Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Common Service Agreement Mistakes
- 1. Treating the Provider Contract as Purely Administrative
- 2. Using Customer Terms That Do Not Match the Payment Process
- 3. Ignoring Termination and Data Portability
- 4. Overlooking Privacy Disclosures
- 5. Accepting Broad Indemnities Without Testing Real Scenarios
- 6. Relying on Sales Material Instead of the Contract
- Key Takeaways
If your business wants to collect recurring payments, a direct debit service agreement can make cash flow more predictable, but this is also where founders often get caught. Common mistakes include accepting a provider's standard terms without checking liability clauses, using unclear customer payment wording, and overlooking privacy and cancellation obligations. Those issues can create disputes, chargeback-style losses, unhappy customers, or a service arrangement that is harder to unwind than expected.
A good direct debit setup is not just about turning payments on. It is about making sure the agreement between your business and the direct debit provider works in practice, and that your customer-facing documents and written terms match what you have actually signed. Before you rely on a verbal promise or a sales pitch, you should know what the contract covers, what risks sit with you, and what changes are worth negotiating.
This guide explains how to set up a direct debit service agreement in New Zealand, what clauses matter most, and what to fix before you sign.
Overview
A direct debit service agreement sets the legal and operational rules for how a provider will process recurring payments on your behalf. The right agreement should line up with your business model, your customer terms, your privacy processes, and the practical way money moves in and out of your account.
The main risks usually sit in liability allocation, customer authority wording, data handling, fees, and termination rights. If those parts are vague or one-sided, your business may carry more risk than you expected.
- who the parties are, and whether you are contracting with a bank, payments platform, or intermediary
- what payment services are actually included, such as recurring debits, failed payment handling, reporting, and customer notifications
- what customer authority or mandate process you must use before debiting an account
- how fees are charged, including setup fees, per-transaction fees, dishonour fees, reserve requirements, and price change rights
- who is responsible for unauthorised debits, fraud, system errors, reversals, and customer complaints
- what privacy and data security obligations apply to bank account details and personal information
- whether your customer terms, cancellation process, and refund wording match the service agreement
- how the agreement ends, including notice periods, suspension rights, access to records, and migration support
What Service Agreements Cover
A direct debit service agreement should clearly state how payments will be collected, what each party must do, and who carries the risk when something goes wrong. Before you sign a contract, make sure the agreement covers both the technical payment flow and the legal responsibilities around that flow.
The Parties and the Service Model
Start with the basics. Some businesses deal directly with a financial institution. Others contract with a payments business that sits between the merchant, the customer, and the banking system. That difference matters because the provider may not control every part of the process, even if the sales material suggests a single end-to-end service.
The agreement should identify:
- the legal entity providing the service
- whether any subcontractors or third-party processors are involved
- which services are included, and which are not
- whether the provider is acting only as a processor, or also as a collection agent
This is where founders often rely on a verbal promise. If a feature, support level, reporting tool, or integration is commercially important, it should appear in the contract or a binding schedule.
Payment Authority and Customer Mandates
Your business usually cannot just decide to debit a customer's account whenever an invoice falls due. You need a valid customer authority process that matches the provider's system and New Zealand banking expectations.
The agreement should spell out:
- how customer consent is obtained
- what mandate or authority wording must be used
- whether digital authorisation is accepted, and on what conditions
- how changes to payment amount, frequency, or timing are notified
- what records you must keep as proof of authority
If your customer sign-up form says one thing but the direct debit service agreement requires another, the main risk is that a debit may be challenged as unauthorised. That can affect revenue, customer trust, and your relationship with the provider.
Fees, Timing and Cash Flow
Price is not just the headline transaction fee. Direct debit arrangements can include several cost layers and timing rules that affect working capital.
Check for:
- initial onboarding or setup fees
- per-transaction processing fees
- dishonour or failed payment fees
- charge reversal or dispute handling costs
- minimum monthly fees or volume commitments
- holdbacks, reserves, or delayed settlement rights
- the provider's ability to change pricing on notice
A low transaction fee can look attractive until you realise the provider can delay settlement, hold a reserve, or pass through every exception cost. Before you spend money on setup or switch providers, map the contract terms against your actual payment patterns.
Suspension, Termination and Exit
An easy sign-up process does not always mean an easy exit. Some direct debit agreements let the provider suspend processing quickly if risk settings change, if complaint levels rise, or if your account falls outside approved use.
You should know:
- how long the contract runs
- whether it renews automatically
- what notice period applies if you want to terminate
- whether there are early exit fees
- what happens to pending payments and stored mandates on termination
- whether you can obtain transaction records and customer authority records in usable form
That exit detail matters if you are moving to another system. A clause that leaves your business without customer payment records or migration support can create real disruption.
Customer-Facing Documents
Your direct debit arrangement is not only the provider contract. You also need customer terms or terms of trade that explain recurring payments in plain language. Those terms should cover billing frequency, variation notices, failed payments, suspension of services for non-payment if relevant, cancellations, and refunds.
If you provide services to consumers, broader New Zealand obligations may also affect how your terms operate, including fair dealing and service quality expectations. Misleading statements about billing, cancellation, or refund rights can create issues under the Fair Trading Act. Service delivery itself may also be judged against consumer protection rules, including the Consumer Guarantees Act where it applies.
Legal Issues To Check Before You Sign
The legal review should focus on risk allocation, compliance fit, and whether your business can realistically follow the process the contract requires. Before you accept the provider's standard terms, test the document against real customer scenarios, not ideal ones.
Liability for Unauthorised or Incorrect Debits
This is usually the most important clause. Many agreements try to shift broad responsibility onto the business, even where a system error, fraud event, or process failure involves the provider's platform.
Look closely at:
- who pays if a debit is processed without valid authority
- who bears loss for duplicate, incorrect, or delayed payments
- whether liability caps apply, and who benefits from them
- whether indirect loss is excluded
- whether the provider can recover losses from your account automatically
You may not be able to negotiate every point, but you should understand where the financial exposure sits. If the clause is broad enough, a single customer complaint pattern or internal admin error can become an expensive issue.
Privacy and Data Handling
Direct debit arrangements involve personal information and bank account details. That means your privacy position matters, even if the provider stores most of the payment data.
In New Zealand, the Privacy Act 2020 can apply to how your business collects, uses, stores, and discloses personal information. The service agreement should address:
- what personal information is collected
- who controls it and who processes it
- where it is stored, including any offshore storage or access
- what security standards apply
- how data breaches are handled and notified
- what happens to data when the agreement ends
Your privacy policy and customer collection notices should also reflect the payment arrangement and any privacy notice shown during sign-up. If customers are giving bank account details through your sign-up flow, your privacy wording needs to be accurate.
Provider Discretion and Operational Control
Many standard agreements give the provider wide discretion to change risk settings, suspend services, reject transactions, or amend operating rules. Some of that is commercially understandable, but the contract drafting still matters.
Check whether the provider can:
- change fees or service terms on short notice
- suspend your account based on broad risk concerns
- refuse transactions without clear criteria
- require reserves or security at any time
- amend technical specifications that force system changes on your side
If your business depends heavily on recurring payments, even a short suspension can affect revenue and customer relationships. This is worth reviewing before you sign, especially for membership businesses, subscription services, education providers, health businesses, and any service model with regular billing.
Consistency With Your Other Contracts
Your direct debit service agreement should not sit in isolation. It needs to fit with the contracts and processes you already use.
In practice, that may include:
- your customer service agreement or terms of trade
- your cancellation and refund policy
- your privacy policy and collection statements
- any outsourced billing or software agreements
- internal finance and complaint-handling procedures
A mismatch between documents creates avoidable risk. For example, if your customer terms allow same-day cancellation but your payment workflow needs three business days' notice to stop a debit, you need to fix that before customers rely on the shorter promise.
Industry-Specific Requirements
Some sectors need extra care because billing disputes can affect access to ongoing services or involve vulnerable consumers. Gyms, childcare providers, wellness businesses, software providers, education businesses, utilities-related services, and clubs often rely on repeating payment models.
The legal issues are still contract, privacy, and fair dealing issues, but the practical expectations are higher. If your business markets flexible cancellation, no lock-in periods, introductory pricing, or pause options, those promises should line up exactly with the direct debit process and the provider's notice requirements.
Common Service Agreement Mistakes
Most direct debit problems come from mismatched documents, unclear customer authority, and signing standard terms too quickly. Before you sign, focus on the points most likely to create a dispute after the service goes live.
1. Treating the Provider Contract as Purely Administrative
Founders sometimes treat payment contracts as back-office paperwork. They assume the legal detail is standard and low risk because the product is common.
It is not just admin. The agreement controls your access to recurring revenue, allocates losses, and can affect your ability to collect, refund, pause, or cancel payments.
2. Using Customer Terms That Do Not Match the Payment Process
This is one of the most common mistakes. A business may copy recurring billing wording from another provider, or use a generic subscription clause, without checking whether it fits the actual direct debit mandate and notice rules.
Problems often show up around:
- how much notice is needed before the first debit
- how changes to payment amounts are communicated
- when a customer can cancel
- what happens after a failed payment
- whether fees for dishonoured payments are disclosed properly
If the contract with the provider and the contract with the customer tell different stories, your business ends up stuck in the middle.
3. Ignoring Termination and Data Portability
Many businesses only read the pricing and onboarding sections. They do not focus on how the arrangement ends until they want to switch provider.
That can leave you asking basic questions too late, such as:
- can we export customer mandate records
- can we continue collecting pending instalments
- how long will settlement continue after termination
- what happens if the provider suspends us without much notice
Those issues are much easier to solve before you sign than after a relationship breaks down.
4. Overlooking Privacy Disclosures
If you collect account details or other payment information through your website, app, or onboarding form, your privacy wording needs to explain that clearly. Businesses often assume the provider handles all privacy obligations because the payment service is outsourced.
That assumption can be risky. Your business may still be collecting personal information directly, deciding why it is collected, and sharing it with the provider. The paperwork should reflect that.
5. Accepting Broad Indemnities Without Testing Real Scenarios
Indemnities can look technical, but they have real commercial impact. A clause might require your business to cover losses arising from customer disputes, invalid mandates, fraud connected to your staff, inaccurate billing information, or breaches of law.
The problem is not that indemnities exist. The problem is when they are drafted so broadly that your business carries losses even where the provider contributed to the issue. Ask what happens in realistic situations, such as:
- a team member enters the wrong debit amount
- a system sync error causes duplicate collections
- a customer disputes authority after signing up online
- the provider's platform fails to send a required notification
If the contract answer is unclear, that is a warning sign.
6. Relying on Sales Material Instead of the Contract
Sales conversations often focus on convenience, automation, and customer experience. The contract may reserve rights that cut across those promises.
Before you rely on a verbal promise, make sure the signed document deals with the service level, reporting, implementation support, and timing assumptions that matter to your business. If a commitment is commercially important, ask for it to be written in.
FAQs
Do I need a written direct debit service agreement?
Yes, if a provider is collecting recurring payments for your business, the arrangement should be documented in writing. You also need aligned customer-facing payment terms and authority wording.
Can I use the provider's standard terms without changes?
Sometimes, but you should still review them carefully. Standard terms often favour the provider on liability, termination, reserves, and pricing changes.
Do I need customer consent before debiting an account?
Yes. You should have a clear authority or mandate process that matches the provider's requirements and the way your business actually bills customers.
What laws should I think about in New Zealand?
Contract terms are central, but privacy, fair trading, and consumer service obligations can also matter. The Privacy Act 2020, Fair Trading Act 1986, and Consumer Guarantees Act 1993 may be relevant depending on your customers and service model.
What should I check before switching providers?
Review termination rights, notice periods, export of payment records, migration support, fees on exit, and what happens to pending or failed payments during the transition.
Key Takeaways
- A direct debit service agreement should clearly set out the service scope, customer authority process, fees, liability, privacy obligations, and exit rights.
- The biggest legal risks usually involve unauthorised debits, broad indemnities, unclear customer consent, and poor alignment between provider terms and your customer documents.
- Your customer terms, cancellation process, notices, and privacy wording should match the direct debit workflow you actually use.
- Before you accept the provider's standard terms, test the contract against real situations such as failed payments, customer disputes, pricing changes, and provider suspension.
- Switching providers can be difficult if the agreement does not deal properly with records, migration, pending collections, and termination timing.
- If you are reviewing or negotiating how to set up a direct debit service agreement and want help with contract review, customer payment terms, privacy wording, and liability clauses, you can reach us on 0800 002 184 or team@sprintlaw.co.nz for a free, no-obligations chat.
Lock in the contract
Turning the information into a usable contract
Once money, deliverables or customer obligations are involved, the next step is usually a clear contract that matches how the business actually works.








