[codicts-css-switcher id=”346″]

Global Law Experts Logo
limitation of liability technology contracts india

Limitation of Liability in Technology Contracts, India 2026: Enforceability, Caps, Carve-outs & Drafting Strategy

By Global Law Experts
– posted 45 minutes ago

Limitation of liability technology contracts india has become a decisive negotiating battleground in 2026, as the Digital Personal Data Protection Act, 2023 and the evolving framework of rules under the Information Technology Act, 2000 reshape where financial exposure actually lands when something goes wrong. For in-house counsel, procurement leads and founders closing cloud, SaaS, platform and AI agreements, the old habit of copying a boilerplate cap into a services contract now carries real risk: intermediary due-diligence obligations, emerging rules on synthetically generated information and personal-data penalties have opened new exposure points that a poorly drafted liability clause cannot contain.

This guide sets out the enforceability tests under Indian contract law, the practical cap structures buyers and vendors are negotiating today, how indemnities should interact with caps and carve-outs, and the specific clause language that survives scrutiny in the current environment. It is written to be used at the drafting table, not read as theory.

Who this is for: in-house counsel, procurement leads, founders and outside counsel negotiating Indian technology agreements in 2026 who need defensible, enforcement-aware liability and indemnity language in light of the DPDP Act and the IT Act rules framework.

Executive summary and recommended approach

Before you get into clause mechanics, three principles should anchor every negotiation over risk allocation clauses india:

  • Enforceability first. Limitation and exclusion clauses are generally enforceable in India where freely negotiated between commercial parties, but they will not stand where they are unconscionable, defeat the main purpose of the contract, or attempt to contract out of a statutory liability that the law does not permit parties to allocate away. Draft with those limits in mind.
  • Match the cap to the deal and the risk. A fees-based cap suits standard, predictable services; multiples of fees suit longer or higher-risk engagements; a negotiated super-cap or an insurance-backed cap suits large platform, cloud and AI deals where a single incident can dwarf the fees paid. There is no single “market” number, the right cap is a function of contract value and regulatory exposure.
  • Keep the highest-risk liabilities outside the cap. As a rule of thumb, indemnities for IP infringement, data breaches, bodily injury, and losses caused by fraud, gross negligence or wilful misconduct sit above the general cap, either uncapped or under a separate super-cap. Everything else lives under the aggregate cap. Say so expressly, silence invites disputes.

The rest of this article turns each of these principles into tested clause language and a negotiation playbook you can apply to any tech services agreement india.

Enforceability & legal tests for limitation of liability technology contracts india

Indian contract law starts from freedom of contract. The Indian Contract Act, 1872 governs the formation and validity of commercial bargains, and courts will ordinarily give effect to a limitation or exclusion of liability india clause that two informed commercial parties have negotiated. That freedom, however, is not absolute. Three constraints determine whether a clause will actually hold when tested.

First, public policy and unlawful objects. Under Section 23 of the Indian Contract Act, an agreement is void where its object or consideration is unlawful or opposed to public policy. This is why you cannot draft your way out of every consequence: where a statute imposes a liability or penalty on a party in the public interest, for example, penalties under the DPDP Act, a contract term purporting to shift or extinguish that statutory liability between the parties will not bind the regulator, and may itself be treated as contrary to public policy.

Second, unconscionability and inequality of bargaining power. Indian courts have long scrutinised clauses in standard-form contracts where one party had no genuine opportunity to negotiate. A cap that is manifestly one-sided, imposed on a party with no bargaining power, and that operates unfairly is vulnerable. Between sophisticated commercial parties with legal advice, this risk is low; in mass-market or consumer-facing terms it is much higher.

Third, defeating the main purpose of the contract. A clause so broad that it effectively frees a party from any obligation to perform at all, reducing the contract to a mere declaration of intent, may be read down. The practical drafting lesson is to avoid absolute exclusions of all liability for core performance failures and instead build a layered structure: a general cap, carve-outs for defined high-risk categories, and a narrow list of truly excluded loss types.

A further point that in-house counsel routinely miss: exclusion clauses are construed strictly and, where ambiguous, against the party relying on them. Precise, unambiguous drafting is therefore not merely tidy, it is what makes the clause enforceable.

Key enforceability takeaways for exclusion of liability india

  • Commercial bargains are respected, freely negotiated caps between informed parties are generally upheld under the Indian Contract Act, 1872.
  • Statutory and regulatory liabilities resist contracting out, penalties imposed by regulators under the DPDP Act and the IT Act framework cannot simply be waived away as between the parties in a way that binds the State.
  • Unconscionable, one-sided clauses are vulnerable, particularly in non-negotiated standard-form terms.
  • Exclusion clauses are read strictly, draft with precision; ambiguity is generally construed against the party relying on the exclusion.
  • Do not exclude everything, a clause that defeats the fundamental purpose of the contract risks being read down.

Choosing and structuring liability caps

The liability cap india is the single most negotiated figure in a technology contract. There is no statutory formula; the cap is a commercial risk-allocation decision. Understanding the standard structures, and the buyer and vendor positions on each, lets you move quickly to a defensible landing zone.

A fees-based cap ties the ceiling to the fees paid under the agreement, commonly expressed as one hundred per cent of total or annual fees. Vendors favour this because it aligns maximum exposure to revenue earned. Buyers accept it for low-risk, commodity services but resist it where a single failure could cause loss far exceeding the fees, a data breach in a small-fee processing contract is the classic mismatch.

A multiple-of-fees cap (typically two to five times fees) is the compromise for higher-risk or longer engagements. It gives the buyer more headroom for losses tied to service stoppage or migration while keeping the vendor’s exposure proportionate and calculable. The multiple should scale with criticality: mission-critical infrastructure warrants a higher multiple than a peripheral tool.

A super-cap sets an absolute monetary ceiling, independent of fees, for specified high-risk categories, data breaches, confidentiality failures, or IP infringement. Enterprise cloud and platform deals routinely layer a low general cap (fees-based) over a materially higher super-cap for the categories that keep the buyer’s board awake. This is the most flexible structure because it lets parties price different risks differently in the same contract.

An insurance-backed cap requires the vendor to maintain a minimum level of cyber or technology errors-and-omissions cover and, in effect, allows recovery up to policy limits for insured events. This is common market practice for large deals with significant data or AI risk. The catch is that policy sublimits, exclusions and the claims process all sit between the buyer and actual recovery, so an insurance requirement should sit alongside, not instead of, a contractual cap.

Cap examples and clause snippets

Illustrative drafting only, adapt to the specific deal and have counsel review before use.

  • Fees-based cap: “Subject to the carve-outs in Clause [X], each party’s total aggregate liability arising out of or in connection with this Agreement shall not exceed one hundred per cent (100%) of the fees paid or payable by the Customer under this Agreement in the twelve (12) months preceding the event giving rise to the claim.”
  • Multiple-of-fees cap: “…shall not exceed an amount equal to three (3) times the total fees paid or payable in the twelve (12) months preceding the first event giving rise to a claim, whether such liability arises in contract, tort or otherwise.”
  • Super-cap plus insurance requirement: “Notwithstanding Clause [general cap], the Supplier’s aggregate liability for breaches of Clause [Data Protection] shall not exceed INR [•] crore (the ‘Data Super-Cap’). The Supplier shall maintain cyber liability insurance of not less than the Data Super-Cap throughout the Term and on request provide evidence of coverage.”

Comparison table, cap structures at a glance

The table below compares the four common cap structures used in Indian technology contracts. Ranges are illustrative of market practice and should be adjusted for deal size, criticality and regulatory exposure rather than treated as fixed benchmarks.

Cap type When to use Pros Cons Typical range (India)
Fees-based cap (total fees paid) Small or standard services agreements with predictable revenue Aligns risk to contract value; easy to calculate May be too low for data breaches or regulatory fines 100%–200% of annual fees
Multiple-of-fees (2x–5x) Higher-risk services or longer engagements Better coverage for consequential loss tied to service stoppage Still may not cover catastrophic regulatory penalties 2x–5x of fees
Super-cap (absolute figure above fees) Large platform or cloud deals Cap not tied to fees; tailored to vendor risk appetite Harder to justify on small deals; negotiation friction Negotiated per deal; often high for enterprise
Insurance-backed cap (minimum policy) High cyber, data or AI-model risk Transfers risk; common for large deals Sublimits, exclusions and claims process still apply Policy limits negotiated per risk profile

Indemnities, caps & carve-outs, interaction and drafting strategy

Indemnity clauses india are where the most expensive drafting mistakes are made, because an indemnity that is silent on its relationship to the cap will be argued both ways. The core question is simple to state and easy to get wrong: does the indemnity sit inside the general liability cap, or outside it?

If you intend an indemnity to be recoverable above the general cap, as buyers almost always want for IP infringement and data protection breaches, the contract must say so in express words. A clean structure is: a general aggregate cap; a defined list of carve-outs that are excluded from that cap; and, for those carve-outs, either no cap at all or a separate super-cap. Leaving the interaction implicit is a common source of post-signing disputes.

The categories that are conventionally carved out of the general cap are consistent across well-drafted Indian technology agreements:

  • IP infringement, third-party claims that the supplier’s technology infringes intellectual property rights.
  • Data protection and security breaches, increasingly the highest-value carve-out given DPDP exposure.
  • Breach of confidentiality, misuse or unauthorised disclosure of confidential information.
  • Bodily injury and damage to tangible property.
  • Fraud, gross negligence and wilful misconduct.

Beyond the carve-out list, several mechanics determine whether an indemnity is actually collectable: the survival period (indemnities for IP and data claims should survive termination and run for a defined tail); priority of recovery where insurance also responds; and clear notice, cooperation and defence-control obligations so that a delayed or mishandled claim does not become a ground to deny the indemnity.

Drafting best practices for indemnities and gross negligence wilful misconduct india

  • Define the triggering events precisely. “Third-party claim arising from” is clearer than a vague reference to “any loss connected with.”
  • Allocate defence control. State who controls the defence and settlement, and prohibit settlements that admit liability or impose non-monetary obligations on the indemnified party without consent.
  • Address subrogation and double recovery. Where insurance responds, provide that recovery under the indemnity is net of insurance proceeds actually received.
  • State the cap interaction expressly. “The indemnity in Clause [X] is not subject to the limitation of liability in Clause [Y]” leaves no room for argument.
  • Impose reasonable notice and cooperation as conditions, but avoid making minor procedural failures a complete bar to recovery, which courts may treat as unfair.

Excluding consequential, indirect and loss of profit damages

Excluding consequential damages india is standard practice, and courts will generally give effect to a clear exclusion of indirect or consequential losses negotiated between commercial parties. The difficulty is definitional. Indian law does not treat “consequential loss” as a fixed category; the recoverability of a loss under Section 73 of the Indian Contract Act depends heavily on remoteness and foreseeability at the time of contracting. A loss that both parties could reasonably contemplate as arising from a breach may be recoverable even if labelled “consequential”, so drafting that simply excludes “all consequential losses” without a defined list invites dispute.

The robust approach is the “black-letter exclusion plus liability ladder.” First, exclude specific, enumerated heads of loss, loss of profits, loss of revenue, loss of anticipated savings, loss of goodwill, loss of data (subject to carve-out), and pure economic loss, rather than relying on the word “consequential” alone. Second, carve back the losses the buyer genuinely needs to recover, such as the cost of procuring replacement services or the cost of restoring lost data, and confirm those sit within the general cap rather than being excluded entirely.

Buyers should resist any exclusion that sweeps up losses flowing directly from a data breach, because those are frequently the losses that matter most and are often the intended subject of a separate indemnity and super-cap. Aligning the consequential-loss exclusion with the indemnity carve-outs prevents the exclusion from silently swallowing the protection the indemnity was meant to give.

Sample clause: broad exclusion with narrow carve-outs

Illustrative drafting only. “Subject to Clause [carve-outs], neither party shall be liable for any loss of profits, loss of revenue, loss of anticipated savings, loss of goodwill, or any indirect or consequential loss, in each case whether arising in contract, tort or otherwise. This exclusion does not apply to the Customer’s costs of procuring replacement services or of restoring data lost as a result of the Supplier’s breach, which shall be recoverable subject to the cap in Clause [general cap].”

Gross negligence, wilful misconduct & fraud, definitions, burden and drafting

Carve-outs for gross negligence wilful misconduct india are near-universal, yet the terms are often left undefined, which is precisely where enforcement risk creeps in. “Gross negligence” is not a term of art with a settled statutory definition in India, and a court asked to apply an undefined standard will construe it narrowly. If the parties intend a meaningful carve-out, they should define it.

Fraud stands apart: a party generally cannot contractually exclude liability for its own fraud, and any clause purporting to do so is at high risk of being unenforceable and may taint surrounding provisions. Wilful misconduct, deliberate wrongdoing or reckless disregard of a known duty, and gross negligence, a serious departure from the standard of care, beyond ordinary carelessness, should each be defined with an objective test so that the carve-out cannot be triggered by ordinary performance shortfalls dressed up as “gross.”

The drafting objective is to make the carve-out real without making it a loophole that swallows the cap. Two techniques help: an objective definition tied to the conduct rather than the outcome, and a requirement that the party alleging gross negligence or wilful misconduct bears the burden of proving the higher standard. Materiality and notice thresholds prevent every routine breach being re-characterised to escape the cap.

Sample carve-out wording and evidentiary notes

Illustrative drafting only. “Nothing in this Agreement limits or excludes either party’s liability for fraud, fraudulent misrepresentation, gross negligence or wilful misconduct. For these purposes, ‘gross negligence’ means conduct that constitutes a significant departure from the standard of care a reasonable supplier would exercise, and ‘wilful misconduct’ means intentional wrongdoing or reckless disregard of a known duty. The party asserting gross negligence or wilful misconduct bears the burden of proving it.”

DPDP Act & IT Act rules, implications for limitation of liability technology contracts india

The regulatory framework changes the risk map for limitation of liability technology contracts india in three concrete ways: personal-data penalties under the Digital Personal Data Protection Act, 2023, due-diligence obligations on intermediaries under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and emerging obligations around synthetically generated information flowing from amendments to those Rules administered by the Ministry of Electronics and Information Technology (MeitY).

The first practical point is that regulatory penalties are not freely contractable. Where a regulator imposes a penalty on a party for its own breach of a statutory obligation, the parties cannot, as between themselves, extinguish that penalty in a way that binds the State. Under the DPDP Act, financial penalties are determined by the Data Protection Board of India within the maximum limits set out in the Act. What the parties can do is allocate the commercial consequences, the cost of remediation, notification, credit monitoring, and defending third-party claims, through indemnities and pass-through provisions.

Draft the DPDP indemnity to cover those commercial costs expressly, and be realistic that a bare “indemnify against all fines” clause may be unenforceable as to the statutory penalty itself.

The second point concerns allocation of compliance responsibility. Under the DPDP Act, the parties should record clearly who is the Data Fiduciary (the entity that determines the purpose and means of processing) and who is the Data Processor acting on the Fiduciary’s behalf, because that allocation drives which party bears which statutory obligation and, in turn, which liabilities the contract should route where. Compliance covenants, breach-notification timing, and joint incident-response obligations should be spelled out rather than left to a generic “comply with applicable law” clause.

The third point is synthetically generated content and generative-AI outputs. Intermediary due-diligence obligations and evolving requirements around synthetically generated information mean that platform and AI-model contracts should now carry specific carve-outs and covenants addressing the outputs of third-party or generative models, mislabelled or manipulated content, and the diligence steps each party must take. Cross-border best practice, reflected in the OECD’s AI principles, supports AI-specific risk allocation, dedicated carve-outs and insurance for these exposures rather than folding them into a generic technology cap.

Drafting checklist for DPDP and IT rules scenarios

  • Record the Data Fiduciary / Data Processor allocation and tie each statutory obligation to the responsible party.
  • Include a data-breach indemnity covering remediation, notification and third-party claim costs, and price it under a super-cap.
  • Set express breach-notification timelines and joint incident-response obligations consistent with DPDP requirements.
  • Add synthetic-content and generative-AI covenants and carve-outs for platform and AI deals.
  • Require evidence of appropriate technical and organisational security safeguards as a condition, not an aspiration.

Insurance, caps & third-party risk transfer

Insurance is the mechanism that makes a large cap or super-cap collectable in practice. For deals with material cyber, data or AI exposure, require the vendor to maintain cyber liability and technology errors-and-omissions cover at limits that are meaningful against the identified risk, and require proof of coverage, a certificate of insurance, at signing and on renewal. Pay attention to the interaction between the policy limit and the retention (the vendor’s own deductible), because a high limit with a high retention still leaves the vendor exposed for the first tranche of loss. Where the buyer wants first recourse, specify primary versus excess placement, and confirm that the insurance obligation supplements the contractual indemnity rather than capping recovery at policy limits.

Sublimits and policy exclusions should be reviewed so that the very events you care about most are not carved out of the cover.

Negotiation checklist & red lines

Use this checklist to score risk quickly and identify walk-away thresholds when negotiating risk allocation clauses india:

  • Is the general cap proportionate to deal value and criticality? (Red line: fees-based cap on mission-critical data processing.)
  • Are IP infringement and data-breach indemnities expressly outside the general cap? (Red line: silence on cap interaction.)
  • Is fraud liability preserved and unexcludable? (Non-negotiable.)
  • Are gross negligence and wilful misconduct defined objectively?
  • Is there a DPDP-specific data indemnity with a super-cap and notification timelines?
  • Does the vendor carry cyber / tech E&O cover at adequate limits, with proof? (Red line: no cover on high-risk AI or data deals.)
  • Are synthetic-content and generative-AI risks addressed for platform deals?
  • Is the consequential-loss exclusion aligned with the indemnity carve-outs?

Clause bank, short templates & drafting notes

All templates below are illustrative and require counsel review and jurisdiction-specific tailoring before use.

  • Liability cap. “Each party’s total aggregate liability under this Agreement shall not exceed [100%/3x] of the fees paid in the preceding twelve months.” Note: fix the reference period and whether it is per-claim or aggregate.
  • Exclusion of consequential damages. “Neither party is liable for loss of profits, revenue, goodwill, or indirect or consequential loss.” Note: enumerate heads of loss; do not rely on “consequential” alone.
  • IP indemnity. “The Supplier shall indemnify the Customer against third-party claims that the Services infringe intellectual property rights.” Note: carve out of general cap; add defence control.
  • Data-breach indemnity and cap carve-out. “The Supplier shall indemnify the Customer for remediation, notification and third-party claim costs arising from a personal-data breach, subject to the Data Super-Cap.” Note: exclude from general cap; align with DPDP notification requirements.
  • Gross negligence carve-out. “Nothing limits liability for fraud, gross negligence or wilful misconduct, as defined in Clause [X].” Note: define terms objectively; allocate burden of proof.
  • Insurance. “The Supplier shall maintain cyber and technology E&O insurance of not less than INR [•] and provide evidence on request.” Note: check sublimits, retention and primary/excess placement.

Conclusion

Getting limitation of liability technology contracts india right in 2026 is less about winning the headline cap number and more about building a coherent structure: an enforceable general cap, express carve-outs for the liabilities that matter, indemnities that clearly sit inside or outside that cap, and insurance that makes the whole thing collectable. The DPDP Act and the evolving IT Act rules framework have raised the stakes on data-breach and synthetic-content exposure, and a clause drafted before those shifts is unlikely to allocate the new risks where the parties intend.

Treat the enforceability tests, the cap structures and the carve-out discipline in this guide as a connected playbook rather than a menu, and pressure-test every template against the specific deal and its regulatory footprint. Given how quickly the framework is moving, parties revising their technology agreements should take qualified Indian counsel before finalising liability and indemnity language.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Mitakshara Goyal at Svarniti Law Offices, a member of the Global Law Experts network.

Sources

  1. Ministry of Electronics & Information Technology (MeitY)
  2. IndiaCode, Central Legislation Repository
  3. OECD, AI Principles

FAQs

Are limitation of liability clauses enforceable under Indian law for technology services?
Yes. Limitation and exclusion clauses freely negotiated between commercial parties are generally enforceable under the Indian Contract Act, 1872, provided they are not unconscionable, do not defeat the main purpose of the contract, and are not contrary to public policy. Certain statutory liabilities and regulatory penalties cannot be contracted away in a manner that binds the regulator.
There is no fixed rule. Common approaches are a fees-based cap of 100–200% of fees, a multiple of two to five times fees for higher-risk engagements, or a negotiated super-cap or insurance-backed cap for large data or AI deals. Choose based on deal value, criticality and regulatory exposure.
Yes, parties can contractually exclude indirect and consequential losses, but recoverability turns on remoteness and foreseeability at the time of contracting under Section 73 of the Indian Contract Act. Enumerate the excluded heads of loss rather than relying on the word “consequential,” and carve back losses the buyer genuinely needs, such as replacement-service and data-restoration costs.
Indemnities for high-risk categories such as IP infringement and data breaches usually sit outside the general cap, but only if the contract says so expressly. Clarify the cap interaction, survival periods, defence control and subrogation to ensure the indemnity is actually collectable.
The statutory penalty itself may not be transferable in a way that binds the regulator. However, indemnities for remediation costs, notification expenses and third-party claims flowing from a breach are commonly used and enforceable. Check the specific statutory language and regulator guidance and draft the indemnity around the recoverable commercial costs.
investing in startups south korea
By Global Law Experts

posted 53 minutes ago

dubai company formation
By Jonathon Richards

posted 55 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Limitation of Liability in Technology Contracts, India 2026: Enforceability, Caps, Carve-outs & Drafting Strategy

Send welcome message

Custom Message