Liability and indemnity in a data supply contract
Five ways a data deal goes wrong, who carries each one by default, and how caps, carve-outs and insurance are actually negotiated.
Five failure modes, five different risks
A single indemnity clause cannot cover all of these, and a contract that tries to cover them in one sentence usually leaves three of them unallocated. Name each one and give it an owner.
- Rights failure: a third party claims the material infringes their copyright or their performer rights. The claim usually arrives after the model has shipped.
- Consent failure: a speaker or a regulator challenges whether the collection was lawful. The cost is not the claim itself but the remediation, because material may have to come out of a training pool that has already been used.
- Quality failure: the delivery does not meet the specification. This is the most familiar failure and the easiest to allocate, because acceptance criteria can be written down.
- Security failure: the corpus leaks, or a subcontractor mishandles it. The exposure is usually contractual liability to third parties rather than the leak itself.
- Continuity failure: the vendor stops supplying or disappears. Nothing is breached on the day it happens, and the damage is the cost of rebuilding.
What an indemnity is, in plain terms
An indemnity is a promise to cover the other side's loss arising from a named event, plus an obligation to defend. Four parts have to be negotiated separately, because each one changes the value of the clause: who controls the defence, who pays for it, how quickly the indemnified party must give notice, and whether the indemnifying party may settle without consent.
The last two are where buyers lose money. A short notice deadline can extinguish an indemnity before the buyer knows a claim exists, and a vendor free to settle without consent can buy peace by accepting an injunction that removes your right to use the data. Require notice within a reasonable period from discovery, and require written consent before any settlement that imposes an obligation on you.
Caps, carve-outs, and the insurance behind them
Liability caps in this market are usually written as a multiple of the fees paid under the agreement, with a smaller sub-cap for data protection breaches. The structure is reasonable; the negotiation is about which multiple, and about what the cap does not reach.
The carve-outs matter more than the number. Standard exclusions from the cap are third-party intellectual property claims, breach of confidentiality, gross negligence or wilful misconduct, and breach of the data protection provisions. Buyers push for the first and last to be uncapped; vendors push to keep them inside the cap or inside a separate, higher cap. That argument is the core of the negotiation, and it is better had explicitly than discovered during a dispute.
Consequential loss exclusions deserve a second look as well. A clause excluding indirect and consequential loss will, on a narrow reading, exclude the buyer's liability to its own customers — which is exactly the loss the buyer is trying to allocate. If faulty data forces a product recall, the recall cost is the point of the clause, and it should be named as recoverable rather than left inside a general exclusion.
Ask whether the vendor carries professional indemnity and cyber cover, and ask for the certificate rather than the assurance. Two details decide whether the policy is worth anything to you: the limit relative to the contract, and whether claims arising from your project are inside the cover or removed by an endorsement.
If the vendor is small, insurance may be the only real security behind an indemnity — a large indemnity from a company with no assets is a piece of paper. The practical alternative is structural: pay in stages, hold back a portion until acceptance, and keep the final payment small enough that walking away from it is survivable for you and painful for them.
When a supplier refuses to sign
Two clauses get refused most often. The first is an uncapped indemnity for third-party rights claims; a vendor reselling a corpus they did not collect cannot carry that risk, and refusing is often the honest answer. The second is a warranty that every speaker consent covers training use in perpetuity across all territories, which some vendors cannot give because their historical forms do not say it.
Both refusals are informative rather than fatal. The counter-move is to trade scope for certainty: a capped indemnity, a warranty of good title, an obligation to cooperate in a defence, and access to the consent records if a claim arrives. A vendor who refuses the warranty and also refuses to hand over the underlying records is telling you where the problem is.
The clauses, in negotiation order
Work through them in this sequence, because each one constrains the next.
- Allocation of the five failure modes, each to a named party.
- Defence control, notice period, and consent to settle.
- The liability cap as a multiple of fees, with a separate data protection sub-cap.
- Carve-outs from the cap, and whether rights and data protection claims sit inside or outside it.
- Whether recall and customer liability are recoverable or excluded as consequential loss.
- Insurance limits, scope, and the certificate as a deliverable.
- A payment structure that keeps real money at risk until acceptance.
- A cooperation obligation covering records access if a claim arrives after the relationship ends.
One caution
Liability drafting is jurisdiction-specific, and the same clause can behave differently in two legal systems — caps that are enforceable in one place can be struck down in another. This is a map of the negotiation rather than legal advice, and both sides should have counsel review the final wording.