Definitions and comparisons
What is a limitation of liability cap in a data license?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A limitation of liability cap in a data license sets the most either party can owe for claims under the contract. Most clauses combine a waiver of indirect damages, a general cap, uncapped carve-outs and sometimes a higher super cap for privacy, security or IP claims. For data owners, the key question is which risks sit above the cap.
Key takeaways
- A liability cap limits damages for claims under the contract; it does not usually limit the fees either side has agreed to pay.
- Carve-outs decide more than the cap amount, because the largest risks are usually the ones taken out of the cap.
- Data owners are exposed mainly through their warranties and indemnities about rights and privacy, not through delivery itself.
- A buyer's use of records beyond the license is the risk owners most often keep outside any cap.
- The cap should line up with insurance, so check whether your policies respond to licensing activity at all.
What does a limitation of liability clause contain?#
A limitation of liability clause contains the rules that limit how much, and what kind of, loss each party can recover from the other. In a data license it usually has four parts, and reading them in order shows where the real exposure sits.
The parts interact. A generous cap means little if the waiver of indirect damages excludes the losses you would actually suffer, and a strict cap matters less if the risks you care about are carved out of it. Many US states also limit how far a contract can excuse fraud or intentional misconduct, which is one reason those carve-outs appear in most drafts.
- A waiver of indirect, consequential, special and punitive damages, such as lost profits or lost business.
- A general cap on all other damages, often tied to the fees under the license.
- Carve-outs: categories excluded from the waiver, the cap or both.
- Super caps: separate, higher limits for named risks such as data protection, security or IP claims.
How is the cap usually measured?#
The cap is usually measured by reference to fees paid or payable under the license over a defined period, though some contracts use a fixed amount or the greater of the two. Each method has a consequence in a data deal.
Fee-based caps can be very low early in a license, before most payments are made, or where pricing is one upfront fee. A cap measured on fees paid during a lookback period can shrink to almost nothing if a claim arises late in the term. Owners often ask for fees paid or payable over the whole term, or a fixed floor.
A mutual cap looks balanced but may not be. The buyer's main obligation is to pay, and unpaid fees usually sit outside the cap; the supplier's main exposure is its warranties. Work out what each party could realistically be liable for before agreeing that one number fits both.
An illustrative structure, line by line#
An illustrative structure shows how the parts fit together. The table is a teaching example, not recommended terms; real clauses depend on the records, the price and each side's risk.
| Element | Illustrative approach | Who it mainly protects | Question for the owner |
|---|---|---|---|
| Indirect damages waiver | Mutual waiver of lost profits and consequential loss | Both, mostly the party facing larger downstream claims | Does it block recovery when the buyer misuses the records? |
| General cap | Fees paid or payable under the license | Both | Is the cap meaningful if most fees arrive later? |
| Super cap | A higher, separate limit for data protection and confidentiality breaches | The party facing claims in those areas | Does it apply to the supplier, the buyer or both? |
| Uncapped carve-outs | Fraud, gross negligence, willful misconduct, use beyond the license, breach of confidentiality | The party whose data or secrets are at risk | Is buyer misuse explicitly outside the cap? |
| Indemnities | Supplier covers third-party rights claims; buyer covers claims from its own use | The party facing third-party claims | Is each indemnity capped, super capped or uncapped? |
| Fees owed | Payment obligations excluded from the cap | The supplier | Are late payments and audit shortfalls included? |
Where a data owner's exposure comes from#
A data owner's exposure comes mainly from promises about the records: that it had the right to license them and that they were prepared as described. If a customer, vendor or former employee claims the records were not yours to license, or personal information turns up after a de-identification warranty, the claim lands on those promises.
That is why owners care about the scope of their warranties as much as the cap. A warranty that records were de-identified using an agreed, documented method is easier to stand behind than a promise that they contain no personal information at all. The stronger the preparation record, the narrower the warranty can safely be.
Exposure also depends on what is in the package. Records drawn from internal engineering discussions carry different risk from records built on customer support conversations, so the cap and any super cap for a first package should reflect its actual contents rather than a template carried over from another deal.
Uncapped indemnities and why buyers ask for them#
Buyers ask for uncapped indemnities on rights and privacy because a third-party claim against a model developer can be large and hard to predict. An uncapped indemnity from the supplier shifts that risk to the party least able to price it.
Common middle positions are a super cap for those indemnities, an indemnity limited to claims caused by the supplier's breach of its own warranties, and control-of-defense terms so the supplier can manage a claim it is paying for. Owners also ask for the reverse indemnity: the buyer covers claims arising from its own training, outputs and products.
How insurance fits the cap#
Insurance fits the cap by funding it: a cap you cannot pay protects nobody, and a cap above your coverage is risk carried on your own balance sheet. The CFO and the broker should review the clause before signing, not after a claim.
- Does the cyber or technology errors and omissions policy cover licensing data, or only operating your own services?
- Are liabilities assumed under a contractual indemnity covered or excluded?
- Does the policy require insurer consent before you agree to certain terms?
- Do the super cap and the policy limits line up, including defense costs?
Illustrative: a property management software company sets its first cap#
Illustrative: a fictional property management software company plans to license de-identified support tickets and linked Jira issues. The buyer's draft has a mutual cap at fees paid in a lookback period, a mutual waiver of indirect damages and an uncapped supplier indemnity for privacy and IP claims.
The CFO and general counsel respond with four changes: the cap measured on fees payable over the whole term, the buyer's use beyond the license and breach of confidentiality left uncapped, the supplier's indemnity limited to breaches of its warranties under a super cap, and the indirect damages waiver not applying to misuse. They attach the preparation method to the de-identification warranty.
After negotiation the parties agree on the super cap and the misuse carve-out, and the company's broker confirms its technology policy responds to the indemnity. The final structure matches what the company can insure and evidence.
How SourceX approaches liability terms#
SourceX keeps liability discussions anchored to documented facts. Warranties about rights and preparation rest on the work done in the Rights and Preparation steps of the SourceX five-step transaction, and the supplier approves the final contract, with its own counsel, before Delivery.
Because the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization, there is less room for later disagreement about what was licensed and how it was prepared.
Frequently asked questions
Does the cap limit the fees the buyer has to pay?
Usually not. Most licenses exclude payment obligations from the cap, so the buyer owes the agreed fees regardless. Check that the exclusion also covers late charges, amounts found due in an audit and fees for use beyond the license, if the contract provides for them.
Should failure to delete data sit inside or outside the cap?
Owners usually treat failure to delete at term end as use beyond the license or a confidentiality breach, both often outside the general cap. Buyers may push for a super cap instead. Whatever is agreed, the deletion duty should be clear enough that a breach is easy to identify.
Is a mutual cap fair in a data license?
Not necessarily. The parties face different risks: the supplier's main exposure is its warranties and indemnities, while the buyer's is misuse of the records. A single mutual number can leave one side well protected and the other not, so test the cap against each party's realistic claims.
Can model outputs that reproduce our records fall outside the cap?
They can, if the contract says so. Owners sometimes treat outputs that reproduce licensed records verbatim as use beyond the license or a confidentiality breach. Whether that works as drafted, and how it would be proven, are questions for counsel during negotiation.
Does the cap stop us from seeking an injunction?
Usually not. A cap limits money damages, while an injunction orders a party to stop doing something, such as using records beyond the license. Owners often add an express right to seek injunctive relief for misuse or confidentiality breaches, because money alone may not undo the harm once records have been used in training.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.