Cloud, hosting and colocation contracts under Dutch law

A quiet server room corridor lit by the racks, seen down its length

Almost every international company operating in the Netherlands buys computing capacity from someone else. The contract governing it is usually a supplier template, signed under time pressure, with a service level agreement bolted on and an exit clause nobody read. This article sets out how Dutch law treats these contracts, where standard terms are weakest for the customer, and what the EU Data Act now requires on switching.

The three layers, plus hosting and colocation

“Cloud” is not one product. What the customer controls changes at each layer, and so does what the contract must protect.

ModelSupplier controlsCustomer controlsContract centre of gravity
ColocationBuilding, power, cooling, physical security, network hand-offIts own hardware and everything above itSpace and power, access rules, right to remove equipment
HostingHardware, network, often OS patching and backupApplications, data, configurationScope of management, patching, tested restores
IaaSPhysical layer, hypervisor, storage and network fabricVirtual machines, OS, middleware, applications, dataAvailability of the region or zone, capacity, egress
PaaSThe above, plus runtime, managed databases, orchestrationApplication code, data, configurationDeprecation of components, lock-in via proprietary services
SaaSThe entire stackData, user administration, limited configurationAvailability, roadmap, data export, processing terms

The further down the stack you sit the more operational risk is yours, and the further up the more locked in you are. Colocation is the outlier: you buy floor space, power and physical security, so the decisive terms are power density and redundancy, notice period, escalation of power charges, remote hands and your right to remove your racks. With plain hosting the dispute is almost always scope: was the supplier responsible for patching, monitoring and backups, or only for keeping the machine powered?

How Dutch law characterises the contract

Dutch law has no contract type called “cloud”. Courts characterise by what the parties agreed and how they performed, then apply the rules of the type or types that fit.

  • Opdracht (art. 7:400 BW): the default for SaaS, PaaS, managed hosting and the service element of IaaS.
  • Huur (art. 7:201 BW): lease requires use of a zaak, a tangible object (art. 3:2 BW). Software and data are not, so pure SaaS is not lease. Colocation space and dedicated hardware plausibly are, which is why colocation agreements often carry lease characteristics whatever the supplier calls them.
  • Koop (art. 7:1 BW): in De Beeldbrigade (HR 27 April 2012, ECLI:NL:HR:2012:BV1301) the Hoge Raad held that acquiring standard software for unlimited use against a one-off payment falls under the sale provisions. That does not carry over to a subscription service, but it matters for perpetual licences in a hybrid deal.
  • Gemengde overeenkomst (art. 6:215 BW): most real contracts are mixed, and the rules of each type apply cumulatively unless irreconcilable.

Why characterisation matters

Termination. Under art. 7:408 BW the client may in principle terminate an opdracht at any time, and art. 7:411 BW governs what the supplier is then owed. Between businesses these rules are largely open to contrary agreement (see art. 7:413 BW), and templates displace them with fixed terms, automatic renewal and long notice. Where an open-ended agreement has no termination clause, Dutch case law generally treats it as terminable, but reasonableness and fairness may require notice, compensation or a serious ground.

Duty of care. If the contract is an opdracht, art. 7:401 BW imposes the care of a good contractor: an enforceable standard Dutch courts have used to hold suppliers to duties of investigation, warning and project management the contract never mentioned. Under a sale or lease characterisation the route is conformity or defect instead.

The service level agreement

Availability, and how it is measured

  • What is measured: the whole service, or one component? A platform answering a health check while login is down counts as “available” under many SLAs.
  • Over what period: 99.9 per cent measured annually permits one long outage; measured monthly it caps a single incident far more tightly.
  • By whom, from where: supplier monitoring inside its own network reports better numbers than a probe from your office.
  • What is excluded: maintenance, third-party network failure, force majeure and “customer-caused” incidents are routinely carved out, and excluded time normally leaves the denominator too, inflating the figure.

Availability is not performance. A service can be fully available and unusably slow. Commit to speed separately: response targets, batch windows, restore time and restore point objectives, and support response times per priority class. Backup needs its own commitment, including a tested restore. Fix maintenance windows too: timing, notice, frequency and duration. For an international operation, “outside office hours” needs a time zone.

Service credits, and the exclusivity trap

  • Are they the exclusive remedy? Supplier terms usually say so, which turns every failure into a modest discount and shuts off damages. At minimum carve out persistent, wilful or grossly negligent breaches, and any breach that is also a security or data breach.
  • Must you claim them? Many regimes require a claim within a short window, failing which the credit lapses. Insist on automatic credit on the invoice.
  • Is there a way out? A credit regime without a right to terminate is weak. A supplier that can miss its targets indefinitely, refund a small percentage of the monthly fee and keep you locked in has bought its way out of performing. Tie repeated or serious failure to termination for cause, without penalty and with full exit assistance.

Duty of care and the duty to cooperate

Dutch IT case law is unusually developed on the supplier’s duty of care. A professional supplier must investigate the customer’s environment and requirements, warn about risks, unsuitable choices and cost overruns, and keep warning when the advice is ignored. Calling the obligation one of best efforts does not neutralise expectations the supplier created before signature.

The mirror obligation is real and underestimated: the customer must cooperate by supplying accurate information, deciding on time, testing when asked, and providing access and competent people. A customer who fails can find itself in creditor’s default (art. 6:58 BW), which blocks the supplier’s default, undermines a damages claim and can defeat termination.

The point extends to security. In Gemeente Hof van Twente v Switch IT Solutions (Gerechtshof Arnhem-Leeuwarden, 25 February 2025, ECLI:NL:GHARL:2025:1046) the court rejected the customer’s claim after a ransomware attack, because the vulnerabilities traced to administration the customer had retained: a firewall change it made itself, and a weak password on an account it managed. Control drives responsibility, so record which side owns each control.

Security, certification and audit

Do not accept “appropriate technical and organisational measures” as the whole obligation. Specify a named standard and scope, such as ISO/IEC 27001 certification or a SOC 2 Type II report, with the certificate actually covering the service you buy; patching timescales by severity; penetration testing frequency; incident notification with a defined trigger, deadline and content; and an audit route. Large suppliers refuse on-site audits; a workable compromise is certification plus a right to audit on notice after an incident.

Sectoral rules may add mandatory content. Financial entities are subject to DORA (Regulation (EU) 2022/2554), which prescribes terms for ICT third-party contracts. The Dutch Cyberbeveiligingswet, implementing NIS2, entered into force on 15 August 2026 and reaches the digital infrastructure and managed service sectors as well as many customers. Both regimes bear directly on the contract: for financial entities under DORA, and for essential and important entities under the Cyberbeveiligingswet, they impose requirements on operational resilience, on incident notification and on the exit strategy. Establish at the outset which of the two catches the supplier and which catches you.

Data protection

Where personal data is processed you need a processing agreement under the GDPR, covering instructions, confidentiality, security, sub-processors, data subject rights, breach notification, and return or deletion at the end. The recurring negotiation points are the sub-processor regime, whether you get prior notice and a right to object, and international transfers. The EU-US Data Privacy Framework survived its first challenge before the General Court, which dismissed the action in Case T-553/23 (Latombe v Commission) on 3 September 2025, holding that the Data Protection Review Court offers sufficient guarantees of independence and that judicial review after the event of bulk collection meets the standard of essentially equivalent protection. An appeal was lodged on 31 October 2025 as Case C-703/25 P and is pending; the adequacy decision remains fully in force in the meantime.

Data location and sovereignty

Location is a commercial and regulatory question before it is a data protection one. Ask, in writing: where is data stored, and from where is it processed or accessed, remembering that support staff outside the EU constitute access even where storage is local; where do backups, disaster recovery copies and logs sit; which entities could be compelled to hand over data under a foreign order; can you fix the region, and what happens if the supplier changes it. The Data Act helps: providers must publish, and reflect in their contracts, the jurisdiction to which the deployed infrastructure is subject and the measures taken against unlawful international governmental access to non-personal data held in the EU.

The exit

An exit clause negotiated at the start is worth more than any other clause in the contract. At the start you have leverage and the supplier wants the deal; at the end you have none, and every day of delay costs you.

  • Format. Structured, commonly used and machine-readable, with a documented schema, including metadata, configuration, audit logs and attachments. An undocumented dump is not a usable return.
  • Scope. Everything, not only the records you loaded: derived data, historical versions, and whatever your retention obligations require.
  • Transition period. A defined period during which the service continues on existing terms while you migrate, extendable at a stated price.
  • Assistance. A duty to assist, with named roles, a day rate agreed now, and cooperation with your new supplier.
  • Deletion. Certified deletion after a defined retrieval window, including backups, with expiry timing stated.
  • Trigger. Exit obligations apply on any termination, including by the supplier for your non-payment. Suppliers frequently exclude that case, and it is the one you are likeliest to need.

Lock-in, portability and the EU Data Act

Regulation (EU) 2023/2854, the Data Act, entered into force on 11 January 2024 and applies from 12 September 2025. Chapter VI creates a switching regime for providers of “data processing services”, defined broadly enough to capture IaaS, PaaS and SaaS.

  • Obstacles must go (art. 23): commercial, technical, contractual and organisational barriers to terminating, moving to a competitor and porting data.
  • Mandatory terms (art. 25): a maximum notice period of two months to start switching; a mandatory maximum transitional period of 30 calendar days, extendable once by the customer and, where switching is technically unfeasible, by the provider up to seven months on reasoned notice; then a data retrieval period of at least 30 calendar days, followed by erasure.
  • Charges (art. 29): from 11 January 2024 to 12 January 2027 providers may impose only reduced switching charges, not exceeding the costs directly linked to the switching process. From 12 January 2027 switching charges are prohibited altogether, ending egress fees on exit.
  • Technical obligations (art. 30): infrastructure-level providers must take all reasonable measures to enable functional equivalence after switching; others must make open interfaces available free of charge. No provider must develop new technology or disclose trade secrets.
  • Information, good faith and exemptions (arts. 26, 27, 31): switching procedures must be disclosed; all parties, including the destination provider, must cooperate in good faith; bespoke and time-limited test services are carved out.

Three cautions. The Data Act sets a floor, not a migration plan: it will not make your data portable if you built on proprietary platform services with no equivalent elsewhere. Timing matters: a contract concluded on or after 12 September 2025 has to satisfy Chapter VI immediately, while a contract concluded before that date must be brought into line by 12 September 2027. To help with that, the Commission published modular standard contractual clauses at the end of 2025 which providers can incorporate into their terms to meet the Chapter VI obligations. The Commission’s Digital Omnibus proposal of 19 November 2025 no longer affects Chapter VI in any material way, the overlap between the two having largely been absorbed into that chapter. And pure colocation and housing fall outside the definition of a data processing service, and so outside the regime, provided no scalable or elastic cloud functionality is supplied with the floor space.

Continuity and supplier insolvency

If your supplier fails, the trustee decides under art. 37 Fw whether to perform outstanding contracts; if not, your claim is unsecured. Source code escrow was built for on-premise software and does little for SaaS: code without the data, the environment and the operational knowledge does not restore a service. SaaS needs a continuity arrangement covering the running instance, the data and the right to keep operating. At a minimum, the contract should state that the data is yours, is not subject to any retention right, and must be released on defined events.

Liability, exoneration and price

Supplier standard terms in the Dutch market are dominated by the NLdigital Voorwaarden, of which the 2025 edition is the current one. It limits liability for direct loss to the price agreed for the contract, or, for a continuing contract running longer than a year, to one year’s fees, and caps it in any event at EUR 500,000, with a separate ceiling of EUR 1,750,000 for death, personal injury and physical damage to property. Indirect and consequential loss, lost profit, lost savings, diminished goodwill, business interruption and claims by the customer’s own customers are excluded outright. The limits fall away only where the loss results from intent or conscious recklessness on the part of the supplier’s management. A claim must be notified as soon as possible after the loss arises and lapses twenty-four months later unless proceedings have been issued. Establish which edition your supplier has incorporated, and whether it has varied it: earlier editions remain in circulation and many suppliers use terms of their own.

Dutch courts do enforce exoneration clauses between businesses. The route round one is art. 6:248 BW: reliance on the clause fails where that would be unacceptable by standards of reasonableness and fairness. Courts apply the test with restraint, weighing the seriousness of the fault, the interests harmed, the parties’ positions and how the risk was priced. Intent or conduct equivalent to it will generally defeat a clause. Where the terms are general conditions (art. 6:231 BW), art. 6:233 BW allows annulment of an unreasonably onerous term. Practically: negotiate a cap bearing some relation to the harm a failure would cause, put data loss, confidentiality, security and IP indemnities outside it, and define “consequential loss”.

On price, fix the mechanism: cap annual indexation against a named index, restrict increases to once a year on stated notice, and take a right to terminate without penalty above a threshold. With consumption-based pricing, commit only to volumes you will use, and control the cost of scaling, support tiers and egress.

Applicable law, disputes and non-EU suppliers

Choose Dutch law and a Dutch forum where you can. Enforcing a Dutch judgment inside the EU is straightforward; enforcing one outside it often is not. Arbitration can be the better answer against a non-EU counterparty, and in Dutch IT disputes the SGOA foundation offers sector-specific arbitration and mediation.

Contracting outside the EU brings three realities. A limitation of liability may be easy to invoke and hard to challenge in a distant forum. Mandatory EU rules, including the Data Act switching regime and the GDPR, can apply on the basis of where the service is offered, but applying and enforcing them are different things. And a foreign parent may face disclosure orders conflicting with your obligations here. Where exposure is material, contract with the supplier’s EU entity and insist on a European forum.

Negotiation checklist

  • Define the service by layer, and record which side controls each component and each security control.
  • Make availability measurable: component scope, period, measurement point and exclusions; commit performance and restore objectives separately.
  • Reject service credits as an exclusive remedy, and attach a termination right to persistent or severe failure.
  • Specify security by standard and scope, with evidence, notification deadlines and an audit route.
  • Sign a processing agreement, and fix data, processing and support locations.
  • Negotiate the exit clause first: format, scope, transition period, priced assistance, certified deletion, and triggers including termination for non-payment.
  • Check the contract against the Data Act switching requirements, diarise 12 January 2027, and settle continuity: data ownership, no retention right, escrow.
  • Test the liability cap against the loss a real failure would cause, and put data, security, confidentiality and IP outside it.
  • Cap indexation, and choose law, forum and contracting entity deliberately.

Is a SaaS contract a lease under Dutch law?

Generally no. Lease under art. 7:201 BW requires the use of a tangible object, and software and data are not tangible objects under art. 3:2 BW. A SaaS contract is normally characterised as an opdracht under art. 7:400 BW, or as a mixed contract under art. 6:215 BW where hardware or perpetual licences are bundled in. Colocation, where you occupy physical space, may carry lease characteristics.

Can I terminate a cloud contract early if the service keeps failing?

Only if the contract permits it, or if the failure is serious enough to justify termination under art. 6:265 BW. Supplier templates frequently make service credits the exclusive remedy and restrict termination, so a long run of minor breaches leaves you with rebates and no way out. Negotiate an express termination trigger for repeated or severe service level failure before you sign.

What does the EU Data Act change for cloud switching?

From 12 September 2025 providers of data processing services must remove obstacles to switching, include prescribed contract terms including a maximum two-month notice period and a 30-day mandatory transitional period, and support portability. Reduced, cost-based switching charges are permitted until 12 January 2027, after which switching charges are prohibited entirely. Genuinely bespoke and non-production test services are carved out.

Will a Dutch court enforce a supplier’s liability cap?

Usually yes, between businesses. The escape route is art. 6:248 BW, under which reliance on the clause fails if that would be unacceptable by standards of reasonableness and fairness, and courts apply the test with restraint. Weight is given to the seriousness of the fault, the interests harmed, the parties’ positions, whether the term was negotiated and how the risk was priced. Intentional misconduct will generally defeat a cap.

Does source code escrow protect a SaaS customer?

Not by itself. Source code without the running environment, the data and the operational knowledge will not restore a live service, and on insolvency the trustee decides under art. 37 Fw whether to perform. A SaaS customer needs a continuity arrangement covering the data and the ability to keep operating, plus contract language confirming that the data is the customer’s and is not subject to any retention right.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Software licensing is the legal framework that determines who can use a piece of software

Decentralised Autonomous Organisations (DAOs) present a significant challenge for traditional Dutch corporate law. Currently, they

The Digital Services Act (DSA) and Digital Markets Act (DMA) are EU regulations that set

Discover how Service Level Agreements (SLAs): Ensuring Performance and Reliability protect businesses and individuals in

Businesses across the Netherlands are increasingly using AI tools to improve their operations. Many face

This is what you as a UK citizen need to know Until 31 December 2020,

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.