Unfair Contract Terms in SaaS Contracts: What Startups Should Fix Before Their Next Customer Renewal

Australian SaaS and platform companies should review their customer terms before the next renewal cycle. Under the unfair contract terms regime, standard form contracts with consumers and small businesses can create regulatory and commercial risk if they contain one-sided clauses that are not reasonably necessary to protect the provider’s legitimate interests.

For SaaS companies, the highest-risk clauses often deal with automatic renewals, difficult cancellation processes, early termination fees, broad unilateral variation rights, one-sided suspension rights, sweeping liability exclusions and terms that let the provider keep customer money without delivering the service.

The practical answer is to make each protective clause proportionate, transparent and connected to a legitimate business need. A SaaS provider can still protect its platform, intellectual property, security, payment position and operational reliability. Risk increases when the contract gives the provider broad discretion but gives the customer little notice, no meaningful exit right, no balancing remedy and no clear explanation of when the power will be used.

Short answer

How should SaaS startups reduce unfair contract terms risk?

SaaS startups should review standard customer terms for clauses that create a significant imbalance, are broader than reasonably necessary to protect legitimate interests, and may cause financial or other detriment if relied on. Priority clauses include automatic renewals, cancellation processes, early termination fees, unilateral price or feature changes, suspension rights, liability exclusions, indemnities and data-use rights.

From 9 November 2023, broader small business thresholds and civil penalties make unfair contract terms in SaaS contracts Australia a more practical governance issue for founders, boards and investors.

Why this matters for SaaS and platform startups in 2026

SaaS companies often scale by using repeatable customer terms: website terms, order forms, master services agreements, clickwrap terms, reseller terms, API terms, marketplace terms and privacy-linked product terms. That repeatability is commercially useful. It also means the same problematic clause can be used hundreds or thousands of times.

The Australian unfair contract terms regime is especially relevant where a technology company contracts on standard form terms with small business customers. Many early-stage and growth-stage SaaS companies sell to clinics, accountants, agencies, trades, consultants, online retailers, fintech operators, franchisees, not-for-profits and other SMEs. Those customers may fall within the small business protections if they have fewer than 100 employees or annual turnover below $10 million. Consumer-facing apps and platforms may also need to consider consumer contract protections.

The ACCC’s 2026-27 compliance and enforcement priorities include unfair contract terms in consumer and small business contracts, with particular focus on harmful cancellation terms associated with automatic renewals, early termination fee clauses and non-cancellation clauses. Those features are common in subscription software contracts.

What is an unfair contract term?

Under the Australian Consumer Law, a term may be unfair if it causes a significant imbalance in the parties’ rights and obligations, is not reasonably necessary to protect the legitimate interests of the party advantaged by the term, and would cause financial or other detriment if relied on. A court also considers the contract as a whole and the transparency of the term.

This is a contextual test. A clause is not automatically unfair because it favours the SaaS provider. A hosting provider may need rights to suspend access for security reasons. A fintech software provider may need audit rights to protect regulatory compliance. A healthtech provider may need data-handling rules that support privacy and clinical safety. The drafting risk is whether the clause goes further than reasonably needed and whether the customer can understand and respond to the risk.

Current small business thresholds

For new or varied standard form contracts from 9 November 2023, the ACCC states that small businesses are covered if they have fewer than 100 employees or make less than $10 million in annual turnover. Financial products and services are regulated under the ASIC Act, where ASIC identifies an additional $5 million upfront price cap for small business contracts in that context.

Which SaaS contracts are most exposed?

The regime is most likely to matter for SaaS businesses using standard form terms with consumers or small businesses. In practice, risk often sits in documents that founders see as operational rather than legal:

  • website terms of service accepted during account creation;
  • online subscription terms linked from an order page;
  • master SaaS agreements used with little or no negotiation;
  • renewal terms embedded in invoices, checkout flows or product settings;
  • partner, reseller or marketplace terms used across a channel program;
  • API terms, acceptable use policies and data processing addenda that can be changed unilaterally; and
  • legacy templates copied from overseas vendors without Australian review.

A contract can still be standard form even if the customer can negotiate minor changes, choose from pre-set options or negotiate a separate document. The more the business presents terms on a take-it-or-leave-it basis, and the more often the same terms are reused, the more carefully the UCT risk should be reviewed.

SaaS clauses that deserve a UCT review

1. Automatic renewal clauses

Automatic renewal is not prohibited. It can be commercially sensible where software is delivered continuously and the customer expects continuity. The risk is an auto-renewal mechanism that quietly locks a small business customer into a new term without reasonable notice or a fair opportunity to cancel.

A safer renewal clause usually explains the renewal cycle clearly, gives timely renewal reminders, identifies any price changes before renewal, provides a practical cancellation method and avoids turning a missed deadline into a disproportionate long-term lock-in.

2. Non-cancellation and difficult cancellation terms

Cancellation friction is a live enforcement theme. For SaaS, risk can arise where sign-up is easy but cancellation requires a burdensome process, such as calling during narrow business hours, contacting an account manager who does not respond, completing unnecessary forms or finding hidden product settings.

If the contract says a customer may cancel, the operational process should match the promise. A clause that looks reasonable on paper may still be commercially dangerous if the cancellation pathway is unreasonably difficult.

3. Early termination fees

An early termination fee can be defensible if it reflects genuine costs, committed infrastructure, onboarding work, discounts granted for a fixed term or other legitimate interests. It becomes more vulnerable when it operates as a penalty, requires payment for services that will not be delivered, or applies even where the provider has materially failed to perform.

SaaS businesses should be able to explain why the amount is reasonable. For example, a fee tied to unrecovered implementation costs is usually easier to justify than a blanket requirement to pay all remaining fees regardless of circumstances.

4. Unilateral price and feature changes

Many SaaS products change over time. Product updates, security patches, integrations and pricing changes are part of the model. The contract risk is a broad right to change any term, price, feature, service level or data condition at any time without meaningful notice or customer rights.

A better approach is to separate routine product improvements from material adverse changes. If the provider needs to make a material change, the contract should usually require advance notice and, where appropriate, give the customer a right to terminate or avoid the change before it takes effect.

5. One-sided suspension rights

SaaS providers need suspension rights for non-payment, security threats, unlawful use, misuse of APIs, sanctions risk, privacy incidents and operational harm. Problems arise when the provider can suspend access for vague reasons, with no notice, no pathway to remedy and no obligation to act proportionately.

Suspension clauses should identify the trigger, allow urgent suspension where genuinely necessary, include notice where practical, and explain what the customer must do to restore access.

6. Broad liability exclusions

Limitation of liability is standard in technology contracts. The issue is overreach. A clause may be vulnerable if it excludes practically all responsibility, including for matters within the provider’s control, while leaving the customer exposed to broad payment, indemnity and usage obligations.

A more balanced clause may include a liability cap, carve-outs for specific serious risks, proportionate indemnities and wording that does not attempt to exclude non-excludable rights under the Australian Consumer Law.

7. Data, AI and customer content rights

Technology companies increasingly include broad rights to use customer data, customer content, usage data, prompts, outputs or analytics to improve products or train models. Those rights can create privacy, confidentiality, intellectual property and UCT issues if they are buried in dense terms or drafted wider than needed.

A safer structure explains what data may be used, for what purpose, whether personal information is involved, whether data is aggregated or de-identified, whether the customer can opt out, and how the clause interacts with the privacy policy, data processing addendum and confidentiality obligations.

A practical SaaS contract review checklist

Founders and operators can start with a targeted review rather than rewriting every document at once. The highest-value exercise is to map the customer lifecycle against the legal terms: sign-up, payment, onboarding, product use, support, renewal, cancellation, suspension, data export and termination.

  1. Identify every customer-facing contract, including order forms, online terms, product policies and renewal notices.
  2. Work out whether consumers or small businesses commonly accept those terms.
  3. Check whether the terms are genuinely negotiated or largely standard form.
  4. Review auto-renewal, cancellation, termination fee and notice mechanics first.
  5. Test whether unilateral change rights are limited to legitimate operational needs.
  6. Check whether suspension powers are tied to clear triggers and fair restoration steps.
  7. Confirm liability exclusions and indemnities are balanced and do not overreach.
  8. Review data use, AI training, analytics and customer content clauses for transparency.
  9. Make sure sales collateral, pricing pages and product workflows match the contract.
  10. Keep version records so the business can prove which terms applied to which customer and when.

How to make protective SaaS clauses more defensible

Protective clauses are easier to defend when they are tied to real operational needs, drafted in plain language and balanced by notice, cure periods, exit rights or other practical safeguards where appropriate.

Clause type Common risk More defensible drafting approach
Auto-renewal Customer is locked in without practical notice. Give clear pre-renewal notice, disclose price changes and allow a realistic cancellation window.
Cancellation Cancellation is harder than sign-up. Provide a clear cancellation method and align the product workflow with the written terms.
Termination fee Fee looks punitive or unrelated to loss. Tie the fee to genuine costs, discounts, committed resources or unpaid services already delivered.
Unilateral changes Provider can change anything at any time. Limit changes by category, give notice for material adverse changes and allow exit where appropriate.
Suspension Provider can suspend for vague reasons. Define triggers, reserve urgent action for real risk and include restoration steps.
Liability cap Provider excludes almost all responsibility. Use a measured cap with sensible carve-outs and non-excludable rights wording.
Data use Customer data rights are broad and hidden. Explain the data categories, purpose, safeguards and relationship with privacy and confidentiality terms.

Examples

Example 1: Annual renewal without reminder

A SaaS provider sells practice management software to small allied health clinics. The online order form says the subscription renews annually unless cancelled at least 60 days before renewal. The clinic receives no renewal reminder, the cancellation process requires emailing an account manager, and the contract requires payment of the full annual fee immediately after renewal.

That arrangement should be reviewed. The provider may have a legitimate interest in revenue certainty, but the combination of no reminder, a long cancellation deadline and a full-year payment obligation may create imbalance and detriment. A better model would include renewal notice, clear cancellation steps and a more proportionate post-renewal remedy.

Example 2: Security suspension for an API platform

An API platform gives itself a right to suspend access immediately if a customer’s use threatens platform security, breaches rate limits, appears unlawful or risks harm to other users. The clause also requires the provider to notify the customer where practical, identify the issue and restore access once the risk is resolved.

That clause is more likely to be defensible because it is tied to a legitimate operational interest and contains practical guardrails. The drafting does not give the provider an open-ended right to suspend for any reason.

Example 3: AI feature terms

A startup adds generative AI features to its platform and updates its terms to say it may use all customer inputs and outputs for product improvement, benchmarking and model development. The clause does not distinguish personal information, confidential information, de-identified data or enterprise opt-outs.

That kind of clause should be narrowed. Even if the UCT regime is only one part of the risk, the broader privacy, confidentiality and IP implications make it commercially important to explain exactly what rights the provider needs and why.

When should a SaaS startup get its terms reviewed?

A legal review is most valuable before the business reaches scale. The cost of fixing a template is usually lower before hundreds of customers have accepted it. SaaS companies should prioritise review when:

  • moving from bespoke pilots to self-serve or repeatable standard terms;
  • selling to Australian SMEs, clinics, accountants, advisers, agencies or franchise networks;
  • introducing annual subscriptions, auto-renewals or minimum commitments;
  • changing cancellation, refund or termination mechanics;
  • adding AI, data analytics or customer content reuse rights;
  • raising capital or preparing for investor or acquirer due diligence; or
  • expanding into regulated sectors such as health, fintech, financial services, crypto or professional services.

Investors and enterprise customers often review the same clauses regulators care about: data use, liability, termination, suspension, service levels, renewal mechanics and compliance with Australian law. Cleaning up the contract stack can therefore support both compliance and sales.

FAQs

Do unfair contract term laws apply to B2B SaaS contracts?

They can. The regime can apply to standard form small business contracts. Many B2B SaaS customers may be small businesses if they meet the current employee or turnover thresholds. The analysis depends on the customer, the contract, the subject matter and how the terms are offered.

Are automatic renewal clauses illegal in Australia?

No. The risk depends on how the clause operates. A clear renewal clause with reasonable notice and a practical cancellation process is different from a hidden renewal mechanism that locks a customer into a further term without a meaningful opportunity to opt out.

Can a SaaS provider still limit liability?

Yes, but the clause should be carefully drafted. Liability caps, exclusions and indemnities should be proportionate, transparent and consistent with non-excludable rights under Australian law. A broad attempt to exclude all responsibility is more vulnerable than a balanced risk allocation.

What happens if a SaaS contract contains an unfair term?

If a court or tribunal finds a term unfair, the term may be void. The contract can continue if it can operate without the term. Since the 9 November 2023 reforms, proposing, applying or relying on unfair terms can also attract penalties in relevant circumstances. Regulators and affected parties may seek orders depending on the contract and conduct.

Should overseas SaaS templates be used in Australia?

Only with Australian review. US, UK or global templates may not address the Australian Consumer Law, small business unfair contract terms, Australian privacy issues, local consumer guarantees or Australian enforcement priorities. Localising the template is often essential before scaling Australian sales.

Sources

Disclaimer

This article is general information only and is not legal advice. The application of the unfair contract terms regime depends on the contract, customer, product, sales process and surrounding facts. Australian SaaS and platform businesses should obtain legal advice before relying on standard terms or changing customer contracts.

Set up, grow, scale or sell your business with expert legal guidance.

Book a free consultation with us and let’s talk about how we can help your business succeed and stay competitive in the market.