Checkory
Liability-cap ladder with data and confidentiality carve-out rungs boxed

How to Review Data-Protection and Confidentiality Liability Carve-Outs

Review data and confidentiality liability carve-outs: fees-paid vs super-cap, covered costs, consequential wipe, then keep, raise, or walk.

•9 min read•Article
💡

Key takeaway in 30 seconds

Knowing how to review data protection and confidentiality liability super-cap carve-outs means treating the carve-out list as the ladder off the general fees-paid cap. Mark uncapped versus super-cap, name covered costs (fines, notice, forensics), stress-test the consequential wipe and indemnity, then keep, raise to a super-cap, or walk — never treat the paper as ready to countersign.

Blair, Ops at a 24-person UK health-tech SaaS, is about to treat “twelve months of fees is market” as the whole risk story. Knowing how to review data protection and confidentiality liability super-cap carve-outs is a 20-minute hunt: general fees-paid rung vs data / confidentiality ladder → uncapped vs super-cap → covered costs → consequential and indemnity → not the cap number / not the injunction → keep / raise / walk.

September 2026. English law; courts of England and Wales. The packet — the exact file set to sign — is a US CRM / support MSA — master services agreement — holding patient-adjacent PII (~£2,800/month). 12.1: fees-paid twelve-month aggregate. 12.2: death/PI and fraud only — no data/confidentiality rung. 12.3 includes consequential loss of data. Schedule D indemnity silent on 12.1. AE Slack: “death and fraud are already carved out.” Signature Friday.

A death/PI sticker is not a data rung. Norton Rose Fulbright Liability 101 (UK tech/outsourcing colour, checked 2026-09-28): data protection and security increasingly sit under a super-cap — a separate or higher limit — and that pattern is extending to confidentiality. The carve-out list decides which risks the headline fees-paid number covers — Blair’s feared breach costs still sit under 12.1 unless the list lifts them.

Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.

What does the fees-paid cap cover — and what sits on the data ladder?

The general fees-paid cap only bites claims that stay under it. Circle 12.1 and the carve-out list. Log whether data-protection, confidentiality, or security still share the missed-SLA rung — or leave it.

Do: open Section 12, not only the heading. Don’t: treat UCTA death/PI colour as a bargain for data. Unfair Contract Terms Act 1977 s.2 already bars excluding liability for death or personal injury from negligence — that sticker is not a data rung. Jonathan Lea: ordinary service failures and data risks often need different ceilings. If the fight is how much money the number is, that is a different hunt — how to review an MSA liability cap. Stay here for the list.

General fees-paid liability rung versus data and confidentiality ladder
General fees-paid liability rung versus data and confidentiality ladder
❌

Typical mistake

“Twelve months of fees is market.” Without a data lift, breach costs share the ordinary-service ceiling.

Which claims leave the general rung — uncapped or super-cap?

Uncapped and super-cap are different rungs. Mark which claims sit outside the fees-paid ceiling, which sit under a higher separate limit, and which still share 12.1.

Do: ask for a named elevated rung — uncapped or a separate multiple / fixed sum — and whether related claims aggregate. Don’t: treat “we cannot go uncapped” as the end. Common Paper frames a super-cap as the middle tier between general cap and uncapped. NRF colour often cites wide fees-multiple bands for data/security — market colour, not Blair’s statute. Cabinet Office PPN 020 steers public buyers toward excluding data-protection breaches from the general cap or setting a separate DP cap — colour that a ladder, not a single rung, is already expected.

Uncapped versus super-cap rungs for data and confidentiality claims
Uncapped versus super-cap rungs for data and confidentiality claims

What does “data protection” and “confidentiality” actually cover on the paper?

Undefined words are not a covered-cost list. Circle data protection / confidentiality / security / privacy. Log whether fines, notice, forensics, remediation, credit monitoring, and third-party claims sit inside the elevated rung.

Do: demand express treatment of breach costs. Don’t: assume “data protection” swallows ICO fines or forensics. ICO personal data breaches guide (checked 2026-09-28): report certain breaches to the ICO within 72 hours where feasible if risk is likely; failing to notify when required can attract up to £8.7 million or 2% of global turnover on the ICO’s published figures. Jonathan Lea and Baker Data Counsel: name notification, forensics, legal fees, and remediation in the elevated bucket. In practice, “privacy” ≠ “security” ≠ “confidentiality” unless the paper says so.

💡

For example

Ask whether regulatory fines sit expressly in or out of the carve-out. Silence is not coverage.

Why can the consequential wipe or indemnity hollow the carve-out?

A money carve-out is empty if consequential language wipes leak losses, or if an indemnity still sits inside the general cap. Circle “loss of data” and any “subject to” pointer from Schedule D into 12.1.

Do: carve elevated claims from the consequential wipe, or list notice / forensics / remediation as acknowledged direct damages. Don’t: assume the indemnity sits outside the fees-paid ceiling. Lexology (2026-09-28): data-security breaches often need carve-outs from both the cap and the consequential disclaimer. HCR Law: clauses that wipe all loss of data on a data tool invite challenge unless a sensible carve-out or super-cap survives. Heads-of-loss grammar: how to review a consequential-loss exclusion under English law — one sentence, then return. Not the injunctive hatch — that stop-order fight is how to review an injunctive-relief carve-out next to a liability cap.

Covered-cost checklist for data-protection and confidentiality carve-outs
Covered-cost checklist for data-protection and confidentiality carve-outs

When is this not the cap-number walk and not the stop-order hunt?

No. This page is the carve-out list off the general fees-paid rung. Computing the £ is a different article; whether a court can still order someone to stop is another.

Do: stay on which claims leave the general rung and whether consequential / indemnity hollows them. Don’t: reopen lookback math or injunctive relief as this spine. Cap number: MSA liability-cap review guide. Stop-order: injunctive-relief carve-out review. One sentence each, then return to Blair’s list.

When do you keep, raise to a super-cap, or walk before Friday?

Keep only with a named elevated rung, matching covered costs, intact consequential treatment, and aligned indemnity. Raise to a super-cap if uncapped is refused but a separate multiple or floor is open. Walk if the list never lifts those claims on a PII tool.

Success bar: one-page log plus one Friday pause sentence (no data rung; consequential “loss of data”). Workflow: ladder → uncapped vs super-cap → covered costs → consequential + indemnity → not £ / not injunction → keep / raise / walk. Optional: upload the same PDF to document analysis for a first-pass — first machine pass extracting clauses — then a named human opens Section 12. Verify every High flag — high-severity item a named human still opens. Escalate to counsel — a qualified lawyer, not the chatbot. Never treat the paper as ready to countersign.

Blair’s carve-out log — keep / raise / walk

CheckBlair’s paperAction
Data / confidentiality lift?Death/PI + fraud onlyFail — no data rung
Uncapped or super-cap?Silence — under 12.1Raise or walk
Covered costs named?UndefinedName fines/notice/forensics
Consequential hollow?Includes loss of dataCarve from wipe
Indemnity vs cap?Schedule D silentAlign or elevate
DecisionPII tool; no data rungRaise or walk

Hunt

1

Freeze the packet

MSA LoL + carve-outs + consequential + indemnity + DPA — data processing agreement — + order form. Search cap / carve-out / super-cap / data protection / confidentiality / loss of data.

2

Separate general rung from ladder

Circle fees-paid aggregate and the carve-out list. Log whether data/confidentiality/security leave that rung.

3

Mark uncapped vs super-cap

Note multiple or fixed sum, per claim vs aggregate, and which claims sit where.

4

Name covered costs

Fines, notice, forensics, remediation, credit monitoring, third-party claims — in or out?

5

Stress-test consequential and indemnity

Does “loss of data” hollow the lift? Is the indemnity subject to the general cap?

6

Fence the sibling hunts

Cap number → MSA liability-cap guide. Stop-order → injunctive-relief carve-out.

7

Keep, raise, or walk

Keep only with a named elevated rung. Raise to a super-cap as the middle tier. Walk if PII sits under fees-paid only.

Frequently asked questions

Should confidentiality liability be uncapped?▼
Commercially negotiated. Historically often uncapped; market colour increasingly uses a super-cap. Log uncapped vs elevated vs still under the general rung.
What is a super-cap multiple?▼
Whatever the paper says: a higher separate ceiling for named claims, often a fees multiple or fixed sum. Middle-tier colour — not a legal minimum.
Do regulatory fines sit inside the data-protection carve-out?▼
Only if the words say so. Name fines expressly in or out. ICO fine ceilings are regulatory colour, not automatic recovery.
Is this the same as reviewing the liability-cap number?▼
No. This page is which claims leave the general rung. Computing fees-paid vs payable is /en-gb/blog/msa-liability-cap-review-guide.
Is this the injunctive-relief carve-out?▼
No. A money carve-out is not a stop-order hatch. See /en-gb/blog/injunctive-relief-carve-out-liability-cap-review.
Can a consequential “loss of data” line empty a carve-out?▼
Yes, if breach costs are treated as consequential and the carve-out does not also survive that wipe. Carve elevated claims from the exclusion or list acknowledged direct damages.

Highlight carve-outs on this file

Upload the same PDF. A human still opens Section 12.

Start document analysis

What to do next

Sources

Read also

Related guides

Updated: September 28, 2026