Limiting liability in SaaS terms

Limitation of liability clauses for a SaaS product's customer terms, drafted for a fixed fee of £995 in five working days.

Share

Limiting liability in SaaS terms

Liability clauses for SaaS terms, drafted to hold against business and consumer customers, covering what cannot be excluded, the statutory tests, the cap and its measure, the exclusion of indirect loss and what that phrase means in England, separate caps for data and confidentiality, indemnities and their place, consumer customers, and the insurance behind the numbers. £995, delivered in five working days.

Buy now, £995

The liability clause is the part of SaaS terms that decides what a bad month costs, and the part most often copied from a document written for a different business in a different country. English law sets what cannot be excluded at all, tests the rest for reasonableness or fairness, and reads phrases such as 'consequential loss' more narrowly than the people who use them expect. The clause has to be built from the statutory tests up: a cap the supplier can justify, exclusions that mean what they say, separate treatment for data and indemnities, and a consumer version where the product is sold to individuals. I draft those clauses, within a set of SaaS terms or as a replacement for the ones in yours, for a fixed fee of £995, delivered in five working days.

Who this is for

SaaS businesses in England and Wales whose liability clause is questioned by enterprise procurement, by an insurer, or by their own reading of it, and who need one drafted to hold under English law for the customers they sell to.

What matters in a SaaS liability clause

What cannot be excluded

Liability for death or personal injury caused by negligence cannot be excluded or limited under section 2 of the Unfair Contract Terms Act 1977, liability for fraud or fraudulent misrepresentation cannot be excluded, and against a consumer the statutory rights in the Consumer Rights Act 2015 cannot be excluded under section 31 for goods, section 47 for digital content and section 57 for services. The clause should carve those out at the top, because a clause that purports to exclude them risks being read against the supplier in its entirety.

The reasonableness test for business customers

Where the terms are the supplier's standard terms, section 3 of the Unfair Contract Terms Act 1977 subjects exclusions and limitations to the reasonableness test in section 11, applied with the guidelines in Schedule 2: the parties' bargaining strength, whether the customer could have contracted elsewhere without the term, whether the customer knew of the term, and whether the supplier could reasonably have insured. A cap tied to the fees paid, with the supplier's insurance behind it, is the shape the courts have accepted; an exclusion of all liability whatever the breach is the shape they have not.

The cap and its measure

The cap should be a stated multiple of the fees paid or payable in the twelve months before the event giving rise to the claim, with a floor where the customer's first year is short, applied in aggregate across all claims in the period rather than per claim, and stated to apply whether the claim is in contract, tort, breach of statutory duty or otherwise. The clause should say whether service credits count towards the cap and whether the cap resets each year, because both are argued after the event if not stated.

Indirect loss and what the words mean

In English law 'indirect or consequential loss' means loss that does not flow naturally from the breach, and an exclusion of it does not exclude loss of profit, loss of business or loss of data that does flow naturally. The clause should therefore list the types of loss excluded by name (loss of profit, revenue, business, anticipated savings, goodwill, and loss or corruption of data beyond the supplier's obligation to restore from backups), whether direct or indirect, so that the exclusion covers what the supplier means it to cover.

Data, confidentiality and indemnities

Enterprise customers ask for data protection and confidentiality breaches to sit outside the general cap, and the clause should offer a separate, higher cap for them that the supplier's cyber insurance supports rather than an uncapped indemnity, with the supplier's IP infringement indemnity and the customer's indemnity for its data and use sitting outside the cap on both sides or inside it symmetrically. Regulatory fines under the Data Protection Act 2018 and compensation claims by individuals should be addressed expressly, because they are the exposure the customer is thinking of.

Consumer customers and a separate clause

Where the product is sold to consumers, the liability clause is tested for fairness under Schedule 2 to the Consumer Rights Act 2015 and must not exclude the statutory rights, including the trader's liability under section 46 for damage to the consumer's device caused by digital content. The clause for consumers should limit liability for other losses to what is fair, exclude losses the consumer could have avoided and business losses, and be kept in a separate section from the business clause rather than applying one to both.

What it costs

SaaS terms of service, £995. Your standard customer-facing terms. Five working days.

Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.

What you get

  • A bespoke contract drafted for how your product is sold, delivered and supported
  • Service levels you can meet, with remedies that are proportionate rather than aspirational
  • A liability position that is defensible and will survive enterprise procurement
  • IP and data provisions that fit together rather than contradicting each other
  • A commercial note on where you will get pushback and what is worth conceding
  • One round of amendments

What is not included

  • Negotiating individual enterprise deals, which I quote separately
  • Advice on the law of jurisdictions outside England and Wales
  • Technical security certification or audit
  • Regulatory advice for regulated sectors such as financial services or health

Questions I am often asked

Can we cap our liability at the fees paid?

For business customers, a cap at the fees paid in the preceding year is the position the courts have accepted as reasonable where the supplier's insurance supports it. The clause is drafted at that level with the aggregate and reset points settled.

Does excluding consequential loss exclude loss of profit?

Not on its own. Loss of profit that flows naturally from the breach is direct loss in English law. The clause lists loss of profit and the other heads by name, whether direct or indirect.

A customer wants an uncapped indemnity for data breaches. What is the alternative?

A separate, higher cap for data claims that your cyber insurance supports, with fines and individuals' claims addressed expressly. Most procurement teams accept a number; the clause is drafted with one.


✉️
Not sure which service fits, or want to ask something first? Email me a few lines about your business and what you need. I reply, usually the same working day.

This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.