Limitation of Liability Clause Explained: How Contract Caps Really Work

A contract is mostly a record of what both sides hope will happen. The limitation of liability clause is different. It’s the part that deals with what happens after somebody makes a mistake, and specifically how much money the other side can recover for it.

For a long time I skimmed right past these clauses. That changed when I started reading software agreements closely and kept running into the same setup, where the vendor’s liability topped out at whatever the customer had paid in the last twelve months. On a tool that costs $300 a month, that works out to $3,600. If the tool ever exposed your customer list, that amount would barely make a dent in the cost of dealing with it.

That gap is why this clause matters, and why it gets negotiated so hard. Below I’ll walk through how these clauses are built, where the hidden exceptions usually sit, and what I’d check before signing one.

Nothing here is legal advice. Contract law differs from state to state, so if serious money is on the line, get an attorney to review the actual agreement.

limitation of liability clause

What a Limitation of Liability Clause Does

At its core, the clause limits what one party can be forced to pay the other if something goes wrong under the contract. It usually does that in two ways. First, it puts a ceiling on the total dollar amount. Second, it rules out certain kinds of damages altogether, with lost profits being the most common one to go.

Vendors want these limits for an understandable reason. Say a company charges a small business $500 a month for scheduling software, and a bug knocks the system offline for a week. The customer might lose more in missed bookings than it ever paid for the software. Without a cap, the vendor could be on the hook for losses far bigger than anything it earned from that customer. Spread that risk across thousands of accounts, and it’s easy to see why no vendor wants to sign without one. Customers have the opposite worry. A cap that’s too low can leave you absorbing the cost of problems you didn’t cause.

The Cap

The cap sets the most one side can ever be made to pay. In the software and service contracts I’ve read, it’s usually pegged to whatever the customer paid during the twelve months before the claim came up. Contracts with more risk attached might set it at two or three times the annual fees instead. Some just name a flat dollar amount, and others say the cap is “the greater of” the fees paid or a fixed minimum, which keeps a brand-new customer from ending up with a cap close to zero.

Also check whether the cap is aggregate or per claim, because the difference matters more than the wording suggests. With an aggregate cap, every claim over the whole life of the contract draws from the same pool, so a single serious incident could use up all of it. A per-claim cap applies fresh to each separate problem. If you have the bad luck of running into more than one issue with the same vendor, you’ll be glad you had the second kind.

The Damages Exclusion

The second piece knocks entire categories of loss off the table. Making sense of it requires one distinction lawyers care a lot about.

Direct damages are the losses that follow naturally from the breach itself. If a vendor never delivers a service you paid for and you have to hire someone else, that extra cost is usually direct. Consequential damages are the knock-on effects: lost profits, deals that fell through, a hit to your reputation, or claims from your own customers.

It’s common for business contracts to rule out consequential damages entirely, and incidental, special, and punitive damages often get excluded in the same sentence. Between two businesses, courts usually go along with that. When the contract is for a sale of goods, the Uniform Commercial Code’s rule on <a href=”https://www.law.cornell.edu/ucc/2/2-719″>limiting contract remedies</a> allows the parties to exclude consequential damages as long as the result isn’t unconscionable.

I assumed lost profits would always count as consequential, but that isn’t how every court sees it. When earning a particular profit was the main reason the contract existed, some judges have treated those profits as direct damages instead. That’s why carefully drafted contracts define exactly which losses are excluded, rather than leaving it to a court to sort out after a dispute.

Carve-Outs

I read the carve-outs more slowly than any other part of the clause. They’re the exceptions, meaning claims that the cap or the damages exclusion doesn’t apply to, and sometimes neither one does.

Almost every list includes fraud, gross negligence, and willful misconduct. Part of the reason is that many states wouldn’t let a company limit its liability for deliberate or reckless conduct even if the contract tried. Bodily injury and property damage are usually on the list too. Technology contracts tend to add breaches of confidentiality, data breaches, intellectual property infringement, and indemnification obligations. Vendors frequently throw in the customer’s unpaid fees as well, which is fair enough from where they sit.

A carve-out doesn’t always leave liability wide open. More and more contracts use a super cap, a separate and higher limit that applies only to certain risks, with data breaches being the most common. The customer gets more coverage for the problems most likely to be expensive, and the vendor still knows the most it could ever owe.

Why Data Breaches Deserve Extra Attention

Anyone who hands customer information to a vendor should spend extra time on this part of the contract. According to IBM’s annual <a href=”https://www.ibm.com/reports/data-breach”>data breach cost research</a>, the average breach in 2025 cost $4.44 million worldwide, and more than $10 million for companies based in the United States. Compare that with a cap equal to one year of fees on a typical software subscription, which might be a few thousand dollars, or maybe tens of thousands for a larger plan. Even a generous cap would cover only a small slice of a breach that size.

That’s why I think businesses should look closely at how liability is handled in any data processing agreement they sign. A vendor can promise excellent security in the DPA, but if the main contract caps its liability at a few thousand dollars, you’ll have a hard time recovering much after a breach.

How It Connects to Indemnification

These two clauses are easy to confuse and even easier to read in isolation, which is a mistake. Indemnification is a promise to cover specific losses, usually from lawsuits brought by outsiders. Limitation of liability restricts total exposure. The question that matters is whether the indemnity sits under the cap or outside it.

Suppose a vendor agrees to cover you if its software infringes someone’s patent. That sounds great. But if the promise is subject to a cap of one year’s fees, and the patent suit costs ten times that, you’ll be paying the difference. I went into more detail on how these promises work in my piece on the indemnification clause.

There’s a sneakier problem too. A broad waiver of consequential damages can hollow out an indemnity without anyone noticing. If most of what you’d be indemnified for counts as lost profits or other indirect losses, and the contract waives those for every type of claim, your indemnification right might not be worth much.

Mutual Isn’t Always Balanced

A mutual clause applies the same limits to both parties. A one-sided clause protects only one of them, typically whoever had more leverage when the contract was drafted.

Mutual sounds fair, and often it is. But think about who actually carries which risks. A vendor’s biggest exposure might be a data breach. A customer’s biggest exposure might be not paying its invoices. A cap that treats both sides identically on paper can end up protecting one of them far more than the other.

A Sample Clause

This is a simplified example, meant to help you spot the parts in a real contract:

“Except for obligations arising from a party’s gross negligence, willful misconduct, breach of confidentiality, or indemnification obligations, neither party shall be liable for any indirect, incidental, special, consequential, or punitive damages, including lost profits, and each party’s total liability under this Agreement shall not exceed the fees paid or payable by Customer in the twelve months preceding the event giving rise to the claim.”

It opens with the carve-outs, then excludes the indirect damages, then sets the cap. Actual contracts vary a lot, so please don’t copy this one into your own agreements.

Will a Court Enforce It?

Usually, when the contract is between businesses and the language is clear, judges tend to respect it. Judges tend to respect a limit that both sides had a fair chance to read and negotiate. They’re less forgiving when the clause is buried, confusingly written, or wildly one-sided. Ambiguous wording often gets interpreted against whoever drafted it. Consumer contracts get more scrutiny, and some consumer protection laws restrict these clauses outright. And as I mentioned, many states won’t enforce a limit on liability for fraud or deliberate wrongdoing no matter what the contract says.

What I’d Check Before Signing

The cap is the first thing I look at. I want to know how the number is calculated, whether it’s aggregate or per claim, and whether it would cover a realistic worst case for the kind of work this vendor is doing. After that, I read the damages exclusion. If the vendor will be storing or handling important data, giving up the right to recover for lost data or lost profits might not be a trade I’d want to make.

The carve-outs get the slowest read. When customer data is involved, I’d expect confidentiality and data breaches to be carved out, or at least covered by a super cap. I also compare the indemnity against the cap to see whether one undercuts the other, because a generous indemnity doesn’t help much if a low cap applies to it. And if the clause is labeled mutual, it’s worth asking whose risks it’s really limiting.

One more step people often skip is a call to their insurance broker. Cyber, professional liability, and general liability policies can pick up some of what a contract leaves uncovered. Your broker can only help with that, though, if you can tell them what the contract actually says.

Final Thoughts

A limitation of liability clause decides how much a failure can cost. The cap sets the ceiling, the damages exclusion removes whole categories of loss, and the carve-outs pull the most dangerous risks back out from under those limits. Read it next to the indemnification clause, never on its own.

If you sell services, this clause keeps one unhappy customer from putting you out of business. If you buy them, it tells you how much protection you’re actually getting. Either way, it’s one of the few paragraphs in a contract I’d never sign without reading slowly.

You may also like...

Shares