The short answer
Before signing a software development contract, confirm six things: that IP in the code is assigned to you in writing, with moral rights consents from the people who wrote it; that you get the source code and credentials, ideally in your own repository throughout; that scope, acceptance testing and change control are defined; that warranties and liability caps are reasonable and sit alongside the Australian Consumer Law; that privacy and security obligations are written in; and that you can leave with everything if the relationship ends.
Key takeaways
- Under section 196(3) of the Copyright Act 1968, an assignment of copyright has no effect unless it's in writing and signed by or on behalf of the assignor. Without it, the developer usually owns the code.
- Moral rights can't be assigned. The contract should secure written consents from the individual authors, which section 195AWA says must relate to specified acts or classes of acts.
- Insist on code in a repository you control, plus ownership of hosting, domain and app store accounts. Escrow matters mainly when a vendor hosts or licenses the software to you.
- Consumer guarantees under the Australian Consumer Law cover services under $100,000, including business purchases, and require due care and skill.
- A vendor with turnover of $3 million or less may not be covered by the Privacy Act, so the contract itself should impose privacy, security and breach notification duties.
What matters most in a software development contract or agreement?
The clauses that decide whether you own, control and can walk away with what you paid for: IP assignment, moral rights consents, source code and account ownership, and exit. Price and timeline get most of the attention in negotiation, but these are the terms that cause the expensive problems years later, when you want to change vendors, raise investment or sell the business.
This checklist is written for Australian buyers of custom software and reflects Commonwealth legislation and regulator guidance as at September 2026. It’s general information, not legal advice. For a significant contract, have your own lawyer review it.
The checklist at a glance
| Clause | What good looks like | Red flags |
|---|---|---|
| IP assignment | Written, signed assignment of IP in deliverables to you, on creation or on payment | ”Licence” only; assignment “on request”; silence |
| Background IP | Vendor keeps its tools, with a perpetual, royalty-free licence for you to use and modify them within the software | Licence ends with the contract or needs ongoing fees |
| Moral rights | Vendor obtains written consents from individual authors covering modification and use without attribution | No mention at all |
| Third-party and open source | Listed, with licences disclosed; copyleft components flagged | Unknown components; “vendor proprietary library” you can’t inspect |
| Source code and accounts | Code in your repository from day one; you own hosting, domain, app store and payment accounts | Code handed over only at the end; vendor owns your cloud account |
| Scope and acceptance | Written scope, acceptance criteria and a testing period | ”Deemed accepted” after a few days with no test |
| Change control | Written variations, priced and approved by you before work | Variations billable on the vendor’s say-so |
| Warranty | Defect fixing period after acceptance, plus Australian Consumer Law rights | Warranties excluded “to the maximum extent”, with no defect period |
| Liability | Mutual cap linked to fees, sensible carve-outs | One-sided cap; no carve-outs for privacy or confidentiality |
| Privacy and security | APP-standard handling, security controls, breach notification to you, onshore or disclosed data locations | Nothing, or “vendor will comply with applicable law” alone |
| Confidentiality | Mutual NDA or clause covering your data, code and business information | One-way, or expires quickly |
| Termination and exit | You can end for convenience, pay for work done, and receive everything | Termination only for breach; handover at vendor’s discretion |
Who owns the code, and how do you make sure it’s you?
Without a written, signed assignment, you probably don’t own the code you paid for. Under the Copyright Act 1968, copyright belongs to the author, and section 35(6) gives it to the author’s employer where the work is made under a contract of employment. That means the development agency or freelancer, not you, is the default owner. Section 196(3) says an assignment of copyright has no effect unless it’s in writing and signed by or on behalf of the assignor.
Check the assignment clause for three things:
- Timing. Either on creation or on payment is common. Section 197 allows an agreement to assign copyright in works not yet created, so a signed contract can make ownership pass automatically when the code is written or paid for. If transfer is on payment, make sure you have a licence to use the work until then, and that each milestone’s IP transfers when that milestone is paid.
- Scope. It should cover source code, object code, designs, documentation, database schemas and configuration, not just “the software”.
- Background IP. Vendors reasonably keep their pre-existing tools and libraries. You need a perpetual, irrevocable, royalty-free licence to use, copy and modify any background IP embedded in your software, including through other developers, and ideally to transfer that licence if you sell the business.
Also ask for a list of open source and third-party components and their licences. Most are permissive, but some copyleft licences carry obligations if you distribute the software.
What are moral rights, and why do they need consents?
Moral rights are personal rights of the individual authors, such as the right of attribution and the right of integrity, and they can’t be assigned. The Attorney-General’s Department states plainly that moral rights cannot be assigned or licensed to another person. So even a perfect IP assignment leaves the individual programmers with rights that could, in principle, be used to object to derogatory treatment of their work.
In practice the fix is written consent. Section 195AWA provides that it isn’t an infringement to do something within the scope of a written consent genuinely given by the author, and that a consent must relate to specified acts or classes of acts and to specified works or works of a described kind. Employees can give broad consents covering all work made in the course of their employment.
Look for a clause in which the vendor promises to obtain consents from its employees and contractors covering modification, adaptation, use without attribution and commercialisation. Our Master Services Agreement includes a moral rights consent clause at clause 10.5, covering use, modification, adaptation, maintenance and exploitation of paid deliverables.
Do you get the source code, and when?
The safest arrangement is that the code lives in your repository, under your account, from the first commit. Then there’s nothing to hand over and nothing to argue about.
Check:
- Repository ownership. Your organisation owns the GitHub, GitLab or Azure DevOps organisation, and the vendor is added as a collaborator.
- Account ownership. Cloud hosting, domain names, DNS, app store developer accounts, payment gateways, email services and analytics are registered to you. A vendor may set them up, but ownership should be yours before launch.
- Credentials and documentation. Deployment instructions, environment variables, infrastructure as code and admin credentials are delivered and kept current.
- Escrow, where relevant. If a vendor licenses or hosts a platform to you and won’t release source code, a source code escrow agreement lets a third party hold the code for release if the vendor becomes insolvent or stops supporting it. For software written for you and held in your own repository, escrow adds little.
What do warranties and the Australian Consumer Law give you?
Contract warranties sit on top of statutory rights: the Australian Consumer Law’s consumer guarantees apply to services costing less than $100,000, including services bought by a business. Those services must be carried out with due care and skill, be fit for any purpose you’ve made known, and be supplied within a reasonable time if no timeframe is agreed. A contract generally can’t take those rights away, so ask your lawyer how the warranty and liability clauses interact with them.
Above the threshold, your protection comes mostly from the contract. Look for:
- A defect warranty for a defined period after acceptance, during which bugs against the agreed scope are fixed at no charge. Ours is 30 days from when the deliverable is first deployed to production, unless a schedule of work says otherwise.
- A warranty that the work is original and doesn’t infringe third-party IP, backed by an indemnity.
- A warranty that the vendor will use appropriately skilled personnel and follow good industry practice.
Also check for unfair terms. The ACL protects small businesses from unfair terms in standard form contracts. business.gov.au gives the example of a term letting only one party vary the contract, such as the price; a court can declare such a term void. Since 9 November 2023, a small business for this purpose is one with fewer than 100 employees or annual turnover under $10 million, and proposing, applying or relying on an unfair term in a standard form contract can attract civil penalties: for a company, up to the greater of $50 million, 3 times the benefit obtained, or 30% of adjusted turnover during the breach period.
Is the liability cap reasonable?
A cap linked to the fees under the contract is normal; what deserves scrutiny is whether it’s mutual and what sits outside it. Our own MSA caps our liability at 100% of the fees payable under the relevant schedule of work, which is a common structure. That cap limits our liability, and the exclusion of consequential loss applies to both parties.
Questions to ask:
- Is the cap mutual, or does it only protect the vendor?
- Are consequential losses, such as lost profits, excluded for both parties?
- What’s carved out of the cap? Breach of confidentiality, privacy breaches, IP infringement indemnities, fraud and wilful misconduct are commonly excluded or given a higher cap.
- Does the vendor hold professional indemnity and cyber insurance of a level that makes the cap meaningful?
Are privacy and security written in?
If the software will handle personal information, the contract should set security and privacy duties explicitly, not rely on the vendor’s general legal obligations. That matters in Australia because the Privacy Act 1988 doesn’t cover most small businesses: the OAIC explains that a business with annual turnover of $3 million or less is generally exempt. Many development agencies fall under that threshold.
Your own obligations don’t disappear. APP 11 requires you to take reasonable steps, including technical and organisational measures, to protect personal information. Under the Notifiable Data Breaches scheme, organisations the Privacy Act covers must notify affected individuals and the OAIC when a breach is likely to result in serious harm. If a vendor’s developers or subcontractors are overseas and can access personal information, APP 8 applies.
A privacy and security clause should cover:
- Handling personal information only for the project and as you instruct.
- Security controls: access management, encryption, secure development practices, no production data in development without approval.
- Prompt notice to you of any suspected breach, and cooperation with your assessment.
- Where data is stored and accessed from, and which subcontractors are involved, including any AI coding or model providers.
- Return or destruction of your data at the end.
Confidentiality is usually covered by a mutual NDA signed before discovery. Our mutual NDA is published if you want to see what one looks like.
Can you leave cleanly?
A good contract makes leaving boring: you can terminate, you pay for work done, and you receive everything needed to continue with someone else. Check for:
- Termination for convenience by you, with reasonable notice, not only for breach.
- Payment on termination limited to work performed and committed costs.
- Transition assistance at agreed rates: handover sessions, documentation, and help moving hosting and accounts.
- Survival of IP, confidentiality and privacy clauses after termination.
- Dispute resolution with negotiation and mediation steps before court, and a stated governing law, usually the law of an Australian state.
What should you check before signing? A quick pre-signing checklist
- IP in deliverables assigned to you in writing, with timing clear
- Perpetual licence to any vendor background IP in the software
- Moral rights consents from individual authors
- Open source and third-party components listed
- Code in your repository; accounts in your name
- Scope, acceptance criteria and a testing period defined
- Written change control with your approval before billing
- Defect warranty period and non-infringement warranty
- Mutual liability cap with sensible carve-outs
- Privacy, security and breach notification obligations
- Data locations and subcontractors disclosed, including AI tools
- Termination for convenience and a handover obligation
- Your own lawyer has reviewed it
When is a full agreement overkill?
For a small, low-risk job, a short letter of engagement that covers IP assignment, confidentiality, price and payment may be enough. A framework agreement with schedules makes sense when you expect repeat work or the system matters to the business. Whatever the size, don’t skip the IP assignment: it’s the one clause that’s hard to fix after the fact. If you’re choosing between contract pricing models, see fixed price vs time and materials, and for vetting vendors more broadly, how to choose a software development company.
How All Webbed Labs handles contracts
We sign an NDA before discovery and work under a published Master Services Agreement with a schedule of work for each project. Our practice is to keep code in your repository from day one; the MSA itself allows either party’s repository during development, with final repository access on payment. Hosting and other production accounts are transferred to your ownership before launch once the related fees are paid, IP in paid deliverables transfers to you, and our pre-existing tools come with a perpetual licence to use and modify them as part of your software. We disclose our use of AI-assisted development in the agreement. Read both documents before we talk, and have your lawyer review them. See our custom software development service.
Frequently asked questions
Who owns the code if the contract says nothing?
Generally the developer or their employer, not you. Copyright in software belongs to its author, or to the author's employer for work done in the course of employment, and it only moves to you through a written, signed assignment. You might have an implied licence to use what you paid for, but that's a weak position if you want to modify, sell or license the software.
Is it normal for IP to transfer only after payment?
Yes. Many Australian development agreements, including ours, assign IP in deliverables when they're paid for. Ours gives you a licence to review and test a deliverable until it's paid for. What matters is that you get a licence that suits how you'll use the work in the meantime, that each milestone's IP transfers when that milestone is paid, and that the vendor's pre-existing tools come with a perpetual licence so you can keep using and modifying the software.
Do I need source code escrow?
If the code is written for you and sits in your own repository, escrow adds little. Escrow is useful when a vendor licenses or hosts software you depend on and won't hand over the source: a third party holds the code and releases it to you if the vendor fails or stops supporting it.
What's a reasonable liability cap?
A cap equal to the fees paid or payable under the contract, or a multiple of them, is common in Australian IT contracts. Look at the carve-outs as much as the number: breaches of confidentiality, privacy, IP infringement and wilful misconduct are often excluded from the cap or given a higher one.
Should the contract say how AI coding tools are used?
It's increasingly common and sensible. Ask the vendor to disclose AI-assisted development, confirm that your confidential information isn't used to train third-party models, and address ownership of AI-assisted output. Australian law on copyright in purely AI-generated material is still being worked through.
What should I know before signing an NDA with a software developer?
Check that it's mutual, so both sides' information is protected, that the definition of confidential information covers your data, code, designs and business plans, and that it lasts long enough to matter after the project ends. Look for the usual exclusions (information already public or independently developed) and a duty to return or destroy your information. An NDA protects confidentiality only; it doesn't give you ownership of any code, which needs the IP assignment in the main contract.
What's the difference between a master services agreement and a statement of work?
A master services agreement (MSA) sets the general terms for the whole relationship: IP, confidentiality, liability, warranties, privacy and termination. A statement of work, sometimes called a schedule of work, sits under it and covers one project's scope, deliverables, price, milestones and acceptance criteria. Check both, and check which one wins if they conflict.
Can I use a software development contract template?
A template is a reasonable starting point for understanding what a software development agreement should cover, and the checklist on this page shows what to look for in one. But templates are written for a generic situation. Have your lawyer adapt it, or review the vendor's version, against your project's IP, privacy and exit needs.
Do I need a lawyer to review the contract?
For anything significant, yes. A checklist helps you ask the right questions, but only a lawyer advising you can weigh the whole document against your situation. The vendor's lawyer acts for the vendor.
This page is general information about Australian law and regulation, current at the date shown. It is not legal advice. Get advice from a qualified lawyer about your circumstances.
Sources
- Copyright Act 1968 (ss 35, 195AWA, 196, 197) , Federal Register of Legislation
- Copyright owners (including moral rights) , Attorney-General's Department
- Copyright and Artificial Intelligence Reference Group (CAIRG) , Attorney-General's Department
- Australian Consumer Law and your business , business.gov.au
- Competition and Consumer Act 2010, Schedule 2 (Australian Consumer Law), ss 23 and 224 , Federal Register of Legislation
- Small business and the Privacy Act , Office of the Australian Information Commissioner
- About the Notifiable Data Breaches scheme , Office of the Australian Information Commissioner
- APP 11: Security of personal information , Office of the Australian Information Commissioner
- APP 8: Cross-border disclosure of personal information , Office of the Australian Information Commissioner