Limitation of Liability in Technology Contracts: A Practical Guide

Published July 1, 2026 · Attyflow Blog

Limitation of Liability in Technology Contracts: A Practical Guide

In every technology transaction, the limitation of liability clause is arguably the most negotiated provision. It determines the financial exposure each party bears if a deal goes wrong. For technology companies—whether SaaS providers, systems integrators, or hardware vendors—a poorly drafted limitation can turn a routine contract into existential risk. This guide offers a practical, US common law perspective on drafting and negotiating these clauses in technology contracts, with concrete examples.

Why Limitation of Liability Matters in Tech Deals

Technology contracts involve complex interdependencies. A software bug, data breach, or service outage can cascade into consequential losses—lost profits, reputational harm, or third-party claims. Without a limitation clause, a provider could face damages far exceeding the contract value. Conversely, customers need assurance that gross negligence or willful misconduct won't be shielded. The balance lies in a clause that is enforceable, clear, and tailored to the specific risk profile of the transaction.

Key Components of a Tech-Friendly Limitation Clause

Under US common law, limitation of liability clauses are generally enforceable if they are conspicuous, unambiguous, and not unconscionable. For technology contracts, focus on three structural elements:

1. The Liability Cap

Most tech contracts cap liability at the total fees paid (or a multiple thereof) over a defined period. For example: "Neither party's aggregate liability arising out of or related to this Agreement shall exceed the total fees paid by Customer to Provider during the twelve (12) months preceding the claim." In a SaaS subscription, this often means the cap resets annually. For a one-time implementation project, a fixed multiple (e.g., 1.5x or 2x contract value) may be more appropriate.

2. Exclusions from the Cap

Certain risks are too severe to cap. Standard exclusions include: (i) death or personal injury; (ii) fraud or willful misconduct; (iii) breach of confidentiality or data protection obligations; and (iv) indemnification obligations for third-party IP claims. In tech deals, data breach liability is increasingly carved out, especially under state data breach notification laws and evolving common law duties.

3. The Consequential Damages Waiver

This is the cornerstone of tech risk allocation. A mutual waiver of consequential damages prevents either side from recovering indirect losses like lost profits, loss of data, or business interruption. However, courts construe "consequential" narrowly. To avoid ambiguity, define the term explicitly. Example: "'Consequential Damages' include, without limitation, lost profits, loss of use, loss of data, and cost of cover." Some courts—like those in New York—enforce clear waivers strictly, while others (e.g., California) may scrutinize them for unconscionability.

Practical Examples and Pitfalls

Example 1: The Software Bug That Took Down a Retailer
A POS software provider's update caused a 48-hour outage during the holiday season. The retailer lost $500,000 in sales. The contract capped liability at $50,000 (the annual subscription fee) and included a mutual waiver of consequential damages. The court enforced the clause, finding the waiver unambiguous and the cap not unconscionable given the low subscription price. Key takeaway: A low cap can be enforceable if the bargain is clear.

Example 2: The Data Breach at a Cloud Provider
A healthcare SaaS provider suffered a breach exposing protected health information. The contract capped liability at six months of fees ($30,000) but excluded breaches of confidentiality. The court held that the data breach fell under the confidentiality exclusion, and the cap did not apply. The provider faced $2 million in settlement costs. Key takeaway: Exclusions for data security are critical; otherwise, a cap may become meaningless for high-risk data.

Example 3: The Integration Failure
A systems integrator guaranteed a custom API would function with the client's legacy ERP. It failed, costing the client $200,000 in lost productivity. The contract had no cap but included a carve-out for "gross negligence." The integrator argued the failure was simple negligence. The court agreed, and the client recovered only direct damages. Key takeaway: Define "gross negligence" specifically if it is an exclusion to the cap.

Negotiation Strategies for Tech Lawyers

  • For Providers: Anchor the cap to fees paid. Resist uncapped liability for service level failures. If the customer demands uncapped data breach liability, propose a separate, higher sub-cap (e.g., $1 million) with a mutual carve-out.
  • For Customers: Push for a multiple of fees (e.g., 2x or 3x) rather than fees alone. Carve out indemnities for third-party IP claims. If the provider insists on a consequential damages waiver, negotiate a "savings clause" that allows recovery if the cap is triggered by the provider's gross negligence.
  • Common Ground: Agree on a clear definition of "consequential damages." Include a list of excluded items (e.g., lost profits, loss of data) to avoid litigation over interpretation. Use a "most favored nation" provision if the contract covers multiple services with different risk profiles.

Enforceability Trends Under US Common Law

US courts generally respect limitation clauses in commercial contracts between sophisticated parties. However, watch for these traps:

  • Unconscionability: A cap that is one-sided or shockingly low (e.g., $100 on a $1 million contract) may be struck down, especially if the customer had no bargaining power.
  • Public Policy: Some states (e.g., Louisiana) limit waivers of liability for certain torts. In tech, data privacy statutes may override contractual caps.
  • Ambiguity: If the clause is vague—e.g., "liability shall be limited to the fees paid"—courts may interpret it narrowly against the drafter. Always specify the time period for the fee calculation.

Drafting Tip: In multi-year agreements, include an "escalator" clause that adjusts the cap annually based on fee changes. For example: "The liability cap for any claim arising in Year 2 shall equal the total fees paid in the preceding 12 months." This avoids disputes over which year's fees apply.

Final Checklist for Your Next Tech Contract

  • Is the limitation clause in bold or all-caps to satisfy "conspicuousness" requirements?
  • Does it explicitly exclude consequential damages with a clear definition?
  • Are the exclusions from the cap (e.g., data breach, IP indemnity) tailored to the specific services?
  • Is the cap tied to fees paid, and is the measurement period unambiguous?
  • Have you considered state-specific law (e.g., California's anti-waiver rules for indemnity)?

A well-crafted limitation of liability clause is not a boilerplate afterthought—it is a risk allocation tool that protects both sides. By focusing on clarity, proportionality, and real-world scenarios, technology lawyers can turn this provision from a source of friction into a foundation of trust. Use this guide as a starting point, but always tailor the clause to the unique facts of each transaction.

Audit your next contract in under 15 seconds

Paste any clause into Attyflow. Get a risk score, legal analysis, and a bulletproof redline — instantly.

Request Sandbox Access