DORA Article 30 mandates that financial entities include specific provisions in all ICT vendor contracts. As a SaaS vendor selling to banks, insurers, payment processors, or other regulated financial entities, you will be required to include these clauses in your customer agreements. Financial entities cannot legally enter into a non-compliant ICT contract under DORA — which means non-compliant vendors lose deals or face delayed sign-offs until contracts are remediated.
Who This Applies To
If you sell to:
- Banks and credit institutions
- Insurance and reinsurance undertakings
- Investment firms
- Payment institutions and e-money institutions
- Crypto-asset service providers (CASPs)
- Central counterparties and trading venues
- Credit rating agencies
...your contracts need DORA Article 30-compliant terms.
You are not directly regulated by DORA — DORA applies to the financial entity, not the vendor. But the financial entity is required to include Article 30 clauses in your contract, and will not sign without them.
DORA Article 30 Mandatory Provisions
1. Clear Description of All ICT Services
The contract must include a clear and comprehensive description of all functions and services provided — including all sub-contracted components. Vague descriptions like "cloud hosting services" are insufficient.
What to include:
- Complete service description including all components
- What infrastructure the service runs on (cloud provider, data centres)
- Any processing performed by sub-contractors and what they access
- Scope of data processed
2. Data Location and Processing
The contract must specify:
- Where data is stored — at country and data centre level
- Where data is processed — if processing occurs in multiple locations, all must be specified
- Where backups are kept
- A requirement that the vendor notifies the financial entity before changing data locations
3. Provisions on Availability, Authenticity, Integrity, and Confidentiality
The contract must include specific provisions on:
- Availability: Service level commitments, uptime guarantees, maintenance windows
- Authenticity: Measures to ensure data is not altered without authorisation
- Integrity: Controls ensuring data remains accurate and complete
- Confidentiality: How the vendor protects the financial entity's data
Generic security statements ("we maintain appropriate security") do not satisfy this requirement. Specific commitments are required.
4. Full Access, Inspection, and Audit Rights
Financial entities must have the right to:
- Access the vendor's premises and systems for audit purposes
- Conduct inspections of relevant systems, data, and documentation
- Engage third-party auditors to perform assessments
- Review audit results from the vendor's own assessments
The contract must specify notice requirements for audits and confirm that the vendor will cooperate with inspections by the financial entity's supervisory authority (the regulator).
Regulatory access clause: The contract must explicitly provide access rights to the financial entity's competent authority (ECB, PRA, ACPR, BaFin, etc.) — not just the financial entity itself.
5. Termination Rights and Exit Assistance
The contract must include:
- Termination rights for the financial entity, including for cause (regulatory requirement, material breach) and convenience
- Exit assistance obligations: The vendor must assist the financial entity in transitioning to an alternative provider
- Data return or deletion: What happens to data on termination, with timelines
- Post-termination support: Minimum period during which the vendor supports migration
6. Incident Notification Obligations
DORA requires financial entities to report major ICT incidents within specific timeframes (4-hour initial notification, 72-hour intermediate report). To meet these timelines, vendors must notify customers of incidents affecting their services with sufficient speed.
The contract must specify:
- Notification timeline for ICT incidents affecting the financial entity's services
- What constitutes a notifiable incident — threshold for notification
- Notification method — who to contact, how (email, dedicated channel)
- Information to include in incident notifications
Best practice: 1–4 hours for major incidents; 24 hours for significant incidents. This requires the vendor to have its own incident detection and notification process.
7. Cooperation with Authorities
The vendor must cooperate with the financial entity's supervisory authority when requested. The contract must confirm:
- Vendor agrees to cooperate with on-site inspections by regulators
- Vendor will provide information requested by the supervisory authority
- Vendor will not obstruct or delay regulatory examinations
8. Sub-Contractor Management
Full disclosure: The contract must include a list of all sub-contractors that access, process, or hold the financial entity's data.
Change notification: The vendor must notify the financial entity before any changes to sub-contractors that may affect the service or data processing.
Chain of obligations: Sub-contractors must be bound to equivalent DORA obligations. The vendor must confirm this through contractual flow-down.
Concentration risk disclosure: If sub-contractors include major cloud providers (AWS, Azure, GCP), this must be disclosed. Financial entities must manage their DORA concentration risk.
Additional Provisions Often Required
Beyond the mandatory Article 30 provisions, financial entity procurement teams typically require:
Business continuity plan:
- BCP documentation available for review
- Annual testing commitment with evidence available
- RTO and RPO commitments specific to the services used
Penetration testing:
- Annual penetration testing commitment
- Remediation timeline for critical findings
- Test results available for review (or evidence of remediation)
Regulatory change:
- Obligation to notify the financial entity of regulatory changes affecting the service
- Obligation to notify of significant changes to the vendor's own compliance status
DORA Contract Addendum Approach
The most efficient approach for SaaS vendors with multiple financial services customers is to create a DORA Addendum — a separate document that adds DORA-specific provisions to your standard MSA without requiring a full contract rewrite.
A standard DORA Addendum covers:
- Service description (incorporating your standard service documentation by reference)
- Data location schedule
- Security commitments schedule
- Audit rights provisions
- Incident notification procedure
- Termination and exit assistance
- Sub-contractor list and change notification procedure
- Cooperation with authorities clause
This approach allows you to add DORA compliance to existing customer relationships and new deals without restructuring your entire contract template.