The indemnity clause in a SaaS agreement under the UAE law

Guide to indemnity clauses in UAE SaaS agreements: mutual indemnity, IP and security liability allocation, caps, and exclusions under UAE Civil Code and DIFC.

Standard Position

In UAE SaaS agreements, indemnity clauses typically allocate risk between vendor and customer across three categories: (1) IP infringement claims arising from the software itself; (2) data breaches or security failures by the vendor; and (3) customer misuse or breach of acceptable-use policies. Market practice in the UAE and DIFC strongly favours mutual indemnity structures, with each party indemnifying the other against claims arising from their own actions or negligence. Vendors commonly exclude indemnity obligations for claims arising from customer data, customer integrations, or use cases outside the agreed scope. Indemnity is often capped at the annual contract value or a multiple thereof, and frequently excludes indirect or consequential damages entirely.

Legal Basis

The UAE Civil Code (Federal Law No. 5 of 1985) addresses contractual liability under Articles 215-236, establishing that parties may contractually allocate risk provided the allocation is not contrary to public policy (ordre public). Neither gross negligence nor intentional breach can be contractually eliminated under UAE law. DIFC contracts (subject to DIFC Law No. 5 of 2004, DIFC Civil Code) permit broader contractual freedom and explicitly recognise limitation-of-liability and indemnity clauses, making DIFC-governed SaaS agreements more vendor-friendly than those governed by the UAE Civil Code alone. ADGM (Abu Dhabi Global Market) similarly permits detailed indemnity allocations under ADGM common law principles. The UAE Courts (including the Court of Cassation) have upheld mutual indemnity clauses where drafted with sufficient clarity, though overly broad disclaimers may be partially struck down as unreasonable.

Drafting and Negotiation

Vendors should clearly separate IP indemnity (covering third-party IP claims related to the software code) from security/data indemnity (covering unauthorized access or loss of customer data during transmission or storage). Define the scope precisely: indemnity for IP should exclude claims arising from customer modifications, customer data, or use of the software in combination with non-approved third-party systems. For security indemnity, exclude breaches resulting from customer failure to implement multi-factor authentication, weak passwords, or failure to update client-side systems.

Customers should negotiate for indemnity if the vendor fails to meet security standards stated in the SLA (Service Level Agreement), such as encryption at rest and in transit, or regular penetration testing. A reciprocal indemnity should require the customer to indemnify the vendor for claims arising from customer data content (e.g., defamatory user-generated content) or breach of data-protection laws by the customer.

The procedural mechanics matter: the indemnified party should be obliged to give prompt written notice (within 30 days) and allow the indemnifying party to control defence and settlement. Cap indemnity at 12-24 months of annual fees for most SaaS contracts; higher caps may be negotiated for mission-critical systems. Exclude indirect, consequential, and punitive damages from indemnity in all cases.

Common Pitfalls

A frequent error is failing to carve out indemnity for claims arising from the customer's own data or instructions. This exposes vendors to unlimited liability for customer-created content. Another pitfall is treating IP indemnity and security indemnity as a single obligation, creating ambiguity about which party covers what. UAE courts have reduced indemnity payouts where the indemnitee failed to mitigate loss or unreasonably rejected a settlement offer. Finally, many SaaS vendors omit a duty to notify; under the UAE Civil Code, unreasonable delay in notice can reduce the indemnifying party's obligation to defend, so procedural clarity is essential.

Sample language

Vendor shall indemnify, defend, and hold harmless Customer from third-party claims that the Software, as used in accordance with this Agreement, infringes a patent or copyright, provided Customer (a) gives Vendor prompt written notice; (b) grants Vendor sole control of defence and settlement; and (c) provides reasonable cooperation. Vendor shall have no indemnity obligation for claims arising from (i) Customer data or instructions; (ii) Customer modifications; (iii) combination with non-approved systems; or (iv) use outside the Documentation. Indemnity is capped at fees paid in the 12 months preceding the claim. Customer shall indemnify Vendor for claims that Customer data or Customer use of the Software breaches applicable data-protection or intellectual-property laws.

This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.

Frequently asked questions

Can a vendor exclude indemnity for gross negligence or intentional breach under UAE law?
No. The UAE Civil Code does not permit exclusion of liability for gross negligence or intentional breach as a matter of public policy. However, DIFC-governed contracts offer greater freedom to limit exposure via properly drafted caps and exclusions of indirect damages, provided the limitation is not unconscionable.
What is the typical indemnity cap in a UAE SaaS agreement?
Market standard is 12-24 months of annual contract fees, though mission-critical or high-value deals may negotiate up to 36 months. Indemnity caps are often lower than overall liability caps and must be clearly distinguished from security-breach indemnity, which may be uncapped if customer data is involved.
Should IP indemnity and data-breach indemnity be in the same clause?
No. Separate them clearly. IP indemnity covers third-party claims about software code ownership; data-breach indemnity covers unauthorized access or loss. Bundling them creates ambiguity and makes it difficult to negotiate appropriate carve-outs and procedures for each type of claim.
What notice period should the indemnitee give when a third-party claim arises?
Standard practice is prompt notice within 30 days of discovery. Under the UAE Civil Code, unreasonable delay may reduce the indemnifying party's obligation to defend, so specifying a precise window protects both sides and ensures early involvement by the indemnifying party's legal team.

Related in the library

Adira drafts and reviews contracts under the law of the jurisdiction they work in.

See Adira