The limitation of liability clause in a SaaS agreement under the United States law

US SaaS limitation of liability clause guidance: enforceability under UCC, negotiation tactics, carve-outs for gross negligence, data breach liability, and stat

Standard Position

In US SaaS agreements, limitation of liability clauses typically cap the vendor's total liability to the greater of (i) fees paid in the preceding 12 months, or (ii) a fixed amount like $100,000 or $500,000. Vendors almost universally exclude consequential, incidental, special, and punitive damages. This is market standard across enterprise SaaS, and most enterprise customers accept it, though negotiation is common for mission-critical deployments. Startups and mid-market companies often push back harder, but vendors rarely agree to uncapped liability.

Legal Basis

Under the Uniform Commercial Code (UCC) and common law contract doctrine, limitation of liability clauses are generally enforceable if they are reasonable and not unconscionable. The UCC Section 2-719 governs remedy limitations for goods, and by analogy, courts apply similar principles to SaaS services. Courts will enforce caps on liability if: (1) they were agreed to by sophisticated parties; (2) they were conspicuous; (3) they are not grossly disproportionate to anticipated harm; and (4) neither party is a consumer. However, most courts will NOT enforce a limitation that purports to exclude liability for a party's own gross negligence, willful misconduct, or fraud. Additionally, state laws vary: some states (like California and New York) scrutinize liability waivers more strictly, especially for personal injury or bodily harm. For data breach or privacy violations under state data protection laws (CCPA, NYDFS, etc.), courts may refuse to enforce caps that conflict with statutory minimum damages.

Drafting and Negotiation

Vendors should define what is excluded: specify "consequential, incidental, special, exemplary, and punitive damages, including lost profits, lost revenue, and lost business opportunity." Use clear language and place the clause in a conspicuous location (often in a separate "Limitation of Liability" section). Expressly carve out exceptions: "This limitation does not apply to [i] either party's indemnification obligations, [ii] breach of confidentiality, [iii] infringement claims, [iv] gross negligence, willful misconduct, or fraud, or [v] either party's liability that cannot be limited by law."

Customers should negotiate for: (1) higher caps if the service is mission-critical; (2) removal of caps on indemnification and data breach/privacy violations; (3) explicit carve-outs for gross negligence and willful misconduct; (4) a separate, higher cap for data breaches (e.g., 2x annual fees or $5M); (5) shorter lookback periods (6 months instead of 12) to cap exposure early. For regulated industries (finance, healthcare), customers often successfully remove or significantly raise caps.

Common Pitfalls

Vendors often fail to carve out gross negligence and willful misconduct explicitly; courts may strike the entire clause if it appears to shield the vendor from liability for its own gross misconduct. Customers frequently accept liability caps without realizing they also cap the vendor's indemnification obligation for third-party IP infringement claims, leaving them exposed. Both parties may overlook state-specific law: California courts are skeptical of broad waivers of liability, and some states prohibit limiting liability for violations of state privacy laws. Never assume a US-wide standard; check the governing law clause. Finally, parties often neglect to address liability for data breaches separately; a single cap that covers both operational downtime and full customer data loss is unbalanced and may be deemed unconscionable.

Sample language

Except for breaches of confidentiality obligations, indemnification claims, gross negligence, willful misconduct, and fraud, neither party's total liability arising out of or relating to this Agreement shall exceed the fees paid by Customer in the twelve months preceding the claim. IN NO EVENT SHALL EITHER PARTY BE LIABLE FOR CONSEQUENTIAL, INCIDENTAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, LOST REVENUE, OR LOST BUSINESS OPPORTUNITY, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

This is general drafting guidance, not legal advice, and not a substitute for advice on your specific facts and jurisdiction. Sample language is a starting point to adapt, not a finished clause.

Frequently asked questions

Are limitation of liability clauses enforceable in US SaaS agreements?
Yes, generally they are enforceable if they are reasonable, not unconscionable, and apply to sophisticated parties who agreed to them knowingly. However, courts will not enforce caps that exclude liability for a party's own gross negligence, willful misconduct, fraud, or violations of certain state privacy laws. State-specific law varies, so check your governing law clause.
What damages are typically excluded from a SaaS liability cap?
Vendors exclude consequential, incidental, special, exemplary, and punitive damages, including lost profits, lost revenue, and lost data. However, most vendors should carve out indemnification obligations, breaches of confidentiality, and claims arising from gross negligence or willful misconduct to ensure the clause is enforceable.
Can I negotiate the liability cap if the SaaS service is mission-critical?
Yes. Enterprise customers regularly negotiate higher caps, shorter lookback periods (6 months instead of 12), separate higher caps for data breaches, and removal of caps on indemnification and data breach liability. Vendors are more willing to negotiate for regulated industries (finance, healthcare) and longer contract terms.
Does a data breach count as consequential damage under the liability cap?
It depends on the language. If the clause broadly excludes all consequential damages, a data breach might be characterized as consequential. Best practice is to expressly carve out data breach and privacy violations from the cap, or impose a separate, higher cap (e.g., 2x annual fees) to avoid disputes and enforceability challenges under state privacy laws.

Related in the library

Adira drafts and reviews contracts under the law of the jurisdiction they work in.

See Adira