Reviewing a cloud hosting agreement

Review of a cloud hosting or infrastructure agreement from the customer's side, marked up with a written explanation of the security, data and exit terms, for a fixed fee of £495 in three working days.

Share

Reviewing a cloud hosting agreement

A customer-side review of a cloud hosting or infrastructure agreement, covering data location and transfers, security and breach notification, availability and credits, shared responsibility, exit and migration, and liability for outages. £495, in three working days.

Buy now, £495

A cloud hosting agreement puts the business's systems and data on infrastructure it does not own, in locations it does not choose, under a provider's security regime it cannot inspect. The agreement has to say where the data is, who is responsible for what, what the provider promises about availability and security, and how the business gets its systems back. I review the agreement from the customer's side and return it marked up with a written explanation of the changes and which ones a hosting provider will accept, for a fixed fee of £495 in three working days.

Who this is for

Businesses in England and Wales contracting with a cloud, managed hosting, colocation or infrastructure provider for their applications, websites, databases or backups, whether a hyperscale platform's standard terms, a managed service provider's agreement or a data centre contract, and want the data, security and exit terms to protect them. Both parties are businesses.

What to look for in a cloud hosting agreement

Data location, transfers and the processor terms

The provider processes the customer's data as a processor, so the agreement needs the mandatory terms of Article 28 of the UK GDPR and the Data Protection Act 2018, and the customer needs to know the region where its data is stored and replicated. The review checks whether the provider may move data between regions, whether support staff outside the UK can access it, and that any transfer outside the UK relies on a mechanism under Article 46 of the UK GDPR, whether the International Data Transfer Agreement, the Addendum or an adequacy decision. It also checks the sub-processor list and the customer's right to object to a new sub-processor.

Security commitments and breach notification

The agreement should state the provider's security measures, the certifications it holds and will maintain, and the customer's right to see audit reports, because Article 32 of the UK GDPR requires the controller to be satisfied that the processor's security is appropriate. The review asks for breach notification to the customer without undue delay and within a stated period short enough for the customer to meet its own 72-hour obligation to the ICO under Article 33, for the provider to give the information the customer needs to assess and report the breach, and for the provider's own obligations under the Network and Information Systems Regulations 2018 where it is a relevant digital service provider to be reflected rather than assumed.

Availability, credits and the shared responsibility model

The availability commitment should state the target, the measurement period, the exclusions and the credit. The review checks the shared responsibility model: which layers the provider secures, patches and backs up and which are the customer's, since a managed service that stops at the hypervisor leaves the operating system, the application and the backups to the customer. It asks for backup frequency, retention and restore times to be stated where the provider manages them, for credits to be applied without a claim, and for a right to terminate for persistent failure.

Suspension, access and the provider's own rights

Providers reserve rights to suspend for non-payment, for security threats and for acceptable use breaches, to access customer systems for maintenance, and to retain data as security for unpaid fees. The review asks for notice and a remedy period before suspension for non-payment, for access to be logged and limited to what the service requires, and for no lien over the customer's data. Unauthorised access to the customer's systems by the provider's staff is an offence under section 1 of the Computer Misuse Act 1990, and the agreement should require the provider to vet and control its personnel.

Exit, migration and the provider's insolvency

The clause that matters at the end is the one that lets the customer leave with its systems and data. The review asks for a right to export data and virtual machines in standard formats, a transition period after termination at the same rates, migration assistance at a stated day rate, and deletion of the data on confirmation. Section 233B of the Insolvency Act 1986 stops the provider terminating only because the customer has entered an insolvency procedure, but does not keep a failed provider's data centre running, so the review also checks the customer's own backup rights and whether backups are held outside the provider's infrastructure.

Liability for outages, data loss and the cap

The provider's standard terms will exclude liability for data loss and consequential loss and cap the rest at the fees for a short period. Where the agreement is the provider's standard form, section 3 of the Unfair Contract Terms Act 1977 subjects those terms to the reasonableness test, and the review asks for a separate higher cap for data protection breaches and security failures, for data loss caused by the provider's failure to perform its backup obligations to be within the cap rather than excluded, and for the Late Payment of Commercial Debts (Interest) Act 1998 position on fees to be stated.

What it costs

Standard review, £495. Marked-up document and a written explanation of the changes. Three working days.

Complex review, £895. Heavily negotiated or unusually complex documents. Five working days.

Buying online forms the engagement on payment. The scope is what the contract review page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • Your own contract returned with my amendments as tracked changes, plus a clean version with every change accepted, ready to send to the other side
  • Comments in the document where a point needs explaining
  • A written explanation of what I have changed and why, by email or as an attachment if it is lengthy, marking the points I would hold firm on and the ones that are negotiable
  • A view on what is normal market practice and what is the other side pushing their luck
  • One round of follow-up questions by email, included

What is not included

  • Negotiating directly with the other side, which I quote separately once I know who is on the other side. Where the other side is willing to share a live document, I can work in that document directly
  • Drafting a replacement contract from scratch
  • Advice on the law of any jurisdiction other than England and Wales
  • Tax, accounting or regulatory advice
  • Disputes about a contract that is already signed

Questions I am often asked

The provider says our data is in the UK but the terms let it move data anywhere. Which applies?

The terms apply, so the review asks for the region to be stated in the agreement or order form and for any move outside it to need your consent, with the Article 46 transfer mechanism identified for any support access from outside the UK.

Who is responsible for backups?

That depends on the shared responsibility model, and the agreement may say the provider does not back up the layers you assume it does. The review identifies which layers the provider backs up, the frequency and retention, and asks for restore time commitments where the provider is responsible.

If the provider suffers a breach, how soon will we know?

As soon as the agreement requires, so the review asks for a stated period, short enough for you to meet your own 72-hour deadline to report to the ICO, and for the provider to give you the information you need about the breach, the data affected and the steps taken.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.