member state law. US tech vendors typically prefer Delaware or New York. EU enterprise customers often push for their home jurisdiction, partly because GDPR compliance arguments sit more naturally under EU law. English law has become the de facto neutral choice for cross-border commercial contracts because it’s well-developed, predictable, and gives neither party a home-court advantage.

English law paired with ICC or LCIA arbitration is the most balanced structure for international SaaS deals, and for good reason. Litigation judgments from US courts are not automatically enforceable in the EU or Korea. Binding arbitration under the New York Convention offers materially better cross-border enforceability, which matters when you actually need to collect on a judgment or enforce a contract term. One critical drafting point: governing law and dispute venue must align. A contract governed by Delaware law that submits disputes to arbitration in Singapore creates conflicts that complicate enforcement at every stage.

Liability Caps, Indemnification, and SLA Terms

The standard general liability cap in enterprise SaaS agreements is 1x annual contract value, defined as fees paid or payable in the 12 months preceding the claim. More heavily negotiated deals may push to 2x or 3x ACV. The structure that works in international deals is a mutual cap with defined carve-outs for IP infringement, data breaches, and gross negligence, since those categories carry disproportionate risk across multiple jurisdictions. An uncapped data breach liability exposure is a substantial commercial risk for any SaaS vendor operating under GDPR, where regulatory fines and customer indemnity claims can stack independently. For practical discussions of cap mechanics, see commentary on SaaS liability caps and the basics of the limitation of liability clause explained.

SLA uptime commitments in enterprise SaaS typically cluster between 99.5% and 99.9% for business-critical applications, with 99.99% for revenue-critical functions like authentication, payment flows, or API access. In most enterprise SaaS agreements we review at Jessica Ingrid, service credit structures are tiered and modest: 10% credit below a higher uptime threshold, 25, 30% credit if uptime falls below a lower floor. For global customers, document support hours in UTC to avoid time zone ambiguity, specify which languages are supported, and state whether after-hours coverage applies for enterprise tiers. Buyers in APAC and LATAM commonly require documented response SLAs by severity level as a procurement standard, not an optional feature. See industry guidance on cloud service-level agreement expectations and a short explainer on uptime SLAs explained (99.9% vs 99.99%).

Export Controls, Sanctions, and Termination Conditions

US-origin SaaS falls under US export control and OFAC sanctions rules regardless of where your servers are located, a point many SaaS vendors don’t fully account for until an enterprise customer’s compliance team raises it. Your contract should require customers to represent that they, their affiliates, and their users are not restricted parties, and should prohibit access from sanctioned jurisdictions. The vendor needs the right to suspend or terminate service immediately upon a sanctions screening match. A flow-down obligation requires customers to impose the same restrictions on their own users, resellers, and downstream recipients. For post-Brexit cross-border considerations and export rules, review the post-Brexit software export rules.

For software classification and operational export-control practice consult vendor resources and white papers, such as the Microsoft Azure export controls white paper. Practical how-to guidance on screening and compliance is available in standard industry write-ups on software export compliance, and for risks tied to incorrect ECCN assignment see analysis of errors in export classification of software products. For encryption-heavy SaaS products, export classification under the EAR may also be relevant, particularly around ECCN 5D002 software and applicable license exceptions.

Termination provisions in international agreements need to cover more ground than domestic contracts. Include termination for cause, termination for convenience with a 30 to 90 day notice period, and automatic termination triggers for insolvency or sanctions exposure. The data return and deletion clause is where international deals fall short most frequently. Specify the file format, the delivery timeline after termination, the deletion certification process, and the window during which deletion of backup copies is completed. Under GDPR, these obligations are legally binding on the processor, not optional commitments that can be waived by contract silence.

Putting It Together Before The Deal Is On The Table

Getting a SaaS licensing agreement right for international customers means building purpose-specific provisions from the start, not retrofitting a domestic contract after a foreign legal team has already flagged the gaps. Each clause category covered here, data protection, IP ownership, tax compliance, governing law, liability, export controls, and termination, carries its own negotiation risk, and a weakness in any one of them creates real exposure the moment the agreement crosses a jurisdiction line.

Enterprise customers in the EU, UK, and APAC have legal teams that will find those gaps. The renegotiation process costs time and commercial goodwill, and the earlier the fix happens, the less it costs, in both legal fees and deal momentum. A well-structured international SaaS licensing agreement is the foundation that lets deals close cleanly and stay closed. For practical checklists and clause-level primers, see collections of key clauses you should not miss in a SaaS agreement, a startup legal guide to SaaS agreements, and broader commentary on key legal considerations in international SaaS agreements. Also monitor regulatory shifts such as the EU Data Act implications for SaaS contracts, which may affect data-sharing and contractual obligations in coming procurements.

Jessica Ingrid offers SaaS agreement review and cross-border contract drafting tailored to US, EU, and Korean market requirements. Every engagement is scoped and priced upfront, no hourly billing surprises. Whether you need a full international SaaS licensing agreement drafted from scratch or an existing contract reviewed before it reaches an enterprise customer’s legal team, contact us to schedule a consultation before the next deal reaches a foreign legal desk.

Ready to strengthen your international SaaS agreements?

At Jessica Ingrid Law, I provide review and drafting of cross-border SaaS licensing agreements tailored for US, EU, and Korean requirements. Whether you need a full agreement from scratch or a pre-deal audit, contact me before the next enterprise contract reaches a foreign legal team.

Contact: jessicaingrid.com

Jessica Ingrid

Intellectual Property & Contract Lawyer

English Speaking Lawyer · Seoul · Tech Contracts

Protecting IP since 2008

www.jessicaingrid.com