← Digital, E-Commerce & AI

Digital · Cloud

Cloud and infrastructure services agreement

In the cloud, control is shared between customer, integrator and infrastructure provider. The agreement must state who configures, monitors, backs up, responds to incidents and ensures data export on termination.

shared responsibility security and data switching and exit
Essential schedulesSLA, security, data and exit plan
Applicable ruleThe Data Act applies from 12 September 2025
Possible regimeNIS2 for providers and entities within its scope
01

The shared responsibility model

IaaS, PaaS, SaaS and managed services allocate control differently. The agreement must describe the service purchased and avoid a blanket exclusion treating every configuration as exclusively the customer’s responsibility.

Privileged accounts, encryption, patches, backup, monitoring and restoration are established. A RACI matrix can turn general standards into verifiable tasks.

02

Data, location and subcontractors

The customer must know what data enter the service, where they may be stored, who may access them and how they are separated from other customers’ data.

  • Hosting regions and whether they may change.
  • Subcontractors and the change-notification mechanism.
  • GDPR roles, transfers and assistance with individuals’ rights.
  • Encryption, keys and provider staff access.
  • Backup, RPO, RTO and restoration testing.
  • Logs, retention and access to evidence after an incident.
03

Data Act: switching, export and charges

The Data Act establishes minimum requirements for data processing service agreements and requires covered providers to remove unjustified barriers to switching and multi-cloud. The agreement must identify exported data, format, transition period and assistance.

Switching and egress charges are transitional and must be fully eliminated from 12 January 2027 for covered operations. Until then, permitted charges must be transparent and linked to actual expenditure within the Regulation’s limits.

04

Security and NIS2

Government Emergency Ordinance No. 155/2024, approved with amendments by Law No. 124/2025, transposes the NIS2 framework in Romania. Cloud, data centre and managed-service providers and other entities may fall within its scope under the statutory criteria.

Implementing Regulation (EU) 2024/2690 details measures and criteria for categories of digital providers. The agreement must enable incident notification, cooperation, auditing and access to necessary information without creating conflicts between customer and provider.

05

How we work together

  1. 01
    Mapping the service

    We clarify the product, users, technical workflows, commercial model and documents already in use.

  2. 02
    Legal analysis

    We establish the B2B or B2C regime, the parties’ roles, applicable legislation and risks to be allocated.

  3. 03
    Drafting and alignment

    We prepare the cloud service agreement and schedules and align them with the interface, offer, technical processes and annexes.

  4. 04
    Implementation

    We deliver the final version and a clear set of observations for publication, signature, configuration or operational use.

QUESTIONS

Frequently asked questions

Is the cloud provider liable for every data loss?

That depends on the service, configuration, backup and liability clauses. The responsibility matrix must show what each party controlled.

Does the Data Act already apply?

Yes, the Regulation mainly applies from 12 September 2025, with transitional rules for certain agreements and charges. The service’s classification must be checked specifically.

Does every cloud customer fall under NIS2?

No. Scope depends on sector, size, entity type and special criteria. The provider may nevertheless itself be a regulated entity.

Need an agreement for cloud or hosting services?

Send your documents for a legal assessment and a solution tailored to your commercial objective.