Negotiating Cloud Contracts
Common Contract Provisions
Definition of Terms
- contract should clearly define terms used
- e.g., what is specifically considered an outage
- clearly define performance metrics for:
- uptime
- availability
- durability
- etc.
- usually appear in SLAs
- contract references the SLA
- adopt service-level management practices that include active monitoring of vendor compliance with SLAs
- specify the remedies that the customer has if the vendor fails to fulfill obligations
Data Ownership
- clearly state that the customer retains ownership of any data used in cloud service
- cover topics on access to data, export of data, and destruction of data
Compliance Obligations
- pass on any compliance requirements to the vendor
- clearly spelled out in contract
- e.g., HIPAA, PCI DSS
Assurance
- contract terms should provide the ability to implement assurance measures
- allow you to verify the vendor is fulfilling obligations
- e.g., retain right to audit vendor
Indemnification
- under indemnification clause, one of the parties agrees to cover losses incurred by the other party
- if customer is asked to indemnify the vendor,
- it is a big financial risk
- may want the vendor to indemnify the customer
Termination
- take into account contract termination and the process that take place
- does contract auto-renew?
- required advance notice for termination
Litigation
- contracts can go wrong
- outline litigation processes and jurisdiction