Technology businesses move faster than the rules that govern them. Software and SaaS contracts, platform terms, artificial intelligence products, e-commerce operations and the processing of personal data each raise their own legal questions, and the answers often differ from one jurisdiction to another.
We advise technology companies, start-ups and businesses adopting new technologies on their contracts, products and compliance. Our work covers software, SaaS and outsourcing agreements, terms of service and privacy notices, AI governance and regulation, e-commerce and digital services rules, cybersecurity and personal data protection under the GDPR and other international data protection regimes.
Scope of services
- 01Software, SaaS, licensing and outsourcing agreements
- 02Platform terms, terms of service and acceptable use policies
- 03Artificial intelligence governance and regulatory compliance
- 04Personal data protection compliance programmes
- 05Privacy notices, consent and cookie practices
- 06Cross-border data transfers and data processing agreements
- 07Data breach response and cybersecurity incidents
- 08E-commerce, digital services and online marketing rules
- 09Any other technology, AI or data protection matter
How we work
We begin with how the product or the system actually works: which data it uses, where it is hosted, who the users are and which markets it reaches. The legal requirements are then translated into concrete contract terms, internal policies and product decisions that the team can apply.
Frequently asked questions
The GDPR may apply to a company established outside the European Union where it offers goods or services to individuals in the Union or monitors their behaviour there. Whether it applies depends on the specific activities of the business.
Before adopting AI tools, a business should consider, among other points, the data that will be entered into the tool, confidentiality and intellectual property, the terms of the provider, the accuracy of the output and the regulatory rules that may apply to the use case.
Among other points, the agreement should address the scope of the licence or service, service levels, data processing, security, intellectual property in the software and the customer data, liability limits and what happens at the end of the contract.
Where a service provider processes personal data on behalf of a customer, data protection laws usually require a written agreement setting out the subject matter, duration, purpose, security measures and the obligations of the processor.
The company should contain the incident, assess the data and individuals affected and determine whether notification to the authority or to the individuals is required under the applicable law. Strict deadlines often apply, so a response plan prepared in advance is valuable.
The answer depends on the terms of the AI provider, the applicable copyright law and the degree of human contribution. Businesses using AI in their products or content should review these terms and their own contracts with clients and contractors.
