September 6, 20267 min read
Indemnification Clause Examples: Market-Standard Language Explained

Indemnification Clause Examples

An indemnification clause shifts the cost of a defined risk from one party to the other. In vendor supply and SaaS contracts it usually covers third-party claims rather than losses the parties cause each other directly. That is a convention of this contract type, not a rule of law: in share purchase agreements, tax deeds and finance documents, direct-loss indemnities are standard and deliberate. The standard vendor version covers third-party intellectual property infringement, usually alongside a data or security breach indemnity.

This page works through the language itself: what each component does, what the market position is, and what a lopsided version looks like when you meet one.

Read this before using anything below

These examples are illustrative and simplified to show structure. They are not legal advice and are not drafting-ready. Indemnity wording interacts with the liability cap, insurance, governing law and the rest of the agreement, and it varies by jurisdiction. Use this page to understand what you are reading and to brief your counsel. Have a qualified lawyer draft or review the actual clause.

Why we publish this

We build Bind, agentic AI for in-house legal teams, and one of the things it holds is a clause library: the standard positions a legal team has agreed it will accept, and the fallbacks it will take under pressure. That means we spend our time on the practical version of this question, which is not "what is an indemnity" but "which of these three versions is the one we normally sign".

We are not a law firm and this page is not a substitute for one. What we can usefully add is structure: which components appear in nearly every indemnity, which are negotiable, and where the disagreements actually happen.

One thing we will not do is invent a statistic. You will see claims elsewhere that a given position appears in some precise percentage of contracts. There is no public dataset behind most of those numbers. Where we describe something as market standard below, it means it is the position we see treated as the default starting point, not that we counted.

The four components of any indemnity

Almost every indemnification clause is these four parts in some order. Read them separately and the clause stops being a wall of text.

The trigger
What kind of claim sets it off. Third-party IP infringement, data breach, personal injury, breach of law. The narrower the trigger, the narrower the exposure.
The obligation
What the indemnifying party must do. Indemnify (reimburse), defend (fund and run the defense), hold harmless (ensure no loss is borne). These are three different promises.
The procedure
Notice, control of the defense, consent to settle, cooperation. This is where practical control of a live claim is decided, and it is routinely skimmed.
The limits
Whether it sits inside the general liability cap, outside it, or under a separate elevated cap. Silence here is the most common drafting failure.

Example 1: the IP infringement indemnity

The near-universal vendor indemnity in software and services. This is the one a customer will expect and the one you will find hardest to refuse.

Illustrative structure, not drafting-ready language

Vendor will defend Customer against any third-party claim alleging that the Service, as provided by Vendor and used in accordance with the Documentation, infringes that third party's intellectual property rights, and will indemnify Customer for damages finally awarded or agreed in settlement of such a claim.

Vendor's obligations do not apply to claims arising from: (a) Customer Data or materials supplied by Customer; (b) modification of the Service by anyone other than Vendor; or (c) use of the Service in combination with anything not supplied by Vendor, where the claim would not have arisen but for that combination.

If the Service becomes, or Vendor believes it may become, subject to such a claim, Vendor may at its option: (i) procure the right for Customer to continue using it; (ii) modify or replace it so it is non-infringing; or (iii) if neither is commercially reasonable, terminate the affected Service and refund prepaid unused fees.

What to notice. The trigger is narrow and specific: the service as provided, used as documented. The carve-outs in the second paragraph are standard and reasonable, because a vendor cannot underwrite what the customer bolted on. The third paragraph is the remedy ladder, and it is the vendor's option rather than the customer's, which is also market standard.

Where it is negotiated. Customers push on two things. First the refund measure: prepaid unused fees can be close to zero late in a term, so buyers ask for fees paid over a defined prior period instead. Second the trigger: as drafted only the vendor can invoke the ladder, so buyers ask for a customer-side right to terminate and recover once the service is materially impaired.

Example 2: the data and security indemnity

The second common vendor indemnity, and in our experience the one buyers now push hardest on.

Illustrative structure, not drafting-ready language

Vendor will defend and indemnify Customer against third-party claims, and against regulatory investigations and enforcement proceedings brought against Customer by a supervisory authority, to the extent arising from Vendor's breach of its security obligations or its unauthorized disclosure of Customer Personal Data, including any resulting monetary penalty to the extent indemnifiable under applicable law and the reasonable costs of legally required breach notification.

What to notice. A regulator's penalty is an enforcement action against the customer, not a third-party claim in the ordinary sense, so an indemnity limited to third-party claims may not reach it at all. That is why the clause above names investigations and enforcement proceedings separately. "To the extent arising from" apportions rather than making it all-or-nothing. Notification costs and penalties are frequently the largest real numbers in a breach, and a generic indemnity may miss both.

Where it is negotiated. Whether a penalty is indemnifiable at all is unsettled and jurisdiction-dependent. No English case has decided the point for UK GDPR penalties, and the FCA prohibits regulated firms from insuring against its own financial penalties, which is why careful drafting says "to the extent indemnifiable under applicable law" rather than promising something a court may not give. Vendors push for this to sit under a super-cap rather than uncapped.

Example 3: the mutual confidentiality indemnity

Illustrative structure, not drafting-ready language

Each party will indemnify the other against third-party claims arising from the indemnifying party's breach of its confidentiality obligations under this Agreement.

Short, genuinely mutual, and rarely contentious, because both sides exchange confidential information and the risk is symmetrical. When you see a one-sided version of this, it is usually a drafting inheritance rather than a considered position, and asking for it to be made mutual is a low-cost win.

Mutual or one-sided, by risk category

Usually one-sided (vendor to customer)
  • Third-party IP infringement in the service
  • Vendor's breach of security obligations
  • Vendor's breach of applicable law in delivering the service
Usually mutual
  • Breach of confidentiality
  • Personal injury or property damage on site
  • Breach of data protection law where both parties are controllers

The principle is control. Whoever controls the risk carries it. A vendor wrote the code, so a vendor underwrites IP infringement in the code. Both parties handle each other's confidential information, so confidentiality runs both ways. When someone asks for a mutual IP indemnity in a SaaS deal, the answer is usually that the customer is not in a position to warrant the vendor's own product.

The interaction that causes most disputes

Indemnities and the liability cap
IP infringement indemnity
Market standard is outside the general liability cap, frequently uncapped.
Data and security indemnity
Outside the cap, or under an elevated super-cap. Commonly drafted at a multiple of annual fees.
Confidentiality indemnity
Varies. Often inside the cap, sometimes carved out with the confidentiality obligations generally.
Everything else
Usually inside the general cap unless specifically carved out.
Silence
The most common failure. If the clause does not say, both parties will read it their own way and neither will find out who was right until it matters.
The one edit worth making to almost any indemnity

State explicitly, for each indemnity, whether it is inside the general liability cap, outside it, or subject to a separate limit. Most disputes over indemnities are not about the trigger. They are about how much is payable, and that turns on a sentence people forget to write.

Five red flags

1
Direct losses where you expected third-party claims
A direct-loss indemnity is a real device, not a mistake. It is standard in share purchase agreements, tax deeds and finance documents, used deliberately to escape the remoteness and mitigation rules that limit an ordinary damages claim. The flag is finding one in a SaaS contract where you expected third-party cover only, because it changes both the measure of recovery and how it interacts with the cap. Check what the trigger actually says.
2
Sole control of the defense with no consent on settlement
The indemnifying party runs the case and can settle on terms that bind you, including admissions. Standard practice is control paired with a consent right on any settlement imposing a non-monetary obligation or admission.
3
Silence on the cap
Neither inside nor outside is stated. This is arguable, and you will be arguing it during a live claim.
4
A one-sided data indemnity where both sides handle data
Common in vendor paper and usually an inheritance rather than a position. Ask for symmetry.
5
No carve-out for your own materials or instructions
An indemnity that covers claims arising from the customer's own data or specified combinations makes the vendor underwrite something it never controlled. Reasonable vendors carve this out; the absence is worth questioning.

How this looks as a clause library entry

The practical version of this page is not prose, it is three positions per clause: what you prefer, what you will accept, and what you will not sign. That is what a clause library holds, and it is the difference between a legal team that negotiates consistently and one where the outcome depends on who picked up the request.

Without a clause library
  • Positions vary by whoever handles the contract
  • Precedent is whatever similar deal someone remembers
  • Escalation happens late, when the deal is already committed
  • Nobody can say what we have actually accepted before
With one
  • Preferred, fallback and unacceptable stated in advance
  • Deviations flagged automatically against the standard
  • Escalation triggered by the position, not by instinct
  • The record of accepted positions is queryable

Bind holds that library and checks incoming drafts against it, which is why we care about this topic. But you do not need software to start: the first version of a clause library is a document with three columns, and it is worth more than the tool that eventually holds it.

In-house legal teams at Slush, the global startup and tech event organizer, at Phoenix Entertainment, and at the stock-listed Outdoor Holding (Nasdaq, US) are among those using Bind.

Bind CEO Aku Pöllänen explains how the playbook drives review:

See how Bind enforces compliance through playbook automation

Not for you if you sign a handful of near-identical agreements a year. The consistency problem this solves only appears at volume.

For what a standard indemnity contains and how the market has moved, see indemnification clauses: what's standard in 2026. For how indemnities interact with the cap, see limitation of liability. For building the library itself, see contract clause library.

A note on sourcing

Sources for the legal points on this page: Morgan Lewis on indemnify, defend and hold harmless for the contested status of hold harmless; the FCA Handbook GEN 6.1 for the prohibition on regulated firms insuring against their own financial penalties; and a standard practitioner guide to warranties and indemnities for the direct-loss indemnity as a deliberate device.

There is no public dataset of indemnity clause frequencies that we consider citable, and we have chosen not to reprint the percentages that circulate without one. Where this page says market standard, it describes the position treated as the default starting point in commercial and SaaS negotiation, based on what we see in contracts running through Bind and on the drafting conventions reflected in widely used precedent. Treat it as an informed description of practice, not as a measurement, and treat none of it as legal advice.

Ready to simplify your contracts?

See how Bind helps teams manage contracts from draft to signature in one platform.

Frequently asked questions

What does a standard indemnification clause look like?
In commercial and SaaS contracts a standard indemnity covers third-party claims rather than direct losses between the parties. The near-universal vendor indemnity is third-party intellectual property infringement, usually paired with a data or security breach indemnity. It typically includes a duty to defend, a defined claim procedure, and sits outside or above the general liability cap.
What is the difference between indemnify, defend and hold harmless?
Defend and indemnify are genuinely different obligations with different triggers. Indemnify means reimburse established losses once liability is determined. Defend means fund and run the legal defense from the moment a claim is filed, regardless of who ultimately wins. Hold harmless is contested: on the majority view it adds nothing to indemnify, and the Delaware Court of Chancery has treated the two as synonymous, though some drafters use it to cover losses that are not the subject of a claim at all. Where a defense obligation exists and is enforceable it is the broadest and starts earliest, which usually makes it the most expensive. Whether you have one at all is jurisdiction-dependent.
Should an indemnity be mutual or one-sided?
It depends on the risk category rather than on fairness. In SaaS the IP infringement indemnity is almost always one-sided from vendor to customer, because the vendor controls the code it wrote. Confidentiality and data-protection indemnities are frequently mutual, because both sides exchange data. A common hybrid pairs a vendor indemnity for the service with a narrower customer indemnity for the customer's own data or misuse.
Which indemnity positions on this page are standard and which are pushback?
The IP infringement indemnity with a vendor-option remedy ladder, and a data indemnity apportioned by "to the extent arising from", are the positions most vendors open with. The pushback positions are naming regulatory investigations separately rather than relying on "third-party claim" to reach them, changing the refund measure from prepaid unused fees to fees paid over a prior period, and adding a customer-side right to invoke the remedy ladder.
Why does an indemnity for regulatory fines often fail to work?
Two reasons. A regulator's penalty is an enforcement action against your company, not a third-party claim, so an indemnity drafted to cover third-party claims may not reach it unless investigations and enforcement proceedings are named separately. And whether a penalty is indemnifiable at all is unsettled and jurisdiction-dependent, which is why careful drafting says to the extent indemnifiable under applicable law rather than promising it outright.
Is the example language on this page safe to use in a contract?
No, not as-is. The examples here are illustrative and simplified to show structure, and they are not legal advice. Indemnity language interacts with the liability cap, insurance, governing law and the rest of the agreement, and it varies by jurisdiction. Use them to understand what you are reading and to brief your counsel, then have a qualified lawyer draft or review the actual wording.