What Is a Limitation of Liability Clause?

Also called: Limitation of liability provision

Related problems: Provider's maximum liability is tiny compared with what an outage costs us; Vendor lost our data and says the contract caps what they owe; Legal says the liability cap is unacceptable but we don't know what's normal; Unsure whether a data breach by our provider would be covered

A limitation of liability clause is a contract term that limits how much one party can be required to pay the other if something goes wrong. It usually does two things: it sets a maximum amount, or cap, on total liability, and it excludes certain kinds of loss altogether, typically indirect or consequential damages such as lost profits. In IT, telecom and SaaS contracts, it is often the single clause that decides how much a provider would actually pay after a major outage, data loss or security breach. Whether and how it applies depends on the exact wording and on the governing law.

At a glance

  • It caps a party’s total liability and often excludes indirect losses such as lost profits.
  • Caps are often tied to fees paid over a defined period, with carve-outs for certain obligations.
  • Carve-outs and separate caps for indemnities, confidentiality and data breaches are commonly negotiated.
  • SLA credits are often the sole remedy for availability failures and may sit under the cap.
  • Some liability can’t be limited under certain laws, and wording matters. This is general information, not legal advice.

What problem it solves

Technology services can cause losses far larger than their price. A circuit that costs a few thousand a month can take down a contact center that books far more revenue. Providers limit liability so that one incident doesn’t create exposure out of proportion to the contract value, which is part of how they price services.

For buyers, the problem is that a standard cap may leave most real losses uncovered. The clause forces a conversation about which risks the provider should carry, which the buyer should insure, and which need a different remedy, such as a termination right.

How it works

The cap. The clause sets a maximum aggregate amount. Common approaches tie it to fees paid or payable in a period before the claim, the total contract value, or a fixed amount, sometimes whichever is greater. Caps are often mutual but sometimes apply only to the provider.

Excluded damages. Many clauses exclude indirect, incidental, special, consequential or punitive damages, and often lost profits, revenue, data or goodwill, however they are classified. Buyers sometimes ask that specific losses, such as costs of restoring data or notifying affected individuals after a breach, be treated as recoverable.

Carve-outs. Certain obligations are often excluded from the cap or the damages exclusion. Common examples are indemnities, breach of confidentiality, data protection breaches, gross negligence or willful misconduct, and the customer’s payment obligations.

Super-caps. Some contracts set a higher cap for specified risks, such as data protection breaches, rather than leaving them uncapped.

Interaction with other remedies. The service level agreement (SLA) may make SLA credits the exclusive remedy for missed targets. The indemnification clause and any insurance requirements need to line up with the cap.

Enforceability and interpretation depend on the governing law, the jurisdiction and the exact wording. Some laws limit how far liability for certain conduct, such as fraud or personal injury, can be excluded, and consumer rules may differ from business rules. This is general information, not legal advice; have counsel review the contract.

Benchmarking liability terms across carrier contracts is part of telecom expense management; our managed network services page covers contract structure for network providers.

When it matters for buyers

  • Critical services. Compare the cap with what an outage or data loss would actually cost you.
  • Sensitive data. If a provider will hold personal, financial or health data, a data breach could cost far more than the fees; check carve-outs and super-caps.
  • Insurance planning. Whatever the provider won’t carry falls to you or your cyber insurance; share the cap with your broker.
  • Small orders under a big agreement. If the cap is tied to fees for the affected service, a low-cost service supporting a critical process may carry a very small cap.
  • Renewals. Renegotiating the cap is easier when you have leverage, such as at renewal.

Questions to ask vendors

  • How is your liability cap calculated, and is it per claim, per year or for the whole term?
  • Is the cap tied to fees for the affected service or for the whole agreement?
  • What is carved out of the cap and the damages exclusions, and does the same apply to us?
  • Will you agree to a separate, higher cap for data protection or security breaches?
  • Which losses do you treat as direct, recoverable damages, such as data restoration or breach notification costs?
  • Are SLA credits the exclusive remedy, and do they count toward the cap?
  • What insurance do you carry, and at what limits?

How it differs from SLA credits

SLA credits are a predefined, usually small remedy for missing a measured service level, applied as a discount on the bill. A limitation of liability clause sets the ceiling on everything a party can recover under the contract, including damages beyond credits where the contract allows them. Credits often operate inside the limitation of liability: they may be the only remedy for downtime, and they may count toward the cap.

Frequently Asked Questions

How are liability caps usually set?
Caps are often tied to the fees paid or payable over a defined period before the claim, sometimes with a fixed minimum amount. For example, a contract might cap liability at the fees paid in the prior twelve months; that is one illustration, and caps vary widely by provider, deal size and service. This is general information, not legal advice; have counsel review the contract.
What is commonly carved out of the cap?
Buyers commonly negotiate to exclude from the cap, or give a higher cap to, indemnification obligations, breaches of confidentiality or data protection obligations, gross negligence or willful misconduct, and amounts the customer owes for services. Which carve-outs are agreed depends on negotiation and on whether the governing law already prevents certain liability from being limited.
What are consequential or indirect damages?
Broadly, losses that flow indirectly from a breach, such as lost profits, lost revenue or business interruption. Many contracts exclude them entirely. How a court classifies a particular loss as direct or indirect depends on the jurisdiction and facts, so some contracts list specific losses, such as data restoration costs, as recoverable direct damages.
Are SLA credits our only remedy for outages?
In many provider contracts, yes for availability failures: the SLA says credits are the sole and exclusive remedy, and the credits count toward or sit beneath the liability cap. Buyers often negotiate exceptions, such as a termination right for chronic outages.
Is a super-cap for data breaches common?
Some contracts include a separate, higher cap for data protection or security breaches, sometimes called a super-cap. It is more often negotiated than offered in standard forms, and its size varies widely.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.