NLdigital Terms and Conditions 2025 Analysed


NLdigital Terms and Conditions 2025 Analysed
The updated NLdigital Terms and Conditions 2025 integrate European legislation such as DORA, the Data Act and the AI Act. This makes them future-proof – although the emphasis remains (still) firmly on protecting the supplier.
They are present in almost every agreement that is concluded: the general terms and conditions. Often referred to as the small print, and not without reason. In practice, they are also printed in small – and sometimes even grey – font.
The NLdigital terms are declared applicable in many IT agreements. The 2020 version was recently updated. Time to examine this new set: NLdigital Terms and Conditions 2025.
Structure
Like the 2020 version, the terms are divided into different chapters. Depending on the nature of the agreement – for example, whether bespoke software is being developed or products are being hired – a specific chapter applies.
The terms have also been translated into English and German, which is an advantage for suppliers operating in the international market.
New topics: European legislation
A major addition is the Compliance chapter, in which a number of European regulations and directives have been integrated into these general terms and conditions, such as the Digital Operational Resilience Act (DORA), the Network and Information Security Directive 2 (NIS2), the Cyber Resilience Act (CRA), the Data Act, the Digital Services Act (DSA) and the AI Act.
The application of these terms and conditions by the supplier does not guarantee that the service or product purchased complies with the legislation applicable to the client (articles 19.3 and 19.4). There is merit to this from the supplier’s perspective: given the wide variety of laws and regulations, it is difficult, if not impossible – particularly for smaller suppliers with a varied customer base – to make binding commitments in this regard. I would not have found somewhat more accommodation misplaced, for example in the form of a best-efforts obligation to support clients.
The supplier is also not obliged to comply with changing legislation. The supplier may be willing to adapt its product or service and charge its usual rates for this. If the supplier cannot or does not wish to comply with the amended regulations on reasonable grounds, a right of termination arises for the part of the agreement that does not (or no longer) comply with the legislation. However, prepaid amounts will not be refunded and any compensation is excluded (article 19.6).
Security (chapter 3)
Cybersecurity is, rightly, receiving increasing attention when concluding agreements. The supplier is, if no separate agreements have been made, obliged to ensure that its security is “not unreasonable”, having regard to the state of the art and the implementation costs.
Data sharing (chapter 5)
The Data Act may apply to parties that supply IoT devices or offer SaaS services, and regulates, among other things, the conditions under which a party can request the data generated, for example, by a sensor. In the case of SaaS services, the client receives certain rights, which should (in theory) make it easier to switch cloud providers. These rights are elaborated in this chapter, including by incorporating a (rudimentary) exit arrangement. For a simple SaaS service, this arrangement is probably sufficient, but for larger and business-critical SaaS services, it is (strongly) recommended to agree on a detailed arrangement when entering into the agreement.
AI Act (chapter 6)
The AI Act has already caused much debate and also has consequences for contracts in cases where the supplier makes AI available. The client must use AI in accordance with the intended purpose; the supplier is not liable for the outcomes of the AI and does not guarantee their accuracy and completeness.
One-sidedness
It is customary for the party drafting the general terms and conditions to draft them in its favour. Nevertheless, in my view, the NLdigital terms and conditions are very supplier-friendly. This applied to the previous version, and this has not changed in this version.
A more or less random selection:
- The client cannot derive any rights from an issued quotation (3.2).
- The client may not suspend payments (3.6).
- Even a final delivery date is not a binding deadline, it is only binding after notice of default (13.2).
- The supplier never refunds money, not even in the event of a lawful termination (14.2).
- In the case of a SaaS service, the client is responsible for taking measures to prevent and limit corruption or loss of data (39.2).
- The supplier is not obliged to follow the client’s instructions (8.4).
- The supplier is only liable for direct damage, up to a maximum of the annual contract value and never more than €500,000. Consequential damage and indirect damage are excluded (15.1, 15.2). Indemnities also fall under this limitation, while no liability limitation applies to the client.
- Operational use of software counts as acceptance (44.8.c).
- The supplier will make best efforts to correct errors free of charge within a reasonable period, provided they are reported within three months of delivery. This does not apply to bespoke work: then the client pays (48.1).
- The supplier is not obliged to restore corrupted or lost data, other than restoring an existing backup (48.4).
- A new version does not have to contain the same functionality as the previous one (56.3).
I had hoped that the new set of terms and conditions would be somewhat less one-sided. For suppliers, it is now comfortable to declare this set applicable, but in my view the balance is lacking. If you compare this set with ARBIT terms and conditions used by the Dutch national government, you see that they take more account of the interests of both parties – which could actually shorten negotiation processes.
And how realistic is it that as a supplier you tell your client that you are not liable if they lose all their data from a system for which you as a supplier are responsible, or that you are not obliged to adapt the system to new legislation?
Advice
Suppliers using the new set of NLdigital terms and conditions have the certainty that they comply with the requirements of various recent European regulations. However, an important risk is that clients will not simply agree to these terms and conditions, partly due to their one-sided nature. This can lead to time-consuming negotiations. For clients confronted with the NLdigital terms and conditions, it is essential to assess whether the one-sided provisions in favour of the supplier are acceptable. In practice, the negotiating position of both parties will be decisive.
This article was previously published in the December 2025 issue of AG Connect magazine.
Do you have questions about the NLdigital terms and conditions? Penrose Advocaten in Amsterdam can assist you. Please contact IT lawyer Martijn Berk or by telephone 06-29575351 for a non-binding introduction.

