The limitation of liability clause in a SaaS agreement under the United Kingdom law

UK SaaS limitation of liability: UCTA reasonableness test, carve-outs for fraud and data protection, market-standard caps at 12-month fees, and negotiation stra

Standard position

Under English contract law, parties are generally free to limit or exclude liability by agreement, subject to the Unfair Contract Terms Act 1977 (UCTA) and the Consumer Rights Act 2015. For B2B SaaS agreements between sophisticated commercial parties, limitation of liability clauses are enforceable and commonplace. The market standard typically caps liability at a multiple of annual fees paid (often 12 months) or at direct damages only, with carve-outs for certain categories such as death, personal injury, fraud, intellectual property indemnification, and data protection breaches. Providers commonly exclude liability for indirect, consequential, or lost profits damages entirely. Caps often apply per incident or in aggregate over a defined period.

Legal basis

Section 2 of UCTA permits exclusion or restriction of liability for breach of contract if the term is 'reasonable'. Reasonableness is assessed by reference to the circumstances known to the parties when the contract was made, including the bargaining strength of the parties and whether alternative suppliers were available. The Consumer Rights Act 2015 (which superseded parts of UCTA) prohibits unfair contract terms in B2C relationships, but B2B agreements between commercial entities fall outside this regime if both parties are acting in the course of a business.

Courts will strike down excessively broad exclusions where they are unreasonable. In Oversea-Chinese Banking Corporation Ltd v Jebsens UK Ltd [2021], the court examined whether a liability cap was proportionate to the risk being allocated. For cloud services where business continuity is critical, courts have scrutinised whether a cap at, say, one month's fees is reasonable when the potential losses far exceed that amount.

Data protection breaches cannot be excluded under GDPR (which applies in the UK under retained law post-Brexit), and limitation clauses must not undermine statutory rights under the UK Data Protection Act 2018.

Drafting and negotiation

Providers should carve out non-excludable items explicitly: death, personal injury, fraud, fraudulent misrepresentation, wilful misconduct, breach of confidentiality obligations, and indemnification for third-party IP claims. Data protection and security obligations should be addressed separately rather than capped, or capped at a significantly higher level.

Negotiate the cap metric carefully. Annual recurring fees is standard for SaaS; for perpetual licences, providers may propose a lump sum or a multiple of average annual fees. Enterprise customers often push for carve-outs of the data protection and security liability cap, or for higher multiples where the customer's business is highly dependent on availability.

Consider tiered caps: a lower cap for general breach, a higher cap (or no cap) for IP indemnification and data protection. Document the customers' ability to mitigate (e.g., by purchasing backup or professional services) and reference this in commercial negotiations.

Be explicit about what constitutes 'indirect' or 'consequential' damage: lost profits, lost revenue, lost data, lost business opportunity, reputational harm. Ambiguity will be construed contra proferentem (against the drafter).

Common pitfalls

Failing to carve out fraud, wilful misconduct, or gross negligence can render the entire clause unenforceable or subject to challenge. Attempting to exclude liability for death or personal injury is void under UCTA s.1(1)(a).

Caps that are grossly disproportionate to fees (e.g., 0.5 months of fees for a service critical to business operations) may be deemed unreasonable and struck down. Courts look at the nature of the service, price point, and whether the customer had opportunity to negotiate or purchase liability insurance.

Defining 'indirect' loss poorly creates disputes: if a customer argues lost revenue is 'direct', courts may side with the customer. Use a whitelist approach: enumerate excluded items rather than defining the exclusion broadly.

Ignoring data protection breaches: if data is processed, confirm whether data controller or processor status applies and document higher or uncapped liability for data breach scenarios, as GDPR fines can vastly exceed service fees.

Sample language

Neither party shall be liable to the other for indirect, consequential, special, or punitive damages, including lost profits, lost revenue, or loss of data, even if advised of the possibility. Except for breaches of confidentiality, indemnification obligations, death, personal injury, fraud, or data protection breaches, each party's total aggregate liability under this Agreement shall not exceed the fees paid by Customer in the 12 months preceding the claim.

This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.

Frequently asked questions

Can we exclude liability for data breaches in a UK SaaS agreement?
No, liability for data protection breaches cannot be excluded or capped below actual loss under GDPR and the UK Data Protection Act 2018. You may negotiate a higher cap for data breaches than for general service failures, but complete exclusion is unenforceable and unlawful. Carve data protection liability out of the general limitation clause.
Is a liability cap of one month's fees reasonable under English law?
Reasonableness depends on context: service criticality, price point, and bargaining power. A one-month cap for non-critical services may survive challenge; for mission-critical systems, courts have questioned whether such a cap is proportionate to risk. If customers had no opportunity to negotiate or buy higher coverage, a very low cap is more vulnerable to challenge.
What damages must never be excluded from a UK commercial contract?
Death, personal injury, fraud, fraudulent misrepresentation, and wilful misconduct cannot be excluded under UCTA. For SaaS, also exclude indemnification obligations (third-party IP claims) and data protection/security breaches. All other categories (lost profits, indirect loss, business interruption) can typically be excluded if the clause meets the UCTA reasonableness test.
Who bears the burden of proving a limitation clause is unreasonable under UCTA?
The party claiming the limitation is unreasonable must prove it. However, the burden of establishing reasonableness lies on the party relying on the clause. In disputes, courts interpret ambiguous liability language against the drafter (contra proferentem), so clarity and balance in wording helps enforce the clause.

Related in the library

Adira drafts and reviews contracts under the law of the jurisdiction they work in.

See Adira