Cross-border

Selling US SaaS into the EU: the contract stack

The first European enterprise customer is where a US SaaS company discovers that its contract template is a US document. What follows is a stack of four agreements, several mandatory terms, and a handful of positions that are simply not negotiable in the EU.

Customer agreement · EU enterpriseContract stack

1Master agreement (New York law)(law of the customer’s member state, or English law as a compromise). 2Data processing agreement with SCCs, module two. 3Security schedule referencing ISO 27001 or SOC 2. 4Terms of service by URL, changeable at will.Fixed terms attached; changes on notice only.

Guide exampleStack
In short
  • An EU enterprise deal is a stack: master agreement, DPA with SCCs, security schedule, and often a local-law addendum. Plan for four documents, not one.
  • Governing law is the clause that changes everything else: under German or French law, some of your US liability and termination language is unenforceable as written.
  • Certain positions are not negotiable in the EU — GDPR Article 28 terms, transfer safeguards, and for some customers, data residency. Budget for them rather than fighting them.

Why the template does not survive contact

A US SaaS master agreement assumes US law, US-style limitation and indemnity mechanics, terms of service that can be updated by posting a new URL, and a data clause that says “industry-standard security”. An EU enterprise procurement team will reject or rewrite each of those. The vendor that knows this in advance closes in six weeks; the one that discovers it clause by clause closes in six months, or not at all.

The stack

1. Master agreement and governing law

Large EU customers will often insist on the law of their member state. When they do, everything else in the document is now read under a civil-law system with mandatory rules that override contract terms: limitation of liability for gross negligence may be unenforceable, unilateral termination rights may be constrained, and general terms and conditions face specific fairness tests (Germany’s AGB rules are the well-known example). English law is frequently accepted as a neutral compromise by both sides. Whatever the answer, it needs a lawyer qualified in that jurisdiction to check the liability, warranty and termination clauses — a US lawyer reading German law is guessing.

2. Data processing agreement

Mandatory under GDPR Article 28 whenever the vendor processes personal data for the customer. It must contain the Article 28 terms, and for data leaving the EU to the US it must incorporate a transfer mechanism: the EU–US Data Privacy Framework if the vendor is certified, or the 2021 Standard Contractual Clauses (module two, controller-to-processor), with a transfer impact assessment on file. UK customers add the UK Addendum. Our DPA guide covers the negotiable points — sub-processors, audit, breach timing.

3. Security schedule

EU buyers expect a named standard — ISO 27001 is more commonly requested than SOC 2 in Europe, though either is usually accepted — plus the mechanics: audit rights satisfied by the report, incident notification windows, sub-processor security flow-down. Some sectors (financial services, public bodies) add their own regulatory requirements, including EU-region data residency, which is a product question before it is a contract one.

4. Local-law addendum

Some customers attach a short document adapting the master to mandatory local rules: statutory notice periods, invoicing requirements, language of the contract, consumer-style protections that apply to small businesses in some member states. These are usually not worth fighting; they reflect law, not preference.

Positions EU buyers will not accept

  • Terms changeable by URL. Attach the terms; changes only on written notice with a right to object.
  • No DPA, or a DPA that omits Article 28 terms. Non-negotiable.
  • Transfers with no mechanism. “We comply with applicable law” is not a mechanism.
  • Exclusive US venue for disputes against a customer with no US presence. Expect arbitration or local courts.
  • Unlimited unilateral price changes mid-term.

Positions that are negotiable, and where the market sits

  • Liability caps — the same logic as in the US, but check enforceability under the chosen law.
  • Data residency — negotiable for most customers, mandatory for some; price it if you can offer it.
  • Audit rights — report-based audits are accepted almost everywhere.
  • Language — English contracts are standard in tech, but some public and regulated customers require a local-language version to prevail.

The commercial side nobody warns you about

Invoicing an EU business customer from the US usually means no EU VAT charged (reverse charge), but the invoice must say so and carry the customer’s VAT number. Currency, payment terms and late-payment rules differ; several member states have statutory maximum payment terms for B2B. And the contract may need a local entity to sign it at all if the customer’s procurement rules require a supplier registered in the EU — a question for corporate counsel before the deal, not after.

How the desk handles this

US law stays with the US attorney. The governing-law question, the local-law addendum and any point that turns on a member state’s rules go to locally qualified counsel through Icon Partners. You see one redline and one invoice.

General information, not legal advice. This page describes how US and cross-border commercial contracts commonly work; it is not advice on your situation and does not create an attorney–client relationship. For advice on a specific contract, speak to a lawyer qualified in the relevant jurisdiction.

Next step

Have a contract like this on your desk?

Send it over. We will mark it up and walk you through it in twenty minutes — no cost, and you will know whether the desk is worth it.

Book a contract call