Skip to content

IT Law

Overview

Most technology disputes begin in a document nobody expected to argue about: a licence scope, a service level, a processing clause agreed in a hurry.

We advise software companies, online platforms and technology-enabled businesses on the agreements they run on - development, licensing and SaaS terms, platform and consumer terms, and the outsourcing and cloud arrangements underneath them.

The data side runs alongside it rather than separately. Who is controller and who is processor, what the processing terms have to carry, how transfers outside the European Union are handled, and what happens in the hours after a breach is discovered.

What we advise on

Development, licence and subscription terms from either side of the table: scope, acceptance, service levels, support, change control, liability and what happens to the data and the service when the contract ends.

Records of processing, lawful bases, notices, data protection impact assessments, and the contractual and supplementary measures that support transfers outside the European Union.

Terms of service and acceptable use for platforms and marketplaces, the consumer rules that apply when users are individuals, and the notice, complaint and transparency arrangements a platform has to operate.

Outsourcing and cloud contracts, including the audit, sub-processing, security and exit provisions, and the oversight a customer keeps when a function is run by someone else.

Preparing the response plan before it is needed, and acting on it afterwards: assessment, the notification decision, communications to affected people, and the record of what was done and when.

Ownership and licensing of code, databases and documentation, open-source compliance, contributor and employee assignments, and the IP terms in development and reseller agreements.

Data protection terms

  1. Controller

    The person or body which, alone or jointly with others, determines the purposes and means of processing personal data.

  2. Processor

    A person or body which processes personal data on behalf of the controller.

  3. Personal data breach

    A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

Discuss your agreements with our team.

Send us the contract or the question behind it and we will tell you what it turns on.

Contact the team