Rights and contracts
Liability caps in data licensing agreements: typical structures
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Limitation of liability in a data licensing agreement usually has three tiers: a general cap tied to fees, a higher super cap for data protection and confidentiality breaches, and uncapped carve-outs such as fraud and use beyond the license. Suppliers generally push to keep a buyer's misuse of the data outside any cap tied to fees.
Key takeaways
- Most data licenses separate a general cap, a super cap for data and confidentiality breaches, and uncapped carve-outs.
- The supplier's main exposure comes from its warranties on rights and preparation; the buyer's comes from misuse, re-identification and security failures.
- A broad consequential damages waiver can quietly block the supplier's main remedy for misuse unless misuse is excluded from it.
- Once records are inside a trained model, remedies such as deletion, certification and injunctive relief matter more than the cap amount.
How is liability usually tiered in a data license?#
Liability in a data license is usually tiered so that ordinary breaches share one limit and a few serious categories get a higher limit or none at all. The structure resembles most commercial contracts, but the categories that land in each tier reflect what can go wrong with data in particular.
| Tier | What it usually covers | How the limit is usually set |
|---|---|---|
| General cap | Ordinary breaches such as late delivery, format defects or missed reports | Tied to fees paid or payable over a lookback period |
| Super cap | Data protection, confidentiality and security breaches, and sometimes indemnities | A separate, higher limit, set as a multiple of the general cap or a fixed figure |
| Uncapped carve-outs | Fraud, willful misconduct, use beyond the licensed scope, re-identification, and sometimes IP indemnities | No contractual limit; the ordinary law of damages applies |
| Excluded damages | Indirect and consequential losses and lost profits | Waived for both sides, subject to listed exceptions |
Where does the supplier's exposure come from?#
The supplier's exposure in a data license comes mainly from its warranties and indemnities, not from delivery. A supplier usually warrants that it has the right to license the records, that delivered data was prepared to the agreed standard, and that delivery does not breach its own contracts or privacy commitments.
Those warranties are where a supplier wants the general cap to apply, ideally measured by fees actually received. A supplier should also resist an uncapped indemnity for any third-party claim about the data, offering instead an indemnity limited to claims that its rights warranty was untrue, inside the super cap.
Knowledge qualifiers help here. A rights warranty given to the supplier's knowledge after a documented review is easier to stand behind than an absolute promise about every record in a multi-year archive.
Where does the buyer's exposure come from?#
The buyer's exposure comes from what it does with the records after delivery: using them beyond the permitted use, sharing them, attempting re-identification, failing to secure them or keeping them after the term. Each of those harms lands on the supplier and its customers, and none is within the supplier's control.
That is why suppliers usually push for misuse and re-identification to sit outside every cap. A limit tied to the fees the buyer paid makes little sense when the harm is a privacy incident involving the supplier's own customers. Buyer obligations that suppliers usually keep outside the general cap include the following.
- Use only for the permitted purposes, such as training and evaluation of named model types.
- No re-identification, and no attempt to link records to individuals or companies.
- No resale, sublicensing or disclosure of raw records to other parties.
- Security controls for stored copies, with prompt notice of any incident.
- Deletion of raw records when the term ends, certified in writing.
Which carve-outs do suppliers and buyers argue about?#
The carve-outs that draw the most negotiation are the ones where each side fears open-ended exposure. Suppliers want the buyer's conduct with the data uncapped; buyers want the supplier's rights and privacy promises uncapped, because a defect there can taint a model they have already trained.
A workable middle ground usually treats deliberate conduct as uncapped for both sides and puts warranty-based exposure under the super cap. The table shows the common positions.
| Carve-out | Supplier's usual position | Buyer's usual position |
|---|---|---|
| Use beyond the licensed scope | Uncapped, and outside the damages waiver | Under the super cap |
| Re-identification | Uncapped, with injunctive relief | Uncapped only if intentional |
| Rights warranty | Under the super cap, knowledge-qualified | Uncapped, with no knowledge qualifier |
| Privacy of delivered data | Under the super cap, tied to the agreed preparation standard | Uncapped for any personal information found after delivery |
| Confidentiality | Mutual and under the super cap, except deliberate disclosure | Mutual and under the super cap |
How does the consequential damages waiver interact with the caps?#
The consequential damages waiver can undo a carefully negotiated carve-out. If a buyer misuses records and the supplier's losses are lost customers, regulatory costs or reputational harm, those losses may be characterized as consequential, so a broad mutual waiver can leave the supplier with little to recover even though misuse is nominally uncapped.
The fix is drafting, not a bigger number. Exclude breaches of use restrictions, confidentiality and data protection duties from the waiver, and state that the supplier's costs of investigating an incident, notifying affected people and responding to regulators count as direct damages. Counsel tailors this to the governing law, because courts read these clauses differently.
Why do remedies matter more than cap amounts after training?#
Remedies matter more than cap amounts after training because damages cannot pull records back out of a trained model. A supplier's real protection lies in clear use limits, deletion of raw copies, certification or audit rights and the ability to seek an injunction quickly.
Agree in the contract that misuse causes irreparable harm and that injunctive relief is available. Decide too what happens to models already trained if the license ends early for breach: whether they may keep operating, must stop being offered or must be retrained without the data. Buyers resist the last option strongly, so it is negotiated case by case.
Illustrative: a distributor negotiates its caps#
Illustrative: a fictional industrial distributor licenses de-identified order exception records from NetSuite and its warehouse management system to a model developer building a supply chain agent. The buyer's first draft proposes one mutual cap equal to fees paid and a broad mutual consequential damages waiver.
The distributor's counsel accepts a general cap for the distributor's own warranties, measured by fees received, and agrees a rights indemnity inside a super cap. In return, the buyer's use restrictions, re-identification ban and deletion duty move outside all caps and outside the waiver, and the buyer agrees to certify deletion of raw files.
Both sides accept that the remedy for models already trained is limited to stopping further use of the records. The distributor judges that acceptable because the package was prepared, non-exclusive and limited to exception workflows rather than customer pricing.
How SourceX approaches liability terms#
SourceX ties liability discussions to the facts recorded during the Rights and Preparation steps of the SourceX five-step transaction. A supplier's warranties should match what the SourceX Evidence Packet documents: the provenance of each record family, the licensing rights relied on, the permitted use and the privacy record.
When warranties and documentation line up, a supplier can give narrower, knowledge-based promises with confidence, and the buyer can see the basis for them. The supplier's counsel signs off on the final allocation of risk; SourceX keeps the record that the allocation rests on.
Frequently asked questions
Should liability caps be mutual in a data license?
Mutual caps are common for ordinary breaches, but data licenses are asymmetric: the supplier hands over records and the buyer controls what happens next. Many suppliers accept a mutual general cap while insisting that the buyer's misuse, re-identification and confidentiality duties sit outside it.
Is the cap usually based on fees paid or fees payable?
Both appear. A cap measured by fees paid stays small early in the term, while a cap measured by fees payable counts amounts still due and gives a larger figure when payments are spread out. Suppliers often prefer their own liability measured by fees actually received, because it never exceeds what they were paid.
Should the cap reset each year of a multi-year license?
Some multi-year licenses use an annual cap measured by fees in the prior period, which keeps the limit proportional as payments accrue. Others use one aggregate cap for the whole term. Suppliers usually prefer the aggregate approach for their own liability and separate, uncapped treatment for the buyer's misuse.
Does insurance affect the cap a supplier can accept?
It can. Cyber and technology errors and omissions policies may cover some data-related claims, subject to their terms and exclusions. Ask your broker whether liability you assume by contract in a data license is covered before agreeing a super cap or an indemnity.
Who pays for a data breach at the buyer's end?
Usually the buyer, when the breach stems from its failure to secure the data. Suppliers ask to be indemnified for notification, investigation and regulatory costs, either uncapped or under the super cap, and for prompt notice so they can meet their own obligations to customers and regulators.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.