The indemnity clause in a SaaS agreement under the United Kingdom law
Indemnity clauses in English SaaS agreements: scope, IP protection, data obligations, caps, and key negotiation points for vendors and customers.
Standard position
In English SaaS agreements, indemnity clauses are mutual but asymmetric. The vendor typically indemnifies the customer for third-party claims that the software infringes intellectual property rights (IP indemnity). The customer indemnifies the vendor for claims arising from the customer's data, use in breach of the agreement, or infringement caused by customer modifications. Each party usually indemnifies the other for breach of representations and warranties, and for breach of data protection obligations.
Vendors commonly cap indemnity exposure at the annual contract value (ACV) or a multiple thereof, or exclude indemnity from the liability cap entirely to signal seriousness while managing risk. English law does not require indemnity caps, but they are standard market practice and heavily negotiated.
Legal basis
Indemnity is a contractual creature in English law: there is no statute imposing indemnity obligations in commercial contracts. Courts enforce indemnity clauses according to their plain language and the contra proferentem rule (ambiguities are read against the drafter).
Key English law principles:
- Indemnity must be clear. Vague language ("indemnify for losses") may be read narrowly to exclude liability for certain types of loss (see Linden Gardens Trust Ltd v Lenesta Sludge Disposals Ltd).
- Exclusions of liability do not automatically apply to indemnity unless explicit; indemnity sits outside the liability cap in hierarchical clauses.
- Indemnity for IP infringement must address whether the vendor has a duty to defend (conduct the claim) or merely reimburse. English law does not presume a duty to defend; this must be stated.
- Data protection indemnities must comply with UK GDPR (as retained in domestic law). An indemnity cannot require a party to indemnify another for the other party's own data controller obligations.
Drafting and negotiation
Key negotiation points:
-
Scope of IP indemnity: Vendors should narrow to claims that the unmodified software infringes; exclude claims arising from customer modifications, use outside the agreement scope, or combination with non-vendor products. Customers should push for coverage of third-party components and ensure the vendor warrants clear ownership of pre-existing IP.
-
Duty to defend vs. reimbursement: State explicitly whether the indemnifying party will assume conduct of the claim, or merely reimburse. Vendors prefer reimbursement; customers prefer assumed defense. Compromise: vendor conducts if customer consents, or vendor reimburses reasonable costs if customer conducts.
-
Procedural obligations: Require the indemnified party to notify promptly, not admit liability, and cooperate. Without these, the indemnifying party may be unfairly prejudiced.
-
Cap and exclusions: Vendors should exclude indemnity from the general liability cap (placing it in a higher tier). Specify whether indemnity covers defense costs, settlements, and judgment. Exclude indemnity for claims arising from the indemnified party's breach, negligence, or misuse.
-
Remedies: If a claim succeeds, the indemnifying party should have a right to modify the software to make it non-infringing, obtain rights for continued use, or terminate and refund prepaid fees. This limits the vendor's exposure to unlimited damages.
-
Data protection: Indemnify only for claims that the vendor has breached data protection law in its role as processor or joint controller. Do not indemnify for the customer's own controller obligations or unlawful instructions.
Common pitfalls
- Omitting the "unmodified software" carve-out: Vendors who do not expressly exclude claims from customer modifications face unlimited exposure.
- Indemnity for customer's own breaches: Indemnifying the customer for the vendor's act arising from the customer's instruction (e.g., processing unlawful data) is unenforceable or highly restrictive under data protection law.
- Assuming a duty to defend without clear budget: Vendors should require customer approval for defense costs; unbounded defense costs can exceed settlement value.
- Nested liability caps: Failing to clarify whether indemnity sits outside the general cap leads to disputes and may render indemnity illusory.
- No remedies clause: Omitting the right to modify, obtain rights, or refund leaves the customer with damages claims but no working solution.
Sample language
The Vendor shall indemnify the Customer against third-party claims that the Software as provided and used in accordance with this Agreement infringes any patent, copyright, or trade secret right, provided the Customer (a) notifies the Vendor promptly in writing, (b) grants the Vendor sole control of defense and settlement, and (c) provides reasonable cooperation. If the Software becomes, or is likely to become, subject to an infringement claim, the Vendor may, at its option and expense, obtain the right for continued use, modify the Software to be non-infringing, or terminate the affected Subscription and refund prepaid fees for the remainder of the Subscription Term.
This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.
Frequently asked questions
- Does English law require an indemnity cap, and can vendors exclude indemnity from the general liability cap?
- English law does not mandate indemnity caps; they are contractual. Vendors can and should exclude indemnity from the general liability cap by placing it in a separate, higher tier or stating "Indemnity is not subject to the Liability Cap in Clause X." This is standard market practice and reduces disputes over cap interaction.
- What happens if a customer modifies the SaaS software and a third party sues for infringement?
- If the vendor has clearly carved out customer modifications from the indemnity scope, the customer bears the risk. Without this carve-out, the vendor may be liable even though the modification caused the infringement. Always include "the Software as provided and used in accordance with this Agreement" language.
- Can a vendor indemnify the customer for the customer's own data protection breaches?
- No. Under UK GDPR, a data controller's obligations are non-delegable; an indemnity cannot shift them to a processor. An indemnity may cover claims that the vendor, as a processor, breached its processing instructions or security obligations, but not claims arising from the customer's unlawful use of personal data.
- Should the vendor conduct defense of infringement claims or just reimburse the customer?
- English law does not presume a duty to defend; this must be explicit. Market practice varies: vendors prefer reimbursement to control costs; customers prefer vendor-conducted defense. Compromise: vendor conducts if customer consents, or vendor reimburses if customer prefers to conduct. Specify whether costs include legal fees and settlement authority.
Related in the library
- What is indemnity under India law?
- The indemnity clause in a employment agreement under the United Kingdom law
- The indemnity clause in a master services agreement (MSA) under the United Kingdom law
- The indemnity clause in a non-disclosure agreement (NDA) under the United Kingdom law
- The indemnity clause in a SaaS agreement under the UAE law
- The indemnity clause in a master services agreement (MSA) under Singapore law
Adira drafts and reviews contracts under the law of the jurisdiction they work in.
See Adira