Indemnification Clause Outsourcing
Definition
Indemnification Clause Outsourcing
An indemnification clause obliges one party to cover losses the other suffers from claims brought by outsiders, such as regulators, customers or rights holders. It moves third-party loss sideways rather than capping what the parties may recover from each other.
That distinction is the whole point — a liability cap limits what the buyer can claim from the provider, and an indemnity decides who funds a claim that neither of them started.
Typical outsourcing indemnities cover intellectual property infringement, data protection breaches, personal injury on site and unpaid taxes or employment claims arising from the provider’s own staff.
Indemnities are often carved out of the liability cap, which makes them the largest single exposure in many contracts — that carve-out deserves as much scrutiny as the cap itself.
Key takeaways
- An indemnity funds third-party claims; a liability cap limits claims between the parties.
- Intellectual property and data protection are the two indemnities that matter most.
- Indemnities are frequently excluded from the cap, creating uncapped exposure.
- Control-of-defence terms decide who runs the claim and who may settle it.
How it works
The clause names the triggering event, who is protected, what costs are recoverable, and who controls the defence of the claim. Weak drafting usually fails on the last of those four.
Public contracting treats third-party exposure as an insurance question. Standard federal terms require a contractor to “provide and maintain workers’ compensation, employer’s liability, comprehensive general liability” and other cover the buyer specifies.
| Indemnity | Typical trigger | Usually capped? |
|---|---|---|
| Intellectual property | Infringement claim by a rights holder | Often not |
| Data protection | Regulator or data subject claim | Sometimes capped separately |
| Personal injury | Incident on buyer premises | Backed by insurance |
| Employment | Claim by provider’s own staff | Capped or uncapped |
| Tax and social charges | Authority reassesses status | Rarely capped |
Privacy law makes the data row unusually sharp. Where a controller and a processor are both responsible for the same damage, each “shall be held liable for the entire damage” so that the individual is effectively compensated.
That joint liability is why buyers insist on a data indemnity — being sued for the whole loss and then chasing the provider separately is a far worse position than being indemnified up front.
Public policy sometimes fixes the answer. UK guidance records an agreed position that a supplier’s liability “should be unlimited for a breach of a third party’s intellectual property rights” while data protection claims are capped.
Examples
Indemnities look abstract until a letter arrives from someone who is not a party to the contract. The four cases below show the clause doing exactly that work.
A software vendor sues a buyer over code a development provider embedded in a delivered system. The intellectual property indemnity puts the cost and the defence with the provider.
A regulator fines a buyer after a processing error at an offshore site. The data processing agreement carries an indemnity, so the provider funds both the penalty and the response.
A contractor’s employee brings an employment claim against the buyer, arguing the buyer was the real employer. The employment indemnity covers the defence, but only because the clause named that scenario.
A buyer discovers the indemnity is capped at the annual charge. The claim is four times that figure, so the cap decides the outcome rather than the indemnity.
Related terms
Indemnities sit inside a wider risk-allocation stack and are routinely confused with the clauses around them. The entries below separate who funds a loss from who is limited in claiming one.
- Right to audit clause: produces the evidence needed to establish which party caused the loss.
- Confidentiality clause: creates one of the breaches an indemnity is most often written to cover.
- Sub-processor clause: extends the chain, and indemnities must follow it or they leave a gap.
- HIPAA compliance: a regime where third-party exposure makes the data indemnity non-negotiable.
- Compliance outsourcing: the service line where regulatory indemnities are most heavily negotiated.
FAQ
How is an indemnity different from a liability cap?
An indemnity funds claims brought by third parties. A cap limits what the buyer and provider can recover from each other. They answer different questions.
Should indemnities be capped?
Intellectual property indemnities usually are not, because the exposure is unpredictable. Data and employment indemnities are often given their own separate, higher cap.
Who controls the defence of a claim?
Whoever the clause says. Most indemnities give control to the indemnifying party, with a duty to consult and a bar on settling in terms that admit the other’s fault.
Does an indemnity cover fines?
Only if it says so, and only where local law permits. Some jurisdictions treat indemnities against regulatory penalties as unenforceable on public policy grounds.
What is a mutual indemnity?
One where both parties indemnify each other against the same category of third-party claim. It is common for personal injury and rare for intellectual property.
Does the indemnity follow sub-processors?
Only where it is drafted to. A provider that passes work down without a matching indemnity retains the exposure itself.
Compare providers on how they allocate risk in the Outsource Accelerator directory.







Independent




