What a Limitation of Liability Clause Can't Cap

Most commercial contracts contain a limitation of liability clause that sets a dollar ceiling on what either party owes the other if something goes wrong. That ceiling is often tied to fees paid under the contract, sometimes over the prior twelve months. The negotiation that actually matters, though, rarely happens over the cap amount. It happens over the carve-outs: the list of claims that fall outside the cap entirely, where a party could be on the hook for the full amount of damages regardless of what number sits in the limitation section.

If you have already read a general explanation of what these clauses do, this article picks up where that one leaves off. It covers what typically gets excluded from the cap, why, and the one structural question that founders consistently get wrong: whether the cap applies equally to both sides.

Confidentiality Breaches

Confidentiality obligations protect trade secrets, customer lists, pricing, source code, and other information that has value precisely because it is not public. If a party leaks that information, the damage is often impossible to quantify in a way that lines up with a liability cap tied to contract fees. A vendor who pays you ten thousand dollars a year could cause losses far exceeding that if it discloses your product roadmap to a competitor.

Because of this mismatch, confidentiality breaches are almost always carved out of the cap, or at minimum given a separate, higher cap. Some agreements instead point to injunctive relief as the primary remedy for confidentiality breaches, since money damages are a poor fit when the real harm is disclosure itself, not a quantifiable financial loss.

Intellectual Property Indemnification

Many contracts include an indemnification clause where one party agrees to cover the other's losses if a third party sues over IP infringement, such as a claim that software you licensed actually infringes someone else's patent or copyright. These claims can involve litigation costs, settlement payments, and sometimes an obligation to redesign or replace the infringing product. A cap set at the value of a modest software license does nothing to protect the licensee if a patent holder comes after them for millions.

For this reason, IP indemnification obligations are frequently uncapped, or capped at a multiple of fees rather than the fees themselves. If you are licensing technology into your business, this is one of the first things to check, not the limitation of liability section in isolation. Founders evaluating a contractor relationship should also look at how the contract handles ownership and indemnification together. Our earlier post on who owns code a contractor wrote covers the ownership side of that same relationship.

Gross Negligence and Willful Misconduct

Ordinary negligence, a mistake made despite reasonable care, is the kind of risk a liability cap is built to manage. Gross negligence and willful misconduct are different. Gross negligence generally means a reckless disregard for the obvious risk of harm. Willful misconduct means the party intended the harmful act or knew it was substantially certain to cause harm. North Carolina and Pennsylvania courts both recognize this distinction, though the exact line between ordinary and gross negligence is fact-specific and gets litigated case by case.

Public policy in both states resists letting a party use a contract to shield itself entirely from the consequences of intentional or reckless harm. As a practical matter, this means liability caps should, and usually do, exclude gross negligence and willful misconduct from the capped amount. A contract that tries to cap these anyway invites a court to question the enforceability of the limitation clause as a whole, not just as to that carve-out.

Data Breaches

If your business collects customer data, handles payment information, or processes data on behalf of clients, a data breach carve-out deserves specific attention rather than being lumped in as an afterthought. Breach response costs add up fast: forensic investigation, notification to affected individuals, credit monitoring, regulatory inquiries, and sometimes contractual penalties owed to the party whose customers were affected.

Vendors handling sensitive data will often resist an uncapped exposure here, proposing instead a separate, elevated cap specific to data breach claims, distinct from the general contract cap. Whether that is acceptable depends on the volume and sensitivity of data involved and what your own exposure looks like if the vendor's systems fail. This is squarely the kind of provision we address in vendor contract reviews. See our posts on vendor agreements that protect user data and what to put in a data processing agreement for related provisions that work alongside the liability section.

Should the Cap Be Mutual?

The carve-outs get the attention, but the question that changes the whole negotiation is simpler: does the cap apply to both parties equally, or only to one? Vendors drafting their own agreements frequently cap their own liability tightly while leaving the customer's obligations, like payment, uncapped. A one-way cap can be appropriate when the risk genuinely runs in one direction, but in many commercial relationships both sides carry real exposure and a one-sided cap simply shifts risk rather than managing it fairly.

Before accepting a cap as written, ask what it would mean in the worst realistic scenario for your business, not the best case the other side is pitching. If you are a growing company negotiating contracts with vendors, customers, or partners on a regular basis, having standard carve-out language and a position on mutuality saved to your own templates avoids relitigating this every time.

Where This Fits Into a Broader Contract Strategy

Liability provisions do not work in isolation. They interact with indemnification clauses, insurance requirements, and the underlying scope of work. A business that negotiates contracts regularly, whether as a startup signing vendor agreements or a growing company issuing its own customer contracts, benefits from having these provisions reviewed as a set rather than one clause at a time. Our startup and business law practice works with founders on exactly this kind of contract architecture, and companies that need this kind of review on an ongoing basis sometimes find a fractional general counsel arrangement more cost-effective than sending each contract out individually.

If you are negotiating a contract with a liability clause that concerns you, whether as the party trying to limit exposure or the party worried about what is excluded from a cap, reach out to our team before you sign.

Questions about your own situation?

Tell us briefly what's going on. An attorney will follow up to confirm a time.

Schedule a Free Consultation

Schedule a Free Consultation

An attorney will follow up to confirm a time.

Submitting this form does not create an attorney-client relationship. Please avoid sharing confidential details until we've confirmed we can take on your matter.