Top trends in tech transformations
There's a tech transaction boom, as organisations shift to modern platforms and address their "tech debt". Here are the big trends we're seeing.

In a recent interview with the New Zealand Herald, Datacom’s CEO, Greg Davidson, identified a significant lift in the volume of technology projects in the past year, with many organisations wary of their level of “tech debt”. “It’s the biggest upswing in demand for advice about moving to modern platforms that I can remember”, he said.
We have also noticed this acceleration to the cloud and a clear increase in the volume of technology contracts being negotiated. This post explores some of the key trends we’re seeing during this tech transaction boom.
1) Implementation Proclamation
Modern software deals generally involve less bespoke development and on premise hosting than in traditional enterprise software. SaaS (software-as-a-service) providers tend to emphasise “configuration” (i.e. tweaking their pre-existing solution within defined parameters) over “customisation” (bespoke development to address specific customer requirements). This means the parties can sometimes overlook the importance of the implementation phase of these projects: “we’re just rolling out a standardised product, how hard can it be”? However, implementing software at an enterprise level almost always involves some level of complexity, whether due to integration with the customer’s technology stack, transfer of existing data to a new platform, the organisational process changes required, or a host of other reasons.
Contracting parties need to consider these potential risks and ensure that the agreement deals clearly and comprehensively with the implementation phase. This is particularly important in“non-refundable” licence deals, which kick in from day one without an ability to pull out if the implementation fails. To de-risk this element of the transaction, many deals include a separate ‘design’ or ‘discovery’ phase, giving the provider a chance to scope what’s required in detail and report to the client on its intended approach before the implementation begins.
2) A Bit Too Agile?
The benefits of agile methodology for technology projects are now widely acknowledged. Although initially designed for internal software development projects, agile is now regularly deployed in tech implementations where both provider and customer teams are involved. While there are some clear benefits to this in terms of the ability to iterate, check in regularly and drive more cohesion between teams, there are also some challenges from a contractual perspective. Agile projects generally take a more open-ended approach, prioritising flexibility over certainty in terms of specifications, timeframes and deliverables. The result is that implementation projects using an agile methodology are often light on detail in these areas, even though the end product – and existing software solution – is largely known at the outset. The parties to these contracts need to ask themselves whether the agile contract provides an adequate roadmap for delivery of the solution.
We have found that a‘hybrid’ approach is often a valid answer – preserving core agile project management processes while being more specific around what will be delivered, at what cost, and in what timeframe.
3) Once More Unto the Breach
Data breaches are fast becoming the number one risk for organisations across the globe, so the need to deal properly with this risk is fast becoming the major priority in technology contracts. There are many complexities to address: How is a data breach defined? Where is the demarcation of responsibility for data (at rest and in transit) between the customer and provider? What is the role of third party hosting providers and who takes responsibility if they cause a breach? Who has the role of “controller” and “processor” for data protection law purposes and how will this affect the allocation of responsibilities between the parties? Liability after the fact is one thing, but just as important is defining how the parties will co-operate in the heat of the moment to discover, notify, mitigate and resolve an incident.
4) Data Without Borders
The dominance of SaaS platforms and cloud-based infrastructure in today’s technology stacks has led to a big increase in cross-border data flows. This is coupled with a number of significant recent developments in the law governing international data transfers, both here and overseas. Further afield, the Schrems II decision last year invalidated the Privacy Shield mechanism previously used as the legal basis for sending data between Europe and the US. More recently, the European Commission has released a new set of ‘Standard Contractual Clauses’ that must be used in most circumstances where there’s a transfer of data from the EU to any outside country not deemed “adequate” by the Europeans (i.e. most of them). In New Zealand (which helpfully does have adequacy for now), the Privacy Act 2020 recently imposed a new regime(including optional model contract clauses) for disclosure of personal data outside New Zealand – although transfers to cloud hosting providers and others processing data purely on someone else’s behalf are not caught. All this means a thorough assessment of the data flows involved, and the legal obligations that apply, is a key component of most tech deals.
5) Indemnities on the Increase
Traditionally, a customer in a software licence could be comfortable it had relatively few contractual obligations to worry about: pay the fees, stay within the licence scope and don’t breach confidentiality or IP. However, many technology providers are now providing ‘one to many’ solutions to a large volume of customers with a range of diverse needs. This, along with the ever-increasing complexity of data use/flows and the global regulatory environment, means providers often have legitimate reasons for looking more closely at the balance of risk. With this in mind, technology providers are increasingly asking customers to provide wide indemnities in relation to the customer’s particular use of their products – often to address data protection concerns, but in many cases wider regulatory and third party risk. These indemnities are often broadly drafted, sometimes making the customer liable for almost everything bar the provider’s negligence. Whatever the reasonableness of specific clauses, it’s important for both parties to step back and think about the specific risk profile of each deal. Standard templates are seldom sufficient to cover all bases in today’s market.
This is just a snapshot of the trends we’re seeing in what is a fascinating time for tech. Please get in touch, or watch our Tech Transformation webinar series here for a more detailed look.
Services in this insight
Consultation opens on New Zealand's payment services regulation
Modern slavery regulation on the way – Is your business ready?
From Hertzian waves to hyperlinks – What the BSA’s online decision means for your business
Space Law in New Zealand — Signals from the ground
Cyber security changes flagged for New Zealand
The four Cs of successful fintech partnerships
New rule 3A introduced to the Biometric Processing Privacy Code
IPP3A is nearly in force – What agencies need to know
OPC shifts public enquiries online – What agencies should do now
AI as a confidante? Legal privilege and the ever-increasing use of AI
New Therapeutic and Health Advertising Code – What you need to know
Building blocks of trade mark law: New Zealand approach to "use as a trade mark" now compatible with Australia
Consumer law update 2025
Open banking launches in New Zealand
Is fair something to fear? The Government announces beefed-up Fair Trading Act
Is it fair? Lessons from Bartz v Anthropic and Kadrey v Meta
Open banking almost live
Why New Zealand businesses should care about the EU Data Act
Product labelling changes flagged for New Zealand
Biometric Processing Privacy Code 2025 introduced to New Zealand
Open banking regulations released for consultation
Ten tips for buy-side M&A success
A recipe for disaster – Is caramel a copyright work?
Becoming a Globally Renowned Fintech Nation (and how regulation can light the path)
Important changes made to the Privacy Act
New Zealand may ban social media for young users
Customer and Product Data Act update – Open banking officially on the way
Tips from the trenches – Your AI policy cheat sheet
Significant regulatory reform proposed for New Zealand media
Security guidance released for emerging tech companies
Customer and Product Data Bill – Select Committee reports back
Consumer law update 2024
New Zealand’s Artist Resale Royalty is ready to go
The shape of coffee – “Moccona” vs “Vittoria”
New Zealand’s Copyright Act gets a sense of humour
WIPO’s traditional knowledge treaty is adopted
Doing business in the Middle East
AI and advertising – What producers need to know
Seven contract clauses every freelancer needs
Baby Reindeer – When truth is stranger than fiction?
Our comments on the Biometric Processing Privacy Code
Therapeutic Products Act to be repealed this year
Is End-to-End to end?
Geographical indications – Changes uncorked by the EU-NZ Fair Trade Agreement
Lawyers and Generative AI – New NZ Law Society guidance released
Facing the future – A biometrics code of practice for New Zealand?
Deepfakes and style mimicking – Should New Zealand adopt a right of publicity?
Five Eyes release the Five Principles to Secure Innovation
The copyright conundrum with generative AI
Innovate at the speed of trust – Privacy Commissioner releases new guidance on artificial intelligence tools
Political advertising on social media: sludge or copyright quagmire?
Privacy Amendment Bill introduced to Parliament
New Data Privacy Framework: Meta gets a lifeline
The long and winding road to royalties
Implications of the Supreme Court’s “new debt” approach in Mainzeal
EU gets closer to AI laws
UK Supreme Court puts Quincecare ‘duty’ back in its box
A Deep Dive into The Customer and Product Data Bill
Searching for a shield: Meta’s €1.2 billion fine and international transfers in the age of Big Data
New NZ-UK Free Trade Agreement signals tech, media and IP law changes
Ditch the fax! Tips for building a tech-savvy law firm
The Incorporated Societies Act 2022 – what you need to know for your society
Common myths about copyright online
Artificial artist, or artificial plagiarist?
Big boost to gaming
Is your product “AI powered”?
The latest on New Zealand’s Consumer Data Right
Space Law in New Zealand
You Cannot Defame the Dead or Can You? Tikanga Māori and NZ Defamation Law
Open Banking is coming – through the Consumer Data Right
Massive SEC Fines for Companies Using Text and Instant Messaging
One Act to Rule Them All
A Legal Guide to Kicking SaaS
Potential changes to the Privacy Act 2020
NZ's Social Media "Code of Practice" Launched
Are you being unfair?
Are you legal?
Power Up 2022
A new Companies Office levy is one step closer
Has Paramount Pictures gone maverick?
From Russia with love: The ‘other’ Russian conflict targeting intellectual property owners
I'm back, baby
Retail Payment System Act 2022 now in force
Paying the price for getting privacy wrong
Can AI be an inventor?
Finfluencer Crackdown
TIN Fintech Insights Report Launch
Britain seeks to regulate 'Big Tech'
Disclosure of personal information - how to, not don't do
The Spice May Flow, But The Copyright Doesn’t
Sound Recording Ownership (Taylor's Version)
The Lowdown (and Lockdown) on Summer Clerkships
Building Blocks of Trust
Firm News | Legal Rankings
Buy Now, Regulate Soon
Ten simple things
Funding the Future
Cyber Security for Start-ups
Fit for purchase
The Screen Industry Workers Bill
Other articles you
might like
New Zealand is consulting on reforms to its payment services regulatory framework, with submissions closing 3 July 2026.
Negotiating a fintech partnership agreement is not a zero sum game.
New rule 3A means individuals must be notified about indirect collection under the Biometric Processing Privacy Code 2025.
.jpg)










