Summary. Two clauses decide what a contract is actually worth when something goes wrong: the indemnity and the limitation of liability. Everything else describes the deal; these two describe the consequences of the deal failing. This article covers both from the ground up: what an indemnity actually does, the difference between third-party indemnification and the first-party indemnity many drafters intend but fail to create, the duty to defend and why it is separate from and often broader than the duty to indemnify, and the procedural terms that determine whether an indemnity is usable. It then covers limitations of liability: the direct-versus-consequential distinction after Hadley v. Baxendale, cap structures including super caps and unlimited categories, the standard carve-outs, the failure of essential purpose problem under UCC § 2-719, and state law limits on exculpation. A long section covers the indemnities that matter most in technology transactions: IP infringement, data protection, and open source. It closes with drafting language, a negotiation playbook, a worked example, an FAQ, and related reading.
Every contract negotiation eventually reaches the same two paragraphs, usually late, usually with a deadline, usually handled by whoever has the least leverage and the most fatigue. One party wants unlimited liability for everything; the other wants liability capped at last month's invoice. They compromise on twelve months of fees, exchange a few carve-outs, and sign.
Two years later, a customer's data is exfiltrated through the vendor's system. There is a $4 million notification bill, a regulatory investigation, and a class action. Everyone goes back and reads the two paragraphs, and one of them discovers that the compromise they accepted at 11 p.m. on a Thursday allocated the entire loss to them.
These clauses are not boilerplate. They are the deal.
The short answer
Indemnification is a promise to make another party whole for specified losses. In its classic form it addresses third-party claims: if someone sues you because of something I did, I will defend you and pay the result.
Limitation of liability caps and excludes what either party can recover from the other, and it typically applies to all claims, including indemnity obligations, unless the drafting says otherwise.
They interact, and the interaction is where most drafting errors live. An indemnity that sits under a cap of twelve months of fees is worth twelve months of fees. If you meant it to be worth more, you must say so.
The three questions to ask about any risk allocation package:
- What losses are covered? Third-party claims only, or direct losses too? Which categories?
- How much? What is the cap, what sits above it, and what is unlimited?
- Who pays first? Is there a duty to defend, and is there insurance behind the promise?
Part I: Indemnification
What it is, and what it usually is not
An indemnity is a contractual shifting of loss. It is not the same as a breach of contract claim; it can cover losses arising without any breach, and it typically has its own procedures, its own notice requirements, and its own remedies.
Third-party indemnity is the classic form and the default reading. "Supplier shall indemnify Customer against any third-party claim alleging that the Services infringe a patent."
First-party indemnity (sometimes called direct indemnity) covers losses one party suffers directly at the hands of the other, without any third-party claim. "Supplier shall indemnify Customer for any losses arising from Supplier's breach of Section 7."
The trap: courts often construe indemnity clauses as limited to third-party claims unless the language unmistakably provides otherwise. The leading statement is Hooper Associates, Ltd. v. AGS Computers, Inc., 74 N.Y.2d 487 (1989), which held that an indemnity clause will not be read to cover attorney's fees between the contracting parties in a suit against each other "unless the intention to do so is unmistakably clear from the language of the promise."
Drafting fix: if you want first-party coverage, say "whether or not involving a third-party claim," and define Losses to include the party's own direct losses and its fees in enforcing the agreement.
The duty to defend
This is the most valuable and most misunderstood part of an indemnity.
- The duty to indemnify arises when liability is established.
- The duty to defend arises when a covered claim is asserted, and is typically triggered by allegations rather than by proven facts.
A duty to defend is broader, earlier, and often more valuable than the indemnity itself, because litigation costs are certain while liability is not. It also determines cash flow: an indemnitor that must defend pays counsel as the case proceeds; one that must only indemnify may pay years later, if ever.
Draft the mechanics explicitly:
- Trigger: "assert, defend, and pay" versus "reimburse reasonable costs of defense."
- Control of the defense: who selects counsel, who directs strategy.
- Settlement: the indemnitor may not settle in a way that imposes non-monetary obligations, admits fault, or fails to fully release the indemnitee, without consent.
- Cooperation: the indemnitee must cooperate, at the indemnitor's expense.
- Notice: prompt written notice, with a proviso that failure to give notice relieves the indemnitor only to the extent of actual prejudice. Without that proviso, a late notice can void the entire indemnity.
- Independent counsel: where a conflict exists (the indemnitor's interests diverge, or the claim includes uncovered theories), the indemnitee may select its own counsel at the indemnitor's expense.
Indemnifying against your own negligence
Many indemnities purport to cover losses arising even from the indemnitee's own negligence. States apply special rules:
- Some require an express negligence statement in conspicuous language. Ethyl Corp. v. Daniel Construction Co., 725 S.W.2d 705 (Tex. 1987), is the canonical formulation: the intent to indemnify against the indemnitee's own negligence must be "specifically stated within the four corners of the contract."
- Anti-indemnity statutes in most states void or limit such clauses in construction contracts, and some states extend them to oil and gas, motor carrier, or design professional agreements. California's Civil Code § 2782 is a leading example. Check the statute of the governing state before drafting a broad-form construction indemnity.
- Some states apply a conspicuousness requirement.
Procedural terms that determine whether an indemnity is usable
Beyond the substantive scope, the terms that decide real-world outcomes:
- Definition of Losses: damages, liabilities, judgments, settlements, fines and penalties (are regulatory fines included? often excluded, and often the largest number), reasonable attorney's fees, and costs of investigation and remediation.
- Mitigation duty on the indemnitee.
- Net of insurance and tax benefits, or not.
- Exclusive remedy language, which can be very valuable to the indemnitor.
- Survival period, which may differ from the general survival clause.
- Baskets and deductibles (common in M&A, less so in commercial agreements).
- Interaction with the liability cap, which must be stated expressly.
Part II: Limitation of liability
The two components
Almost every limitation of liability clause has two independent parts, and they are frequently confused:
1. The exclusion of damage types. Typically: "Neither party shall be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, loss of goodwill, or business interruption."
2. The cap on direct damages. Typically: "Each party's total aggregate liability shall not exceed the fees paid or payable in the twelve months preceding the claim."
Both must be negotiated. A generous cap is worth little if everything you would actually lose is excluded as consequential.
Direct versus consequential: the Hadley problem
Hadley v. Baxendale, 156 Eng. Rep. 145 (Ex. 1854), remains the framework. Recoverable damages are those arising naturally from the breach (general or direct damages) or those that were in the contemplation of both parties at the time of contracting as the probable result of breach (special or consequential damages). Restatement (Second) of Contracts § 351 codifies the modern version, adding that damages are not recoverable if the party in breach did not have reason to foresee them.
The trouble is that the labels are not self-applying. Lost profits, the most-litigated category, can be direct damages where the profits are the very thing bargained for (a distributor's margin on goods the supplier failed to deliver) and consequential where they arise from collateral arrangements (profits the buyer would have made on a downstream contract the seller never knew about).
Courts split on this constantly, and the same loss can be characterized either way depending on the deal structure.
Drafting fix: do not rely on the labels. Enumerate. "For the avoidance of doubt, the following are excluded regardless of characterization: lost profits, lost revenue, lost business opportunity, and cost of substitute services." Or, from the other side: "For the avoidance of doubt, Customer's cost of procuring substitute services and the fees paid for non-conforming Services are direct damages."
Cap structures
Single cap. One number for everything. Simplest, and increasingly rare in enterprise deals.
Tiered caps (super caps). A general cap (often 12 months of fees) plus a higher cap for enumerated categories:
- Data breach and privacy obligations: often 2x to 5x the general cap, or a fixed dollar amount, or tied to cyber insurance limits.
- IP infringement indemnity: often uncapped or at a high multiple.
- Confidentiality breach: commonly super-capped.
Uncapped categories. Typically:
- Indemnification obligations (or specified ones).
- Breach of confidentiality (contested).
- Gross negligence and willful misconduct.
- Fraud and fraudulent misrepresentation.
- Death or bodily injury and damage to tangible property caused by negligence.
- A party's payment obligations (fees owed).
- Violations of law, or specified violations.
- Misappropriation of intellectual property.
Cap metrics matter as much as multiples. "Fees paid in the twelve months preceding the claim" produces a very small number early in a contract and in low-fee, high-risk arrangements. Alternatives: fees paid over the entire term, total contract value, a fixed dollar amount, or the greater of a fixed floor and a fee-based figure. In a $50,000-per-year contract that touches a million customer records, a fee-based cap is not a serious risk allocation.
Carve-outs: the negotiation
The carve-out list is where most of the value is exchanged. Positions, roughly:
| Category | Customer position | Vendor position | Common landing |
|---|---|---|---|
| Fraud, willful misconduct | Uncapped | Uncapped | Uncapped |
| Gross negligence | Uncapped | Capped or excluded | Uncapped in the U.S.; heavily negotiated |
| Death, bodily injury, property damage | Uncapped | Uncapped | Uncapped |
| IP indemnity | Uncapped | Super cap | Super cap or uncapped with a settlement/replacement remedy |
| Data breach | Uncapped | Super cap tied to insurance | Super cap, often 2x to 5x |
| Confidentiality breach | Uncapped | Within cap | Super cap, with an uncapped carve-out for misuse of data |
| Payment obligations | Uncapped | Uncapped | Uncapped |
| Violation of law | Uncapped | Limited to specified laws | Specified laws (privacy, anti-corruption, export) |
One drafting point worth more than any of these: state expressly whether the exclusion of consequential damages applies to the carve-outs. An "uncapped" indemnity that is still subject to the consequential damages exclusion may recover far less than the parties intended, because the third party's claim against the indemnitee may itself consist largely of consequential-type losses. The standard fix is to provide that the exclusion does not apply to amounts payable to third parties under an indemnity.
Failure of essential purpose
UCC § 2-719(2) provides that "[w]here circumstances cause an exclusive or limited remedy to fail of its essential purpose, remedy may be had as provided in this Act."
The classic case: a contract limits the buyer's remedy to repair or replacement, and the seller cannot repair or replace. The limited remedy has failed.
The split: does that failure also invalidate a separate consequential damages exclusion?
- The majority (dependent) view in older cases treats the provisions as an integrated allocation, so failure of the limited remedy opens up consequential damages.
- The modern majority (independent) view treats them as separate provisions, so the consequential damages exclusion survives unless it is independently unconscionable.
Drafting fix: say which you intend. "The exclusion of consequential damages in Section 12.1 is independent of and shall survive any failure of essential purpose of any limited remedy."
Unconscionability and public policy limits
- UCC § 2-719(3): limitation of consequential damages for personal injury in the case of consumer goods is prima facie unconscionable; limitation where the loss is commercial is not.
- Exculpation for fraud is unenforceable essentially everywhere. In Delaware, Abry Partners V, L.P. v. F&W Acquisition LLC, 891 A.2d 1032 (Del. Ch. 2006), held that a contract cannot limit a party's liability for its own deliberate contractual fraud, though it may limit liability for a non-fraudulent misrepresentation and may bar reliance on extra-contractual statements. That decision is the reason nearly every acquisition agreement now contains a carefully negotiated fraud carve-out and an anti-reliance clause.
- Gross negligence and willful misconduct. New York holds that an exculpatory clause is unenforceable as against public policy where it purports to exempt a party from liability for "willful or grossly negligent acts." Kalisch-Jarcho, Inc. v. City of New York, 58 N.Y.2d 377 (1983). But New York courts have read "intentional wrongdoing" in a limitation (as opposed to complete exculpation) context more narrowly, requiring conduct that "smacks of intentional wrongdoing" or is done in bad faith to achieve a purpose unrelated to the contract. Metropolitan Life Insurance Co. v. Noble Lowndes International, Inc., 84 N.Y.2d 430 (1994). The distinction between an exculpatory clause and a mutually negotiated cap matters.
- California Civil Code § 1668 provides that contracts exempting anyone from responsibility for their own fraud, willful injury, or violation of law are against public policy.
- Public interest exculpation. Tunkl v. Regents of the University of California, 60 Cal. 2d 92 (1963), sets out factors for when an exculpatory clause affecting the public interest is invalid: a business suitable for public regulation, performing a service of practical necessity, holding itself out to the public, with decisive bargaining advantage, using a standardized adhesion contract, and placing the customer under the seller's control. Most commercial software contracts do not meet it; consumer contracts for essential services sometimes do.
Part III: The indemnities that matter in technology deals
Intellectual property infringement
The most common and most negotiated indemnity in software and services contracts.
Scope questions:
- Which rights? Patent, copyright, trade secret, trademark. Patent is the expensive one and the one vendors most often try to limit, sometimes to patents issued in specified countries.
- Which territories? Vendors commonly limit to the United States, the European Union, and a listed set. A customer operating globally should push back.
- Which claims? Claims that the deliverable "infringes," or claims "alleging" infringement (the latter is broader and better for the customer).
Standard exclusions (vendor-favorable, and mostly reasonable):
- Modification of the deliverable by the customer.
- Combination with items not supplied or approved by the vendor.
- Use outside the documented scope or in violation of the agreement.
- Continued use after notice of infringement and provision of a non-infringing alternative.
- Customer-supplied specifications, content, or data.
Watch the combination exclusion. Software is always combined with something. An exclusion for "combination with any hardware or software not provided by Vendor" swallows the indemnity entirely. Narrow it to combinations that are not contemplated by the documentation, or where the combination itself is the cause of the infringement.
The remedy ladder. Vendors typically reserve the right, at their option, to: (a) procure the right to continue using the deliverable, (b) modify or replace it with a functionally equivalent non-infringing alternative, or (c) terminate and refund. The customer's protections: functional equivalence must be real; the refund should be pro rata over a stated amortization period rather than the last month's fees; and termination should not be available until the vendor has genuinely attempted (a) and (b).
AI outputs. A newer and rapidly evolving category. Customers now demand indemnity for third-party IP claims arising from model output. Read carefully for: exclusions where the customer's prompt caused the output; requirements to use the vendor's filters and safety features; caps; and whether the indemnity covers only the model provider's own model or also third-party models accessed through the platform. See AI Governance and Compliance and Fair Use After Warhol.
Related warranties. UCC § 2-312(3) implies a warranty against infringement in sales of goods by a merchant regularly dealing in goods of the kind, subject to disclaimer. Services and licenses require an express warranty.
Data protection and security
The category that has moved the most in the last five years.
What the indemnity should cover: third-party claims arising from a security incident affecting data in the vendor's custody, and, ideally as first-party coverage, the customer's own costs: forensic investigation, legal fees, notification, call center, credit monitoring, and regulatory fines where insurable and lawful.
The hard negotiation is over first-party breach costs, which are the largest and most certain component and which vendors resist because they are not third-party claims. The market landing is usually a super cap covering enumerated response costs.
Regulatory fines are often excluded, and in some jurisdictions indemnifying a party for its own regulatory penalties is unenforceable. Where fines are covered, expect a separate sub-cap.
Insurance behind it. Require cyber liability coverage at a stated limit, with the customer as additional insured where appropriate, and a waiver of subrogation. An uncapped indemnity from a company with no assets and no insurance is a rhetorical device.
Interaction with the data processing addendum. The DPA usually contains its own liability provisions, and inconsistency between the DPA and the master agreement is a recurring source of disputes. Add an ordering-of-precedence clause and check that it says what you want. See State Consumer Privacy Laws.
Open source
Where the deliverable contains open source components, allocate the risk of license non-compliance:
- A warranty that the deliverable does not include software licensed under terms that would require disclosure of the customer's source code or grant of patent rights (the "copyleft" concern), except as disclosed.
- A bill of materials listing components and licenses, ideally in a machine-readable software bill of materials format.
- An indemnity covering claims arising from open source license non-compliance.
- Remediation obligations if non-compliant components are found.
See Open Source Software: Licenses, Compliance, and Risk and Open Source Licensing Landmines in Enterprise Software Development.
Insurance requirements
Insurance is the credit support for every indemnity. The standard package in a technology services agreement:
- Commercial general liability, typically $1 million per occurrence and $2 million aggregate, with the customer as additional insured for the vendor's acts.
- Technology errors and omissions / professional liability, which is the policy that actually responds to a defective-software claim, typically $2 million to $10 million depending on deal size.
- Cyber liability, which may be combined with tech E&O, covering breach response, network security liability, and privacy liability.
- Workers' compensation and employer's liability where personnel are on site.
- Umbrella/excess to reach the negotiated limits.
- Certificates of insurance delivered at signing and annually, with 30 days' notice of cancellation.
- Waiver of subrogation in favor of the customer.
- A statement that insurance does not limit the vendor's liability under the agreement.
Part IV: Drafting language
Below are neutral formulations you can adapt. They are illustrations, not a substitute for drafting for the specific deal and governing law.
Third-party indemnity with defense:
Vendor shall defend Customer and its officers, directors, employees, and agents against any third-party claim, suit, action, or proceeding alleging that the Services or Deliverables infringe or misappropriate any patent, copyright, trade secret, or trademark, and shall indemnify and hold harmless Customer from any damages, liabilities, penalties, settlement amounts, and reasonable attorneys' fees finally awarded or agreed in settlement of such claim. Customer shall give Vendor prompt written notice of the claim (provided that failure to give prompt notice shall relieve Vendor of its obligations only to the extent it is actually prejudiced thereby), reasonable cooperation at Vendor's expense, and sole control of the defense and settlement, except that Vendor may not enter into any settlement that imposes any liability or obligation on Customer, admits fault by Customer, or fails to unconditionally release Customer, without Customer's prior written consent.
First-party clarification:
The indemnification obligations in Section X apply whether or not the Losses arise from a third-party claim, and the term "Losses" includes Losses suffered directly by the indemnified party.
Limitation of liability with tiered caps:
Except for Excluded Claims, (a) neither party shall be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost data, or business interruption, however caused and under any theory of liability, even if advised of the possibility of such damages; and (b) each party's total aggregate liability arising out of or related to this Agreement shall not exceed the greater of (i) the fees paid or payable by Customer under this Agreement in the twelve (12) months preceding the event giving rise to the claim and (ii) $______.
"Excluded Claims" means (1) a party's indemnification obligations under Sections __; (2) Vendor's breach of Section __ (Confidentiality) or Section __ (Data Protection), for which each party's aggregate liability shall not exceed __ times the cap in subsection (b); (3) either party's fraud, gross negligence, or willful misconduct; (4) death or bodily injury or damage to tangible property caused by a party's negligence; and (5) Customer's obligation to pay fees. The limitations in subsection (a) shall not apply to amounts payable to a third party under a party's indemnification obligations.
Essential purpose:
The exclusions and limitations in Section __ are independent of, and shall apply notwithstanding, the failure of essential purpose of any limited remedy provided in this Agreement.
Insurance:
Vendor shall maintain, at its own expense and with insurers rated A- VII or better by AM Best, the following coverages: [list], naming Customer as an additional insured on the commercial general liability policy, with a waiver of subrogation in favor of Customer. Vendor shall provide certificates of insurance upon execution and annually thereafter and shall give Customer thirty (30) days' prior written notice of cancellation or material reduction. The maintenance of insurance does not limit Vendor's liability under this Agreement.
Part V: The negotiation playbook
Prepare before you negotiate. Know, for this deal:
- The realistic worst-case loss scenario and its rough magnitude.
- The contract value, so you can evaluate whether a fee-based cap is meaningful.
- Your own insurance coverage and limits.
- The counterparty's likely insurance.
- Whether this is a template you will use a thousand times or a one-off.
Positions worth spending capital on (customer side):
- A cap metric that is not "last twelve months of fees" in a low-fee, high-risk deal.
- Data breach super cap with first-party response costs covered.
- IP indemnity with a narrow combination exclusion and a real remedy ladder.
- Confirmation that the consequential damages exclusion does not apply to third-party indemnity payments.
- Insurance requirements with limits that make the caps real.
Positions worth spending capital on (vendor side):
- A cap that bears some relationship to the revenue from the deal.
- Mutual application of the exclusions and the cap.
- Exclusive-remedy language for the IP indemnity.
- Exclusions for customer-caused issues (modifications, misuse, customer data and content).
- A carve-out for the customer's indemnity of the vendor for customer content and customer's use.
Things to stop arguing about. Fraud, willful misconduct, death and bodily injury, and payment obligations are uncapped in essentially every negotiated agreement. Time spent there is time not spent on the cap metric.
Escalation ladder. If you cannot agree on a number, try: a higher cap with a longer look-back; a fixed floor plus a fee multiple; a super cap for the specific category driving the concern; an insurance requirement in lieu of a higher cap; or a shorter contract term with renegotiation.
A worked example
Larkspur Health Networks (fictional), a hospital system, engages Tessellate Software, Inc. (fictional) to provide a scheduling platform for $120,000 per year. The platform will hold patient names, contact information, appointment types, and provider notes. Tessellate's standard terms cap liability at fees paid in the prior twelve months and exclude all consequential damages.
The mismatch. Tessellate's maximum exposure under its template is $120,000. Larkspur's exposure in a breach affecting 400,000 patient records is orders of magnitude higher: notification, credit monitoring, regulatory investigation under HIPAA, state attorneys general, and class litigation. See HIPAA, Business Associates, and Cloud Computing.
What Larkspur should insist on:
- Business associate agreement with HIPAA-required terms, and a precedence clause making it control over inconsistent provisions.
- Data breach super cap of, say, $5 million or the limit of Tessellate's cyber policy, whichever is greater, explicitly covering Larkspur's first-party response costs: forensics, legal, notification, call center, and credit monitoring.
- Consequential damages carve-back so that the exclusion does not bar recovery of enumerated breach response costs, which a court might otherwise call consequential.
- Cyber insurance at $10 million, with certificate delivery, Larkspur as additional insured where the policy permits, and waiver of subrogation.
- Security obligations with specificity (encryption at rest and in transit, access controls, penetration testing cadence, subprocessor approval, incident notification within 24 hours) rather than "commercially reasonable security."
- IP indemnity with a narrow combination exclusion, given that the platform will integrate with Larkspur's electronic health record.
- Termination and transition assistance with data export in a usable format.
What Tessellate can reasonably hold:
- The general cap at 12 months of fees for ordinary performance claims.
- Exclusion of consequential damages for non-breach claims.
- Exclusions for Larkspur's own misconfiguration, Larkspur-supplied content, and use outside documentation.
- A commercially reasonable sub-cap on regulatory fines, if covered at all.
- Mutuality throughout.
The likely landing. A $120,000 contract with a $5 million breach super cap backed by insurance. That looks lopsided until you notice that the risk is lopsided: Tessellate controls the security of a system holding 400,000 patient records, and no amount of contract drafting changes who can prevent the loss. Risk should sit with the party that controls it, and price should reflect that. If Tessellate cannot accept the allocation, Larkspur has learned something important about Tessellate's security posture.
Frequently asked questions
What is the difference between "indemnify," "defend," and "hold harmless"? "Indemnify" is the promise to pay covered losses. "Defend" is the separate, usually broader and earlier obligation to provide and fund a defense. "Hold harmless" is often treated as synonymous with indemnify, though some courts read it as a broader promise to protect against liability. Because the terms are read differently in different states, spell out the obligations rather than relying on the words.
Are liability caps enforceable? Between sophisticated commercial parties, generally yes. Limits arise for fraud, willful misconduct, gross negligence in many states, personal injury in consumer transactions, and public-interest services under doctrines like Tunkl. Statutes also restrict them in construction and some regulated sectors.
What is a reasonable cap? There is no universal answer, but the market conventions are: 12 months of fees as a general cap in SaaS, higher multiples for data and confidentiality, and uncapped for the standard categories. The better question is whether the cap bears a relationship to the plausible loss. If it does not, the cap metric is wrong.
Should indemnities be inside or outside the cap? Depends on which side you are on and which indemnity. IP indemnity is commonly outside or super-capped. Data breach is commonly super-capped. Whatever you decide, say it expressly; silence produces litigation.
Do we need a mutual indemnity? Usually. Customers indemnify vendors for customer content, customer data, and use outside the agreement. Vendors indemnify for IP and security. Mutuality also makes the clause easier to sell internally on both sides.
What if the other side has no insurance? Then the indemnity is worth what the counterparty is worth. Insurance requirements are how you convert a promise into a payable claim. Ask for certificates before signing, not after a loss.
Does an indemnity cover our own attorney's fees in a dispute with the indemnitor? Only if the drafting is unmistakably clear that it covers first-party claims and fees between the parties. Hooper Associates. Most standard clauses do not.
Can we indemnify against regulatory fines? Sometimes, and in some jurisdictions and for some penalties, no. Where covered, expect a sub-cap and a carve-out for fines resulting from the indemnitee's own conduct.
What happens if the limited remedy fails? UCC § 2-719(2) provides a remedy, and courts split on whether a separate consequential damages exclusion survives. Address it expressly with an independence clause.
How do these clauses interact with insurance we buy? Closely. Indemnity obligations may or may not be covered by your own liability policies (contractual liability exclusions and "insured contract" definitions matter). Have your broker review the indemnity language in significant agreements. It costs nothing and occasionally reveals that you have assumed an uninsurable obligation.
Closing thought
The most useful reframing I know for these clauses is this: an indemnity is a credit decision, and a liability cap is a pricing decision.
An indemnity is worth the counterparty's ability to pay, which means the analysis includes their balance sheet and their insurance, not just their promise. A cap is a statement about how much risk the price supports, which means the right response to an unacceptable cap is often a conversation about price rather than a conversation about drafting.
Approached that way, the negotiation gets shorter and more honest. The vendor that cannot accept meaningful data breach exposure at $120,000 a year may be able to at $180,000, or may be telling you it does not have the security program to support the deal. Both of those are useful things to learn before signing, and neither is discoverable by trading redlines on the word "consequential" for three weeks.
Related articles
- Software Licensing Agreements: An Overview — where these clauses sit in a license.
- Drafting Software License Agreements — the surrounding terms.
- Software License Agreement Review Checklist — a review workflow.
- Open Source Software: Licenses, Compliance, and Risk — the open source indemnity problem.
- AI Governance and Compliance — AI vendor indemnities and output risk.
- State Consumer Privacy Laws — data processing addenda and their liability terms.
- HIPAA, Business Associates, and Cloud Computing — sector-specific allocation.
- Website Terms of Service and Online Contract Formation — limitations in consumer-facing terms.
- Trademark Licensing and Quality Control — product liability allocation in licensing.
- IP Transactions and Agreements Toolkit — the transactional workflow.
This article is provided for general informational purposes and does not constitute legal advice. The enforceability of indemnity and limitation of liability provisions varies substantially by governing law and by industry-specific statutes. Sample language is illustrative only. Consult qualified counsel about any particular agreement.