RedlineREDLINE

← The Redline Blog

Sample Limitation of Liability Clause: 7 Forms to Know

Find a sample limitation of liability clause for any contract. Explore 7 key examples with plain-English analysis of risks, pitfalls, and negotiation tips.

22 min read

Sample Limitation of Liability Clause: 7 Forms to Know

You sign the deal. Two months later, the vendor goes down, customer data is exposed, or a client claims your work caused lost revenue. The fight usually turns on one clause, not the pricing page or statement of work. The limitation of liability clause.

That clause decides how much each side can recover, which types of losses are off the table, and which mistakes are too serious to excuse. Get it wrong and you can accept a tiny cap for the other side while leaving your own biggest risks fully exposed.

A strong sample limitation of liability clause does more than cap damages. It allocates risk on purpose. That means you need to read it in layers: the standard language, the plain-English meaning, the practical risk, and the redlines that fit your role.

That is the playbook here.

You will see the common versions of these clauses, what they mean in real disputes, and how to revise them if you are a freelancer, a SaaS company, or a buyer signing standard terms. If you want a faster way to identify hidden contract traps, use that checklist before you agree to any liability language.

Do not treat this clause as boilerplate. Treat it as the part of the contract that decides who writes the check.

Table of Contents

1. Cap on Direct Damages Limitation

You buy a low-cost service that runs a high-value part of your business. It fails, the fallout spreads, and then you find the contract says your maximum recovery is only what you paid over the last 12 months. That is how a basic liability cap turns a serious claim into a small refund.

This clause sets the ceiling for ordinary breach claims. The standard version usually says each party's total liability under the agreement will not exceed the fees paid, or payable, under the agreement during a stated lookback period, often the prior 12 months. Some contracts use a fixed floor such as $5,000. Others use only the fees paid. The formula matters because it decides whether the cap is realistic or cosmetic.

Standard language

A common version reads like this:

“Each party's total liability arising out of or related to this Agreement will not exceed the amounts paid or payable under this Agreement in the twelve (12) months preceding the event giving rise to the claim.”

Plain-English translation

If the other side causes real damage, you still recover only up to the cap. If you paid little, your remedy is little, even when your actual loss is much larger.

That is why you should never measure the cap against the contract price alone. Measure it against the cost of a credible failure. Lost project value, replacement costs, customer refunds, rework, and emergency vendor spend add up fast.

One court even enforced a contractual cap strongly enough to cut a much larger verdict down to the contract limit, as described in ASCE's discussion of enforced caps.

The real risk

A low cap is not automatically fair just because it is common.

For freelancers, the trap is asymmetry. The client's liability is capped at fees paid, but your exposure for indemnity, IP infringement, or confidentiality may sit outside the cap or stay uncapped entirely.

For SaaS customers, the trap is mismatch. You may pay a modest subscription fee for software that controls billing, access, fulfillment, or customer data. If the platform fails, the cap may cover only a fraction of the harm.

For consumers, a tiny flat cap usually signals that the terms were written to shut down meaningful claims before they start.

Redlines that work

Do not ask whether the other side is “open” to changes. Mark the clause.

  • Raise the formula: Change “fees paid” to “fees paid or payable,” or extend the lookback beyond 12 months.
  • Set a real floor: If the annual spend is low, propose a minimum cap that matches the business risk.
  • Tie the cap to function: Core systems, payment tools, and data-sensitive services justify a higher cap than low-impact support tools.
  • Make it mutual: If the cap applies to ordinary breach, it should apply evenly to both sides.
  • Check the rest of the agreement: A cap can look acceptable until indemnity, confidentiality, and IP sections blow holes through it. Use a review process that helps you identify hidden contract traps.

Best play by context

Freelancer: Ask for a cap of at least the total project fees, and refuse one-way exposure where your special obligations survive outside the cap.

SaaS buyer: Push for the greater of 12 months of fees or a fixed dollar floor that reflects migration, downtime, and recovery costs.

Consumer: Treat a nominal cap as a warning. If the service handles payments, communications, or personal data, the clause is written for the company's protection, not yours.

2. Exclusion of Consequential and Indirect Damages

Sometimes the cap isn't the harshest part. The damages exclusion is.

Many clauses say neither party is liable for indirect, incidental, special, consequential, punitive, or exemplary damages, including lost profits, lost revenues, lost data, or business interruption. That sounds technical. In practice, it often removes the very losses you'd care about most after a serious failure.

A store protected by a glass dome from a chain of dominoes representing business risks and liabilities.

Plain-English translation

If a payment processor goes down during your product launch, your direct damages might be limited to the fee you paid for the service. Your lost sales, customer churn, reputational harm, and downstream contract penalties may all be excluded.

That's why this language shows up so often with the cap. One controls how much can be recovered. The other controls what categories of harm count in the first place.

If your business depends on uptime, data access, or transaction flow, a broad consequential damages waiver can erase most of your real-world claim.

For freelancers, this usually appears in platform terms and agency agreements. For SaaS customers, it's routine in cloud contracts. For consumers, it often shows up in app terms, telecom contracts, and subscription services where the company wants to avoid responsibility for knock-on harm.

Best redlines by context

Don't try to delete the entire exclusion first. Narrow it.

  • Freelancer redline: carve out unpaid fees, misuse of your work product, and confidentiality breaches.
  • SaaS customer redline: carve out security failures, IP infringement, and breaches of specific service commitments.
  • Consumer redline: focus on preserving remedies for unlawful conduct, billing abuse, and failures that affect property, safety, or access to paid services.

A strong compromise reads more like this: consequential damages remain excluded for ordinary breaches, but the exclusion doesn't apply to fraud, gross negligence, willful misconduct, confidentiality violations, or IP claims.

3. Liability Exclusion for Third-Party or User-Generated Content

Marketplace and platform contracts use this clause to say: we run the venue, but we're not responsible for what users do inside it.

You'll see versions of this in creator platforms, freelance marketplaces, rental apps, and social platforms. Meta may host content. Etsy may connect buyers and sellers. Fiverr and Upwork may connect clients and freelancers. Airbnb may connect hosts and guests. The contract often says the platform isn't liable for user conduct, listings, representations, or disputes.

What this shifts onto you

Plain English: if another user lies, steals, defames, counterfeits, or fails to deliver, the platform may argue that your problem is with that user, not with them.

That doesn't mean the platform has no responsibilities. It means your practical remedy may depend more on internal dispute procedures, takedown systems, escrow rules, payment protection, or refund policies than on suing the platform itself.

For creators, the biggest hidden risk is reputation and IP. If someone reposts your work, impersonates you, or files a bogus claim, the limitation language may push you into a narrow complaint process with little influence. For small businesses using marketplaces, the issue is fraud and nonperformance. For consumers, it's counterfeit goods, scams, unsafe rentals, or failed bookings.

Negotiation moves that work

This isn't always a clause you can negotiate in clickwrap terms, so your strategy shifts from redlining to selection.

  • Check the remedy system: Read the dispute policy, payment hold rules, refund process, and takedown process before you sign up.
  • Choose platforms with protections: A strong refund or payment-protection program can matter more than broad legal language.
  • Protect yourself off-platform: Keep screenshots, order records, delivery proofs, and message logs.
  • Cover your own exposure: If your business depends on platform visibility or user interactions, consider insurance and backup channels.

The legal clause matters. The operational safety net matters more when the platform contract is non-negotiable.

4. Limitation of Liability for Data Breaches or Unauthorized Access

Your vendor gets breached. Customer data is exposed. Regulators start asking questions, customers want answers, and your internal team drops everything to contain the mess. Then you check the contract and find the vendor's liability is capped at a few months of fees.

That is a bad deal.

A sample limitation of liability clause gets dangerous when it treats a security incident like an ordinary service problem. If the provider handles customer records, health data, payment details, login credentials, or confidential business files, a low fee-based cap can leave you holding nearly all of the risk.

Local law still matters. Courts do not enforce every liability cap the same way, and some limits fail under jurisdiction-specific rules or public policy concerns. For a useful overview of how enforceability changes by jurisdiction, see Sirion's discussion of jurisdiction-specific enforceability.

A data server with a broken holographic digital lock attached to a red liability cap tag.

Standard language

A vendor version often says something like this: the provider is not liable for unauthorized access, hacking, data loss, or security incidents beyond the general liability cap, which may be limited to fees paid under the agreement.

Plain-English translation

The vendor wants its maximum exposure for a breach to stay small and predictable, even if your costs are not. Your actual losses can include forensic work, legal review, notice obligations, customer support, credit monitoring, system restoration, and contract fallout with your own clients.

For a password manager, payroll processor, CRM, cloud storage provider, or healthcare platform, this clause should never be accepted on autopilot.

The real risk

The problem is not just the cap amount. The problem is the mismatch between the type of harm and the remedy.

A service outage may justify credits. A data breach does not.

Security failures create layered exposure. You may face regulatory scrutiny, third-party claims, incident response costs, and business interruption at the same time. If the contract folds all of that into a low general cap, the clause protects the vendor right where you need protection most.

Redline suggestions that work

Ask for contract mechanics, not broad promises about “industry-standard security.”

  • Set a separate security cap: Put data breach, unauthorized access, and confidentiality failures under a higher cap than ordinary performance issues.
  • Add a clear carve-out: Exclude gross negligence, willful misconduct, fraud, and failure to follow stated security commitments from the ordinary cap.
  • Define response duties: Require prompt notice, cooperation, forensic support, and a clear allocation of remediation responsibilities.
  • Match the rest of the contract: Check that the security exhibit, warranty language, indemnity section, and liability cap do not cancel each other out.

Context-specific negotiation playbook

Use the same clause differently depending on your role.

  • Freelancer: If you handle client logins, customer lists, or confidential files, cap your liability to fees paid, but do not accept unlimited exposure for every security incident. Tie your risk to your actual control over the systems.
  • SaaS buyer or vendor: Split ordinary downtime risk from security risk. Security incidents deserve a higher cap, a defined response process, and tighter wording around subcontractors and hosted infrastructure.
  • Consumer or small business user: You usually cannot redline clickwrap terms, so choose providers with clear breach notice commitments, published security practices, and a realistic support path after an incident.

If the vendor insists on a low cap, narrow the clause. Limit it to incidents outside the vendor's reasonable control. Exclude failures to patch known vulnerabilities, follow written security commitments, or restrict access properly.

If you need a quick visual on how these risks show up in real contracts, this short explainer is useful before you start redlining.

5. Liability Waiver for Service Interruptions or As-Is Availability

This clause is common in cloud software, payment tools, web hosting, communication platforms, and consumer subscriptions. It says the service may be unavailable, delayed, degraded, or interrupted, and your remedy is limited or nonexistent.

Sometimes the provider offers only service credits. Sometimes the terms go further and say the service is provided “as available,” with no promise of uninterrupted access.

A 3D cloud icon with a pause symbol next to a ticket labeled service credit.

What vendors are trying to achieve

They want to convert outage risk into a predictable, low-cost remedy. Instead of paying for your actual business harm, they offer a credit against future fees or no compensation at all.

That approach can be reasonable for noncritical tools. It's a bad fit for systems that process payments, route customer support, store active files, manage bookings, or run your website. If the service is mission-critical, downtime isn't an inconvenience. It's operational failure.

A lot of buyers make one mistake here. They negotiate only the SLA percentage and ignore the remedies section. An uptime promise without a meaningful remedy is mostly marketing.

What to ask for instead

Push for a layered remedy structure.

  • Start with service credits: Fine for minor misses.
  • Add fee relief: If outages become recurring, require price adjustments or refunds.
  • Add termination rights: If performance repeatedly fails, you should be able to leave without penalty.
  • Protect continuity: Ask for export rights, transition help, and clear restoration obligations.

A service credit is not real protection if your business can't function without the service.

For freelancers, this matters when a client requires one platform for deliverables or approvals. For startups, it matters in vendor procurement. For consumers, it shows up in internet, phone, streaming, and app subscriptions.

6. Liability Cap with Carve-Outs Gross Negligence Willful Misconduct Indemnification

A capped liability clause looks reasonable until the other side hides exposure in the exceptions. You sign a contract with a neat fee-based cap, then discover that indemnity claims, IP claims, and certain security failures sit outside it entirely. At that point, the cap is only partial protection.

Used well, this structure is still the right target. It puts a ceiling on ordinary contract risk and keeps extreme conduct, plus a few high-stakes categories, subject to higher exposure. The job is not just to accept carve-outs. The job is to control which claims escape the cap and how far they can go.

Standard language

A common version reads like this:

Except for liability arising from gross negligence, willful misconduct, fraud, or a party's indemnification obligations, each party's total liability under this Agreement will not exceed the fees paid or payable under this Agreement during the twelve months preceding the claim.

Plain-English translation

Everyday mistakes are capped.

But if the claim involves gross negligence, intentional wrongdoing, fraud, or indemnity, the cap may not apply at all. In plain terms, one sentence limits risk and the carve-outs give some of it back.

That can be fair. It can also be dangerous if the carve-outs are broad, undefined, or one-sided.

Where the risk actually sits

The fight is rarely about the existence of carve-outs. It is about scope.

A vendor may agree to a low general cap, then exclude all confidentiality breaches, all data incidents, all IP claims, and all indemnification obligations from that cap. That creates a clause that looks balanced but exposes one side to open-ended liability in the claims most likely to become expensive.

Drafting details matter here. Courts have treated phrases like “per claim,” “per event,” “series of related events,” and “in the aggregate” very differently. If you leave that wording loose, you invite a later dispute over whether the cap resets multiple times or applies once across the life of the contract. DLA Piper's analysis of liability cap drafting shows how much turns on a few words.

Red flags to catch before you sign

  • Indemnity sits fully outside the cap: That is often the biggest hidden exposure. If the indemnity is broad, the uncapped risk is broad too. If you need help spotting indemnification risks, review that clause beside the liability section.
  • Gross negligence or willful misconduct is undefined: Some jurisdictions treat those terms narrowly. Others leave room for argument. If the contract adds custom definitions, read them carefully.
  • Only one side gets carve-out protection: Mutual cap, one-sided exceptions. That is not balanced.
  • Confidentiality carve-out is too broad: Limit uncapped exposure to misuse of highly sensitive data, not any technical breach of a confidentiality clause.
  • The cap structure is unclear: State whether it is aggregate, per claim, or per event. Do not leave this implied.

Redline suggestions by context

Freelancer

Keep the general cap tied to the project value or fees paid. Push back on uncapped indemnity. If the client insists on IP indemnity, limit it to your original work and exclude client-provided materials, instructions, and modifications.

Suggested redline:
“Contractor's indemnification obligation applies only to claims alleging that Contractor's original deliverables, as provided and used as permitted, infringe a third party's intellectual property rights, and such obligation will be subject to a separate cap equal to two times the fees paid under this Agreement.”

SaaS buyer or vendor

Use a layered structure. General claims get one cap. Data breaches, confidentiality breaches, and IP indemnity get a higher cap, not automatic unlimited liability. Reserve uncapped liability for fraud, willful misconduct, and maybe deliberate misuse of the other party's data.

Suggested redline:
“The liability cap for breaches of confidentiality, security obligations, and indemnification obligations will be two times the fees paid or payable in the twelve months preceding the claim. The general cap will continue to apply to all other claims.”

Consumer contract

This language often appears in app terms, marketplace terms, and product warranties, though consumers usually get little room to negotiate. Still, you should read the carve-outs because they show what the company itself considers serious enough to treat differently. The same issue appears when reviewing 'as is' car agreements, where disclaimers and carve-outs can decide whether you have any practical remedy after a major problem.

What to ask for

Ask for a cap table, not a vague paragraph. Spell out each category.

  • General breach: capped at fees paid in the prior 12 months
  • IP indemnity: separate higher cap
  • Confidentiality breach: capped, unless intentional
  • Data security breach: higher cap tied to actual risk
  • Fraud and willful misconduct: uncapped
  • Gross negligence: either uncapped or under a clearly higher cap, depending on bargaining power

A good carve-out structure separates routine disputes from serious misconduct. A bad one makes the cap look safe while leaving the biggest claims exposed.

If you remember one rule, make it this: never review the liability cap without reviewing indemnity, confidentiality, security, and IP language in the same pass. That is where the primary risk allocation happens.

7. No Warranty and Limitation of Implied Warranties As-Is Disclaimers

An as-is disclaimer says the product or service comes with no implied promises. No promise it's fit for your purpose. No promise it's merchantable. Sometimes no promise of non-infringement, accuracy, availability, or legal compliance either.

For low-value, experimental, free, or beta products, that may be expected. For paid, important, or safety-related services, it's aggressive.

What as-is really means

Plain English: if the thing doesn't work the way a reasonable buyer expected, the seller wants to argue that expectation was your problem, not theirs.

This shows up in software terms, template libraries, marketplaces for used goods, stock content licenses, and consumer sales. It also appears in professional-service templates where the provider wants maximum flexibility and minimum performance commitments.

A broad as-is clause is especially risky when paired with a low cap and a consequential damages waiver. That combination can leave you with no practical remedy even if the service fails in a way that disrupts your business.

When to push back hard

Consumers should challenge this language most aggressively. B2B buyers should narrow it and ask for express warranties.

  • Request an express warranty: Ask for specific promises about performance, conformity to documentation, or legal authority to provide the goods or service.
  • Protect critical issues: Exclude security, compliance, safety, and fraud from the disclaimer's reach.
  • Tie warranty failure to remedies: A warranty without a repair, refund, replacement, or termination right doesn't help much.
  • Read adjacent terms: If you're reviewing “as is” car agreements, the disclaimer must be read together with return rights, inspection rights, and local consumer protections.

Some clauses go too far and try to disclaim things local law won't let them disclaim. That's why governing law and jurisdiction matter so much with this language.

7-Point Comparison of Limitation of Liability Clauses

A dispute hits after a failed rollout, a security incident, or a long outage. The clause that looked like boilerplate now decides whether you recover real money, get a few service credits, or get nothing useful at all.

Use this table as a negotiating playbook, not a glossary. Each clause type changes the deal in a different way. Your job is to match the language to the risk, then redline the parts that leave you exposed.

Clause What it usually says in practice Plain-English effect Main risk to watch Best fit Redline move
Cap on Direct Damages Limitation Liability is capped at fees paid in a stated period, often 12 months The maximum payout is fixed, even if your loss is larger A low cap can make the contract nearly worthless after a serious failure Recurring-fee SaaS, standard vendor deals Ask for a higher cap, a per-claim cap, or a separate cap for security and IP issues
Exclusion of Consequential and Indirect Damages Neither party is liable for lost profits, lost revenue, or other indirect losses Big-ticket business losses are usually off the table The wording may wipe out the losses you would actually suffer Commodity services, lower-risk tools Carve out confidentiality, data loss, IP infringement, and fees paid to replacement vendors
Liability Exclusion for Third-Party / UGC The provider is not responsible for user posts, third-party listings, or linked content Responsibility shifts away from the platform and toward users or outside parties The clause can be drafted so broadly that the platform avoids blame for its own bad moderation or notice failures Marketplaces, forums, creator platforms Add responsibility for content the platform promotes, edits, or ignores after clear notice
Limitation for Data Breaches / Unauthorized Access Breach-related liability is capped, sometimes under the general cap Even a serious security incident may lead to limited recovery The cap may be far below the actual cost of response, notice, and customer fallout Low-sensitivity services with limited data exposure Set a higher breach cap or remove breach claims from the general cap entirely
Liability Waiver for Service Interruptions / "As‑Is" Availability Outage claims are limited to service credits or excluded altogether If the service goes down, your remedy may be tiny compared with the business harm Credits rarely cover real operational loss Low-cost, non-critical services Tie uptime failures to termination rights, refunds, or stronger SLA remedies
Liability Cap with Carve‑Outs (gross negligence, indemnity) General liability is capped, but certain conduct is excluded from the cap Ordinary mistakes are capped. Serious misconduct is not Undefined carve-outs create fights later, especially around indemnity scope Complex B2B contracts, high-risk or data-sensitive services Define each carve-out tightly and make clear which indemnity claims stay capped or uncapped
No Warranty / Limitation of Implied Warranties ("As‑Is") Goods or services are provided without promises beyond any express terms You take more performance risk from the start Combined with a low cap, this can leave you without a practical remedy Used goods, discounted sales, some business-to-business deals Add express warranties for performance, authority, security, or compliance

The pattern is simple. The harshest contracts stack protections for the provider. Low cap. Broad consequential-damages waiver. Service-credit-only remedy. As-is disclaimer. That combination deserves an aggressive markup, especially if the product touches revenue, customer data, or core operations.

Your redlines should change by context. Freelancers should keep liability tied to fees and cut back open-ended indemnity. SaaS buyers should push hardest on breach caps, uptime remedies, and IP carve-outs. Consumers should treat low caps and broad disclaimers as warning signs and look closely at local law protections before accepting the terms.

From Red Flag to Redline Taking Control of Liability

A limitation of liability clause isn't boilerplate decoration. It's the clause that tells you what the contract is really worth when things go wrong.

If you remember one principle, make it this one: don't read the liability clause alone. Read the cap, the damages exclusion, the warranty disclaimer, the indemnity, the security promises, and the remedies section together. A “reasonable” cap can become harsh when it's paired with a broad consequential damages waiver. An acceptable as-is clause can become dangerous when there's no refund right, no express warranty, and no termination option. The risk sits in the combination.

You should also stop accepting vague drafting. Structure changes outcomes. Courts can treat a lifetime aggregate cap differently from a per-event cap. A security incident may deserve a separate cap. Ordinary negligence shouldn't be treated the same as fraud or willful misconduct. Clear drafting gives you an advantage before a dispute and protection during one.

For freelancers, the priority is simple. Keep liability proportional to your fee, carve out what shouldn't sit on your shoulders, and don't let indemnity obligations subtly undermine the cap. For SaaS buyers and startups, match the cap to operational reality, not just annual spend. If the vendor touches your data, customer flow, revenue engine, or IP, demand better carve-outs and better remedies. For consumers, treat low caps and broad as-is language as a signal to slow down and read the surrounding terms carefully.

The best sample limitation of liability clause is balanced. It caps ordinary business risk, excludes speculative damages where appropriate, and preserves accountability for the conduct that should never be protected. That's the standard you should negotiate toward.

Redline can help you get there faster. It can flag limitation clauses, surface the surrounding terms that change their meaning, and help you draft firm, practical pushback before you sign.


If you want a faster way to review a sample limitation of liability clause before you agree to it, try Redline. It scans contracts, highlights risky language in plain English, scores the document, and helps you turn red flags into clean, confident redlines.

Keep reading