Blog
Business22 July 2026 11 min🇩🇰 Denmark

IT service contract: support and service agreements

A complete guide to IT service contracts: SLA, support agreements, uptime, limitation of liability, GDPR and exit terms for software and systems.

Karoline, Dokumentkonsulent

Written for Danish law and Danish contract practice.

Modern businesses depend on IT systems, servers and software. When these systems fail, production stops, and the lost hours cost money. An IT service contract (also called a support agreement, operations agreement or maintenance agreement) ensures the business knows exactly what the IT supplier is obliged to deliver: when support is available, how quickly faults are fixed, and who is liable if the system is down.

What is an IT service contract?

An IT service contract is an agreement between an IT supplier (a software supplier, operations supplier or managed service provider) and a customer for the ongoing delivery of IT services.

IT service contracts typically cover:

  • Support and fault handling: technical support, helpdesk and fault correction
  • Operations and monitoring: server monitoring, backup and security updates
  • Maintenance: regular updates of systems and software
  • SaaS subscriptions: the ongoing delivery of cloud-based software
  • Managed services: full or partial IT outsourcing

Service Level Agreement (SLA): the core of the IT contract

An SLA (Service Level Agreement) is the agreed service levels: what the customer can expect from the supplier, and what happens if the supplier does not meet them.

Key SLA parameters

Availability (uptime):

  • 99.9% uptime corresponds to at most about 9 hours of downtime a year
  • 99.5% uptime corresponds to at most about 44 hours of downtime a year
  • 99.0% uptime corresponds to at most about 88 hours of downtime a year

State whether uptime is measured 24/7 all year or only during normal hours.

Response time: the time from a fault report being received until the supplier confirms and begins handling it. Typically varies by severity.

Resolution time: the time from the fault report until the fault is fixed. Differentiate by severity.

Example of an SLA table:

Severity Definition Response time Resolution time
Critical System down, business stopped 1 hour 4 hours
High A critical function fails, workaround possible 4 hours 8 hours
Medium Limited functionality 1 working day 3 working days
Low A cosmetic fault or a wish 3 working days Next release

SLA consequences (service credits)

What happens if the supplier does not meet the SLA?

  • Service credits: a reduction in the monthly invoice (for example a discount per hour of downtime over the SLA limit)
  • Damages: in serious cases the customer can claim damages for a documented loss
  • Right to terminate: on repeated SLA breaches the customer can terminate the agreement

Exceptions to the SLA

State clearly when the SLA does not apply:

  • Planned maintenance windows (typically a couple of hours a month)
  • Downtime caused by the customer's own systems
  • Force majeure
  • Third-party systems (for example an external cloud provider)

What should an IT service contract contain?

1. The scope of the services

Describe precisely which systems, software and tasks the contract covers: named systems and versions, the number of users and devices, included services (support, updates, backup) and excluded services (for example hardware, third-party software, consultancy work).

2. Support availability

  • Helpdesk hours (for example Mon-Fri 08:00 to 17:00)
  • Contact channels (phone, email, ticketing system)
  • On-call service outside hours (with any surcharge)
  • Language (Danish-language support is not a given with foreign suppliers)

3. Change management

How are changes to the system handled? Set an approval procedure for updates, test procedures before deployment, and any change-freeze periods in critical business periods.

4. Security and GDPR

An IT supplier often processes personal data. The contract must address encryption and access control, backup frequency and location, and a procedure for a data breach. A data processing agreement is required under the GDPR when the supplier processes personal data on the customer's behalf.

5. Prices and payment

  • A fixed monthly subscription fee
  • Any hourly rate for work beyond the scope of the contract
  • An adjustment mechanism (for example the net price index or an agreed rate)
  • The invoicing interval and payment deadline

6. Limitation of liability

An IT supplier's liability is typically limited. Standard terms include:

  • A maximum liability, often limited to a few months' fee
  • The exclusion of indirect loss and loss of operations (lost profit, lost orders)
  • The exclusion of loss caused by the customer's own faults

This is often reasonable, but the customer should assess whether the limitations are acceptable in light of the business's IT dependence. Note that a limitation of liability can be set aside in cases of gross negligence or intent.

7. Backup and recovery

  • Backup frequency (daily, weekly, in real time?)
  • Backup location (off-site, cloud, geographic distribution)
  • Recovery Point Objective (RPO): how old may backup data be at most?
  • Recovery Time Objective (RTO): how quickly can systems be restored?

8. Transfer and sub-suppliers

Can the supplier transfer the contract or use sub-suppliers? Make sure this requires the customer's consent, especially with sensitive data.

9. Duration and termination

  • The contract period (typically 1 to 3 years)
  • The notice period (typically 3 to 6 months)
  • A right to terminate on SLA breaches
  • A procedure on termination: what happens to data and systems?

10. Exit terms and data portability

This is critical and often overlooked:

  • What happens to the customer's data on termination?
  • For how long is data available after termination?
  • In what format is data delivered?
  • Does the supplier help with migration to a new supplier?

The supplier should not have an incentive to withhold data to keep the customer.

Managed services vs. break-fix

There are two basic models for IT support:

Break-fix: the customer pays only when something goes wrong. No fixed agreement, and the hours are invoiced. Cheapest in the short term, but with unpredictable costs and no guaranteed response times.

Managed services: a fixed monthly fee for proactive IT administration, with monitoring, updates and support included. Predictable costs and a higher service level, but it requires a clear contract.

Most SMEs with some IT dependence are best served by a managed services agreement.

Cloud and SaaS agreements

A SaaS supplier's standard terms are typically non-negotiable; you accept them as they are. For critical systems the business should review the SLA and uptime guarantees, understand the data-processing terms and GDPR matters, assess whether there is a right to data export on termination, and check which law applies. For business-critical SaaS it can make sense to negotiate a supplementary agreement.

Frequently asked questions about IT service contracts

Is there a difference between an SLA and an IT service contract?

An SLA is part of the IT service contract: it is the section that defines the specific service levels. The IT service contract is the overall agreement, including prices, liability, security and terms.

Can we terminate the agreement with immediate effect if the system is down for days?

It depends on the contract. Expressly include a right to terminate on repeated SLA breaches, for example "three critical SLA breaches within 6 months give the customer the right to terminate without notice".

Is a data processing agreement mandatory?

Yes. Under the GDPR a data processing agreement is required when the supplier processes personal data on the customer's behalf. Most IT support suppliers process employee and user data at a minimum.

What does SLA in percent (uptime) mean?

SLA is often stated as a percentage of the system's availability. 99.9% uptime corresponds to about 43 minutes of downtime a month, while 99% uptime corresponds to about 7 hours of downtime a month.

Conclusion

An IT service contract with clear SLA requirements, defined areas of responsibility and well-thought-out exit terms is indispensable for any business that outsources its IT operations or uses managed IT services. Use a thorough template as a starting point and adapt it to your specific IT infrastructure.


The content of this article is for guidance only and does not constitute legal advice. Contact an IT lawyer for advice on specific IT service agreements or GDPR questions.

This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.