Under Dutch law, a service level agreement (SLA) is an ordinary contract: its commitments are binding and enforceable like any other contractual obligation. The main exception lies in the wording: a service level only becomes an enforceable obligation of result if it is written as one, and not as a target or an effort.
What distinguishes an SLA is that it tries to make performance measurable. Whether it succeeds depends on one drafting choice: is each commitment an obligation of result (resultaatsverbintenis) or an obligation of best efforts (inspanningsverbintenis)? That distinction decides what happens when the service falls short. Where availability is expressed as a defined percentage over a defined measurement period, failing to reach it is a failure to perform, and the agreed consequence follows. Where the provider undertakes to “use reasonable endeavours” to maintain availability, the customer must prove that the provider did not act as a reasonably competent provider would have done, which is a much harder case to make. The same applies to response and resolution times: a target is not an obligation unless it is written as one.
Three further elements determine whether an SLA works in practice. Service credits are usually the agreed remedy. If the contract makes them the exclusive remedy, the customer gives up its right to damages and often its right to terminate. Such a limitation is valid in principle, but cannot be invoked where that would be unacceptable in the circumstances, particularly when the failure was serious. Measurement must be defined: who measures, with which tools, over which period, and what is excluded as planned maintenance or force majeure. And the exit must be arranged in advance, because the moment a customer most needs its data returned in a usable format is the moment relations have broken down.
Below we set out what belongs in an SLA, how to draft commitments that can be enforced, how to calibrate service credits and what to negotiate on either side of the table.
What is an SLA and what is its legal status?
An SLA sets out the service levels a provider must deliver, how they are measured and what happens if they are not met. It can be a separate contract or an annex to a main agreement, such as an IT services, cloud or outsourcing contract.
Which rules of Dutch law apply to an SLA?
Dutch law has no specific statute for SLAs. The general rules of contract law in Book 6 of the Dutch Civil Code (Burgerlijk Wetboek, BW) apply, and for most services also the rules on the contract for services (overeenkomst van opdracht) in Articles 7:400 and following BW.
Under Article 7:401 BW, a service provider must observe the care of a good contractor. Without specific agreements, a provider of services is therefore usually held to an obligation of best efforts. An SLA can go further by setting concrete results, such as a guaranteed availability. That makes the SLA legally important: it converts abstract promises into measurable commitments.
Like any contract, an SLA is interpreted not only on its wording but on what the parties could reasonably expect of each other in the circumstances. Clear definitions of terms such as “availability”, “incident” and “resolution” therefore reduce the room for argument. An SLA that is part of the provider’s general terms and conditions is also subject to the rules on general terms (Articles 6:231 and following BW).
Which performance metrics are common, and what do they mean legally?
Common metrics are availability (uptime) as a percentage, response time, resolution time and quality standards. Legally, each metric only has force if it is clearly defined and it is clear what happens if it is not met.
Take availability. An availability of 99.9 percent per month allows roughly 43 minutes of downtime; 99.5 percent allows about three and a half hours. The difference between these numbers matters, but so does the definition: is availability measured at the provider’s data centre or at the customer’s end, is planned maintenance excluded, and over which period is the percentage calculated?
If the provider does not meet an agreed service level, that is in principle a failure to perform (tekortkoming). The customer can then, depending on the contract and the law, claim performance, damages or dissolution of the contract (Articles 6:74 and 6:265 BW). In most cases, a notice of default setting a reasonable period for performance is required first (Article 6:82 BW), unless performance within the agreed time was essential. A well-drafted SLA regulates these consequences explicitly, so that the parties do not have to rely only on the general rules.
How does an SLA help manage risk?
An SLA helps both parties manage the risk of service disruptions. The customer knows what it can expect and what remedies it has; the provider knows exactly what is required and can limit its liability.
For the customer, an SLA is part of its own risk management: it shows what happens if critical services fail and allows the customer to plan fallback options. For regulated companies, it is sometimes a legal obligation. Financial institutions, for example, must include specific provisions in contracts with ICT service providers under the EU Digital Operational Resilience Act (DORA, Regulation 2022/2554), including precise descriptions of service levels for critical functions. Organisations covered by the NIS2 Directive must also manage risks in their supply chain, which affects the agreements they make with IT suppliers.
Whether the service is in technology, healthcare, finance or another sector, an SLA is more than a formality. It is an instrument that balances operational efficiency with legal protection, provided it is drafted with care.
What are the key elements of an effective SLA?
An effective SLA contains precise metrics, clear consequences for missing them, a measurement and reporting method, and a procedure for review. Each element must be drafted so that it can be enforced.
How do you define measurable service levels?
Define each service level in objective terms: what is measured, how, by whom and over which period. Generic statements such as “high availability” or “prompt response” cannot be enforced.
A good SLA uses definitions and tables. For example: priority 1 incidents (complete outage of a critical system) must be responded to within 30 minutes and resolved within four hours, 24 hours a day; priority 3 incidents within one working day. Make clear whether times run only during business hours, what counts as “resolved” (a workaround or a permanent fix), and when the clock starts: when the customer reports the incident or when the provider detects it.
Metrics should be detailed enough to be meaningful, yet limited to what really matters to the business. A long list of metrics that nobody monitors adds little. Focus on the services that are critical to your operations.
What consequences should follow if a service level is not met?
The SLA should state explicitly what happens when a service level is missed: service credits, an improvement plan, escalation and, for serious or repeated failures, a right to terminate. Without such provisions, you depend on the general rules of contract law.
Service credits are the most common remedy: a reduction of the fee, for example a percentage of the monthly fee for each percentage point below the agreed availability. Depending on their wording, service credits can qualify as a penalty clause (boetebeding) under Article 6:91 BW. That has an important consequence: unless otherwise agreed, a penalty replaces the statutory right to damages (Article 6:92(2) BW). If the customer wants to be able to claim damages above the service credits, the SLA must say so expressly. A court can reduce a penalty if fairness clearly requires it (Article 6:94 BW).
Balance is key. Service credits that are too low give the provider no incentive to improve; credits that are too high will be resisted by the provider or reflected in the price. Combine financial consequences with constructive measures, such as a root cause analysis and an improvement plan, and include a right to terminate if the service levels are missed repeatedly, for example in three consecutive months.
How do you keep the SLA up to date?
Include a periodic review, for example every quarter or every year, in which the parties discuss performance and adjust service levels where necessary. Record who may agree changes and how they are documented.
Business needs and technology change. A service level that was adequate at the start may no longer fit two years later. Regular service reviews, based on the provider’s reports, allow the parties to discuss trends, agree on improvements and adjust the SLA. Make clear that changes to the SLA require written agreement signed by authorised representatives, so that there is no uncertainty about what applies.
Well-drafted SLAs thus become a tool for cooperation: they create transparency, a shared understanding of priorities and a joint commitment to service quality. That depends on clear communication, measurable performance and accountability on both sides.
The table below summarises the key elements of an effective SLA.
| Key element | Main purpose |
|---|---|
| Precise performance metrics | Define clear, measurable service levels as obligations of result where intended |
| Consequences of non-performance | Service credits, improvement plans, escalation and termination rights |
| Measurement and reporting | Agree who measures, how, over which period and what is excluded |
| Review procedure | Enable regular updates to reflect changing needs |
| Relationship with damages and liability | State whether service credits are exclusive or come on top of damages |
By focusing on precision, accountability and adaptability, businesses can use an SLA not just as a legal document but as a practical tool for continuous improvement.
How do you avoid common pitfalls in SLAs?
Most SLA problems come from vague definitions, unclear escalation, inadequate measurement and a lack of exit arrangements. You avoid them by checking the draft for these points before signing.
Which weaknesses should you look for?
Review the draft SLA for ambiguity in service definitions, metrics and legal consequences. Every point that can be read in two ways is a potential dispute.
Typical weaknesses are imprecise measurement, missing or unclear escalation procedures, an unclear relationship between the SLA and the main contract, and exclusions that are so broad that the service levels mean little in practice, for example a broad definition of “planned maintenance” without limits on duration or timing. Check also whether the limitation of liability in the main contract undermines the SLA: a very low cap on liability can make even a clear service level of little value. Assessing these points requires both legal and technical knowledge.
The table below lists typical vulnerabilities and how to address them.
| Vulnerability | Example | Mitigation |
|---|---|---|
| Imprecise metrics | “High availability” without a percentage | Specific, quantifiable definitions |
| Inadequate dispute resolution | No agreed steps before going to court | Escalation steps with deadlines, choice of forum |
| Unclear escalation | Confusion about who to contact when | Step-by-step escalation procedure with names or roles |
| Insufficient monitoring | Only the provider measures, without access for the customer | Shared reporting, audit rights |
| Contractual ambiguity | Conflict between SLA and main contract | Order of precedence clause, legal review |
How do you monitor and verify performance?
Agree on how performance is measured and reported, and make sure the customer can verify the figures. A service level that only the provider can measure is difficult to enforce.
In practice, the provider usually measures with its own monitoring tools and reports monthly. The customer should have the right to receive these reports, to inspect the underlying data and, where necessary, to have an independent audit carried out. Agree what happens if the customer’s own measurements differ from the provider’s, for example that incidents reported by the customer are logged in a ticketing system and count for the calculation.
The best approach combines automated monitoring with human review. Regular service meetings, in which reports are discussed and deviations explained, help to detect problems before they escalate. Keep the reports: in a dispute, they are the main evidence of whether the service levels were met.
How do you prepare for disruption and exit?
Plan for the scenarios that matter: a serious outage, a data breach, the provider’s insolvency and the end of the contract. For each, the SLA or the main contract should state what the provider must do.
Include business continuity and disaster recovery obligations, such as recovery time and recovery point objectives, and the obligation to test them. Arrange data protection properly: if the provider processes personal data on your behalf, a data processing agreement is required under Article 28 of the General Data Protection Regulation (GDPR).
Arrange the exit in advance. The SLA should state that the provider must return your data in a usable, standard format, cooperate with the transition to a new provider and continue the service during a transition period. For cloud services, the EU Data Act (Regulation 2023/2854) has applied since 12 September 2025: customers may switch provider with a maximum notice period of two months, after which the provider must complete the transition within a transitional period of in principle 30 days. From 12 January 2027, providers may no longer charge switching fees. Where the provider could become insolvent, consider an escrow arrangement for critical software.
Compliance with an SLA is not a one-off check but a continuous process. Parties that monitor performance, discuss deviations openly and adjust the SLA where necessary turn potential risks into better cooperation.

How do you negotiate a good SLA?
Prepare by defining your own needs, compare the provider’s offer with alternatives, and negotiate the service levels, the remedies and the exit together. The best SLA is precise where it matters and flexible where business needs will change.
How do you prepare for the negotiation?
Start with an internal assessment: which services are critical, what downtime can the business tolerate, and what does an outage cost per hour? The answers determine which service levels you really need and what they are worth to you.
Involve legal, IT, operations and finance in the preparation. Compare the provider’s standard SLA with market practice and with offers from other providers. Pay attention to the provider’s standard terms: they often contain broad exclusions and low liability caps that affect the value of the service levels. As a provider, assess realistically what you can deliver, and make sure your own subcontractors, such as data centre or cloud providers, offer at least the same service levels.
How do you negotiate the metrics themselves?
Negotiate metrics that are precise, measurable and linked to the business impact of the service. Build in a mechanism to adjust them as the service or your business changes.
Next to quantitative metrics such as availability and resolution time, qualitative elements can matter, such as customer satisfaction or the quality of reports. These are harder to enforce, so link them to concrete follow-up steps rather than to financial consequences. Consider trend indicators as well: repeated incidents of the same kind may point to a structural problem even if the monthly average is met.
Agree how service levels can be adjusted, for example after a change in the service, a migration or growth in usage. A change procedure with clear rules on price and timing prevents discussions later. For the customer, it is also important that service levels cannot be lowered unilaterally by the provider, for example through a change in its general terms.
How do you arrange governance and dispute resolution?
Agree on a governance structure with regular meetings, an escalation ladder and, if needed, an independent expert for technical disputes. Also agree on the applicable law and the competent court or arbitration.
A typical escalation ladder starts with the service managers, then moves to senior management and only then to mediation, expert determination or proceedings, with deadlines for each step. Make sure the escalation procedure does not prevent urgent measures, such as summary proceedings (kort geding) to force the provider to continue the service. For technical disputes about whether a service level was met, a binding opinion (bindend advies) from an independent IT expert can be quicker and cheaper than court proceedings.
In international SLAs, the choice of law and forum matters. Parties can choose Dutch law under the Rome I Regulation, and a choice of a Dutch court is in principle respected within the EU. Arbitration is an option when the other party is outside the EU.
Approach SLA negotiations as the basis for a long-term relationship. The most effective agreements are precise about what must be delivered and flexible about how the service develops, with clear expectations for both parties.
In summary
- An SLA is an ordinary contract under Dutch law; for services, Articles 7:400 and following BW apply alongside general contract law.
- Write service levels as obligations of result with defined percentages, measurement periods and exclusions; “reasonable endeavours” is much harder to enforce.
- Service credits can qualify as a penalty clause that replaces damages unless the SLA says otherwise (Article 6:92(2) BW).
- Agree who measures, how performance is reported and verified, and when repeated failures justify termination.
- Arrange the exit in advance; for cloud services, the EU Data Act gives customers switching rights since 12 September 2025.
Frequently asked questions
What is a Service Level Agreement (SLA)?
An SLA is a contract, or an annex to a contract, that sets out the service levels a provider must deliver, such as availability, response and resolution times, how these are measured and what happens if they are not met. Under Dutch law it is binding like any other contract.
Why are SLAs important for businesses in the Netherlands?
Without an SLA, a service provider is usually only held to the care of a good contractor (Article 7:401 of the Dutch Civil Code), which is hard to enforce. An SLA makes performance measurable, sets out the consequences of failures and arranges the exit, which gives both parties certainty and reduces disputes.
What key elements should be included in an effective SLA?
An effective SLA contains precise and measurable service levels, a measurement and reporting method, service credits and their relationship with damages, an escalation procedure, termination rights for repeated failures, a review procedure and exit arrangements, including the return of data.
How do SLAs contribute to risk management in organisations?
SLAs make clear what service a business can rely on and what happens if it fails, so that fallback options can be planned. For some organisations, such as financial institutions under the Digital Operational Resilience Act, specific contractual provisions on service levels are a legal requirement.
How can Law & More help with your SLA?
An SLA only protects you if its service levels are enforceable, its remedies are clear and its exit is arranged. Vague indicators or one-sided escalation clauses can turn certainty into a costly dispute. Law & More drafts and reviews SLAs and IT and outsourcing contracts for customers and providers, with attention to both the legal and the technical side. Contact our IT and contract lawyers for an assessment of your SLA, or request a consultation directly on our website.
Unsure where you stand? Tell us about your situation. We will let you know your options within one working day.
How Law & More can help you with this is explained on our IT lawyer page.


