Skip to content

Industry 06

Technology Businesses

Technology contracting, privacy, information security regulation and platform rules for technology companies serving regulated and international customers.

Topics: Technology contractingPrivacyInformation security regulationPlatform regulationCross-border operations

Patterned silicon wafers, one standing in a slotted stone block, their dies breaking the light into colour.

Who we advise

  • SaaS and software providers
  • ICT and cloud providers to financial institutions
  • Data-driven and analytics businesses
  • Platform and app developers
  • Technology groups operating in several jurisdictions

Specialisations

Business models we advise

01SaaS & Software Providers
Licensing, subscription and service terms, and the regulatory clauses regulated customers require.
02ICT Providers to Financial Entities
The contractual requirements, audit rights and exit arrangements that DORA brings to providers of financial institutions.
03Data-Driven Businesses
Businesses whose product depends on personal data: lawful bases, transfers and impact assessments.
04Online Platforms & Apps
Platform regulation, consumer rules and user terms for consumer-facing technology.
05Cross-Border Technology Groups
IP ownership, contracting entities and compliance for groups operating in several markets.

Context

The regulatory landscape

Technology companies increasingly inherit regulation from their customers. A software provider to banks is drawn into DORA's third-party requirements, a SaaS business processing customer data carries data protection obligations in every market it serves, and a platform with users in the EU falls within digital services rules.

We advise technology businesses on the contracts, privacy and security frameworks and regulatory positions that let them sell to regulated customers and operate across borders — without importing more regulation than actually applies.

Challenges

Where businesses need support

  1. 1.

    Selling to regulated customers

    Meeting the contractual and audit requirements that banks, payment firms and insurers must impose on their technology providers.

  2. 2.

    Information security regulation

    Frameworks such as DORA and NIS2 that apply directly or reach you through customer contracts.

  3. 3.

    Data protection

    Controller and processor roles, international transfers and privacy by design.

  4. 4.

    Technology contracting

    Licensing, SaaS, development and service level terms, including liability and IP ownership.

  5. 5.

    Platform regulation

    Obligations for online platforms and intermediaries under digital services rules.

  6. 6.

    Cross-border operations

    Group structure, IP ownership and contracting entities for teams and customers in several jurisdictions.

Services

How we help

  • Privacy compliance and GDPR programmes, notices and DPAs, DPIAs, data mapping and ROPA, transfers, audits and breach response.

  • Trademark and patent registration and protection, copyright protection, domain name disputes, portfolio support and IP agreements.

  • Group architecture, incorporation, substance and governance built around your licences, banking and investors.

  • Regulatory, business model, perimeter, payment, gaming, crypto-asset and cross-border opinions for banks, partners and investors.

Jurisdictions

Relevant frameworks

Cartography by ROZSUD from Natural Earth data (public domain).

Questions

Frequently asked

We are an ICT provider to banks. Does DORA apply to us?

DORA's obligations fall mainly on the financial entities themselves, but they must include specific provisions in their contracts with ICT providers, and providers designated as critical are subject to direct oversight. In practice, most providers to EU financial entities need to be ready to accept DORA-compliant terms.

Discuss your matter with a senior advisor.

Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.