Our Expert in India
No results available
Limitation of liability technology contracts india has become a decisive negotiating battleground in 2026, as the Digital Personal Data Protection Act, 2023 and the evolving framework of rules under the Information Technology Act, 2000 reshape where financial exposure actually lands when something goes wrong. For in-house counsel, procurement leads and founders closing cloud, SaaS, platform and AI agreements, the old habit of copying a boilerplate cap into a services contract now carries real risk: intermediary due-diligence obligations, emerging rules on synthetically generated information and personal-data penalties have opened new exposure points that a poorly drafted liability clause cannot contain.
This guide sets out the enforceability tests under Indian contract law, the practical cap structures buyers and vendors are negotiating today, how indemnities should interact with caps and carve-outs, and the specific clause language that survives scrutiny in the current environment. It is written to be used at the drafting table, not read as theory.
Who this is for: in-house counsel, procurement leads, founders and outside counsel negotiating Indian technology agreements in 2026 who need defensible, enforcement-aware liability and indemnity language in light of the DPDP Act and the IT Act rules framework.
Before you get into clause mechanics, three principles should anchor every negotiation over risk allocation clauses india:
The rest of this article turns each of these principles into tested clause language and a negotiation playbook you can apply to any tech services agreement india.
Indian contract law starts from freedom of contract. The Indian Contract Act, 1872 governs the formation and validity of commercial bargains, and courts will ordinarily give effect to a limitation or exclusion of liability india clause that two informed commercial parties have negotiated. That freedom, however, is not absolute. Three constraints determine whether a clause will actually hold when tested.
First, public policy and unlawful objects. Under Section 23 of the Indian Contract Act, an agreement is void where its object or consideration is unlawful or opposed to public policy. This is why you cannot draft your way out of every consequence: where a statute imposes a liability or penalty on a party in the public interest, for example, penalties under the DPDP Act, a contract term purporting to shift or extinguish that statutory liability between the parties will not bind the regulator, and may itself be treated as contrary to public policy.
Second, unconscionability and inequality of bargaining power. Indian courts have long scrutinised clauses in standard-form contracts where one party had no genuine opportunity to negotiate. A cap that is manifestly one-sided, imposed on a party with no bargaining power, and that operates unfairly is vulnerable. Between sophisticated commercial parties with legal advice, this risk is low; in mass-market or consumer-facing terms it is much higher.
Third, defeating the main purpose of the contract. A clause so broad that it effectively frees a party from any obligation to perform at all, reducing the contract to a mere declaration of intent, may be read down. The practical drafting lesson is to avoid absolute exclusions of all liability for core performance failures and instead build a layered structure: a general cap, carve-outs for defined high-risk categories, and a narrow list of truly excluded loss types.
A further point that in-house counsel routinely miss: exclusion clauses are construed strictly and, where ambiguous, against the party relying on them. Precise, unambiguous drafting is therefore not merely tidy, it is what makes the clause enforceable.
The liability cap india is the single most negotiated figure in a technology contract. There is no statutory formula; the cap is a commercial risk-allocation decision. Understanding the standard structures, and the buyer and vendor positions on each, lets you move quickly to a defensible landing zone.
A fees-based cap ties the ceiling to the fees paid under the agreement, commonly expressed as one hundred per cent of total or annual fees. Vendors favour this because it aligns maximum exposure to revenue earned. Buyers accept it for low-risk, commodity services but resist it where a single failure could cause loss far exceeding the fees, a data breach in a small-fee processing contract is the classic mismatch.
A multiple-of-fees cap (typically two to five times fees) is the compromise for higher-risk or longer engagements. It gives the buyer more headroom for losses tied to service stoppage or migration while keeping the vendor’s exposure proportionate and calculable. The multiple should scale with criticality: mission-critical infrastructure warrants a higher multiple than a peripheral tool.
A super-cap sets an absolute monetary ceiling, independent of fees, for specified high-risk categories, data breaches, confidentiality failures, or IP infringement. Enterprise cloud and platform deals routinely layer a low general cap (fees-based) over a materially higher super-cap for the categories that keep the buyer’s board awake. This is the most flexible structure because it lets parties price different risks differently in the same contract.
An insurance-backed cap requires the vendor to maintain a minimum level of cyber or technology errors-and-omissions cover and, in effect, allows recovery up to policy limits for insured events. This is common market practice for large deals with significant data or AI risk. The catch is that policy sublimits, exclusions and the claims process all sit between the buyer and actual recovery, so an insurance requirement should sit alongside, not instead of, a contractual cap.
Illustrative drafting only, adapt to the specific deal and have counsel review before use.
The table below compares the four common cap structures used in Indian technology contracts. Ranges are illustrative of market practice and should be adjusted for deal size, criticality and regulatory exposure rather than treated as fixed benchmarks.
| Cap type | When to use | Pros | Cons | Typical range (India) |
|---|---|---|---|---|
| Fees-based cap (total fees paid) | Small or standard services agreements with predictable revenue | Aligns risk to contract value; easy to calculate | May be too low for data breaches or regulatory fines | 100%–200% of annual fees |
| Multiple-of-fees (2x–5x) | Higher-risk services or longer engagements | Better coverage for consequential loss tied to service stoppage | Still may not cover catastrophic regulatory penalties | 2x–5x of fees |
| Super-cap (absolute figure above fees) | Large platform or cloud deals | Cap not tied to fees; tailored to vendor risk appetite | Harder to justify on small deals; negotiation friction | Negotiated per deal; often high for enterprise |
| Insurance-backed cap (minimum policy) | High cyber, data or AI-model risk | Transfers risk; common for large deals | Sublimits, exclusions and claims process still apply | Policy limits negotiated per risk profile |
Indemnity clauses india are where the most expensive drafting mistakes are made, because an indemnity that is silent on its relationship to the cap will be argued both ways. The core question is simple to state and easy to get wrong: does the indemnity sit inside the general liability cap, or outside it?
If you intend an indemnity to be recoverable above the general cap, as buyers almost always want for IP infringement and data protection breaches, the contract must say so in express words. A clean structure is: a general aggregate cap; a defined list of carve-outs that are excluded from that cap; and, for those carve-outs, either no cap at all or a separate super-cap. Leaving the interaction implicit is a common source of post-signing disputes.
The categories that are conventionally carved out of the general cap are consistent across well-drafted Indian technology agreements:
Beyond the carve-out list, several mechanics determine whether an indemnity is actually collectable: the survival period (indemnities for IP and data claims should survive termination and run for a defined tail); priority of recovery where insurance also responds; and clear notice, cooperation and defence-control obligations so that a delayed or mishandled claim does not become a ground to deny the indemnity.
Excluding consequential damages india is standard practice, and courts will generally give effect to a clear exclusion of indirect or consequential losses negotiated between commercial parties. The difficulty is definitional. Indian law does not treat “consequential loss” as a fixed category; the recoverability of a loss under Section 73 of the Indian Contract Act depends heavily on remoteness and foreseeability at the time of contracting. A loss that both parties could reasonably contemplate as arising from a breach may be recoverable even if labelled “consequential”, so drafting that simply excludes “all consequential losses” without a defined list invites dispute.
The robust approach is the “black-letter exclusion plus liability ladder.” First, exclude specific, enumerated heads of loss, loss of profits, loss of revenue, loss of anticipated savings, loss of goodwill, loss of data (subject to carve-out), and pure economic loss, rather than relying on the word “consequential” alone. Second, carve back the losses the buyer genuinely needs to recover, such as the cost of procuring replacement services or the cost of restoring lost data, and confirm those sit within the general cap rather than being excluded entirely.
Buyers should resist any exclusion that sweeps up losses flowing directly from a data breach, because those are frequently the losses that matter most and are often the intended subject of a separate indemnity and super-cap. Aligning the consequential-loss exclusion with the indemnity carve-outs prevents the exclusion from silently swallowing the protection the indemnity was meant to give.
Illustrative drafting only. “Subject to Clause [carve-outs], neither party shall be liable for any loss of profits, loss of revenue, loss of anticipated savings, loss of goodwill, or any indirect or consequential loss, in each case whether arising in contract, tort or otherwise. This exclusion does not apply to the Customer’s costs of procuring replacement services or of restoring data lost as a result of the Supplier’s breach, which shall be recoverable subject to the cap in Clause [general cap].”
Carve-outs for gross negligence wilful misconduct india are near-universal, yet the terms are often left undefined, which is precisely where enforcement risk creeps in. “Gross negligence” is not a term of art with a settled statutory definition in India, and a court asked to apply an undefined standard will construe it narrowly. If the parties intend a meaningful carve-out, they should define it.
Fraud stands apart: a party generally cannot contractually exclude liability for its own fraud, and any clause purporting to do so is at high risk of being unenforceable and may taint surrounding provisions. Wilful misconduct, deliberate wrongdoing or reckless disregard of a known duty, and gross negligence, a serious departure from the standard of care, beyond ordinary carelessness, should each be defined with an objective test so that the carve-out cannot be triggered by ordinary performance shortfalls dressed up as “gross.”
The drafting objective is to make the carve-out real without making it a loophole that swallows the cap. Two techniques help: an objective definition tied to the conduct rather than the outcome, and a requirement that the party alleging gross negligence or wilful misconduct bears the burden of proving the higher standard. Materiality and notice thresholds prevent every routine breach being re-characterised to escape the cap.
Illustrative drafting only. “Nothing in this Agreement limits or excludes either party’s liability for fraud, fraudulent misrepresentation, gross negligence or wilful misconduct. For these purposes, ‘gross negligence’ means conduct that constitutes a significant departure from the standard of care a reasonable supplier would exercise, and ‘wilful misconduct’ means intentional wrongdoing or reckless disregard of a known duty. The party asserting gross negligence or wilful misconduct bears the burden of proving it.”
The regulatory framework changes the risk map for limitation of liability technology contracts india in three concrete ways: personal-data penalties under the Digital Personal Data Protection Act, 2023, due-diligence obligations on intermediaries under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and emerging obligations around synthetically generated information flowing from amendments to those Rules administered by the Ministry of Electronics and Information Technology (MeitY).
The first practical point is that regulatory penalties are not freely contractable. Where a regulator imposes a penalty on a party for its own breach of a statutory obligation, the parties cannot, as between themselves, extinguish that penalty in a way that binds the State. Under the DPDP Act, financial penalties are determined by the Data Protection Board of India within the maximum limits set out in the Act. What the parties can do is allocate the commercial consequences, the cost of remediation, notification, credit monitoring, and defending third-party claims, through indemnities and pass-through provisions.
Draft the DPDP indemnity to cover those commercial costs expressly, and be realistic that a bare “indemnify against all fines” clause may be unenforceable as to the statutory penalty itself.
The second point concerns allocation of compliance responsibility. Under the DPDP Act, the parties should record clearly who is the Data Fiduciary (the entity that determines the purpose and means of processing) and who is the Data Processor acting on the Fiduciary’s behalf, because that allocation drives which party bears which statutory obligation and, in turn, which liabilities the contract should route where. Compliance covenants, breach-notification timing, and joint incident-response obligations should be spelled out rather than left to a generic “comply with applicable law” clause.
The third point is synthetically generated content and generative-AI outputs. Intermediary due-diligence obligations and evolving requirements around synthetically generated information mean that platform and AI-model contracts should now carry specific carve-outs and covenants addressing the outputs of third-party or generative models, mislabelled or manipulated content, and the diligence steps each party must take. Cross-border best practice, reflected in the OECD’s AI principles, supports AI-specific risk allocation, dedicated carve-outs and insurance for these exposures rather than folding them into a generic technology cap.
Insurance is the mechanism that makes a large cap or super-cap collectable in practice. For deals with material cyber, data or AI exposure, require the vendor to maintain cyber liability and technology errors-and-omissions cover at limits that are meaningful against the identified risk, and require proof of coverage, a certificate of insurance, at signing and on renewal. Pay attention to the interaction between the policy limit and the retention (the vendor’s own deductible), because a high limit with a high retention still leaves the vendor exposed for the first tranche of loss. Where the buyer wants first recourse, specify primary versus excess placement, and confirm that the insurance obligation supplements the contractual indemnity rather than capping recovery at policy limits.
Sublimits and policy exclusions should be reviewed so that the very events you care about most are not carved out of the cover.
Use this checklist to score risk quickly and identify walk-away thresholds when negotiating risk allocation clauses india:
All templates below are illustrative and require counsel review and jurisdiction-specific tailoring before use.
Getting limitation of liability technology contracts india right in 2026 is less about winning the headline cap number and more about building a coherent structure: an enforceable general cap, express carve-outs for the liabilities that matter, indemnities that clearly sit inside or outside that cap, and insurance that makes the whole thing collectable. The DPDP Act and the evolving IT Act rules framework have raised the stakes on data-breach and synthetic-content exposure, and a clause drafted before those shifts is unlikely to allocate the new risks where the parties intend.
Treat the enforceability tests, the cap structures and the carve-out discipline in this guide as a connected playbook rather than a menu, and pressure-test every template against the specific deal and its regulatory footprint. Given how quickly the framework is moving, parties revising their technology agreements should take qualified Indian counsel before finalising liability and indemnity language.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Mitakshara Goyal at Svarniti Law Offices, a member of the Global Law Experts network.
posted 24 seconds ago
posted 9 minutes ago
posted 18 minutes ago
posted 27 minutes ago
posted 36 minutes ago
posted 53 minutes ago
posted 55 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message