Key Takeaways
- Liability risk depends on operational scope, not contract value, making cap reviews critical even for low-dollar deals.
- Explicitly enumerate disclaimed damage types and carve-outs to eliminate costly disputes over what counts as direct vs. indirect losses.
- Avoid blanket uncapped exposure by assigning distinct risk categories (e.g., data breaches, IP) into standard caps, super caps, or uncapped buckets.

Limitation of Liability (LoL) clauses remain one of the most fiercely negotiated sections in commercial agreements. Regardless of whether a deal is worth $5,000 or $5,000,000, a partyโs real-world liability exposure hinges almost entirely on these provisions. A low-value contract can easily pull a company into a multimillion-dollar dispute if the liability caps aren’t carefully structured.
In a recent Contract Nerds webinar I hosted on Limitation of Liability Clauses: Ins, Outs, Exclusions, and Super Caps, industry experts Brian Heller (Partner at Outside GC LLC) and Michael Epstein (Senior Counsel at IBM and Adjunct Professor at NSU Shepard Broad College of Law) broke down the core mechanics, drafting traps, caps, and negotiation strategies surrounding LoL clauses.
Missed the live webinar? I recommend watching the full webinar recording on YouTube and accessing the presentation and bonus materials to dive deeper into this topic.
1. Disclaiming Consequential Damages Disclaimers
The foundational tier of liability management begins with disclaiming indirect, special, and consequential damages. Drafting standard laundry lists of excluded damages serves a vital commercial purpose. Michael notes, “There’s a reason these are all listed out; itโs because parties don’t always agree as to whether or not something is quote-unquote consequential or indirect”.
Without explicit definitions, opposing counsel can construct novel arguments attempting to reclassify indirect losses as direct harms. The core legal justification for disclaiming these damages rests entirely on risk predictability.
2. The Confidentiality and Data Breach Catch-22
Disclaiming indirect damages for confidentiality or data security breaches can effectively strip the non-breaching party of any meaningful recovery, as almost all data breach harms (e.g., credit monitoring, regulatory fines, public relations, call center setups) are technically second-tier, consequential ripple effects. This creates a Catch-22 that contract drafters should be aware of.
To bridge this gap during negotiations, Michael and Brian recommended the following:
- Define covered costs: Explicitly enumerate recoverable breach-related expenses (e.g., notification costs, government fines, credit monitoring).
- Disclaim speculative damages: Keep recovery tied to known, quantifiable expenses while continuing to exclude purely speculative harm.
- Tie liability to specific fault: Vendors should ensure breach liability is triggered only โto the extentโ caused by the vendor’s failure to adhere to agreed-upon security schedules (e.g., Exhibit E), rather than unavoidable acts by sophisticated third-party hackers.
3. Ordinary Liability Caps: Pitfalls and Drafting Tactics
Structuring the Liability Cap
Once indirect damages are disclaimed, the standard liability cap establishes the monetary ceiling for direct damages. In typical vendor-customer arrangements, vendors advocate for lower caps, while customers naturally push for higher recovery limits. So it is important to establish context for each side. Brian says unequivocally, โContext matters.โ
Brian adds, “Before you start thinking about what the cap should be, what the carve-out should be, what the exclusion should be, what the super cap should be, the very first thing you should do as a lawyer is think about who’s doing what for who, and who could cause what liability”.
Below is a table that shows different ways of structuring liability caps from the vendor perspective vs. the customer perspective, and how to reach a practical compromise.
Cap Element
Vendor Perspective
Customer Perspective
Practical Compromise
Calculation Basis
Prefers “Fees Paid” to limit
Prefers “Fees Paid or Payable”
Use “Fees paid or payable” or average
Scope of Fees
Tied strictly to the specific Statement of Work (SOW).
Tied to total aggregate fees across the entire agreement.
Separate evergreen master terms from individual SOW risk profiles.
Mutuality
Often drafts unilateral caps protecting only the vendor.
Pushes for complete mutuality across all terms.
Make core caps mutual, adjusted for asymmetric operational risks.
During the webinar, a live poll asked audience members whether limitation of liability clauses should always be mutual. While a few attendees favored “Always” or “Never,” the overwhelming majority selected “It depends.”
Community Perspective

As the poll indicates, most contract lawyersโwhether representing buyers or sellersโremain uncomfortable with pursuing an apportioned or balanced mutuality of liability, even though it establishes a fair legal baseline for modern commercial transactions. In my view, the contract legal and professional community needs to investigate this concept further by analyzing available data and contract types. By adopting the foundational premise that each party accepts its respective share of responsibility, we can prevent negotiations from stalling at the liability clause.
Actionable Takeaways:
- Incorporate “Fees Payable”: Draft liability caps using “fees paid or payable” to ensure valid remedy ceilings exist before full invoice settlement.
- Align caps to scope: Match liability caps to the financial scale of the specific Statement of Work rather than allowing master agreement caps to balloon uncontrollably over decades-long commercial relationships.
4. Negotiating Carve-Outs and Exclusions

The other biggest friction in contract negotiations concentrates on the exceptions, exclusions, and carve-outs to the standard liability cap. Standard carve-outs requested by customers routinely cover data security breaches, confidentiality violations, and third-party intellectual property indemnification. Conversely, vendors focus carve-outs on customer payment breaches, breach of license restrictions, and customer IP infringement.
When evaluating carve-outs, negotiating parties should avoid absolute posturing. Michael observes that “If you say something is never, and then it gets overturned… You’ve lost your credibility”. Additionally, meticulous contract drafting ensures that routine non-performance is not incorrectly escalated into claims with uncapped liability. Michael adds that “You either breach the contract, or you don’t. It doesn’t matter how negligent you were, or how grossly negligent you were; breach is a breach, the associated damage is a damage”.
Actionable Takeaways:
- Tie data breach liability to specific obligations: Limit vendor exposure by requiring that data breach carve-outs stem directly from failure to comply with contractually specified security schedules rather than broad, undefined breach standards.
- Maintain precise legal terms: Utilize statutory or governing case law definitions for terms like gross negligence or willful misconduct to prevent minor contractual disputes from being recharacterized as uncapped claims.
5. Designing Effective Super Caps
Uncapped liability is often unacceptable and unreasonable, so parties implement a super cap, a secondary, higher limit applicable to specific high-risk breaches like data security incidents or IP indemnification.
Sample Clause: Integrated Super Cap Provision
EXCEPT FOR DAMAGES ARISING FROM A PARTY’S FRAUD OR WILLFUL MISCONDUCT, NEITHER PARTY’S AGGREGATE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATED TO DATA PROTECTION OR CONFIDENTIALITY OBLIGATIONS SHALL EXCEED THE GREATER OF $1,000,000 OR THREE TIMES (3X) THE TOTAL FEES PAID OR PAYABLE UNDER THIS AGREEMENT.
Establishing the appropriate value for a super cap requires evaluating real-world exposure rather than defaulting to arbitrary multipliers. Brian emphasizes that “A super cap… is just a secondary cap that’s bigger than the ordinary cap, but smaller than unlimited”. Attempting to tie super caps directly to insurance policy limits also introduces hidden risks. Brian highlights that “If you’re a vendor, and you have $10 million worth of insurance, and you have a data breach… each client of yours isn’t gonna have $10 million of coverage. You’re gonna have $10 million of coverage total across 1,000 clients”.
Actionable Takeaways:
- Isolate distinct risk buckets: Map every risk type explicitly into its designated bucketโstandard cap, super cap, or uncappedโto avoid internal contractual contradictions.
- Draft exclusive remedies: Explicitly state that super-capped clauses represent the sole and exclusive monetary recovery path for specified breaches to prevent claimants from stacking caps across multiple contractual provisions.
Mastering limitation of liability clauses requires legal professionals to move beyond generic templates and embrace the reality that context matters for every unique deal. By intentionally defining specific damage types, mapping risk categories into well-structured super caps, and avoiding blanket uncapped exposure, parties can ensure predictability and protection. Ultimately, while legal frameworks offer a necessary baseline, the most successful negotiations are those that adopt a tailored, granular approach to risk allocation, ensuring that the final agreement reflects the actual operational scope and potential liabilities of the partnership.
Continued Learning Opportunities
- You can access the full webinar recording for no charge here.
- Join our next free webinar live to get CLE or CPE credit plus a chance to win prizes! We host one webinar a month. Follow us on LinkedIn to stay updated on upcoming webinars.
- Join 24,000+ lawyers and contracts professionals who want to master contracting skills by subscribing to our weekly newsletter.
This webinar was made possible by Docusign, Intelligent Agreement Management.


















