
How to Review Data-Protection and Confidentiality Liability Carve-Outs
Review data and confidentiality liability carve-outs: fees-paid vs super-cap, covered costs, consequential wipe, then keep, raise, or walk.
Key takeaway in 30 seconds
Knowing how to review data protection and confidentiality liability super-cap carve-outs means treating the carve-out list as the ladder off the general fees-paid cap. Mark uncapped versus super-cap, name covered costs (fines, notice, forensics), stress-test the consequential wipe and indemnity, then keep, raise to a super-cap, or walk — never treat the paper as ready to countersign.
Blair, Ops at a 24-person UK health-tech SaaS, is about to treat “twelve months of fees is market” as the whole risk story. Knowing how to review data protection and confidentiality liability super-cap carve-outs is a 20-minute hunt: general fees-paid rung vs data / confidentiality ladder → uncapped vs super-cap → covered costs → consequential and indemnity → not the cap number / not the injunction → keep / raise / walk.
September 2026. English law; courts of England and Wales. The packet — the exact file set to sign — is a US CRM / support MSA — master services agreement — holding patient-adjacent PII (~£2,800/month). 12.1: fees-paid twelve-month aggregate. 12.2: death/PI and fraud only — no data/confidentiality rung. 12.3 includes consequential loss of data. Schedule D indemnity silent on 12.1. AE Slack: “death and fraud are already carved out.” Signature Friday.
A death/PI sticker is not a data rung. Norton Rose Fulbright Liability 101 (UK tech/outsourcing colour, checked 2026-09-28): data protection and security increasingly sit under a super-cap — a separate or higher limit — and that pattern is extending to confidentiality. The carve-out list decides which risks the headline fees-paid number covers — Blair’s feared breach costs still sit under 12.1 unless the list lifts them.
Disclaimer: Checkory provides AI support, not legal advice. Consult a qualified lawyer for binding decisions.
What does the fees-paid cap cover — and what sits on the data ladder?
The general fees-paid cap only bites claims that stay under it. Circle 12.1 and the carve-out list. Log whether data-protection, confidentiality, or security still share the missed-SLA rung — or leave it.
Do: open Section 12, not only the heading. Don’t: treat UCTA death/PI colour as a bargain for data. Unfair Contract Terms Act 1977 s.2 already bars excluding liability for death or personal injury from negligence — that sticker is not a data rung. Jonathan Lea: ordinary service failures and data risks often need different ceilings. If the fight is how much money the number is, that is a different hunt — how to review an MSA liability cap. Stay here for the list.

Typical mistake
“Twelve months of fees is market.” Without a data lift, breach costs share the ordinary-service ceiling.
Which claims leave the general rung — uncapped or super-cap?
Uncapped and super-cap are different rungs. Mark which claims sit outside the fees-paid ceiling, which sit under a higher separate limit, and which still share 12.1.
Do: ask for a named elevated rung — uncapped or a separate multiple / fixed sum — and whether related claims aggregate. Don’t: treat “we cannot go uncapped” as the end. Common Paper frames a super-cap as the middle tier between general cap and uncapped. NRF colour often cites wide fees-multiple bands for data/security — market colour, not Blair’s statute. Cabinet Office PPN 020 steers public buyers toward excluding data-protection breaches from the general cap or setting a separate DP cap — colour that a ladder, not a single rung, is already expected.

What does “data protection” and “confidentiality” actually cover on the paper?
Undefined words are not a covered-cost list. Circle data protection / confidentiality / security / privacy. Log whether fines, notice, forensics, remediation, credit monitoring, and third-party claims sit inside the elevated rung.
Do: demand express treatment of breach costs. Don’t: assume “data protection” swallows ICO fines or forensics. ICO personal data breaches guide (checked 2026-09-28): report certain breaches to the ICO within 72 hours where feasible if risk is likely; failing to notify when required can attract up to £8.7 million or 2% of global turnover on the ICO’s published figures. Jonathan Lea and Baker Data Counsel: name notification, forensics, legal fees, and remediation in the elevated bucket. In practice, “privacy” ≠ “security” ≠ “confidentiality” unless the paper says so.
For example
Ask whether regulatory fines sit expressly in or out of the carve-out. Silence is not coverage.
Why can the consequential wipe or indemnity hollow the carve-out?
A money carve-out is empty if consequential language wipes leak losses, or if an indemnity still sits inside the general cap. Circle “loss of data” and any “subject to” pointer from Schedule D into 12.1.
Do: carve elevated claims from the consequential wipe, or list notice / forensics / remediation as acknowledged direct damages. Don’t: assume the indemnity sits outside the fees-paid ceiling. Lexology (2026-09-28): data-security breaches often need carve-outs from both the cap and the consequential disclaimer. HCR Law: clauses that wipe all loss of data on a data tool invite challenge unless a sensible carve-out or super-cap survives. Heads-of-loss grammar: how to review a consequential-loss exclusion under English law — one sentence, then return. Not the injunctive hatch — that stop-order fight is how to review an injunctive-relief carve-out next to a liability cap.

When is this not the cap-number walk and not the stop-order hunt?
No. This page is the carve-out list off the general fees-paid rung. Computing the £ is a different article; whether a court can still order someone to stop is another.
Do: stay on which claims leave the general rung and whether consequential / indemnity hollows them. Don’t: reopen lookback math or injunctive relief as this spine. Cap number: MSA liability-cap review guide. Stop-order: injunctive-relief carve-out review. One sentence each, then return to Blair’s list.
When do you keep, raise to a super-cap, or walk before Friday?
Keep only with a named elevated rung, matching covered costs, intact consequential treatment, and aligned indemnity. Raise to a super-cap if uncapped is refused but a separate multiple or floor is open. Walk if the list never lifts those claims on a PII tool.
Success bar: one-page log plus one Friday pause sentence (no data rung; consequential “loss of data”). Workflow: ladder → uncapped vs super-cap → covered costs → consequential + indemnity → not £ / not injunction → keep / raise / walk. Optional: upload the same PDF to document analysis for a first-pass — first machine pass extracting clauses — then a named human opens Section 12. Verify every High flag — high-severity item a named human still opens. Escalate to counsel — a qualified lawyer, not the chatbot. Never treat the paper as ready to countersign.
Blair’s carve-out log — keep / raise / walk
| Check | Blair’s paper | Action |
|---|---|---|
| Data / confidentiality lift? | Death/PI + fraud only | Fail — no data rung |
| Uncapped or super-cap? | Silence — under 12.1 | Raise or walk |
| Covered costs named? | Undefined | Name fines/notice/forensics |
| Consequential hollow? | Includes loss of data | Carve from wipe |
| Indemnity vs cap? | Schedule D silent | Align or elevate |
| Decision | PII tool; no data rung | Raise or walk |
Hunt
Freeze the packet
MSA LoL + carve-outs + consequential + indemnity + DPA — data processing agreement — + order form. Search cap / carve-out / super-cap / data protection / confidentiality / loss of data.
Separate general rung from ladder
Circle fees-paid aggregate and the carve-out list. Log whether data/confidentiality/security leave that rung.
Mark uncapped vs super-cap
Note multiple or fixed sum, per claim vs aggregate, and which claims sit where.
Name covered costs
Fines, notice, forensics, remediation, credit monitoring, third-party claims — in or out?
Stress-test consequential and indemnity
Does “loss of data” hollow the lift? Is the indemnity subject to the general cap?
Fence the sibling hunts
Cap number → MSA liability-cap guide. Stop-order → injunctive-relief carve-out.
Keep, raise, or walk
Keep only with a named elevated rung. Raise to a super-cap as the middle tier. Walk if PII sits under fees-paid only.
Frequently asked questions
Should confidentiality liability be uncapped?▼
What is a super-cap multiple?▼
Do regulatory fines sit inside the data-protection carve-out?▼
Is this the same as reviewing the liability-cap number?▼
Is this the injunctive-relief carve-out?▼
Can a consequential “loss of data” line empty a carve-out?▼
Highlight carve-outs on this file
Upload the same PDF. A human still opens Section 12.
Start document analysisWhat to do next
How to Review an MSA Liability Cap
Compute the fees-paid / super-cap number. This page is the carve-out list only.
RelatedHow to Review an Injunctive-Relief Carve-Out Next to a Liability Cap
Stop-order hatch. This page is the money-side data/confidentiality ladder.
RelatedDocument analysis
Upload the same PDF. A human still opens Section 12.
RelatedHow to Review a Consequential-Loss Exclusion Under English Law
Heads-of-loss list hunt when “loss of data” may hollow the carve-out.
RelatedIndemnity Clause Review Checklist Before You Sign
Align Schedule D indemnity with the liability rung. This page is the carve-out ladder.
Sources
- Norton Rose Fulbright — Liability 101 (UK tech/outsourcing)
- Jonathan Lea — Liability Caps in Technology Contracts
- HCR Law — New year, new caps
- Common Paper — Super Cap clause
- Cabinet Office PPN 020 — data protection legislation guidance
- ICO — Personal data breaches: a guide
- legislation.gov.uk — Unfair Contract Terms Act 1977 s.2
- Baker Data Counsel — DPAs, indemnities and data-breach cost
Read also
Related guides





