Navigating Modern IT Agreements: What Businesses Need to Consider

Modern IT agreements are increasingly complex. Businesses are rarely buying a standalone software licence; instead, arrangements often combine SaaS subscriptions, hosting, system integration, support, maintenance, AI functionality and other related services.
Poorly drafted or rushed agreements can expose organisations to hidden costs, data risks, service failures and supplier lock-in. To help, our specialist Commercial Law and IT Contract Solicitors have identified eight key factors to consider in modern IT agreements:
1. Avoid scope creep with properly drafted agreements
Disputes often arise because of disagreements around what a supplier is expected to deliver. This uncertainty typically stems back to a poorly defined scope of service and its boundaries.
It’s important to ensure clarity over what’s included within the agreed price and what classes as additional work.
Organisations should ensure that agreements properly demonstrate:
- The services being provided
- Deliverables and milestones
- Acceptance criteria
- The responsibilities of each party
- Any exclusions or limitations on obligations
- The agreed processes for any changes to the project scope
2. Fully interrogate service levels and availability targets
IT agreements should do more than set headline commitments, such as uptime guarantees. They should clearly explain how performance will be measured and what happens if service levels are missed. Service credits may provide some compensation, but the agreement should also define what amounts to a critical service failure and when the customer has a right to terminate.
When next reviewing an IT agreement, look for clarity on:
- Availability targets
- Response and resolution times
- Maintenance windows
- Reporting requirements and frequency
- Circumstances where service levels don’t apply
3. Data protection and security obligations
Data breaches can result in significant damage: financial, operational and reputational. Organisations should therefore satisfy themselves that their suppliers have appropriate security measures in place. Agreements need to reflect the importance of protecting data, particularly where customer data may be processed by the supplier. It is sometimes more appropriate to include these obligations in a separate data processing agreement.
Ensure strong data protection and information security by focusing on:
- Compliance with UK GDPR requirements
- Defined controller and processor responsibilities
- Appropriate Article 28 data processing provisions
- Security standards and technical controls
- Breach notification obligations
- International data transfer arrangements
- Audit and compliance rights
4. Negotiation of risk allocation
Ensure that limitation of liability, indemnities and warranties are carefully considered and negotiated so that risk sits with the intended party.
Many standard supplier agreements contain provisions that seek to limit the supplier’s exposure while placing significant risk on the customer.
Businesses should ensure that limitation of liability, indemnities and warranties are carefully considered and negotiated so that risk sits with the party best placed to manage it.
When drafting or reviewing IT agreements, carefully review and negotiate key risk allocation provisions, such as:
- Limitations of liabilityHigher liability caps for data breaches, confidentiality breaches and IP claims, where potential losses may be significant
- Exclusions of loss
- Warranties and performance commitments
- Indemnities
- Insurance obligations
5. IP ownership and usage rights:
Technology projects often create valuable intellectual property, data and digital outputs, but ownership and usage rights are frequently overlooked during agreement negotiations. Questions may also arise about who can use those outputs and how they may be used.
Uncertainty in this area can create disputes and limit a business’s ability to use systems or data in the future. Clear contractual drafting can help ensure both parties understand their respective rights throughout the relationship and following termination.
To ensure ownership and usage, businesses should consider:
- Who owns newly developed software or customisations
- Whether the supplier retains rights to underlying platforms and tools
- How customer data can be used by the supplier
- Whether anonymised or aggregated data may be exploited commercially
- Rights relating to AI-generated content, insights or outputs
6. Use of AI functionality
AI functionality is now being built into many IT products, from automated decision-support tools to generative AI features embedded within SaaS platforms. This can create additional legal and operational risk, particularly where the system uses customer data, produces outputs relied on by the business, or changes over time through model updates or training.
Agreements should therefore be clear about what AI is being provided, how it will be used, what data it may access, and who is responsible if the AI produces inaccurate, infringing, biased or otherwise problematic outputs.
Where AI is part of the solution, businesses should consider:
- Whether the AI functionality is clearly described, including its intended use, limitations and any human oversight requirements
- Whether customer data, prompts, outputs or usage data may be used to train, fine-tune or improve AI models
- Who owns or may use AI-generated outputs, insights and derived data
- What warranties, testing obligations and accuracy commitments apply to the AI system
- How risks relating to bias, hallucinations, infringement, confidentiality and regulatory compliance are allocated
- Whether the supplier must notify the customer of material model changes, new AI features or changes to third-party AI providers
7. Third party software and supply chain risk
Supply chain resilience is becoming an increasingly important issue, particularly where a business depends on key technology systems for day-to-day operations.
Many technology suppliers rely on third-party providers to deliver all or part of their services, including cloud hosting providers, software vendors, infrastructure providers and specialist subcontractors.
Organisations need visibility over these dependencies and ensure their IT agreements reflect:
- Which third parties are involved in service delivery
- What third-party licence terms apply
- Whether licences can be passed through to the customer
- The supplier’s responsibilities for subcontractors
- What protections exist if a third-party provider fails to deliver its obligations
8. Transition and exit
While organisations often focus on getting a new system up and running, they can overlook what happens when the relationship comes to an end.
Termination, transition assistance and data retrieval provisions are critical in subscription-based models. Without clear exit rights and transition, businesses risk being locked into underperforming systems, losing critical data and experiencing business continuity failure.
To ensure a dispute-free termination or exit, IT agreements should address:
- Termination rights
- Exit assistance and transition support
- Data export and retrieval processes
- Knowledge transfer requirements
- Ongoing access arrangements during migration
- Data deletion or return obligations
Drafting or reviewing IT agreements involves a wide range of legal and commercial considerations. Our Commercial Law Solicitors are here to help. We have particular expertise in the legal issues relating to software licences and IT agreements. We take time to understand your business needs and provide tailored support based on that understanding. If you’d like to know more, please get in touch.
FAQs
Liability for data breaches is often subject to negotiation. Businesses should consider whether liability caps adequately reflect the potential risks associated with data breaches, confidentiality breaches and intellectual property claims, particularly where potential losses may be significant.
IT agreements should clearly explain what happens if service levels are missed. Businesses should consider whether the agreement identifies critical service failures and provides appropriate remedies, including the ability to terminate where serious or repeated failures occur.
Businesses should review AI and data usage provisions carefully to understand whether customer data, prompts, outputs or usage data may be used to train, fine-tune or improve AI models. The agreement should clearly explain how data may be used and what rights the supplier has.
Without clear termination, transition and data retrieval provisions, businesses may face difficulties moving to a replacement provider, retrieving critical data or maintaining business continuity. IT agreements should clearly address these issues before problems arise.
Many technology suppliers rely on third-party providers to deliver parts of their services. Businesses should understand which third parties are involved, what licence terms apply, the supplier’s responsibilities for subcontractors and what protections exist if a third-party provider fails to perform.
Businesses can reduce the risk of scope creep by ensuring agreements clearly define the services being provided, deliverables, acceptance criteria, responsibilities, exclusions and the process for making changes to the project scope.
Businesses should ensure the agreement clearly addresses who owns newly developed software or customisations, whether the supplier retains rights to underlying platforms and tools, how customer data may be used and what rights apply to AI-generated outputs, insights and derived data.
Businesses should ensure IT agreements address compliance with UK GDPR requirements, define controller and processor responsibilities, include appropriate data processing provisions, set out security obligations, establish breach notification requirements and deal with international data transfers where relevant.
Sign up for legal insights
Stay up to date with the latest alerts, training and event invitations.




