Platform, white-label, B2B supply, SaaS, affiliate and outsourcing agreements drafted for regulated environments.
Industry 06
Technology Businesses
Technology contracting, privacy, information security regulation and platform rules for technology companies serving regulated and international customers.
Topics: Technology contractingPrivacyInformation security regulationPlatform regulationCross-border operations

Who we advise
- SaaS and software providers
- ICT and cloud providers to financial institutions
- Data-driven and analytics businesses
- Platform and app developers
- Technology groups operating in several jurisdictions
Specialisations
Business models we advise
- 01SaaS & Software Providers
- Licensing, subscription and service terms, and the regulatory clauses regulated customers require.
- 02ICT Providers to Financial Entities
- The contractual requirements, audit rights and exit arrangements that DORA brings to providers of financial institutions.
- 03Data-Driven Businesses
- Businesses whose product depends on personal data: lawful bases, transfers and impact assessments.
- 04Online Platforms & Apps
- Platform regulation, consumer rules and user terms for consumer-facing technology.
- 05Cross-Border Technology Groups
- IP ownership, contracting entities and compliance for groups operating in several markets.
Context
The regulatory landscape
Technology companies increasingly inherit regulation from their customers. A software provider to banks is drawn into DORA's third-party requirements, a SaaS business processing customer data carries data protection obligations in every market it serves, and a platform with users in the EU falls within digital services rules.
We advise technology businesses on the contracts, privacy and security frameworks and regulatory positions that let them sell to regulated customers and operate across borders — without importing more regulation than actually applies.
Challenges
Where businesses need support
- 1.
Selling to regulated customers
Meeting the contractual and audit requirements that banks, payment firms and insurers must impose on their technology providers.
- 2.
Information security regulation
Frameworks such as DORA and NIS2 that apply directly or reach you through customer contracts.
- 3.
Data protection
Controller and processor roles, international transfers and privacy by design.
- 4.
Technology contracting
Licensing, SaaS, development and service level terms, including liability and IP ownership.
- 5.
Platform regulation
Obligations for online platforms and intermediaries under digital services rules.
- 6.
Cross-border operations
Group structure, IP ownership and contracting entities for teams and customers in several jurisdictions.
Services
How we help
Privacy compliance and GDPR programmes, notices and DPAs, DPIAs, data mapping and ROPA, transfers, audits and breach response.
Information security compliance, security governance and policies, gap assessments, DORA, NIS2, vendor risk and incident governance.
Trademark and patent registration and protection, copyright protection, domain name disputes, portfolio support and IP agreements.
Group architecture, incorporation, substance and governance built around your licences, banking and investors.
Regulatory, business model, perimeter, payment, gaming, crypto-asset and cross-border opinions for banks, partners and investors.
Jurisdictions
Relevant frameworks

Questions
Frequently asked
We are an ICT provider to banks. Does DORA apply to us?
DORA's obligations fall mainly on the financial entities themselves, but they must include specific provisions in their contracts with ICT providers, and providers designated as critical are subject to direct oversight. In practice, most providers to EU financial entities need to be ready to accept DORA-compliant terms.
Discuss your matter with a senior advisor.
Share a few details about your business and plans. We will come back to arrange a confidential initial conversation.
