Negotiating Cloud Contracts


Common Contract Provisions

Definition of Terms

  • contract should clearly define terms used
  • e.g., what is specifically considered an outage

Performance Metrics and Remedies

  • clearly define performance metrics for:
    • uptime
    • availability
    • durability
    • etc.
  • usually appear in SLAs
    • contract references the SLA
  • adopt service-level management practices that include active monitoring of vendor compliance with SLAs
  • specify the remedies that the customer has if the vendor fails to fulfill obligations

Data Ownership

  • clearly state that the customer retains ownership of any data used in cloud service
  • cover topics on access to data, export of data, and destruction of data

Compliance Obligations

  • pass on any compliance requirements to the vendor
    • clearly spelled out in contract
  • e.g., HIPAA, PCI DSS

Assurance

  • contract terms should provide the ability to implement assurance measures
    • allow you to verify the vendor is fulfilling obligations
  • e.g., retain right to audit vendor

Indemnification

  • under indemnification clause, one of the parties agrees to cover losses incurred by the other party
  • if customer is asked to indemnify the vendor,
    • it is a big financial risk
  • may want the vendor to indemnify the customer

Termination

  • take into account contract termination and the process that take place
  • does contract auto-renew?
  • required advance notice for termination

Litigation

  • contracts can go wrong
  • outline litigation processes and jurisdiction