Romain Jacquet-Lagrèze, Sham Shui Po

Service Level Agreement (SLA): A Legal Drafting Guide for Hong Kong B2B Contracts

About the authors

Written by Jessica Lau · Solicitor at Slotine. Jessica advises on commercial contracts, service level agreements, and B2B transactional matters.

Reviewed by Maeva Slotine · Founder and Solicitor at Slotine. Maeva leads Slotine’s commercial contracts and cross-border outsourcing practice.

An SLA without enforceable remedies is a wish list. An SLA with disproportionate penalty clauses is unenforceable under Hong Kong common law. The art of SLA drafting lies in calibrating the consequences of breach so they are commercially meaningful and legally sustainable.

A Service Level Agreement (SLA) sets out the performance standards a service provider must meet, the metrics by which performance is measured, and the consequences if those standards are not achieved. In B2B contracts for IT, cloud services, outsourcing, professional services and managed services, the SLA is often the single most heavily negotiated annex of the underlying contract.

This guide explains what an SLA is, how it sits within the contractual architecture alongside the Master Service Agreement and Statement of Work, the components of a well-drafted SLA, the typical metrics used, the Hong Kong common law and statutory framework that constrains SLA drafting, and the recurring pitfalls we see in practice. SLAs are one of the eleven core commercial agreement types we routinely draft for Hong Kong businesses.

Drafting or reviewing a Service Level Agreement?

Whether you are negotiating an SLA from the vendor side or the customer side, Slotine reviews the architecture, metrics and remedies before you sign. Initial conversations are confidential and without obligation.

Request a consultationEmail Slotine

Maëva Slotine

Founding Partner

What is a Service Level Agreement?

A Service Level Agreement is a contractual document, signed between a service provider and a customer, that defines the level of service expected, the way it is measured and the remedies available to the customer if the agreed levels are not met. SLAs are most common in technology and outsourcing contracts but apply to any B2B service relationship where measurable performance is critical.

An SLA may sit as a standalone agreement, as a schedule to a Master Service Agreement (MSA), or as a section within a single integrated contract. In each case, the SLA’s function is the same: to translate the high-level promise of service delivery into specific, measurable, enforceable commitments.

SLA vs MSA vs Service Agreement vs KPI: clarifying the hierarchy

These terms are sometimes used loosely. Each has a distinct function in the contractual architecture.

Master Service Agreement (MSA)

Overarching commercial framework: governance, IP, liability, term, payment, governing law. The legal backbone of the relationship.

Statement of Work (SOW)

Description of the specific scope of services for a defined engagement, signed under the MSA. Often contains its own pricing and timeline.

Service Level Agreement (SLA)

Performance standards, metrics, measurement methodology, reporting and remedies for service shortfalls. Often a schedule to the MSA or SOW.

KPIs (Key Performance Indicators)

Individual measurable indicators (uptime %, response time, resolution time, throughput). KPIs are the metrics; the SLA is the contractual frame around them.

The three types of SLAs

SLA structure varies according to the customer relationship. Three models dominate.

Customer-based SLA

A single SLA covering all services provided to one specific customer. The customer negotiates bespoke metrics tailored to its operational needs. Common in large enterprise outsourcing arrangements.

Service-based SLA

A single SLA covering one specific service provided to all customers of that service. Common in standardised cloud, SaaS and telecom offerings. The customer receives the published service levels with limited room for variation.

Multilevel SLA

A layered structure combining corporate, customer and service-level commitments. Common in large outsourcing deals where multiple business units consume the same shared services with differentiated treatment.

Anatomy of a well-drafted SLA

A complete SLA contains the following building blocks. Missing any of them creates a gap that the parties will eventually need to fill, often in less favourable circumstances than the original drafting.

Agreement overview and parties

Identification of the parties, effective date, term, relationship to the MSA or SOW

Description of services

Services in scope, technical specifications, geography, hours of service

Exclusions

Services not covered, scheduled maintenance windows, force majeure, third-party network issues

Performance metrics

Uptime %, response time, resolution time, throughput, error rates, customer satisfaction

Measurement methodology

How each metric is calculated, monitoring tools, reporting frequency, data sources

Reporting

Periodic service reports, dashboards, exception reports, governance reviews

Service credits / remedies

Financial credits or fee rebates payable when SLAs are missed, with caps and floors

Earn back

Mechanism for the provider to recover credits by sustained over-performance

Indemnification

Provider indemnity for specific risks (IP infringement, data breach, regulatory non-compliance)

Limitation of liability

Cap on aggregate liability, exclusions of consequential loss, carve-outs (fraud, gross negligence, breach of confidence)

Security and data protection

Information security standards, encryption, access controls, breach notification, PDPO compliance

Term, renewal, termination

Initial term, renewal mechanics, termination for chronic SLA breach, transition obligations

Governing law and dispute resolution

Hong Kong law, HKIAC arbitration or HK courts, mediation as pre-condition

Reviewing a vendor SLA against your operational reality? Slotine maps your service requirements to the contractual mechanics before you sign.

Scope an SLA review

Common SLA metrics

While the legal architecture of an SLA is what makes it enforceable, the metrics are what give it commercial meaning. The metrics chosen must be measurable, attributable, and proportionate to the service criticality.

Uptime / availability %

Percentage of time the service is available within a measurement window. Typical in cloud, hosting, SaaS, telecom.

Mean Time to Acknowledge (MTTA)

Average time from incident logged to first substantive response. Typical in help desk, managed services.

Mean Time to Resolve (MTTR)

Average time from incident logged to service restoration. Typical in outsourced operations, support.

Mean Time Between Failures (MTBF)

Average time between consecutive service failures. Typical in hardware, infrastructure, network.

First Call Resolution

Percentage of issues resolved on first contact, without escalation. Customer service operations.

Throughput

Volume of transactions, calls or work units processed per time unit. BPO, payment processing.

Error rate

Percentage of transactions or outputs containing errors. Data processing, accounting BPO.

Customer Satisfaction (CSAT)

Customer-reported satisfaction score over a defined window. All service contexts.

Drafting an SLA step-by-step

A workable process for drafting an SLA from scratch, or for reviewing a counterparty’s draft.

  1. Define the service. Be explicit on what is in scope and what is excluded. Reference the SOW or service catalogue where appropriate.
  2. Verify the achievable service levels. Performance benchmarks should be informed by operational data, not by aspirational marketing claims.
  3. Determine the metrics. Each metric must be measurable, attributable to the provider, and material to the customer’s business.
  4. Define the measurement methodology. Specify the monitoring tool, the calculation formula, the data source and the reporting cadence.
  5. Set the remedies. Service credits, fee rebates or termination rights, calibrated to the severity and frequency of the breach. Avoid disproportionate penalty figures.
  6. Add governance. A periodic service review meeting, escalation paths, change control for SLA modification.
  7. Layer the boilerplate. Indemnities, limitation of liability, confidentiality, governing law, dispute resolution.
  8. Review and iterate. SLAs need testing against realistic operational scenarios before signing.

Hong Kong common law and statutory considerations

Hong Kong SLAs are governed by the general common law of contract, refined by case law and overlaid by specific statutes. Four areas deserve particular attention.

Liquidated damages versus unenforceable penalties

Hong Kong common law, following the English Supreme Court decision in Cavendish v Makdessi and longstanding authority from Dunlop Pneumatic Tyre v New Garage, distinguishes between liquidated damages (enforceable) and penalties (unenforceable). A service credit clause that bears no genuine relation to the loss likely to be suffered, and that operates ‘in terrorem’ on the breaching party, may be struck down as a penalty. The modern test asks whether the clause protects a legitimate commercial interest of the innocent party and whether the sum stipulated is extravagant or unconscionable in relation to that interest.

Control of Exemption Clauses Ordinance (Cap. 71)

Limitation of liability clauses in SLAs are subject to the reasonableness test under Cap. 71 in many B2B contexts. The factors in Schedule 2 include the bargaining position of the parties, whether the customer received an inducement to accept the term, the customer’s knowledge of the term, and whether the goods were manufactured to the customer’s special order. A liability cap that fails the reasonableness test will not be enforced. See our commercial agreements practice for the broader framework on Cap. 71.

Personal Data (Privacy) Ordinance (Cap. 486)

Where the service involves processing personal data, the customer (as data user) remains responsible under the PDPO for the acts of its data processors. SLAs in cloud, BPO and managed services contexts should include clear obligations on data security, breach notification, sub-processing controls, and PDPO-aligned contractual safeguards.

Force majeure and material change

Hong Kong common law does not imply a general doctrine of force majeure into contracts. Express force majeure clauses are essential where the parties wish to suspend performance obligations during specified disrupting events. Material change clauses can also be used to allow renegotiation in defined long-term contexts.

Common drafting pitfalls

  • Ambiguous metrics. ‘Reasonable response time’ is not a metric. Quantify everything.
  • No measurement methodology. If the contract does not say how to calculate the metric, the parties will dispute the calculation.
  • Missing exclusions. Scheduled maintenance, third-party network issues and force majeure events must be expressly excluded from SLA calculations.
  • Penalty clauses dressed up as service credits. A credit equal to 100% of monthly fees for a single missed metric, with no relation to actual customer loss, is likely a penalty and unenforceable.
  • No governance mechanism. Without periodic service review and a change control process, the SLA degrades over time as operational reality drifts from contract.
  • No earn back. Provider has no path to recover credits even after sustained over-performance, leading to deteriorating commercial relations.

Found a penalty-style service credit clause in your draft SLA? It may be unenforceable under Cavendish v Makdessi. Slotine can recalibrate it before you sign.

Request a contract review

Is an SLA transferable?

When the service provider is acquired or undergoes a change of control, the customer often asks whether the SLA continues unaffected. The answer turns on three issues. First, the assignment and change-of-control clause in the underlying contract or MSA. Second, whether the SLA contains its own assignment provisions. Third, whether the customer has separately agreed to consent or has bargained for a termination right on change of control.

Well-drafted MSAs include a change-of-control termination right for the customer, particularly where the provider’s identity is material (specialist services, sole supplier of critical infrastructure). Where the right is not exercised, the SLA transfers with the underlying contract by novation or by operation of the assignment clause.

Frequently asked questions

  • A Service Level Agreement is a contractual document, signed between a service provider and a customer, that defines the performance standards expected, the metrics by which performance is measured, the methodology for measurement, and the remedies available if the agreed levels are not met. SLAs are common in B2B IT, cloud, outsourcing and managed services arrangements.

  • Three models are commonly used. A customer-based SLA covers all services provided to one specific customer. A service-based SLA covers one specific service provided to all customers (typical of standardised cloud or SaaS offerings). A multilevel SLA combines corporate, customer and service-level commitments in a layered structure, common in large outsourcing deals serving multiple business units.

  • A complete SLA includes: identification of the parties, description of services, exclusions, performance metrics, measurement methodology, reporting obligations, service credits or other remedies, indemnification, limitation of liability, security and data protection standards, term and termination provisions, and governing law and dispute resolution. Missing any of these elements creates a contractual gap.

  • The standard remedy is the payment of service credits, calculated as a defined percentage of the monthly fee for the affected service. Credits typically increase with the severity and frequency of the breach. Other remedies include the right to terminate for chronic breach, the right to insource the service at the provider’s cost, and indemnification for specific losses. Pure penalty clauses (disproportionate punitive sums) are unenforceable under Hong Kong common law.

  • A KPI (Key Performance Indicator) is an individual measurable indicator (uptime percentage, response time, resolution time, throughput, error rate). An SLA is the contractual frame around the KPIs: it defines which KPIs apply, how they are measured, what thresholds must be met, and what happens when they are not. KPIs are the metrics; the SLA is the contract.

  • In standardised service offerings (cloud, SaaS, telecom), the vendor typically provides its own template SLA, with limited customer negotiation. In bespoke outsourcing or managed services arrangements, the customer commonly drafts or co-drafts the SLA, with iterative negotiation. In either case, the customer should not accept the vendor’s template without legal review against its operational needs and the applicable governing law constraints.

  • Typically yes, by operation of the assignment clause in the underlying contract or MSA, subject to any change-of-control termination right held by the customer. Well-drafted MSAs include a change-of-control termination right where the identity of the vendor is material (specialist services, critical infrastructure). The SLA itself usually transfers with the underlying contract unless separately structured.

  • An indemnification clause is a contractual promise by one party to compensate the other for specific defined losses. In an SLA context, typical indemnities cover IP infringement claims arising from the service, data breach incidents, regulatory penalties, and third-party claims caused by the provider’s negligence. Indemnities operate alongside the limitation of liability cap, often with specific carve-outs.

  • An earn back is a contractual mechanism that allows a service provider to recover service credits previously due, by demonstrating sustained over-performance against the SLA thresholds in subsequent measurement periods. Earn back arrangements are common in long-term outsourcing contracts where the parties wish to incentivise recovery and avoid deteriorating commercial relations after a difficult period.

  • Hong Kong common law distinguishes between liquidated damages (enforceable) and penalties (unenforceable). The test, following Cavendish v Makdessi and longstanding authority, asks whether the clause protects a legitimate commercial interest of the innocent party and whether the stipulated sum is extravagant or unconscionable in relation to that interest. Service credits calibrated to the likely customer loss are typically enforceable. Disproportionate, punitive sums unrelated to actual loss are not. Liability caps within the SLA are separately subject to the reasonableness test under the Control of Exemption Clauses Ordinance (Cap. 71).

Discuss your SLA

If you are drafting, reviewing or negotiating a Service Level Agreement — standalone or as part of an MSA — Jessica Lau and Maeva Slotine can walk through the metrics, remedies and Hong Kong constraints with you. Initial conversations are confidential and without obligation.

Commercial Agreements practice[email protected]

1200 675 Slotine
Search for...
Privacy Overview

Slotine respects your privacy and commit to protecting it through our compliance with the practices described in its privacy policy statement.

This statement describes our practices for collecting, using, maintaining, protecting, and disclosing the personal data we may collect from you or that you may provide when you visit our website or other digital properties, communications, or forms that link or refer to this statement (our “Website”). This statement applies to the personal data collected through our Website, regardless of the country where you are located.

The Website may include links to third-party websites, plug-ins, services, social networks, or applications. Clicking on those links or enabling those connections may allow the third party to collect or share data about you. We do not control these third-party websites, and we encourage you to read the privacy statement of every website you visit.

Please read this statement carefully to understand our policies and practices for processing and storing your personal data. By engaging with our Website, you accept and consent to the practices described in this statement. This notice may change from time to time (see Changes to Our Privacy Notice). Your continued engagement with our Website after any such revisions indicates that you accept and consent to them, so please check the statement periodically for updates.

More information about our privacy policy.