Skip to content
Contract Review

Top 15 Compliance Clauses Missing from Startup Contracts

6 min readUpdated 5 August 2026

Startup contracts — both vendor agreements and customer MSAs — routinely omit compliance clauses that become significant issues when enterprise customers arrive, regulatory audits happen, or acquisitions require due diligence. The 15 clauses below are the most commonly missing. Each one is either required by regulation or will be required by enterprise customers during their security and compliance review.


1. Data Processing Agreement (GDPR Article 28)

What's missing: No DPA at all, or a DPA that references the wrong regulation (EU GDPR only, missing UK GDPR), or one that uses outdated standard contractual clauses.

Why it matters: Every SaaS that processes personal data on behalf of customers needs a compliant DPA. Enterprise customers will block or delay deals until one is in place. ICO and EDPB enforcement will ask for it in any investigation.


2. Sub-Processor Notification

What's missing: No obligation to notify customers when sub-processors change. Or a clause that says "we will update our sub-processor list" without specifying a notification timeline or a right for the customer to object.

Why it matters: GDPR Article 28(2) gives customers the right to object to new sub-processors. Without this clause, customers cannot exercise this right, and the controller is in breach.


3. Incident Notification Timeline

What's missing: A vague "we will notify you of security incidents" clause with no timeline. Or a clause tied only to regulatory timelines (72 hours) without a faster internal notification to customers.

Why it matters: Financial services customers under DORA require 4-hour notification for major ICT incidents. Enterprise customers generally expect faster notification than the regulatory minimum. Specific timelines make the obligation enforceable.


4. Data Residency

What's missing: No specification of where data is stored. The contract is silent, leaving customers to assume data stays in the EU — when in reality it may be on US-based infrastructure.

Why it matters: Many enterprise customers (especially in financial services, healthcare, and public sector) have data residency requirements. Discovering post-contract that data is stored in the US creates immediate issues.


5. Audit Rights

What's missing: No explicit right for the customer to audit the vendor's security and compliance practices. Some contracts say certifications (ISO 27001, SOC 2) satisfy this — but that must be explicitly agreed, not assumed.

Why it matters: DORA Article 30 mandates audit rights in ICT vendor contracts with financial entities. Many enterprise procurement processes require contractual audit rights. Without them, security incidents cannot be properly investigated.


6. Business Continuity and Recovery Commitments

What's missing: No specific RTO/RPO commitments in the contract. Or a reference to a BCP policy document that customers cannot access.

Why it matters: Enterprise customers need to understand their exposure if the vendor has an outage. Contractual RTO/RPO commitments are required for DORA-regulated customers and expected by most enterprises.


7. Data Deletion Procedure

What's missing: "We will delete your data within 30 days of contract termination" — without addressing backup retention, how deletion is confirmed, or what happens to data at sub-processors.

Why it matters: GDPR requires confirmation of deletion. Enterprise customers need to know their data is genuinely gone, not sitting in a backup for years after they've left.


8. Liability Cap and Data Breach Carve-Out

What's missing: Standard limitation of liability clause caps all liability at 12 months' fees — including data breaches. No carve-out for regulatory fines or data breach notification costs.

Why it matters: A data breach affecting thousands of customer records creates liability that far exceeds the contract value. Enterprise customers require data breach carve-outs, and courts may not enforce unreasonable liability caps in the context of regulatory violations.


9. Intellectual Property on Customer Data

What's missing: No clause specifying who owns customer data. Or an ambiguous clause that could be read to give the vendor rights to use customer data for product improvement, training AI models, or benchmarking.

Why it matters: Enterprise customers will not accept ambiguity on data ownership. Financial services customers are often legally prohibited from sharing customer data with third parties without specific authorisation.


10. Penetration Testing Commitment

What's missing: No obligation to conduct annual penetration testing, or no requirement to remediate findings within a specified period.

Why it matters: ISO 27001 and SOC 2 require penetration testing. Enterprise customers frequently ask for evidence. DORA requires regular ICT security testing. Without a contractual commitment, there is no enforceable standard.


11. Regulatory Change Notification

What's missing: No obligation to notify customers of regulatory changes that affect the service. If GDPR transfers rules change, if DORA introduces new requirements, customers may not learn until problems arise.

Why it matters: Customers are responsible for their own compliance. They need to know if changes in the vendor's regulatory environment affect their obligations.


12. Concentration Risk / Multi-Cloud Disclosure

What's missing: No disclosure of which cloud providers the service depends on. No commitment to notify customers of changes to underlying infrastructure providers.

Why it matters: DORA requires financial entities to manage concentration risk — if all their critical SaaS vendors run on the same cloud provider, that creates regulatory exposure. Without disclosure, customers cannot manage this risk.


13. Employee Screening

What's missing: No confirmation that employees with access to customer data are subject to background checks appropriate to their access level.

Why it matters: Financial services, healthcare, and public sector customers often require confirmation of screening. ISO 27001 includes personnel security controls.


14. Change Management Notification

What's missing: No obligation to provide advance notice of material changes to the service — new features that change data processing, changes to authentication mechanisms, modifications to sub-processor use.

Why it matters: Material changes can affect customers' own compliance positions. GDPR requires data subjects to be informed of changes in processing. Enterprise customers need advance notice to manage their own obligations.


15. Governing Law and DPA Alignment

What's missing: A contract governed by US law with a UK/EU GDPR DPA attached — creating inconsistencies about which law governs data protection disputes. Or a DPA governed by a different law than the main contract.

Why it matters: Governing law and jurisdiction clauses in the DPA must align with the data protection framework. EU enterprise customers require EU-law governed DPAs for transfers within the EU.

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →