The limitation of liability clause in a SaaS agreement under India law
Limitation of liability in SaaS agreements under Indian law: caps, carve-outs, enforceability, and negotiation strategy.
Standard Position
In Indian SaaS agreements, limitation of liability clauses typically cap the vendor's financial exposure to the fees paid in the preceding 12 months, or in some cases to direct damages only. Indian courts and the Indian Contract Act 1872 do permit parties to limit or exclude liability by express agreement, but such clauses are construed strictly and must be clear, unambiguous, and not unconscionable. Most vendors exclude liability for indirect, consequential, incidental, special, or punitive damages entirely. Carve-outs for indemnification (IP infringement, data breach), confidentiality breaches, and gross negligence or wilful misconduct are standard and enforceable.
Legal Basis
Section 55 of the Indian Contract Act permits parties to limit damages by agreement, provided the clause is not unconscionable under common law principles. Indian courts have upheld liability caps in commercial contracts between sophisticated parties (e.g., HCC v. Shivalik Sugars 2008 SC). However, Section 23 voids clauses that are contrary to public policy. Clauses that exclude all liability for personal injury, death, or gross negligence may be struck down as against public policy. The Information Technology Act 2000, Section 72A (as amended by the Information Technology (Intermediary Guidelines and Digital Ethics Code) Rules 2021) requires reasonable security measures; vendors cannot contractually exclude liability for gross negligence in data protection. Under the Bharatiya Nyaya Sanhita 2023 (which will eventually replace procedural aspects), substantive principles of contract interpretation remain unchanged.
Drafting and Negotiation
Vendors should expressly state that liability is limited to direct damages only, capped at 12 months of fees paid (or a fixed amount if fees are variable or minimal). Clearly list exclusions: indirect, consequential, special, incidental, and punitive damages; loss of profits, revenue, or data; reputational harm; and business interruption. Use bullet points or numbered sub-clauses for clarity, as Indian courts scrutinize ambiguity against the drafter. Carve-outs for the vendor's indemnification obligations, breaches of confidentiality, data protection violations, and wilful misconduct or gross negligence must be explicit and prominent; these cannot be capped or excluded entirely without risking unenforceability.
Negotiation flashpoints: customers often push for higher caps (24 months of fees) or exceptions for data loss. Vendors should resist uncapped indemnification but may accept higher caps (12-24 months) for critical services. For data or security breaches, consider a tiered cap: lower cap for ordinary faults, higher cap (or no cap) for gross negligence in data handling. Avoid language such as 'any liability howsoever arising' without carve-outs; this invites judicial interpretation as contrary to public policy. A sunset provision (liability cap applies for 12 months post-termination for survival clauses) is advisable.
Common Pitfalls
Drafters often omit carve-outs for data protection and IP indemnity, rendering the entire clause vulnerable to challenge. Using unilateral caps (applying only to the vendor) without reciprocal customer liability caps can appear inequitable and invite judicial scrutiny. Failing to define 'direct damages' with examples creates ambiguity; Indian courts may hold that 'lost profits' is a type of direct damage in breach of contract cases, contrary to vendor intent. Over-reliance on generic global templates without adapting to Indian jurisprudence (which interprets limitation clauses conservatively) is common. Mixing liability limitations with exclusions (e.g., 'no liability for X, capped at Y') without clarity confuses enforceability. Finally, attempting to cap liability for breaches of statutory duties under data protection, consumer protection, or labour laws is unenforceable under Section 23 of the Contract Act.
Sample language
Except as expressly provided in the Indemnification Clause and subject to Section 1.2 below, in no event shall either party's total aggregate liability under this Agreement exceed the fees paid by Customer in the 12 months preceding the claim. Neither party shall be liable for indirect, consequential, incidental, special, or punitive damages, including loss of profits, revenue, data, or business interruption, even if advised of the possibility of such loss. Liability limitations do not apply to: (a) breaches of confidentiality; (b) infringement of intellectual property rights; (c) gross negligence, wilful misconduct, or fraud; (d) either party's indemnification obligations; or (e) violations of data protection laws or regulations.
This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.
Frequently asked questions
- Can a vendor fully exclude liability in a SaaS agreement under Indian law?
- No. Indian courts will strike down blanket exclusions of liability, particularly for gross negligence, wilful misconduct, data protection breaches, and indemnification obligations under Section 23 of the Contract Act (public policy). Vendors may cap direct damages but cannot exclude all liability without risking unenforceability.
- What is the standard liability cap amount in Indian SaaS agreements?
- The market standard is 12 months of fees paid by the customer. For critical or high-value services, customers negotiate 24 months or a fixed amount. Tiered caps (lower for ordinary breaches, higher for data protection failures) are increasingly common and are judicially favoured as reasonable and balanced.
- Are liability exclusions for indirect and consequential damages enforceable in India?
- Yes, provided they are drafted clearly and do not exclude liability for gross negligence or statutory breaches (e.g., data protection). Indian courts enforce such exclusions between commercial parties of equal bargaining power, but construe them strictly against the drafter and require explicit carve-outs for unexcludable obligations.
- Must vendors include carve-outs for data protection liability in the limitation clause?
- Yes. Section 72A of the Information Technology Act 2000 imposes a statutory duty of care. Attempting to cap or exclude liability for gross negligence in data protection will be void under public policy. Explicit carve-outs for data breaches and confidentiality violations are essential for enforceability of the rest of the clause.
Related in the library
- The limitation of liability clause in a consultancy agreement under India law
- The limitation of liability clause in a employment agreement under India law
- The limitation of liability clause in a master services agreement (MSA) under India law
- The limitation of liability clause in a non-disclosure agreement (NDA) under India law
- The limitation of liability clause in a master services agreement (MSA) under the United Kingdom law
- The limitation of liability clause in a employment agreement under the United States law
Adira drafts and reviews contracts under the law of the jurisdiction they work in.
See Adira