Contracts
SaaS and cloud agreements, limitation of liability, service levels and exit. Practical guidance for anyone buying or selling technology.
Articles on this topic
AI agent liability: who pays when an AI agent causes harm?
Under Norwegian law, AI agent liability rests primarily with the business that puts the agent to work. An agent is neither a legal person nor an employee, so the harm is treated as the business's own. Towards customers, ordinary contractual liability applies. The vendor is liable only as far as the contract allows, and the new EU Product Liability Directive does not yet apply in Norway.
Nordlo judgment: why did the customer get only NOK 8,280 after a cyber attack?
In the Nordlo judgment of 30 June 2026, Gulating Court of Appeal held that Btec AS, which lost its production data in a ransomware attack on its IT supplier and claimed over NOK 57 million, was bound by the supplier's unsigned standard terms. The attack was not force majeure, the supplier was not grossly negligent, and a cap of three months' fees gave NOK 8,280.
AI hallucinations: who is liable when your chatbot promises a customer too much?
A business is liable for AI hallucinations in its own customer service. The chatbot is not a separate legal person, and what it says counts as the business's own statements. Towards consumers, wrong answers can give rise to claims for non-conformity, and misleading answers can breach Norwegian marketing law. A disclaimer in the chat window helps little.
Choice of law and jurisdiction: which country's law governs your contract?
Choice of law and jurisdiction clauses decide which country's law governs the contract and where a dispute is resolved. As a rule, the parties can agree both. If the contract is silent, Norwegian law applies the law of the country with the closest connection, while jurisdiction follows the Dispute Act and the Lugano Convention. Choose deliberately, especially under US standard terms.
Cloud exit: how do you secure your data when the contract ends?
A cloud exit must be secured in the contract before it is signed. The contract should give a right to all data in a machine-readable format, assistance from the provider, a transition period and documented deletion. In the EU the Data Act requires at most two months' notice, a 30-day transition and at least 30 days' access to the data. In Norway the regulation does not yet apply.
Copyright and AI: who owns the text, code and images that AI creates?
Content that AI creates entirely on its own probably has no copyright under Norwegian law, because the Copyright Act requires original and individual creative effort by a human. If a human reworks the output creatively, the human contribution may be protected. A vendor's promise that you own the output gives no more protection than the law itself provides.
Transferring personal data to the US: how safe is the Data Privacy Framework?
The Data Privacy Framework makes it lawful to transfer personal data to US companies certified under it. The adequacy decision applies in Norway and was upheld by the EU General Court in 2025, but the case has been appealed and US oversight bodies have been weakened. Businesses should use the framework, but keep standard contractual clauses and an exit plan in reserve.
NDA: what should it contain, and what does it not protect?
A non-disclosure agreement (NDA) is a contract under which confidential information may only be used for a specific purpose and must not be passed on. It should define what is confidential, set out exceptions, duration and remedies, and regulate the use of AI tools. It binds only the parties, and it cannot prevent whistleblowing or protect information that is already known.
SaaS data processing agreement: what must it contain, and what should you require?
When a SaaS supplier processes personal data on your behalf, GDPR Art. 28 requires a written SaaS data processing agreement. It must cover instructions, confidentiality, security, sub-processors, assistance, deletion and audits, among others. The supplier's standard terms often meet the minimum, but rarely the customer's needs on breach notification, insight, transfers outside the EEA and exit.
SaaS limitation of liability: what holds up under Norwegian law?
A SaaS limitation of liability is, as a rule, valid between businesses under Norwegian law. A liability cap and an exclusion of indirect loss normally hold, but as a starting point they do not protect the supplier against wilful misconduct or gross negligence. Unusual and onerous terms may also fall away as not accepted, be read restrictively or be adjusted under the Contracts Act § 36.
SaaS price increase from your provider: what can you do?
A SaaS price increase requires a basis in the contract. Without a change clause, the agreed price is binding for the contract term. Where the provider has reserved the right to change prices, the clause is generally valid between businesses, but it may be read narrowly or adjusted under section 36 of the Norwegian Contracts Act. The customer's key tools are a right to terminate and an agreed cap.
Your secrets in ChatGPT: can you lose protection for trade secrets?
Trade secrets are only protected if the business has taken reasonable steps to keep them secret. One employee pasting a confidential document into ChatGPT does not normally remove that protection. But if the business lets employees use AI tools freely, without rules and without an enterprise agreement, it becomes hard to show reasonable steps when the secret later has to be enforced.
Vibe lawyering: what is the risk when management drafts contracts with AI?
Vibe lawyering means managers and specialists producing contracts with AI without legal review. The contract binds the company in full, even when it rests on foreign concepts, hallucinated references or liability rules that do not work under Norwegian law. AI can be used for simple agreements, but not without review when a lot is at stake.
The legal framework
- Norwegian Damages Act (skadeserstatningsloven)lov
- Norwegian Contracts Act (avtaleloven)lov
- Norwegian Sale of Goods Act (kjøpsloven)lov
- Norwegian Product Liability Act (produktansvarsloven)lov
- Product Liability Directive (EU) 2024/2853EU
- Artificial Intelligence Act, Regulation (EU) 2024/1689EU
- Norwegian Dispute Act (tvisteloven)lov
- General Data Protection Regulation (EU) 2016/679EU
- Norwegian Consumer Purchases Act (forbrukerkjøpsloven)lov
- Norwegian Marketing Control Act (markedsføringsloven)lov
- Norwegian Act on the Law Applicable to International Sales of Goods (kjøpslovvalgsloven)lov
- Norwegian Arbitration Act (voldgiftsloven)lov
- Data Act, Regulation (EU) 2023/2854EU
- Norwegian Copyright Act (åndsverkloven)lov
- Commission Implementing Decision (EU) 2023/1795 on the EU-US Data Privacy FrameworkEU
- Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countriesEU
- Norwegian Trade Secrets Act (forretningshemmelighetsloven)lov
- Norwegian Working Environment Act (arbeidsmiljøloven)lov
- Norwegian Personal Data Act (personopplysningsloven)lov
- Commission Implementing Decision (EU) 2021/915 on standard contractual clauses between controllers and processorsEU
- Norwegian Private Limited Liability Companies Act (aksjeloven)lov