Limitation of liability

What is the most this contract can cost me if it goes wrong?

Favours the drafting party

What it does

Sets a ceiling on liability, usually by reference to fees paid, and excludes indirect, consequential and often lost-profit damages entirely.

Why it matters

This clause, not the indemnity, is usually what decides your real exposure. A generous indemnity sitting above a cap of twelve months' fees is worth twelve months' fees.

What to watch for

  • A cap measured against fees paid in a period, when the potential harm is unrelated to fee size
  • Mutual-looking language that in practice only ever binds one side
  • Lost profits excluded even where they are the direct and expected loss
  • Carve-outs that do not include the vendor's own indemnity obligations
  • The cap applying to confidentiality and data-breach liability

What to ask for

  • Carve-outs from the cap for breach of confidentiality, data protection, IP infringement, and the indemnity itself
  • A supercap for security incidents, set against the plausible harm rather than the fee
  • Genuine mutuality, tested by reading it from the other side
  • Deletion of lost profits from the exclusion where they are direct damages

How common is it

Documents filed with the SEC containing the exact phrase limitation of liability.

Too common to count. This phrase exceeds 10,000 filed documents in every year measured, which is where EDGAR stops counting. A censored year sits at the maximum by definition, so a chart drawn from this would have its scale anchored to a lower bound. The figures are in the table below instead.

YearDocuments
201910,000+
202010,000+
202110,000+
202210,000+
202310,000+
202410,000+
202510,000+

Real filings using it

Source: SEC EDGAR full-text search (efts.sec.gov). Retrieved 2026-08-30. Counts are filed documents matching an exact phrase, not deals, and EDGAR indexes public-company filings — read these as public-company practice, not as evidence of what private mid-market agreements contain.

What usually gets agreed

Standard carve-outs for confidentiality, IP indemnity and gross negligence are widely accepted. A data-breach supercap at a multiple of fees is increasingly common and is usually the more productive ask than raising the general cap.

Related