Blog
Business20 June 2026 10 min🇩🇰 Denmark

IT company: contracts and legal documents

A guide to legal documents for IT companies: data processing agreements, NDA, consultancy agreements, SaaS terms, employment contracts, IP (s. 59) and GDPR compliance.

Karoline, Dokumentkonsulent

Written for Danish law and Danish contract practice.

You have built the product. You have the first customers. And suddenly someone asks: "Will you send an agreement?", and you are not sure what you should actually send.

That is the moment many IT entrepreneurs and freelance developers discover that their legal documents are a bit up in the air. This guide gives you an overview of which contracts and documents are indispensable for an IT company in Denmark, whether you are a freelance developer, a SaaS founder or run a small IT agency.

Why are legal documents extra important in IT?

IT companies work with intangible assets, that is code, data, algorithms and trade secrets, which are harder to protect than physical products. A single unclear agreement can mean:

  • That the customer thinks they own all the code you have written, including your reusable framework
  • That your client passes your prototype code to a competitor
  • That you are exposed in a GDPR case because there was no data processing agreement
  • That you cannot document what was actually agreed when the project goes off track

The right documents are not bureaucracy; they are the foundation your business rests on.

1. Data processing agreement (DPA)

For IT companies, the data processing agreement is the document most people underestimate, until Datatilsynet comes knocking.

When are you a processor?

If you process personal data on a customer's behalf, for example by storing user data in your SaaS platform, having access to customers' HR data or handling email marketing, you are a processor under the GDPR. This requires a written data processing agreement (Article 28).

What must the agreement contain?

A valid data processing agreement must, among other things, govern the purpose and scope of the processing, the categories of personal data and data subjects, your security and confidentiality obligations, the use of sub-processors, the procedure on a data breach (notification to the controller without undue delay) and what happens to the data on termination.

2. Non-disclosure agreement (NDA)

Before you share code, architecture, a business idea or pricing with a potential customer, partner or investor, you should have a non-disclosure agreement (NDA) signed.

Typical situations in the IT industry

  • Proof of concept: you show an early product to a potential big customer
  • Code review: a freelancer or external partner gets access to your repository
  • Partnership: two software companies consider an integration or a joint venture
  • Due diligence: an investor or buyer reviews your code and architecture

An NDA defines what is confidential, who is bound, and the consequences of a breach. For IP-heavy IT companies it is one of the most important documents.

3. Consultancy agreement

If you are a freelance developer, an IT consultant or run an agency, the consultancy agreement is the primary document in your customer relationship.

What should an IT consultancy agreement contain?

Delivery and scope: what exactly is delivered (technologies, functionality, integrations)? What is not included? Who approves the delivery, and on what criteria?

Timetable and milestones: when is what delivered, and what happens on delay from the customer's side (missing feedback or access)?

Payment: hourly rate or fixed price, payment terms, any advance and final payment, and the consequences of late payment.

Intellectual property: this is the most important section for most IT consultants. Who owns the code?

  • It is often agreed that the customer gets the rights to what is created specifically for them, for full payment.
  • Avoid transferring your generic libraries, frameworks and standard components.
  • List clearly the pre-existing components that remain your property, and give the customer a licence to use them.

Limitation of liability: limit your liability, for example to the fee paid, and exclude indirect loss, subject to gross negligence and intent.

Termination: notice from both sides, and what happens to work in progress and payment.

4. SaaS agreement or terms of service

If you sell a software product as a subscription (SaaS), your terms of service are the foundation of the whole customer relationship. They are not just a supplement; they are the contract.

Access and licence terms: what may the customer use the software for, are there limits on the number of users, API calls or data volume, and is transfer allowed?

Service level (SLA): the guaranteed uptime (typically 99.5% or 99.9%), the response time on downtime and the compensation on an SLA breach.

Payment and renewal: the invoicing model, automatic renewal and termination, and price adjustment.

Data and ownership: the customer owns their data, and you only have the right to process it to deliver the service. Describe what happens to data on termination (export and deletion).

Limitation of liability: limit your liability for downtime, faults and consequential loss, within the limits of the law.

Termination and breach: when can you terminate (for example on non-payment or misuse), and what is the notice?

For B2B SaaS a master agreement with service schedules is a good model. For B2C, clear information and compliance with the consumer rules are decisive.

5. Employment contracts for developers

If you employ developers, designers or other staff, the employment contract defines, among other things, who owns what they create.

Intellectual property in employment

For software (computer programs) there is a clear statutory rule: under section 59 of the Copyright Act, the copyright to a program created by an employee as part of their work or on the employer's instructions passes in full to the employer. The rule can be departed from by agreement. For other types of work there is no corresponding statutory rule; here, under an unwritten main rule, the rights necessary for the company's ordinary operations pass to the employer.

Even though section 59 covers software, it is good practice to clarify the rights in the contract:

  • That code, documentation and software created as part of the work belongs to the company
  • That the employee assists in transferring the relevant rights
  • That contributions to open-source projects require prior approval

Non-compete and customer clauses

For key employees, clauses can be relevant, but the rules in the Employment Clauses Act are strict:

  • A non-compete clause requires a specially trusted position, a written agreement and compensation: at least 40% of pay per month for a binding of up to 6 months and at least 60% for up to 12 months. The clause can apply for at most 12 months.
  • A customer clause can likewise apply for at most 12 months and requires compensation.
  • If a non-compete and a customer clause are combined, the combined clause can apply for at most 6 months.

These clauses are complex; seek legal advice before using them.

6. GDPR documentation

As an IT company you almost always process personal data, either as a controller (your own customers' data) or as a processor (your customers' user data). The GDPR requires, among other things:

As a controller:

  • A privacy policy, visible on your website and in the product
  • A cookie solution, if you use cookies for statistics or marketing
  • A record of processing activities (Article 30). The exemption for businesses with fewer than 250 employees does not apply if the processing is not occasional, involves sensitive data or entails a risk. In practice, most IT companies process data on an ongoing basis and must therefore keep a record.

As a processor:

  • A data processing agreement with your customers
  • Agreements with your sub-processors (for example hosting, payment and marketing services)

Missing GDPR documentation is one of the most frequent causes of cases at Datatilsynet.

7. General terms of trade

For IT companies that sell products, licences or standard services to many customers, general terms of trade are an effective way to create uniform terms. They supplement the individual agreement and set out, among other things, payment terms, limitation of liability, choice of law (Danish law), venue and dispute resolution.

Prioritise the documents correctly

Not all documents are equally important from day one. A recommended order:

Straight away:

  1. An NDA, before you share anything with anyone
  2. A consultancy agreement or SaaS terms, before you take the first krone

Before the first employee: 3. An employment contract with an intellectual-property clause 4. Internal GDPR policies

Before you process customer data: 5. A data processing agreement 6. A privacy policy and cookie solution

Frequently asked questions

Who owns the code I write as a freelancer?

As a rule you, as the freelancer, own the copyright to the code, unless the contract says otherwise. Most customers expect to own what they pay for, so make sure the contract clearly defines what is transferred and what you keep.

Do I need a data processing agreement if I use third-party software?

Yes. If you use, for example, hosting, payment or tracking services, these suppliers are your sub-processors. Make sure they have appropriate processor terms; most large providers offer standardised agreements.

Can I use English-language contract templates in Denmark?

Yes, English contracts can be valid in Denmark. But for national customers, Danish contracts are recommended, as they reduce interpretation doubt and are easier to enforce before Danish courts.

What is the difference between a consultancy agreement and an employment contract?

A consultancy agreement applies to the self-employed (B2B), while an employment contract applies to employees. The distinction has significant tax and legal consequences. If you let a consultant work exclusively and on your terms for a long time, the relationship can be reclassified as employment.

Conclusion

IT companies live on intangible assets, and the right contracts are what protect them. Start with an NDA and a consultancy agreement (or SaaS terms), and build from there with a data processing agreement and employment contracts as the company grows.


The content of this article is for guidance only and does not constitute legal advice. Consult a lawyer for advice on your specific situation.

This article is for general guidance only and is not individual legal advice. LegalDock documents are templates — consult a lawyer about your specific situation.