An indemnification clause is a contract term in which one party, the indemnifying party, agrees to cover certain losses of the other, usually losses from claims brought by third parties. In IT, telecom and SaaS contracts, the classic example is a provider promising to defend the customer if someone claims the provider’s software infringes their patent or copyright. Customers are often asked to give indemnities in return, for example for their own data or misuse of the service. How far an indemnity reaches, and how courts read it, depends on its wording and on the governing law.
At a glance
- One party agrees to cover the other’s losses from specified claims, usually third-party claims.
- Common provider indemnities cover intellectual property infringement; data breach and regulatory indemnities are more often negotiated.
- The procedure (notice, control of the defense, settlement approval) matters as much as the scope.
- The interaction with the limitation of liability clause decides how much an indemnity is actually worth.
- Meaning varies by jurisdiction and wording. This is general information, not legal advice.
What problem it solves
When a technology service causes harm to someone outside the contract, that person can sue whichever party they choose, often the customer whose name is on the business that was affected. An indemnity moves the cost of defending and resolving that claim to the party better placed to control the risk. A customer usually can’t evaluate whether a vendor’s code infringes a patent; the vendor is better placed to. A vendor usually can’t control what data a customer uploads; the customer can.
Without an indemnity, the injured party usually has to pursue the other side through a separate claim for breach of contract, subject to the contract’s caps and exclusions, which can leave a gap between what the customer pays out and what it recovers.
How it works
Scope. The clause lists the claims covered, such as infringement of intellectual property, bodily injury or property damage, breach of confidentiality or data protection obligations, violations of law, or gross negligence and willful misconduct. Clauses often use broad language like “any and all claims arising from…”, and the breadth of “arising from” is commonly negotiated.
Mutual or one-way. Many contracts include indemnities running both ways, each covering risks that party controls.
Procedure. The indemnified party is usually required to give prompt notice, let the indemnifying party control the defense, and cooperate. Settlements that admit fault or impose obligations often require the indemnified party’s consent.
Remedies for infringement. IP indemnities often let the provider modify the service, obtain a license, or, if neither is practical, end the service and refund prepaid fees.
Caps and insurance. The limitation of liability clause may exclude some indemnities from the cap, apply a separate cap, or cap them with everything else. Insurance, including cyber insurance, may or may not respond to contractual indemnities.
Enforceability and interpretation depend on the governing law, the jurisdiction and the exact wording. Some jurisdictions restrict indemnities for a party’s own negligence or treat the phrases “indemnify” and “hold harmless” differently. This is general information, not legal advice; have counsel review the contract.
Reviewing contract risk terms across many providers is part of telecom expense management, and our managed network services page covers provider agreements for network operations.
When it matters for buyers
- Buying SaaS or software. IP infringement claims can target customers who use the product; an IP indemnity is a common ask.
- Sharing sensitive data. If a provider will process personal, health or payment data, consider how a data breach caused by the provider would be paid for, alongside the data processing agreement (DPA) or business associate agreement (BAA).
- Giving indemnities. Customer-side indemnities in provider forms can be broad; read them before signing.
- Vendor risk reviews. Third-party risk management (TPRM) programs often check indemnity and insurance terms for critical vendors.
Questions to ask vendors
- What claims will you indemnify us for, and is the indemnity mutual?
- Does your IP indemnity cover the service as we will use it, including integrations and APIs?
- Will you indemnify claims arising from a breach of your security or data protection obligations?
- Are your indemnities subject to the liability cap, a separate cap or uncapped?
- What insurance supports your indemnities, and can you show certificates?
- What indemnities are you asking from us, and can they be narrowed to claims we control?
How it differs from a limitation of liability clause
An indemnification clause decides who pays for certain claims, often third-party claims. A limitation of liability clause decides how much a party can be made to pay at all, by capping damages and excluding categories such as lost profits. The two work as a pair: a broad indemnity subject to a low cap may be worth little, while an indemnity carved out of the cap can expose a party to much larger amounts. Read both clauses, and their cross-references, together.
