The limitation of liability clause in a SaaS agreement under the United States law
US SaaS limitation of liability clause guidance: enforceability under UCC, negotiation tactics, carve-outs for gross negligence, data breach liability, and stat
Standard Position
In US SaaS agreements, limitation of liability clauses typically cap the vendor's total liability to the greater of (i) fees paid in the preceding 12 months, or (ii) a fixed amount like $100,000 or $500,000. Vendors almost universally exclude consequential, incidental, special, and punitive damages. This is market standard across enterprise SaaS, and most enterprise customers accept it, though negotiation is common for mission-critical deployments. Startups and mid-market companies often push back harder, but vendors rarely agree to uncapped liability.
Legal Basis
Under the Uniform Commercial Code (UCC) and common law contract doctrine, limitation of liability clauses are generally enforceable if they are reasonable and not unconscionable. The UCC Section 2-719 governs remedy limitations for goods, and by analogy, courts apply similar principles to SaaS services. Courts will enforce caps on liability if: (1) they were agreed to by sophisticated parties; (2) they were conspicuous; (3) they are not grossly disproportionate to anticipated harm; and (4) neither party is a consumer. However, most courts will NOT enforce a limitation that purports to exclude liability for a party's own gross negligence, willful misconduct, or fraud. Additionally, state laws vary: some states (like California and New York) scrutinize liability waivers more strictly, especially for personal injury or bodily harm. For data breach or privacy violations under state data protection laws (CCPA, NYDFS, etc.), courts may refuse to enforce caps that conflict with statutory minimum damages.
Drafting and Negotiation
Vendors should define what is excluded: specify "consequential, incidental, special, exemplary, and punitive damages, including lost profits, lost revenue, and lost business opportunity." Use clear language and place the clause in a conspicuous location (often in a separate "Limitation of Liability" section). Expressly carve out exceptions: "This limitation does not apply to [i] either party's indemnification obligations, [ii] breach of confidentiality, [iii] infringement claims, [iv] gross negligence, willful misconduct, or fraud, or [v] either party's liability that cannot be limited by law."
Customers should negotiate for: (1) higher caps if the service is mission-critical; (2) removal of caps on indemnification and data breach/privacy violations; (3) explicit carve-outs for gross negligence and willful misconduct; (4) a separate, higher cap for data breaches (e.g., 2x annual fees or $5M); (5) shorter lookback periods (6 months instead of 12) to cap exposure early. For regulated industries (finance, healthcare), customers often successfully remove or significantly raise caps.
Common Pitfalls
Vendors often fail to carve out gross negligence and willful misconduct explicitly; courts may strike the entire clause if it appears to shield the vendor from liability for its own gross misconduct. Customers frequently accept liability caps without realizing they also cap the vendor's indemnification obligation for third-party IP infringement claims, leaving them exposed. Both parties may overlook state-specific law: California courts are skeptical of broad waivers of liability, and some states prohibit limiting liability for violations of state privacy laws. Never assume a US-wide standard; check the governing law clause. Finally, parties often neglect to address liability for data breaches separately; a single cap that covers both operational downtime and full customer data loss is unbalanced and may be deemed unconscionable.
Sample language
Except for breaches of confidentiality obligations, indemnification claims, gross negligence, willful misconduct, and fraud, neither party's total liability arising out of or relating to this Agreement shall exceed the fees paid by Customer in the twelve months preceding the claim. IN NO EVENT SHALL EITHER PARTY BE LIABLE FOR CONSEQUENTIAL, INCIDENTAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, LOST REVENUE, OR LOST BUSINESS OPPORTUNITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.
Frequently asked questions
- Are limitation of liability clauses enforceable in US SaaS agreements?
- Yes, generally they are enforceable if they are reasonable, not unconscionable, and apply to sophisticated parties who agreed to them knowingly. However, courts will not enforce caps that exclude liability for a party's own gross negligence, willful misconduct, fraud, or violations of certain state privacy laws. State-specific law varies, so check your governing law clause.
- What damages are typically excluded from a SaaS liability cap?
- Vendors exclude consequential, incidental, special, exemplary, and punitive damages, including lost profits, lost revenue, and lost data. However, most vendors should carve out indemnification obligations, breaches of confidentiality, and claims arising from gross negligence or willful misconduct to ensure the clause is enforceable.
- Can I negotiate the liability cap if the SaaS service is mission-critical?
- Yes. Enterprise customers regularly negotiate higher caps, shorter lookback periods (6 months instead of 12), separate higher caps for data breaches, and removal of caps on indemnification and data breach liability. Vendors are more willing to negotiate for regulated industries (finance, healthcare) and longer contract terms.
- Does a data breach count as consequential damage under the liability cap?
- It depends on the language. If the clause broadly excludes all consequential damages, a data breach might be characterized as consequential. Best practice is to expressly carve out data breach and privacy violations from the cap, or impose a separate, higher cap (e.g., 2x annual fees) to avoid disputes and enforceability challenges under state privacy laws.
Related in the library
- The limitation of liability clause in a employment agreement under the United States law
- The limitation of liability clause in a master services agreement (MSA) under the United States law
- The limitation of liability clause in a non-disclosure agreement (NDA) under the United States law
- The limitation of liability clause in a master services agreement (MSA) under the United Kingdom law
- The limitation of liability clause in a consultancy agreement under India law
- The limitation of liability clause in a non-disclosure agreement (NDA) under Singapore law
Adira drafts and reviews contracts under the law of the jurisdiction they work in.
See Adira