legal247

SaaS limitation of liability: what holds up under Norwegian law?

In brief

A SaaS limitation of liability is, as a rule, valid between businesses under Norwegian law. A liability cap and an exclusion of indirect loss normally hold, but as a starting point they do not protect the supplier against wilful misconduct or gross negligence. Unusual and onerous terms may also fall away as not accepted, be read restrictively or be adjusted under the Contracts Act § 36.

Almost every SaaS agreement limits the supplier’s liability. Typically, liability is capped at what the customer has paid over the past twelve months, indirect loss is excluded and loss of data is disclaimed. The question for the customer is what actually holds if the service fails. The answer is that most of it holds between businesses, but not all of it.

What is a limitation of liability in a SaaS agreement?

A limitation of liability is a contract term that restricts how much compensation one party can claim from the other for breach of contract. In SaaS agreements this is done in three ways, often at the same time.

  • Liability cap. Total compensation is limited to a fixed amount, often the fees for twelve months.
  • Exclusion of indirect loss. Loss of profit, business interruption and third-party claims are not covered.
  • Specific disclaimers. The supplier disclaims liability for loss of data, failures by subcontractors or downtime beyond what the service level agreement compensates.

For the customer, this means that much of the real risk of an outage or data loss often stays with the customer. The supplier prices the service on the basis that its liability is limited, so the customer must decide whether the remaining risk should be covered by its own measures, insurance or a better agreement.

Is a SaaS limitation of liability valid under Norwegian law?

Yes, as a rule. Freedom of contract applies between businesses, and a limitation of liability in a SaaS agreement is a lawful and common way of allocating risk. Norwegian courts start from the position that they will respect the risk allocation agreed between professional parties.

There is no statute that specifically governs liability in SaaS agreements. The Sale of Goods Act (kjøpsloven) applies to the sale of goods, not to ongoing services. It is nevertheless often used as an aid to interpretation and as an expression of general principles of contract law where the agreement is silent or unclear.

A limitation of liability can still fall away or be narrowed on four grounds, which are discussed below. In contracts governed by the law of another country, such as US standard terms, the answer first depends on which law applies. Read more about choice of law and jurisdiction in international agreements.

When does the limitation of liability not hold?

Wilful misconduct and gross negligence

The starting point in Norwegian contract law is that a limitation of liability does not protect a party that has caused the loss wilfully or through gross negligence. The rule is not statutory. It rests on the view that it would be offensive to allow a party to limit its liability for its own serious failures.

Gross negligence has been described in case law as a marked departure from ordinary prudent conduct, where the party is considerably more to blame than in cases of ordinary negligence (Rt. 1989 s. 1318). The threshold is high. A breach of the service level agreement or an ordinary operational error is not grossly negligent.

Nor is the rule absolute. In Rt. 1994 s. 626 (Kaiinspektør), the Supreme Court upheld a monetary cap even though the damage had been caused by gross negligence on the part of an employee who was not part of management. The court emphasised that the terms had been negotiated between industry organisations, the availability of insurance and the need for predictability. How far the exception for gross negligence extends to employees and subcontractors therefore depends on a specific assessment.

On 30 June 2026, Gulating Court of Appeal held that a hosting provider was not grossly negligent, even though its backup server sat in the same network as the production data that was lost in a ransomware attack. The court emphasised that the customer had bought a low-priced standard service, and measured the level of security against industry practice among comparable suppliers at the time of the attack in 2021. Missing written procedures and the lack of a multi-factor authentication requirement were not enough either. Liability was limited to three months’ fees, NOK 8,280. The judgment shows that the threshold is high even where the failure concerns the core service. Read more in the article on the Nordlo judgment.

Many SaaS agreements address the question themselves. So does the Norwegian government’s standard agreement SSA-L, under which the limitation of damages expressly does not apply in the event of gross negligence or wilful misconduct by the supplier “or anyone for whom the supplier is responsible” (clause 9.2.7).

Where the term was never accepted

An unusual and onerous term must have been clearly brought to the other party’s attention to become part of the agreement. In Rt. 2004 s. 675 (Agurkpinne), the Supreme Court held that a limitation of liability to the invoice value had not been accepted. The term had not been given a prominent place, had not been raised in the negotiations and involved a significant transfer of risk to the buyer.

For the SaaS customer, this means that terms hidden in linked online terms that depart sharply from what is customary are more vulnerable than terms in a negotiated master agreement. It is nevertheless not a reliable strategy to depend on. Standard liability caps in SaaS agreements are so widespread that they are normally regarded as foreseeable.

Terms can also become binding without the customer having signed or read them. In HR-2026-780-A, the Supreme Court held that the decisive question is whether a party had reasonable grounds to expect that the other party had accepted the terms, and that attempts to hide onerous terms count against incorporation. In the Nordlo judgment, the customer was bound by the supplier’s standard terms even though no written agreement was ever made. The customer had ordered the same standard service that a company it owned already used on those terms, and did not follow up the supplier’s invitations to meetings. The Court of Appeal also gave weight to the fact that similar limitations of liability are common in the industry.

Restrictive interpretation

Limitations of liability are often interpreted strictly against the party that drafted them. If it is unclear whether a disclaimer covers a particular loss, the doubt will normally count against the supplier that wrote the terms. Precise definitions are therefore in both parties’ interest.

Under section 36 of the Contracts Act

The Contracts Act (avtaleloven) allows the courts, under Contracts Act § 36, to set aside or amend a contract term where it would be unreasonable or contrary to good business practice to rely on it. The provision also applies between businesses, but the threshold is high where the parties are professionals and have had the opportunity to assess the risk. In the Kaiinspektør case, neither general principles nor section 36 led to the cap being set aside.

Section 36 is most relevant where bargaining power is unequal, for example where a small business has accepted a global supplier’s standard terms with no real opportunity to negotiate, and where the limitation renders the supplier’s performance obligation virtually meaningless.

The liability cap is not a formality. It decides who pays when the service fails.

What is indirect loss?

Indirect loss is a legal category of consequential loss that is often excluded from compensation. Sale of Goods Act § 67(2) defines indirect loss as loss resulting from business interruption, loss of use, loss of profit because a contract with a third party lapses, and loss resulting from damage to anything other than the goods themselves. In the Agurkpinne case, the Supreme Court took the view that the list is exhaustive.

In SaaS agreements, the definition of indirect loss is often far wider than in the Sale of Goods Act. The supplier’s terms may cover all lost revenue, lost savings, loss of data and reputational harm. The wider the definition, the smaller the direct loss the customer can recover. SSA-L clause 9.2.6 confines itself to loss of profit, lost savings and third-party claims, and treats the additional cost of replacement purchases and extra work as direct loss.

How do SaaS suppliers’ standard terms compare with the government standard agreement?

The Norwegian Government Standard Agreements (SSA), administered by the Norwegian Agency for Public and Financial Management (DFØ), are not law. They are nevertheless widely used as a benchmark for a balanced risk allocation in the Norwegian market, including in private procurement. The table compares SSA-L 2026 with common supplier terms.

Topic SSA-L 2026 Common supplier terms
Liability cap Fees invoiced over the past 12 months Often 12 months, sometimes 3 or 6 months
Indirect loss Loss of profit, lost savings and third-party claims Broad definition, often including loss of data
Wilful misconduct and gross negligence The cap does not apply Often not addressed, or only wilful misconduct excluded
Loss of data Duty to restore and reconstruct Often fully disclaimed
Data protection GDPR Art. 82 outside the cap, each party bears its own fines Often within the cap, or a separate low cap

Why is loss of data the most important point?

Loss of data is the risk that hits a SaaS customer hardest, and it is often the one that is least well regulated. SSA-L clause 8 requires the supplier to restore data from the most recent backup free of charge where the loss is due to circumstances for which the supplier is responsible, and to cover reconstruction beyond that if the supplier has acted negligently. Many commercial terms instead disclaim liability entirely and leave backups to the customer.

The same risk arises when the agreement ends. See the article on cloud exit and the return of data. If the supplier processes personal data, the data processing agreement for SaaS must also be consistent with the liability provisions in the master agreement. GDPR Art. 82 gives data subjects a direct claim for compensation, and administrative fines under GDPR Art. 83 cannot be contracted away between the parties.

What about AI features in the service?

Suppliers of AI features often disclaim liability for the content the model produces. Towards its own customers, however, the business remains liable for incorrect answers from a chatbot, as discussed in the article on AI hallucinations and liability. This creates a liability gap between what the business must answer for externally and what it can recover from the supplier. The gap must be closed in the agreement, or covered by controls and insurance.

Nor should the contract text be drafted or amended with AI without legal review. Liability clauses are precisely where small differences in wording have large consequences. Read more about vibe lawyering and the risks of AI-drafted contracts.

What should the business do?

  1. Map the real loss. Calculate what a week without the service or a loss of data would cost the business, and compare it with the liability cap.
  2. Negotiate the cap. Require at least twelve months’ fees, and a higher cap or a separate cap for breaches of confidentiality, information security and data protection.
  3. Narrow the definition of indirect loss. Use the definition in the Sale of Goods Act or SSA-L as a reference, and make sure that the additional cost of replacement purchases and data restoration counts as direct loss.
  4. Include exceptions for wilful misconduct and gross negligence. Make the exception also apply to anyone for whom the supplier is responsible, as SSA-L does.
  5. Regulate loss of data specifically. Require backups, a restoration time and a duty on the supplier to reconstruct data.
  6. Check the governing law. A limitation of liability under US state law may have a different effect than under Norwegian law.
  7. Look at the agreement as a whole. The liability provisions must fit together with service levels, price increases in the SaaS agreement and exit.

A SaaS limitation of liability is negotiable, particularly for customers with some volume. Read more about agreements for buying cloud services on the contracts topic page.

Questions and answers

Is loss of data an indirect loss?

Not under the list in the Sale of Goods Act, which does not mention loss of data. Many SaaS agreements nevertheless define loss of data as indirect loss or exclude liability for it specifically. Read the definition in the agreement and require a separate clause on data restoration, as SSA-L has in clause 8.

Does the liability cap also cover administrative fines from the Norwegian Data Protection Authority?

An administrative fine is imposed on the party that has infringed the GDPR, and each party bears its own fines as a starting point. SSA-L states exactly this, and also places liability towards data subjects under GDPR Art. 82 outside the liability cap.

Can we as the customer also limit our liability towards the supplier?

Yes. A good liability clause is mutual. The customer can also breach the agreement, for example by misusing licences, and should have the same cap and the same exclusion of indirect loss as the supplier.

Next legal review: 1 April 2027