Category: SaaS Agreements

  • NDA Essentials, Part 3: The Four Exclusions, and Whose Job It Is to Prove Them

    NDA Essentials, Part 3: The Four Exclusions, and Whose Job It Is to Prove Them

    Two years from now, a competitor ships something that looks a lot like what you shared with them in a conference room, under an NDA that expired a year ago. Nobody is going to fight about whether the NDA existed. They’re going to fight about whether what shipped came from your disclosure or from the other side’s own engineering, and the paragraph that decides that fight is the one almost nobody negotiates: the exclusions.

    The bottom line: the four standard exclusions exist so a recipient isn’t stuck treating its own prior knowledge, or plain public information, as somehow restricted. Whether they’re present in your NDA isn’t the negotiation. Whether your NDA says who has to prove one applies is, and on that question courts don’t agree with each other, which means your contract needs to answer it instead of leaving it to whichever judge you end up in front of.

    Part 1 of this series named these four exclusions among the nine provisions that actually get negotiated. This post is the deeper look, plus the fight nobody sees coming until they’re already in it.

    The Four Carve-Outs, and Where Each One Actually Fails

    Every NDA I’ve reviewed uses some version of the same four. Say them out loud and they sound uncontroversial: you’re not liable for information that was already public, that you already knew, that came to you honestly from someone else, or that you built yourself without touching what was disclosed. Each one fails in a specific, predictable spot.

    Already Public

    Through no fault of the recipient is the phrase doing the work here, and it needs to survive in every version you sign. Drop it and a recipient could leak your information itself and then claim the exclusion, because the information is now, in fact, public. I’ve seen forms shorten this sentence by cutting exactly that phrase. Don’t let it happen to yours.

    Already Known

    This one lives or dies on paper that predates the NDA, not memory. “We already had this” is a sentence anyone can say two years into a dispute, and it’s worth exactly nothing without a business record, an email, a file with a modification date, something dated before the disclosure. Keep the kind of dated record Part 2 recommended for oral disclosures. It does double duty here.

    From a Third Party

    The recipient should have to reasonably believe the third party had the right to disclose the information, not just point to a third party who happened to hand it over. A supplier who breached its own NDA with your counterparty shouldn’t hand your counterparty a clean defense merely by being the source. Push for language that requires the recipient to have no reason to know of a restriction, not language that asks nothing of the recipient at all.

    Independently Developed

    This is the one that actually gets litigated, and it’s the one I’ll spend the rest of this post on.

    Compelled Disclosure Still Isn’t a Fifth Exclusion

    Part 1 of this series flagged this, and it’s worth restating because forms keep getting it wrong: a subpoena or a regulatory demand belongs in its own provision, not bolted onto the exclusions as a fifth carve-out. The difference matters more than it looks. An exclusion removes information from protection permanently, against everyone. A compelled-disclosure clause authorizes one specific disclosure, to one specific requester, while the information stays protected against the rest of the world. Write compelled disclosure as an exclusion, and a single subpoena can read as stripping your trade secret of protection altogether, which is the opposite of what either side actually wants. Structure it instead as prompt notice where notice is lawful, cooperation in seeking protective treatment, and disclosure of no more than the law actually requires. If the disclosure involves an employee or contractor reporting suspected illegal conduct to the government, the Defend Trade Secrets Act’s own whistleblower immunity, 18 U.S.C. § 1833(b)(3), already overrides anything your NDA says regardless. Part 1 has the notice requirement that comes with it.

    The Independent-Development Fight, and Who Has to Prove It

    Every independent-development carve-out I’ve drafted or reviewed uses some version of “without use of or reference to” the disclosed information. Reference to is the clause that should stop you. Use means the recipient actually relied on what it received. Reference to is broader and murkier, close enough to “was aware the information existed while building something similar” that a sufficiently aggressive plaintiff can argue awareness alone defeats the defense, even where the recipient’s engineers never opened the file. I flagged this in Part 1 as one of the two live negotiation points buried in the exclusions, and it’s worth being specific about why: a recipient wants use, full stop, because that’s a standard it can actually meet by running a clean-room process. A discloser wants reference to, because it lowers the bar for a later claim.

    Here’s the part that doesn’t get talked about enough. Even where the contract language is settled, courts don’t agree on who has to prove independent development once a dispute actually lands in front of one of them. The Third Circuit, applying Pennsylvania law in Moore v. Kulicke & Soffa Industries, Inc., 318 F.3d 561 (3d Cir. 2003), held that the burden of persuasion never leaves the party claiming misuse: the recipient only has to offer some evidence of independent development, and the discloser still has to prove that evidence wrong. The Eighth and Ninth Circuits will shift that burden onto the recipient instead. In Garter-Bare Co. v. Munsingwear, Inc., 723 F.2d 707 (9th Cir. 1984), once the discloser showed a confidential relationship and later use of similar information, the recipient had to prove it could have arrived there on its own. Pioneer Hi-Bred International, Inc. v. Holden Foundation Seeds, Inc., 35 F.3d 1226 (8th Cir. 1994), shifted the burden the same way, though the Eighth Circuit tied it to specific facts: the defendant had pursued the plaintiff’s secrets, discarded records that would have shown otherwise, denied obtaining the material, and ended up holding secrets shown to have probably been derived from the discloser’s secrets. Three circuits, two different rules, and in the Eighth Circuit’s case, a rule that depends on facts nobody sorts out until well into the litigation.

    An Example from My Home Jurisdiction, Oklahoma

    The Tenth Circuit recently ruled on a question relevant to this discussion. In Double Eagle Alloys, Inc. v. Hooper, et al., 134 F.4th 1078 (10th Cir. 2025), a Tulsa metals company sued a former employee and the competitor he joined, Ace Alloys, claiming the former employee wrongfully took Double Eagle’s confidential information to his new employer. The Tenth Circuit affirmed summary judgment for the defendants under the Oklahoma Uniform Trade Secrets Act, and a paper trail did the work. Double Eagle lost because it never proved with sufficient evidence that the specifications were secret to begin with: its own website had posted similar numbers, and its customers held nearly identical specs sourced from other suppliers, which the court treated as evidence the information was readily ascertainable through proper means, the same threshold an exclusion never needs to reach if the plaintiff can’t clear it first. Ace Alloys won the independent-development point outright, and won it with a paper trail: “the undisputed evidence also demonstrates that Ace Alloys developed its own … specifications almost a year before [the former employee] even left Double Eagle.” Id. at 1090. A dated engineering file from before the former employee’s departure did more for Ace Alloys than any argument about who had to prove what would have. That’s the fix this post keeps circling back to: whichever exclusion you’re relying on, win it with a record that predates the dispute, not a story assembled after one starts.

    The foregoing split in the Circuit Courts is exactly why leaving this to background law is a bad plan. Your governing-law clause picks a state, not a circuit’s approach to burden-shifting, and you may not know which rule you’re actually going to get until you’re already in the dispute. The fix costs one sentence: state directly in the exclusions provision which side carries the burden of establishing that an exclusion applies, and require that it be established by evidence that predates the disclosure, not by testimony reconstructed after the fact. Something close to “the Receiving Party bears the burden of establishing the applicability of any exclusion under this Section by contemporaneous written evidence” does the job. Whichever side of a given deal you’re usually on, know whether that sentence is doing you a favor or costing you one before you sign it.

    Whose Burden Is It in Your NDA?

    • Confirm your NDA actually says “through no fault of the recipient” on the public-information exclusion, not just “became public.”
    • Check whether your independent-development carve-out uses “use of” or the broader “reference to,” and know which one you want depending on which side of the disclosure you’re usually on.
    • Look for a sentence assigning the burden of proving an exclusion. If there isn’t one, you’re relying on whichever circuit’s rule a court decides applies, and that isn’t a plan.
    • Keep dated records for anything you might need to prove later as prior knowledge or independent development. A file’s timestamp beats a witness’s memory every time.
    • Make sure compelled disclosure lives in its own clause, not folded into the exclusions as a fifth item.

    Part 4 of this series turns to the permitted purpose clause: the one line that decides whether your own ordinary use of what you received counts as a breach.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact Ken McConkey to discuss your company’s specific confidentiality agreements.

  • NDA Essentials, Part 2: What Counts as Confidential (and the Step Everyone Skips)

    NDA Essentials, Part 2: What Counts as Confidential (and the Step Everyone Skips)

    You said it out loud in a conference room, not in an email. Nobody stamped a document, nobody sent a follow-up memo, and eight months later the relationship went sideways. If your NDA requires written confirmation of anything disclosed orally, that unrecorded conversation may never have been protected at all.

    Part 1 of this series covered nine provisions and gave the definition of confidential information a single paragraph. That undersold it. Everything else in the agreement, the standard of care, the remedies, is arguing about a term the parties often never pinned down. This post covers what actually counts as confidential, why the two standard ways of defining it each fail in their own ways, and the follow-up step almost nobody performs.

    What Actually Gets Called Confidential

    Every definition of confidential information, however it’s worded, is reaching for the same handful of categories:

    • Technical data: source code, architecture documents, product specifications, engineering drawings, algorithms, and features that haven’t shipped yet.
    • Business operations: financials, pricing models, cost structures, strategic plans, and internal processes.
    • Client insights: customer lists, contact information, usage data, and anything that reveals who a company’s customers are or how they use its product.
    • Intellectual property that isn’t yet protected by a patent, copyright registration, or trademark: inventions still in progress, unpatented designs, and plain know-how.

    None of that is where the fight happens. The fight is over how the definition decides whether something you actually said or sent falls into one of these buckets in the first place.

    Two Competing Definitions, and Why Both Fail Alone

    Most NDAs pick one of two approaches to defining confidential information, and each fails in its own way.

    The Marking-Based Definition

    This approach protects only what’s labeled confidential in writing at the time of disclosure, or reduced to a written summary within a set number of days if it wasn’t written to begin with. Clean to apply, and it fails the moment someone forgets, which is often, since nobody marks a Slack message, a shared screen, or a photo of a whiteboard.

    The Catch-All Definition

    This approach instead covers anything a reasonable person would understand to be confidential given the nature of the information and the circumstances of its disclosure. That protects the discloser against exactly the human error above, and it leaves the recipient guessing, in real time, about what it can and can’t use. I’d rather negotiate a longer marking deadline than fight later over what a reasonable person would understand, because that phrase means whatever a judge wants it to.

    Most NDA forms split the difference: marking required for anything written or tangible, a written follow-up required for anything oral or visual. That hybrid is certainly the right idea. But it also creates an obligation almost nobody actually performs.

    The Oral-Disclosure Follow-Up (The One Nobody Performs)

    Here’s the obligation. If your NDA uses the hybrid approach above and you disclose something in a meeting, a demo, or a phone call instead of a document, the agreement typically gives you a window (e.g. 10, 20, sometimes 30 days) to send the other side a written summary identifying what was disclosed and confirming it’s confidential. Miss that window, and under the plain language of most NDA forms, what you talked about in that room was never covered as confidential information.

    This can be more than a mere technicality. It cost a company its trade secret protections in at least one case. In Convolve, Inc. v. Compaq Computer Corp., 527 F. App’x 910 (Fed. Cir. 2013), the NDA required that information disclosed orally or visually be identified as confidential at the time of disclosure and confirmed in a writing delivered within twenty days of the disclosure. Convolve disclosed trade secret information about hard disk drive technology at a meeting and never sent the follow-up confidentiality memo. The Federal Circuit court held the NDA’s language was clear, and rejected Convolve’s argument that both sides understood the information was confidential anyway. A written contract, the court said, supplants whatever informal understanding the parties may have shared. Therefore, what was said in that meeting received no protection under the NDA because its specific provisions were not followed.

    The lesson isn’t that talking is dangerous. It’s that a specific, calendarable obligation is probably sitting in your NDA form right now, and it doesn’t enforce itself. If your form works this way, the fix costs about five minutes after any meeting where you say more than you type; a short email listing what was covered and stating that it’s confidential information under the agreement. Send it before the deadline in your NDA runs.

    The Catch-All Trap

    A definition reading “any and all information disclosed by either party, in any form” looks like maximum protection. It’s closer to the opposite. Courts have pushed back on definitions this broad, especially once they start looking like they restrain a recipient’s ordinary business rather than protect a specific disclosure, and an agreement nobody can actually comply with tends to get read narrowly by a judge deciding what it was reasonable to expect the recipient to do. There’s a practical cost too, not just a legal one. A recipient covering “everything” either ignores the restriction in practice, since no team treats every internal document that touched a vendor conversation as under lock and key, or it locks down so hard that ordinary work grinds to a halt. Either way, the breadth on paper and the reality of how the company actually operates come apart, and that gap is exactly what gets argued over once there’s a dispute.

    The better draft names the categories, technical data, business operations, client insights, unregistered intellectual property, and pairs that with a reasonable marking or written-confirmation mechanism instead of either extreme. It tells your own team what actually needs protecting instead of asking them to guess.

    Which Side of the Table You’re On

    The right structure for this clause depends on which side of the table you’re sitting on more often.

    If You’re Mostly Disclosing

    That’s often still true even when you’re also receiving, in a bidirectional NDA. You want the definition broad enough to cover the ways you actually share information, and you want the marking or follow-up deadline generous enough that your own team can hit it. Thirty days beats ten.

    If You’re Mostly Receiving

    You want the opposite: real categories instead of a catch-all, and a marking or written-confirmation requirement with actual teeth, because that’s what tells you, in the moment, what you’re restricted from doing with what just landed in your inbox or your head. In a mutual NDA you’re negotiating both roles at once, so know which one describes more of your actual dealings with this counterparty before deciding which way to push.

    Before You Sign the Next One

    Pull your current NDA form and check it against this list before the next one lands in your inbox with a signature deadline attached.

    • Match the definition’s categories, technical data, business operations, client insights, intellectual property, to what you’ll actually disclose or receive, not a generic list copied out of a form.
    • If your NDA has a marking requirement, build the habit of stamping documents before they leave the building, not after someone asks.
    • If your NDA allows oral or visual disclosure with a written follow-up window, find that window today and put a five-minute recurring task on your calendar for the day after any substantive meeting with a counterparty.
    • Keep dated records for anything you might need to prove later as prior knowledge or independent development. A file’s modification date is worth more than someone’s memory of who thought of what first.
    • Don’t let a catch-all “everything is confidential” clause substitute for the habits above. Broad language protects you on paper and does nothing for you in a conversation nobody can point back to.
    • Read your current NDA form against this list and note which of these your team is actually equipped to do, not just which ones are already in the document.

    Part 3 of this series turns to the exclusions clause: information already publicly available through no fault of the recipient, information the recipient already knew free of any duty, information from a third party free of any duty, and information independently developed without use of or reference to what was disclosed.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact Ken McConkey to discuss your company’s specific confidentiality agreements.

  • NDA Essentials, Part 1: The Provisions That Actually Get Negotiated

    NDA Essentials, Part 1: The Provisions That Actually Get Negotiated

    The non-disclosure agreement (“NDA”) is the contract most companies sign fastest and read least. It shows up early, it is short, someone calls it standard, and it gets signed so the real negotiation can start. Then, unless you have overriding confidentiality provisions in a later definitive agreement, it governs your business’s confidential information for the next three to five years.

    The takeaway: an NDA is a real contract with real teeth, and about nine provisions in it do all of the work. This discussion covers those nine common provisions at a high level, and each one gets its own post later in this series.

    NDAs come in one of two formats, unidirectional or bidirectional. While it is not unusual to have a vendor or customer provide you with their unidirectional NDA template, I recommend against using such a one-direction NDA unless your business will be disclosing absolutely no confidential information. NDAs in technology and SaaS deals tend to be mutual (bidirectional), as both sides disclose and both sides receive. Every position you take against the other side’s confidential information gets taken against yours, which is why you must stay aware of what restrictions and obligations you are placing on the other party as they are also being placed upon you.

    1. What Counts as Confidential Information

    Two drafting approaches, failing in opposite directions. A marking requirement protects only what is marked as confidential, which is clean on paper and problematic in practice, because people forget to mark a Slack message, a screen share, or a whiteboard photo as confidential. Conversely, a catch-all definition covers anything a reasonable person would understand to be confidential from its nature and the circumstances of disclosure, which protects the discloser and leaves the recipient with no reliable way to know what is restricted.

    2. The Exclusions

    Four carve-outs are standard: information already publicly available through no fault of the recipient, information the recipient already knew free of any duty, information from a third party free of any duty, and information independently developed without use of or reference to what was disclosed. The negotiation is rarely about whether these are present in the NDA. It is about which party carries the burden of proving one of the exclusions, and whether the words “or reference to” survive in the independent-development carve-out.

    Compelled disclosure is where I part company with a lot of forms. A subpoena or regulatory demand often gets drafted as a fifth exclusion, which strips the information of protection the moment a court asks for it. This topic belongs in its own provision as a permitted disclosure: prompt notice where notice is lawful, cooperation in seeking protective treatment, and no more disclosed than the law requires.

    3. The Permitted Purpose

    “Solely to evaluate a potential business relationship between the parties” is one line, and the entire use restriction hangs on it. Draft it too narrowly and your ordinary operations breach the agreement. Draft it too broadly and it’s near unenforceable and useless.

    This clause could matter more than the definition of confidential information and gets a fraction of the attention. The part that is missed by many people is that if the evaluation succeeds and the parties sign an MSA, an NDA limited to evaluating a potential relationship no longer authorizes use of that information to perform the contract. Either the MSA’s confidentiality provision takes over cleanly, or the NDA’s purpose has to cover performance under the later definitive agreement. You must understand the NDA does not exist in a vacuum. It must work with your other agreements. You don’t want conflicting provisions or gaps in coverage.

    4. Who Is Allowed to See Confidential Information

    A need-to-know standard applied to a defined group: employees, affiliates, officers, directors, advisors, contractors, sometimes financing sources. There are two common points of contention; whether affiliates are included and whether those recipients must be bound by written obligations at least as protective as the NDA.

    The provision that makes the rest enforceable is the one making the receiving party responsible for any breach by any party it has communicated your confidential information to, as if it had breached itself. Without it, your remedy could run against an individual contractor instead of the company that handed them the file.

    5. The Standard of Care

    The common standard is reasonable care, and in no event less than the care the recipient uses for its own confidential information of like importance. Both halves matter, because a company with weak internal security has a very low bar for its own information.

    There is a reason to care beyond the contract. State law tends to define trade secrets by the methods used to protect them from public disclosure. For example, information qualifies as a trade secret under the Oklahoma Uniform Trade Secrets Act only if it is “the subject of efforts that are reasonable under the circumstances to maintain its secrecy,” 78 Oklahoma Statutes § 86(4)(b). Your NDAs, and your actual practice under them, are much of what proves that element later. A confidentiality program that exists only in your contract file is not evidence of much.

    6. Two Time Components: Term and Duration

    These are different time components, and confusing them is one of the most common errors in short-form NDAs. The “term” dictates how long new disclosures are covered. The “duration” controls how long the recipient has to protect what was already disclosed. A two-year term with a three-to-five-year survival period is common.

    What commonly gets left out is the trade secret carve-out: obligations as to trade secrets continue for as long as the information remains a trade secret under applicable law. Without a specific trade secret carve-out, a fixed expiration date in your NDA reads as your own agreement that trade secret protection ends on a date certain, an awkward position to hold while arguing you made reasonable efforts to maintain secrecy.

    8. Remedies and Injunctive Relief

    Nearly every NDA states that breach will cause irreparable harm for which money damages are inadequate, and that the disclosing party may obtain injunctive relief without posting a bond. Keep the clause. But do not rely on it as some courts have ruled that where parties have contractually agreed that any breach would constitute irreparable harm, that stipulation without more is insufficient to support an irreparable harm finding. See Dominion Video Satellite, Inc. v. EchoStar Satellite Corp., 356 F.3d 1256 (10th Cir. 2004).

    The damages disclaimer is also worth your consideration. If your NDA waives indirect, incidental, and consequential damages, look hard at what is left, because loss from disclosure of confidential information is very often exactly the category just waived. Accept a broad waiver, lose your injunction, and you are holding an agreement with no effective remedy in it.

    9. The Residual Clause

    Most common in enterprise and SaaS forms, and the provision people are most likely to sign without reading. A residuals clause lets the receiving party use information retained in the unaided memory of individuals who had authorized access. In a technical evaluation, that covers a great deal.

    It is not automatically unacceptable, and it is sometimes necessary, since you cannot ask an engineer to forget an architecture. If you accept one, narrow it: unaided memory only, no intentional memorization, no license under any patent or copyright, no use to develop a competing product, and customer data, pricing, and source code excluded outright.

    Also Worth Thinking About

    • No license, no warranty as to accuracy or completeness, and no obligation to proceed with any transaction. Three sentences that keep an evaluation from turning into an implied deal.
    • The Defend Trade Secrets Act notice, 18 U.S.C. § 1833(b)(3), when the agreement is with an employee or an individual contractor. Omit it and you cannot recover exemplary damages or attorney fees under the DTSA against that person.
    • Governing law and venue, which decide how much the nine provisions above are actually worth to you.

    The Fastest Way to Get This Wrong

    Sign the counterparty’s form because it is only four pages. Length has nothing to do with risk here. Four pages that give away your permitted purpose, your remedies, and your residuals will cost you more than forty pages of a well-built MSA. Read your own template against these nine provisions and find out which side of each one you are on.

    Part 2 of this series will discuss the definition of confidential information: marking requirements, catch-all standards, the oral-disclosure follow-up nobody actually performs, and how to write a definition your own team can follow.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact Ken McConkey to discuss your company’s specific confidentiality agreements.

  • MSA, SOW, or Both? Structuring SaaS Commercial Contracts Correctly

    MSA, SOW, or Both? Structuring SaaS Commercial Contracts Correctly

    Most SaaS companies eventually end up with some combination of a Master Services or Subscription Agreement (“MSA”) and a Statement of Work (“SOW”), often without ever deciding on purpose which document is supposed to do what. That usually happens by accident: an early customer needed a signed contract fast, so a single document covered everything, and each deal since has been a variation on that first one. It works until it doesn’t, usually right when a dispute or a new professional-services engagement exposes the gaps. Some companies call the SOW an Order Form or Commercial Agreement. Still others designate an SOW for professional services only and use a separate Order Form or Commercial Agreement for product purchases or subscriptions. For simplicity, this post uses “SOW” to refer to all of these documents, regardless of what your company calls them.

    What an MSA Actually Does

    The MSA is the overall governing document for the relationship. It sets the terms that should stay constant across every engagement with a given customer: limitation of liability, indemnification, intellectual property ownership and license grants, confidentiality, term and termination, and terms dictating how disputes get resolved. It also incorporates or references other supporting documents that carry the operational detail, typically a Data Processing Agreement (“DPA”) for personal data handling and a Service Level Agreement (“SLA”) for uptime and support commitments. Once an MSA is signed, it should not need to be renegotiated every time the relationship changes (i.e. additional services/products are added, or a subscription is renewed, etc.).

    What an SOW Actually Does

    The SOW carries the deal-specific detail: scope of work, deliverables, timeline, fees, and any engagement-specific assumptions or acceptance criteria. A well-drafted SOW does not restate liability caps, indemnification, or IP ownership; it incorporates the MSA by reference and leaves those terms where they belong. That separation is what lets a SaaS company add a new project, a new module, or a new phase of implementation without reopening the entire contract.

    When You Need Both

    If the product involves a recurring subscription plus periodic professional services, onboarding, custom integration work, implementation, or training, you need both documents. The MSA governs the relationship and the risk allocation; each SOW governs a discrete piece of work under that umbrella. This structure lets you sign a new SOW in days instead of weeks, because the terms that actually take time to negotiate are already settled.

    When a Single Order Form Is Enough

    Not every deal needs a freestanding SOW. A self-serve subscription with no custom implementation or professional services can often be handled with an MSA plus a short order form specifying the plan, term, and price. Reserve the full SOW structure for engagements that involve actual scoped work, deliverables, or a project timeline.

    Where SaaS Companies Typically Get Tripped Up

    Three recurring problems show up again and again:

    1. An SOW that includes its own liability or indemnification language that conflicts with the MSA, creating ambiguity about which terms actually control.
    2. An SOW signed for an early pilot or proof of concept with no MSA in place at all, so there is no governing framework once the relationship expands.
    3. No order-of-precedence clause specifying which document controls if the MSA and an SOW conflict, which turns a drafting oversight into a battle of contracts with no clearly stated winner. Most well-drafted MSAs default to the MSA controlling unless the SOW expressly says otherwise, so state that default in your own template rather than leaving it for a judge to decide.

    A Note on Execution

    All 50 states are covered by the federal ESIGN Act, and each state also has its own laws recognizing electronic signatures and records as legally effective, so executing MSAs and SOWs through AdobeSign, DocuSign or a similar platform is enforceable. However, that is not a substitute for good contract structure. A clean order-of-precedence clause and clear incorporation-by-reference language matter regardless of how the documents get signed.

    A Practical Starting Point

    Review your current templates for three things: a clear order-of-precedence clause, proper incorporation of the DPA and SLA by reference rather than restating their terms, and a standard SOW template that pulls its liability and IP terms from the MSA rather than reinventing them each time. Getting this structure right once saves renegotiation on every deal after.

    This post is provided for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. Contact ME to discuss your company’s specific contract structure.