Skip to main content

Limitation of Liability

Liability Cap · Limitation Clause · LoL Clause

A Limitation of Liability clause caps the maximum monetary exposure one party faces for losses caused to the other under a contract. It typically combines a total damages ceiling — often 12 months of fees paid — with a blanket exclusion of indirect or consequential damages such as lost profits, loss of data, and business interruption.

What a limitation of liability clause actually does

The clause works on two axes at once. First, it sets a ceiling on the total damages either party can recover — most commonly 12 months of fees paid under the contract, sometimes a fixed dollar amount, occasionally an uncapped figure for enterprise deals. Second, it excludes whole categories of loss entirely: indirect damages, consequential damages, loss of profits, loss of goodwill, loss of data, business interruption. On top of both mechanics sit the carve-outs — obligations the cap does NOT apply to, typically IP infringement indemnity, confidentiality breach, gross negligence, willful misconduct, payment obligations, and data-breach liability. Those carve-outs are where most of the negotiation happens.

Why it matters

Liability caps control the asymmetry between contract value and potential loss. A $50,000 SaaS contract whose failure costs the customer $5 million in downstream losses is the classic mismatch — the cap prevents liability from dwarfing deal value, but it also means the customer bears the remaining risk. Getting the cap wrong in either direction is painful: too low and customers have no real remedy, too permissive and vendors sign contracts that can bankrupt them. This is where commercial and legal teams must align on risk appetite before signature, not after.

Common pitfalls

  • 1.Cap too low relative to potential harm — 3 months of fees on a mission-critical service does not come close to covering a real outage or data loss.
  • 2.No carve-outs for gross negligence or willful misconduct — lets bad actors hide behind the cap for conduct that should never be shielded.
  • 3.A mutual cap applying the same ceiling to both sides — often inappropriate when only one party holds the data, IP, or operational risk.
  • 4.Excluded damages drafted so broadly that every meaningful remedy is swept away — a blanket "consequential damages" exclusion can eliminate the losses that actually matter.
  • 5.Ambiguous cap resets or rollovers — vague drafting creates disputes about which 12-month window counts and whether breaches aggregate or reset.

Frequently asked questions

What is a typical liability cap?
Most SaaS and services contracts cap liability at 12 months of fees paid under the agreement. Enterprise and regulated contexts often negotiate higher multiples — 2× or 3× annual fees — or uncapped liability for specific breach categories such as data protection, confidentiality, or IP indemnity. The right number depends on deal size versus the downside risk the service creates.
What are super-cap carve-outs?
Super-cap carve-outs are obligations that sit outside the general liability cap, meaning damages for those breaches are either uncapped or subject to a much higher ceiling. Standard super-caps cover IP infringement indemnity, breach of confidentiality, willful misconduct, gross negligence, payment obligations, and data-breach liability. They are the single most negotiated part of any limitation clause.
Can the liability cap be negotiated?
Yes — particularly on material contracts. The usual levers are raising the cap multiple (12 months to 24 or 36), adding carve-outs for data-protection and confidentiality breaches, narrowing the definition of excluded indirect damages, and ensuring the cap applies per cause of action rather than in aggregate. Vendors push back hardest on uncapped data-breach liability.

Review liability clauses with Attorly

Upload any commercial contract and get a per-clause breakdown of the cap, excluded damages, carve-outs, and how the terms compare to market — in under 60 seconds.

Analyse the contract