Key Takeaways:

  • Limitation of liability clauses are really three or four clauses in one — a consequential-damages disclaimer, a standard cap, carve-outs, and possibly a super cap — and they only work if drafted to interact correctly.
  • The real negotiation happens in the carve-outs: which claims (e.g., indemnity, confidentiality, data breach, IP infringement, fraud, gross negligence) get treated differently, and where they land — under a super cap or fully uncapped.
  • Look out for conflicts within the agreement (e.g., how these clauses interact with the indemnification section), and in other related agreements (e.g., a data processing addendum with its own limitation of liabilities clause).
  • Beware of double and triple negatives and exceptions to exceptions. These clauses can be logically confusing: there’s a cap (negative), but there are things excluded from the cap (double negative), but those excluded things may be subject to a different cap (triple negative). 

Limitation of Liability Clauses: The Fine Print That Decides What a Dispute Is Actually Worth By Brian Heller

Limitation of liability clauses have a way of getting shoved to the end of the negotiation, after all the “business” terms are settled. But these clauses often have the biggest business impact of all. In most disputes, the limitation of liability section is what actually determines a party’s real-world exposure. A carefully negotiated services agreement with an uncapped or badly drafted limitation of liability clause can still blow up a company’s balance sheet. And a small deal can carry outsized risk if the cap, the carve-outs, and the exceptions aren’t properly evaluated. Every dollar of exposure a company faces from a contract dispute is filtered through this one provision, so it deserves heightened scrutiny.

The trouble is that “the limitation of liability clause” is rarely just one clause. It is a stack of several distinct mechanisms, each doing different work, each negotiated differently, and each capable of quietly undoing what the others accomplish if they aren’t drafted to work together.

It’s Not One Clause — It’s Four

Strip away the boilerplate and a typical limitation of liability section is really four layers stacked on top of each other:

  • A disclaimer of “consequential” damages — categories of harm excluded, including indirect or consequential damages, such as lost profits or loss of goodwill.
  • A standard (or ordinary) cap — a dollar ceiling on most damages.
  • Carve-outs and exceptions — categories pulled back out of the disclaimer and/or cap
  • A super cap or unlimited liability — what happens to those carved-out claims: a second, higher ceiling, and/or no ceiling at all.

 

Understanding each layer separately — and how they interact — is the difference between a limitation of liability clause that does what the parties think it does, and one that quietly fails in the exact scenario it was supposed to address.

Layer 1: The Disclaimer of Consequential Damages

The first layer excludes entire categories of damages. The standard list — consequential, incidental, indirect, special, and punitive damages, including lost profits[1], lost revenue, loss of data, and loss of business or goodwill — shows up in some form in nearly every commercial contract. The rationale is straightforward: these are the categories of harm that are hardest to predict, hardest to price into a deal, and most likely to be disproportionate to the size of the contract itself.

The list is a grouping of overlapping and related ideas. “Consequential,” “incidental,” “indirect,” and “special” damages all describe harm that doesn’t flow directly from the breach itself — lost business with a third party, the cost of scrambling to cover a missed delivery, or losses other than those directly traceable and predictably and measurably occurring due to a breach.

Courts don’t use these terms consistently, and a loss one court calls “consequential” another might call “special” or “indirect.” Rather than pick one label and litigate the boundary, drafters typically list all of these related phrases so that whichever doctrinal bucket a court reaches for, the damages are already excluded. Punitive damages get added to the same list for a related but different reason: they’re rarely available for a straight breach of contract claim anyway, but naming them expressly forecloses any argument that a claim styled in tort — fraud or bad faith, for example — should open the door to them.

Lost profits, lost revenue, loss of data, and loss of business or goodwill are called out by name for the same belt-and-suspenders reason: each could plausibly be argued to be a “direct” loss rather than a “consequential” one, so naming them specifically closes any gap the general list might leave open. Lost profits is the clearest example — courts are genuinely split on how to classify it, which is exactly why it’s named rather than left to fall under “consequential damages” and hope for the best. Loss of data and loss of business or goodwill are included because they are inherently hard to price: a data-loss claim can range from remediation costs to speculative downstream harm, and a goodwill claim invites a damages theory built on reputational guesswork rather than anything with a natural dollar anchor.

Layer 2: The Standard (Ordinary) Cap

The standard cap (sometimes called the ordinary cap) limits the amount of damages. The formulation varies, but it usually takes one of a few shapes: fees paid in the prior twelve months, a fixed dollar amount, or a multiple of fees.

A few drafting details determine how that cap actually behaves in a dispute, and they’re easy to gloss over at the negotiating table:

  • “Fees paid” vs. “fees payable” — the latter can produce a much larger number if invoices are outstanding or fees are deferred.
  • Scope — is the cap measured against the applicable services, SOW or order (e.g., 2x fees paid or payable “for the applicable services”) or against the entire relationship (2x fees paid or payable under “this agreement”)?
  • The look-back window — twelve months is standard, but twelve months from what: the claim date, the incident date, or the demand date? Each can produce a materially different number.

 

As a general matter, the vendor wants a lower, narrower cap and the customer wants a higher, broader one — typically because the vendor carries more of the performance risk, though that dynamic can flip depending on which side is more exposed in a given deal.

Layer 3: Carve-Outs and Exceptions — Where the Real Negotiation Happens

If the disclaimer and the standard cap were the whole story, limitation of liability clauses would be short and boring. They aren’t, because almost every contract carves certain claims back out of the disclaimer, the cap, or both. This is where the negotiation actually lives. The table below walks through the carve-outs that show up most often, the rationale behind each, and which side typically pushes for it.

Carve-Out

Rationale

Who Typically Pushes For It

Breach of confidentiality

Damages from leaked information are often unquantifiable and

reputational; the size of the harm has no relationship to the size of the deal

Customer (especially where sensitive data is involved)

Data breach / security incidents / privacy breach

Forensics, notification, credit monitoring, and regulatory fines can dwarf the value of the contract

Customer (especially where sensitive data is involved)

Vendor IP infringement / indemnification

Harm from a third-party infringement claim is unrelated to the size of the deal

Customer

Customer infringement / indemnification

Turns on whether the customer had consents to share certain data; harm is unrelated to the size of the deal

Vendor

Breach of payment obligations

Vendor wants unpaid fees fully recoverable, not subject to a cap

Vendor

Breach of use restrictions / license scope

Vendor wants overage or misuse fully recoverable

Vendor

Death / bodily injury / property damage

Most states prohibit capping this type of liability regardless of contract language

Both sides should expect this — if and when applicable, essentially non-negotiable

Violation of law / fraud

Parties cannot contract around statutory liability

Customer – and courts, in some states, by default

Gross negligence / willful misconduct

Public policy in many states won’t allow capping intentional or reckless conduct

Customer – and courts, in some states, by default

Which bucket a carve-out lands in — subject to a super cap, or fully uncapped — is usually the real fight, not whether the carve-out exists in the first place.

Layer 4: The Super Cap

A super cap is a second, higher ceiling that applies to the carved-out claims instead of leaving them fully uncapped. It’s usually the negotiated middle ground: the vendor doesn’t want unlimited exposure on confidentiality or data-breach claims, and the customer doesn’t want those claims subject to the (often low) standard cap.

Sizing varies — a fixed dollar amount (say, $1 million) or a higher multiple of fees (often three to five times) — and the structure varies too:

  • A single super cap applying to all “enhanced” carve-outs.
  • A tiered system: standard cap, then super cap, then fully uncapped for the truly non-negotiable items (death/bodily injury, fraud).
  • An insurance-linked super cap, where the cap equals available insurance proceeds — increasingly common for data breach. If using this structure, define “available insurance” precisely: per-occurrence limit or aggregate, and whether excess or umbrella coverage counts. A vague insurance tie-in creates more disputes than it resolves.

 

Vendor-side strategy typically pushes for a super cap on data breach and confidentiality claims rather than full inclusion in the standard cap — that’s usually the realistic ask, not uncapped exposure.

Customer-side strategy typically pushes for a high super cap on those same categories, since fully uncapped liability may not be realistic to obtain.

Where It All Interacts: Mutuality and Indemnification

The four layers above rarely get negotiated in isolation, and a few cross-cutting questions determine whether they actually work together as drafted:

  • Is the cap mutual, and do the same obligations and carve-outs apply to both parties? Should they, based on roles and responsibilities?
  • Do the carve-outs pull a claim out of the disclaimer of consequential damages as well as the cap, or only the cap? This matters more than it looks — for something like a data breach, much of the real harm is indirect. A carve-out that only lifts the dollar cap but leaves the consequential-damages disclaimer in place may be far narrower than either side intended.
  • Does the cap apply to indemnity payouts at all? Vendors typically want indemnity obligations subject to the cap (or a small super cap); customers typically want indemnity — especially for IP infringement and confidentiality or data-breach claims — fully carved out and uncapped, or subject to a generous super cap.

 

Indemnity and limitation on lability clauses work very closely together.

Watch closely for circular or conflicting cross-references between the indemnification section and the limitation of liability section — a common drafting trap when the two sections are negotiated by different people or imported from different templates. It’s easy to end up with an IP infringement indemnity that’s uncapped in one section while the limitation of liability section super-caps IP claims (or vice versa). The same problem shows up with data-breach indemnity.

A related but distinct drafting point: an exclusion and a cap are different mechanisms, and conflating them is a common and costly error. An exclusion removes an entire category of damages regardless of amount; a cap limits the dollar amount of whatever damages survive. A clause that treats these as interchangeable can leave a gap neither side intended.

These clauses can be logically confusing because of double and triple negatives, and exceptions to exceptions. A typical provision may be capped (first negative), but then certain things are excluded from the cap (a double negative – now they’re potentially uncapped), but some things may be excluded from that exclusion (subject to a different super cap; triple negative – the uncapped become capped again). 

Personally, I like to look at the indemnity and limitation on liability clauses as one of the first things I do, before reading the totality of the agreement from top to bottom.

The very first thing I do is to verify pricing and scope and nature of work for context – is this a big deal or small, critical or nice to have, is there sensitive data involved and what other contextual risks should I be concerned about. But LoL clauses are right behind that.

Finally, look beyond the four corners of the agreement being negotiated. A related document — a data processing addendum, for example — may carry its own uncapped liability provision that conflicts with the cap in the master agreement. Carve-out mapping should extend to the whole family of documents, not just one agreement.

A Quick Drafting Checklist

  • Consider your role (or your client’s role) and any unusual risk factors, such as sensitive data. Your position on many points will depend on this.
  • Consider whether mutuality should apply (and confirm whether it does).
  • Confirm both mechanisms are present: the disclaimer of consequential damages and the standard cap.
  • Check the size and scope of the standard cap
  • Check the carve-out list against the standard set and flag anything unusual.
  • Determine whether there is (or should be) a super cap, and how large it is.
  • Map every carve-out to its bucket: standard cap, super cap, or uncapped.
  • Cross-check the carve-outs against the indemnification section — and any related agreements, like a DPA — for consistency.

 

The Bottom Line

This is a popular topic. For more reading on this, see also my article on capped or uncapped indemnity obligations

A limitation of liability clause is not boilerplate, and it doesn’t deserve to be treated as the provision to trade away just to close out the negotiation. It is, in a very real sense, the provision that decides what the rest of the contract is worth if things go wrong. A few extra hours spent mapping every carve-out to its bucket and cross-checking the cap against the indemnification section is far cheaper than discovering the gap after a dispute has already arisen.


[1] Courts are split on whether lost profits are always “consequential” or whether they can be direct damages depending on how closely they flow from the breach. This is jurisdiction-dependent and fact-specific — worth flagging to a client as a real risk, but not worth overstating as settled law in either direction. If lost profits are a realistic possibility in a given deal, don’t assume the standard exclusion list resolves the question; it may not

https://www.linkedin.com/pulse/limitation-liability-clauses-fine-print-decides-what-dispute-heller-obbse/?trackingId=coaMuqw7SyGqOGOeQEu1CA%3D%3D

Photo of Brian Heller Brian Heller

I’m Brian Heller, a corporate (contracts) lawyer at Outside GC (a virtual business law firm). I specialize in technology transactions (SaaS, Digital Media Advertising, IT Agreements, Marketing Deals, etc.). Located in Northern Virginia, but I practice nationwide. Outside GC is a mid-size law…

I’m Brian Heller, a corporate (contracts) lawyer at Outside GC (a virtual business law firm). I specialize in technology transactions (SaaS, Digital Media Advertising, IT Agreements, Marketing Deals, etc.). Located in Northern Virginia, but I practice nationwide. Outside GC is a mid-size law firm with lots of practice areas, but we’re virtual (low overhead makes us cost effective) & all our lawyers have in-house GC or business experience.

Industry agnostic, but lots of experience in contracts and law relating to tech, digital media, advertising, entertainment, social media, marketing.

Blog “Contract Law Tips & Checklists”: https://www.linkedin.com/newsletters/7199518572912476160/

#Attorney #Law