What Is an Indemnification Clause?

Also called: Indemnity clause, Indemnification provision

Related problems: A third party is suing us over something our vendor did; Vendor wants us to cover claims arising from our use of their service; Worried our SaaS provider's software infringes someone's patent; Legal flagged the indemnity section and we don't know what to push back on

An indemnification clause is a contract term in which one party, the indemnifying party, agrees to cover certain losses of the other, usually losses from claims brought by third parties. In IT, telecom and SaaS contracts, the classic example is a provider promising to defend the customer if someone claims the provider’s software infringes their patent or copyright. Customers are often asked to give indemnities in return, for example for their own data or misuse of the service. How far an indemnity reaches, and how courts read it, depends on its wording and on the governing law.

At a glance

  • One party agrees to cover the other’s losses from specified claims, usually third-party claims.
  • Common provider indemnities cover intellectual property infringement; data breach and regulatory indemnities are more often negotiated.
  • The procedure (notice, control of the defense, settlement approval) matters as much as the scope.
  • The interaction with the limitation of liability clause decides how much an indemnity is actually worth.
  • Meaning varies by jurisdiction and wording. This is general information, not legal advice.

What problem it solves

When a technology service causes harm to someone outside the contract, that person can sue whichever party they choose, often the customer whose name is on the business that was affected. An indemnity moves the cost of defending and resolving that claim to the party better placed to control the risk. A customer usually can’t evaluate whether a vendor’s code infringes a patent; the vendor is better placed to. A vendor usually can’t control what data a customer uploads; the customer can.

Without an indemnity, the injured party usually has to pursue the other side through a separate claim for breach of contract, subject to the contract’s caps and exclusions, which can leave a gap between what the customer pays out and what it recovers.

How it works

Scope. The clause lists the claims covered, such as infringement of intellectual property, bodily injury or property damage, breach of confidentiality or data protection obligations, violations of law, or gross negligence and willful misconduct. Clauses often use broad language like “any and all claims arising from…”, and the breadth of “arising from” is commonly negotiated.

Mutual or one-way. Many contracts include indemnities running both ways, each covering risks that party controls.

Procedure. The indemnified party is usually required to give prompt notice, let the indemnifying party control the defense, and cooperate. Settlements that admit fault or impose obligations often require the indemnified party’s consent.

Remedies for infringement. IP indemnities often let the provider modify the service, obtain a license, or, if neither is practical, end the service and refund prepaid fees.

Caps and insurance. The limitation of liability clause may exclude some indemnities from the cap, apply a separate cap, or cap them with everything else. Insurance, including cyber insurance, may or may not respond to contractual indemnities.

Enforceability and interpretation depend on the governing law, the jurisdiction and the exact wording. Some jurisdictions restrict indemnities for a party’s own negligence or treat the phrases “indemnify” and “hold harmless” differently. This is general information, not legal advice; have counsel review the contract.

Reviewing contract risk terms across many providers is part of telecom expense management, and our managed network services page covers provider agreements for network operations.

When it matters for buyers

  • Buying SaaS or software. IP infringement claims can target customers who use the product; an IP indemnity is a common ask.
  • Sharing sensitive data. If a provider will process personal, health or payment data, consider how a data breach caused by the provider would be paid for, alongside the data processing agreement (DPA) or business associate agreement (BAA).
  • Giving indemnities. Customer-side indemnities in provider forms can be broad; read them before signing.
  • Vendor risk reviews. Third-party risk management (TPRM) programs often check indemnity and insurance terms for critical vendors.

Questions to ask vendors

  • What claims will you indemnify us for, and is the indemnity mutual?
  • Does your IP indemnity cover the service as we will use it, including integrations and APIs?
  • Will you indemnify claims arising from a breach of your security or data protection obligations?
  • Are your indemnities subject to the liability cap, a separate cap or uncapped?
  • What insurance supports your indemnities, and can you show certificates?
  • What indemnities are you asking from us, and can they be narrowed to claims we control?

How it differs from a limitation of liability clause

An indemnification clause decides who pays for certain claims, often third-party claims. A limitation of liability clause decides how much a party can be made to pay at all, by capping damages and excluding categories such as lost profits. The two work as a pair: a broad indemnity subject to a low cap may be worth little, while an indemnity carved out of the cap can expose a party to much larger amounts. Read both clauses, and their cross-references, together.

Frequently Asked Questions

What does "defend, indemnify and hold harmless" mean?
Clauses often use all three words. Broadly, "defend" refers to handling or paying for the legal defense of a claim, "indemnify" to covering resulting losses, and "hold harmless" to protecting the other party from liability. Whether these words mean different things, and how far they reach, varies by jurisdiction and wording. This is general information, not legal advice; have counsel review the contract.
Is an indemnity limited by the liability cap?
Only if the contract says so. Some contracts exclude certain indemnities, such as intellectual property infringement, from the limitation of liability; others apply the cap or a separate, higher cap to them. Check how the indemnification and limitation of liability clauses cross-reference each other.
What indemnities do SaaS and cloud providers commonly offer?
An indemnity against claims that the service infringes a third party's intellectual property is common, usually with exceptions for customer modifications, combinations with other products or customer-supplied content. Indemnities for data breaches or regulatory fines are less common in provider forms and are more often negotiated.
Why does the vendor want us to indemnify them?
Providers commonly ask customers to cover claims arising from customer data or content, the customer's misuse of the service, or violations of the acceptable use policy. Those requests can be reasonable, but check their breadth and ask that they be mutual and subject to the same cap and procedures as the provider's indemnity.
Does our insurance cover what we owe under an indemnity?
Sometimes. Contractual liability can be excluded or limited in some policies. Ask your broker whether the indemnities you're giving are covered, and ask the vendor what insurance backs the indemnities it gives you.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.