The Supercap: The Middle Tier of Liability Nobody Explains Until You’re Negotiating One

TL;DR: A supercap is a second, higher liability ceiling that sits above your general cap but below unlimited liability, and it applies only to named high-risk categories such as data breaches, confidentiality, and IP indemnities. It is usually set as a multiple of fees (2x or 3x is common) or a fixed sum, and the single most important drafting rule is to make it a defined number, never open-ended. This guide covers what a supercap actually does, how the number gets set, the trap that quietly makes one worthless, and how courts treat caps across India, the US, the UK, and the EU, UAE and Singapore.

Quick overview: Most limitation of liability clauses end in a single figure, often twelve months of fees. The more carefully negotiated ones end in two. The first number is the general cap for ordinary claims like bugs and outages. The second, higher one is the supercap, and it applies to a short list of serious risks where the standard cap felt too low but uncapped liability felt uninsurable. It is the compromise that closes deals. It is also where the drafting mistakes hide. What follows is a balanced, both-sides look at how to build one, where to set the number, and whether the cap holds up in the places your contract actually reaches.

What a supercap actually is

A limitation of liability clause allocates the financial risk in a contract. It says how much a party can be made to pay if things go wrong. Left simple, it has one cap, one ceiling on total liability, usually pegged to the fees paid over some period.

The problem is that not all breaches are equal. A missed service level and a data breach that exposes a million customer records are not the same event, and a single low cap treats them as if they were. So a customer looks at a 12-month fee cap covering a catastrophic data incident and says, reasonably, that the remedy is smaller than the harm. The vendor looks at a demand for unlimited liability on that same risk and says, just as reasonably, that no business can sign exposure it cannot insure or survive.

The supercap is the middle ground. It carves the high-risk categories out of the general cap and gives them their own, higher ceiling, still finite, still a number. A common structure is a general cap at 1x annual fees for ordinary claims, and a supercap at 2x or 3x fees, or a fixed sum, for data protection, confidentiality, and third-party IP claims. Separate, higher supercaps for data-breach and security liability have become a common feature of SaaS agreements and master service agreements negotiated since 2020. Academics have started calling the whole structure a liability ladder, with the general cap and the supercap as rungs. That is a good way to picture it: not one wall, but steps, each sized to the risk behind it.

If you are meeting this concept for the first time, it helps to be solid on the base layer first, which is covered in our piece on why a limitation of liability clause matters. The supercap is the next tier up from that.

The three tiers of a liability ladder

Read enough contracts and the same structure appears. There are three levels, and a supercap is the middle one.

The general cap sits at the bottom. It applies to ordinary claims, routine breaches, performance failures, the day-to-day things that go wrong, including the kind of service level misses that a services contract deals with as a matter of course. It is typically the lowest number, often a single year of fees.

The supercap sits in the middle. It applies to a defined, closed list of higher-risk categories, most commonly breach of confidentiality, breach of data protection obligations, and third-party IP infringement. It is set higher than the general cap but is still a fixed, knowable figure.

Uncapped liability sits at the top. Some things cannot be capped at all, either because the parties agree they should not be or because the law forbids it. Death or personal injury caused by negligence, fraud, and wilful misconduct usually live here. A party’s liability for these is unlimited whatever the contract says, a point we come back to when we look at how different countries treat caps.

The skill is deciding which risk belongs on which rung, and pricing each rung to the risk behind it rather than to whatever number survived the last five minutes of a negotiation.

How the number gets set: multiple of fees or fixed sum

Here is the practical heart of it, and the one rule worth carrying out of this article: a supercap must be a defined amount. Never leave it open-ended. An open-ended supercap is just uncapped liability wearing a disguise, and it defeats the entire reason the tier exists.

There are two main ways to set the number, and they suit different deals.

A multiple of fees ties the supercap to what the customer pays, for example two or three times the annual fees. This keeps the ceiling proportionate to the size of the relationship, which is why it is the more common choice. When surveyed, most parties who use an increased cap pick a multiplier rather than a fixed figure. The logic is clean: a bigger contract carries a bigger cap, automatically, without renegotiation.

A fixed sum states a hard number, for example one million in the relevant currency for third-party IP claims. This suits deals where a multiple of fees would produce a figure that is either too small to matter or too large to insure. On a small contract, 3x a modest fee may not cover the real exposure. On a very large one, 3x fees can reach a number no vendor can carry. A fixed sum, or a hybrid such as “the lower of a fixed amount or a multiple of fees,” keeps the ceiling sensible at both ends.

Whichever route you choose, the number has to be visible in the contract. A pattern we see: a supercap drafted as “an amount sufficient to cover the customer’s losses” or left to be “agreed in good faith” later. That is not a cap. It is an argument waiting to happen, and in a serious dispute it gives the customer an opening to push toward unlimited recovery. If you take one thing from this piece, take this: name the number.

The trap that makes a supercap worthless

A supercap can be perfectly negotiated and still be worth nothing, because of one drafting move that is easy to miss.

The trap is the shared aggregate cap. If the confidentiality, data-protection, and IP claims that the supercap is meant to protect are all quietly folded back under the same single aggregate ceiling as everything else, the higher tier does nothing. The customer thinks they bargained for a 3x supercap on data breaches. In practice, one bad outage earlier in the year has already eaten the aggregate cap, and there is nothing left when the data breach hits.

A pattern we see: a clause that lists impressive carve-outs and a higher figure for them, then closes with a line making all liability “in the aggregate” subject to one overall cap that happens to be the low one. The carve-outs look protective. They are decorative.

To avoid it, be explicit about how the tiers interact. State whether the supercap is separate from the general cap or shares an aggregate with it. State whether each cap is per-claim or in the aggregate. If a supercap is meant to give real additional protection, it needs its own ceiling that the general cap cannot exhaust. This is exactly the kind of interaction a careful contract drafting review is built to catch, because the words that create the trap are boring and easy to skim past.

The cap and the carve-outs are one negotiation

It is tempting to treat the cap number and the list of carve-outs as two separate fights. They are not. They are one negotiation, and winning one while conceding the other is a false victory.

A high supercap means little if the carve-out list is drawn so narrowly that the real risks fall outside it. Equally, a broad carve-out list means little if everything in it is folded back under a low aggregate cap. The number and the list move together. When you raise the supercap, the party giving it will try to tighten the list of what triggers it. When you widen the list, they will try to lower the number. A sensible outcome balances the two, rather than trading a headline figure for a gutted set of triggers.

This is why the supercap should be drafted by reference to specific clauses, not vague categories. “Breach of Section 7 (Confidentiality) or Section 9 (Data Protection)” is precise and enforceable. “Serious breaches” is neither. Tying the supercap to identified sections of the agreement closes the gap between what the parties think they agreed and what a court will later read. It also keeps the supercap consistent with the indemnity provisions and warranties, since those three together define the whole risk allocation of the deal and should not contradict each other. Third-party IP claims are one of the most common supercap triggers, and how you allocate that risk should line up with your IP assignment and ownership position elsewhere in the deal.

Does the cap even hold up? A global view

A supercap is only as good as its enforceability, and that changes with the governing law. Here is how the four jurisdiction groups treat contractual caps.

India

Indian law sets no statutory ceiling or formula for a liability cap. Parties are free to agree a cap linked to contract value, fees paid, or insurance cover. Those caps then operate within Sections 73 and 74 of the Indian Contract Act, 1872, which limit recovery to reasonable compensation for losses that arise naturally and are not remote. In Mahanagar Telephone Nigam Ltd. v. Tata Communications Ltd. (2019) 5 SCC 341, the Supreme Court treated a stipulated liability figure as the maximum recoverable, provided it is a fair and reasonable estimate of loss. So an Indian-law supercap is generally enforceable, but a court can still test whether the figure is a genuine pre-estimate rather than a penalty. The drafting lesson is the same one that runs through this whole piece: a defined, reasonable number is defensible; an inflated or arbitrary one invites the court to pare it back.

United States

The US is broadly permissive. Contractual liability caps, including tiered supercaps, are widely enforceable under freedom-of-contract principles, and there is no general statutory reasonableness test of the kind the UK has. The limits come from doctrine rather than a single act: a cap can fall to unconscionability, particularly where bargaining power is very unequal, and most states will not let a party cap or exclude liability for gross negligence, fraud, or wilful misconduct on public-policy grounds. This is the home turf of the supercap, and the tiered ladder structure originated largely in US enterprise SaaS negotiations. Enforceability is rarely the problem; precise drafting is, because US courts read the specific categories as written and will not stretch a supercap to cover a risk it did not name.

United Kingdom

The UK runs the reasonableness test. Under the Unfair Contract Terms Act 1977, a business cannot exclude or restrict liability for death or personal injury caused by its negligence, and cannot exclude liability for fraud. For most other losses, a limitation or exclusion is effective only so far as it satisfies the statutory requirement of reasonableness in Section 11, judged on what the parties knew or ought to have known when they contracted. There is no specific statutory rule on excluding liability for gross negligence or wilful default, so those turn on drafting and interpretation. For a supercap, the practical effect is helpful: a genuinely negotiated, category-specific higher tier is far easier to defend as reasonable than a single very low cap applied to everything, which is exactly the sort of term UCTA is most likely to strike down.

EU, UAE and Singapore

Group these because cross-border deals routinely touch all three, and each adds a hard limit worth knowing.

Singapore applies its own Unfair Contract Terms Act 1977, structured like the UK’s, with the same reasonableness test and the same absolute bar on excluding liability for death or personal injury from negligence. A supercap there is assessed much as it would be in England.

Across EU civil-law systems the detail varies by member state, but a recurring theme is that caps and exclusions will not save a party from liability for intent or gross negligence, and consumer-facing terms face separate unfair-terms control. In business-to-business deals the parties have more freedom, but the intent and gross-negligence limit is a common floor.

Onshore UAE is the sharpest outlier. Under Article 296 of the Civil Code, any agreement purporting to exclude liability for a harmful act, meaning tort, including negligence, is void as a matter of public policy, and the same logic constrains attempts to limit it. The obligor also remains liable for fraud and gross negligence whatever the contract says. The reformed Civil Transactions Law keeps pre-agreed damages subject to judicial control, and confirms that parties may increase liability by agreement but not exempt or reduce liability for harmful acts. The practical upshot: a single aggregate cap drafted to cover “all liability howsoever arising” is risky under UAE law, because it reaches tort liability the law will not let you cap. A supercap scoped carefully to contractual breaches, and kept clear of tort and gross-negligence territory, is the safer structure. Note that DIFC and ADGM, the common-law free zones, follow English-style principles rather than the onshore Civil Code, so the governing law and forum you choose changes the answer.

The pattern across all four

Jurisdiction Are caps enforceable? The hard limits
India Yes, no statutory ceiling Reasonable compensation only (ss.73-74); cap must be a genuine pre-estimate, not a penalty
US Yes, broadly (freedom of contract) Unconscionability; usually no cap on gross negligence, fraud, or wilful misconduct
UK Yes, if reasonable (UCTA s.11) Cannot exclude death/personal injury from negligence, or fraud
EU Yes in B2B, varies by state Commonly void for intent and gross negligence; consumer terms separately controlled
UAE (onshore) Contractual caps yes; tort no Art. 296 voids limits on harmful-act liability; fraud and gross negligence always uncapped
Singapore Yes, if reasonable (UCTA) Cannot exclude death/personal injury from negligence

The theme across all of them is the same. The law lets you cap ordinary contractual risk, and every system carves out a category, fraud, gross negligence, death, or tort, that no cap can touch. A supercap works with that grain rather than against it: it raises the ceiling on the serious contractual risks the law does let you cap, instead of pretending to cap the ones it never will.

How to build a supercap that works

Pulling the practical points together, a supercap that actually protects, on either side of the table, tends to do six things.

It names a defined number, a multiple of fees or a fixed sum, never an open-ended or “to be agreed” figure. It ties the trigger to specific clauses of the agreement rather than vague categories like “serious breaches.” It states clearly whether it is separate from the general cap or shares an aggregate, so it cannot be quietly exhausted by unrelated claims. It is sized to the real risk behind the category, using a fixed sum or hybrid where a fee multiple would be too small or too large. It stays consistent with the indemnity and warranty provisions, which allocate the same risks. And it respects the governing law’s hard limits, so it does not try to cap what fraud, gross negligence, or local public policy will not allow.

Get those six right and the supercap does its job, which is to let a deal close by giving the customer real protection on the risks that frighten them, while keeping the vendor’s exposure to a number it can actually carry.

Frequently asked questions

What is a supercap in a contract?

A supercap is a higher liability ceiling that applies only to specific high-risk categories in a contract, such as data breaches, confidentiality, and third-party IP infringement. It sits above the general liability cap, which covers ordinary claims, but below unlimited liability. It is usually set as a multiple of fees, commonly 2x or 3x, or as a fixed sum. The purpose is to give greater protection for serious breaches without exposing the other party to uninsurable, unlimited risk. It is also called an enhanced, elevated, increased, or tiered cap.

How is a supercap different from a general liability cap?

A general cap is the overall ceiling on liability for ordinary claims, often set at around twelve months of fees, and it covers routine breaches like outages and performance failures. A supercap is a second, higher ceiling that applies only to a defined list of higher-risk categories, such as data protection, confidentiality, and IP claims. The general cap is the default rung; the supercap is a raised rung for the risks where the default felt too low. A well-drafted clause makes clear whether the supercap is separate from the general cap or shares an aggregate.

How high should a supercap be set?

There is no single correct figure; it depends on the risk profile of the deal and the data involved. Common structures set the supercap at two or three times annual fees, or at a fixed sum for categories like third-party IP claims. A fee multiple keeps the cap proportionate to contract size and is the more common choice. A fixed sum, or a hybrid such as the lower of a fixed amount or a fee multiple, works better where a multiple would be too small to matter or too large to insure. The essential rule is that the number must be defined, never left open-ended.

Should a supercap be a multiple of fees or a fixed amount?

Both are used, and the right choice depends on deal size. A multiple of fees ties the cap to what the customer pays, so it scales automatically with the relationship, which is why most parties who use an increased cap choose a multiplier. A fixed sum suits deals where a fee multiple would produce a figure that is either too small to cover the real exposure or too large for a vendor to carry. On large contracts a hybrid, capping at the lower of a fixed amount or a fee multiple, keeps the ceiling sensible. Whichever you pick, state the number in the contract.

What is the most common mistake with supercaps?

Folding the supercap categories back under the same single aggregate cap as everything else. When that happens, the higher tier is worthless, because an unrelated claim earlier in the year can exhaust the shared aggregate before the serious breach the supercap was meant to protect ever occurs. The fix is to state explicitly whether the supercap has its own separate ceiling or shares an aggregate with the general cap, and to make each cap’s per-claim or aggregate nature clear. A supercap that looks protective but sits under a low shared cap is decorative, not real.

Are liability caps and supercaps enforceable everywhere?

Broadly yes for ordinary contractual liability, but every system has hard limits. India enforces caps within the reasonable-compensation framework of Sections 73 and 74 of the Contract Act. The US enforces them under freedom of contract, subject to unconscionability and a general bar on capping fraud or gross negligence. The UK and Singapore apply a statutory reasonableness test and forbid excluding liability for death or personal injury from negligence, or for fraud. EU civil-law systems commonly void caps for intent and gross negligence. Onshore UAE goes furthest: Article 296 of the Civil Code voids attempts to limit liability for harmful acts, and fraud and gross negligence are always uncapped. A supercap should be scoped to the risks the governing law actually permits you to cap.


Written by Prakhar Rai, founder of My Legal Pal. Prakhar is an advocate enrolled with the Bar Council of India with over ten years of experience advising founders and companies on corporate and commercial matters. He is an alumnus of the National Law School of India University, Bangalore, where he completed his Master of Business Laws, and of La Martiniere. He believes in foresight and clarity first, paperwork second. Connect on LinkedIn.

This article is general information, not legal advice. How a liability cap or supercap is enforced varies by jurisdiction and by the specific facts and governing law of your contract, and the position can change. For advice on your own agreement, speak to a qualified lawyer.

If you are drafting or negotiating a limitation of liability clause and want the general cap, the supercap, and the carve-outs to work together and hold up in the jurisdictions your contract reaches, our team can help you get the structure and the numbers right. Learn more about our contract drafting service.

Leave a Reply

Your email address will not be published. Required fields are marked *

Are you human? Please solve:Captcha