Rules and ethics

A checklist for reading a UK marketplace software contract on liability and exit

Seller software contracts need checks on liability caps, UK GDPR data processing, subprocessors, service credits and termination under English law before you sign.

What to take away

  • A seller software contract is only as good as its liability cap, its data processing schedule and its exit route, so read those three first.
  • Check what the liability cap excludes: data protection fines, IP infringement and confidentiality breaches are often carved out, which means the cap does not protect you there.
  • UK GDPR data processing clauses must name controller and processor roles, set out subprocessors and cover international transfers.
  • Service credits are usually a discount, not compensation, and are often the only remedy the vendor offers for downtime.
  • Termination under English law turns on notice periods, material breach remedies and what happens to your data on exit.
  • Put the vendor's sales claims next to the contract text, because the contract usually wins.

Liability caps and what they exclude in UK software contracts

A liability cap is the maximum the vendor will pay for a claim. It is normally expressed as a multiple of fees paid in the previous 12 months, or a fixed sum. Read the number, then read what sits outside it.

Most UK software contracts carve out a list of claims that are uncapped. Typical carve-outs include death or personal injury caused by negligence, fraud, breach of confidentiality, infringement of intellectual property rights, and sometimes breach of data protection law.

If data protection breaches are uncapped, the vendor carries more risk and may price accordingly. If they are capped, you carry more.

The cap usually applies to each claim or to all claims in a period. A per-claim cap with no annual aggregate can be worse than it looks, because a single incident can generate several claims. Check whether the cap is shared across affiliates and whether it reduces as fees are paid.

Watch the exclusion of indirect and consequential loss. Lost profits, lost sales and reputational harm are commonly excluded, even where they flow directly from a failure. For a seller whose listings, stock feeds or order data depend on the software, lost sales are the main loss. Ask the vendor to name the categories it will cover.

Also check the interaction with indemnities. A vendor indemnity for IP infringement or data breach is only useful if it sits outside the cap and is backed by insurance. Ask for the policy wording or a certificate.

Clause What to check Why it matters to a seller
Cap amount Multiple of fees or fixed sum Sets the ceiling on recovery
Carve-outs Data, IP, confidentiality, fraud Uncapped claims change the risk balance
Aggregate Per claim or annual Several claims can exhaust one cap
Consequential loss Named exclusions Lost sales are often excluded
Indemnities Scope, cap, insurance An indemnity inside the cap is weak

This is the same ground covered in our guide to reading a marketplace software contract for identity, money, audit and exit, which sets out the commercial terms that sit alongside the liability position.

UK GDPR data processing clauses and controller roles

The data processing clause is where a software contract does most of its regulatory work. It should say who is the controller and who is the processor for each category of personal data.

In most seller software arrangements, the seller is the controller of customer and order data, and the vendor is the processor. Where the vendor uses data for its own purposes, such as product analytics or benchmarking, it may be a controller for that activity. The contract should be explicit rather than leaving it to a schedule.

The clause should cover the subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subject. It should also set out the processor's obligations: processing only on documented instructions, confidentiality, security, breach notification, assistance with data subject rights and assistance with impact assessments.

The UK GDPR guidance and resources from the ICO set out what those obligations look like in practice, including the requirement for a written contract between controller and processor. Definitions used in the checklist, such as personal data and processing, come from the Data Protection Act 2018.

Check the breach notification window. The controller has 72 hours to notify the ICO, so a processor that promises notice within 72 hours leaves no time to assess and report. Look for a shorter window, and for a named contact and a defined format.

Check what happens to data on termination. The clause should require deletion or return within a set period, with certification. It should also cover backups, archives and any data the vendor holds in test or analytics environments.

Subprocessors, transfers and the Data (Use and Access) Act 2025

A subprocessor is any third party the vendor uses to process your data. Cloud hosting, email delivery, payment processing, support tooling and analytics are common examples. The contract should list them or point to a list the vendor maintains.

Check the approval mechanism. General authorisation with a right to object is common, but the objection right is often hollow if the vendor can terminate rather than change provider. Look for advance notice of new subprocessors and a genuine right to object.

The vendor should remain liable for its subprocessors. If the clause says the vendor is not responsible for subprocessor acts or omissions, your route to a remedy narrows to a party you have no contract with.

International transfers matter if data leaves the UK. Check whether transfers rely on adequacy regulations, the International Data Transfer Agreement or the UK Addendum to the EU standard contractual clauses. Ask for the transfer risk assessment where one is required.

The Data (Use and Access) Act 2025 is the current UK data rules framework and it changes parts of the regime that contracts refer to. Clauses drafted against older legislation may cite provisions that have moved. Check that the contract refers to the law as it stands rather than a superseded version.

  • Subprocessors named, or a list with a change notice period
  • Right to object to a new subprocessor, with a workable remedy
  • Vendor remains liable for subprocessor acts and omissions
  • Transfer mechanism named for each destination country
  • Transfer risk assessment available on request
  • Security measures described, not just promised
  • Breach notification window shorter than 72 hours

Service credits and remedies that actually bite

A service credit is a credit against future fees when the service misses an agreed service level. It is a price adjustment, not compensation for loss.

Check the availability target and the measurement window. A 99.9% monthly target sounds strong until you see that planned maintenance is excluded, that the measurement is monthly rather than daily, and that a single outage under the threshold earns nothing.

Check the credit scale. Credits are often a small percentage of the monthly fee, capped at a fraction of that month. If the cap is 10% of one month's fee, the remedy is modest against a peak trading weekend.

Check whether credits are the sole and exclusive remedy for service failures. If they are, you may have given up the right to claim damages for the same failure. That is a reasonable trade only if the credits are meaningful and the service levels match your trading pattern.

Check the claim process. Some contracts require you to claim within a short window, with evidence, or the credit is lost. Diarise the process and keep monitoring records.

For a worked example, take a seller on a £2,000 monthly fee with a 99.9% target and a credit of 5% of the monthly fee per hour of downtime, capped at 20%. Six hours of downtime in a month produces a credit of £400 against a cap of £400.

If the outage falls in the pre-Christmas peak, the lost margin is likely to exceed that figure several times over.

Termination rights and exit under English law

Termination under English law is a matter of the contract, not a general right to walk away because the relationship has soured. Read the term, the notice provisions and the breach remedy.

Check the initial term and the renewal mechanism. Auto-renewal with a long notice period is common. If notice must be given 90 days before renewal, a missed date locks you in for another year.

Check termination for convenience. If the vendor has it and you do not, the balance is one-sided. If neither has it, you need a material breach route that works.

Check the material breach clause. It usually requires notice and a cure period, often 30 days. Some breaches cannot be cured, such as a persistent failure to meet service levels. Check whether repeated breaches of the same obligation count as material.

Check insolvency triggers. These should be mutual and should cover administration, liquidation and composition with creditors.

On exit, the contract should cover data return or deletion, transition assistance, wind-down of integrations and the fate of any prepaid fees. Check whether the vendor will provide data in a usable format and how long it will hold it. Check whether your listings, order history and customer records can be exported before the licence ends.

Our due diligence guide covers the vendor checks that sit alongside this, from identity to the terms of exit, and it is worth reading before you negotiate the termination clause.

Questions to put to a vendor before signature

Ask these in writing and keep the answers. A vendor that will not answer in writing is telling you something.

  1. What is the liability cap, and which claims sit outside it?
  2. Are data protection breaches, IP infringement and confidentiality breaches capped?
  3. Who are your current subprocessors, and how much notice will I get before a new one is added?
  4. Which countries will my data be transferred to, and under which transfer mechanism?
  5. What is the breach notification window, and who do I contact?
  6. What are the service levels, the measurement window and the credit scale?
  7. What notice must I give to prevent auto-renewal, and what happens to my data on exit?

These questions map onto the checklist in our quality guide, which uses evidence IDs and an exit test to record what a vendor has actually demonstrated rather than claimed.

Reading the contract against the vendor's own claims

Sales material is not the contract. A vendor may describe 24/7 support, unlimited API calls or a 99.99% uptime record in a pitch deck, while the contract sets out business hours support, fair use limits and a 99.9% target.

Collect the claims and match each one to a clause. Where a claim has no clause behind it, ask for it in writing as a contractual commitment or treat it as marketing.

The Business regulation guidance and tools from GOV.UK are a useful starting point for the compliance side of that review, particularly where the software touches regulated activity.

Check the order of precedence clause. It usually puts the main body of the contract above schedules, and schedules above any proposal or statement of work. That ordering decides which version of a promise survives.

Check the entire agreement clause. It normally excludes pre-contract representations, which is why a written answer to your questions matters more than a verbal assurance.

Check the variation clause. If the vendor can change terms or service levels unilaterally, the terms you signed are a starting point rather than a fixed deal. Look for notice and a right to terminate if a change is material.

Finally, check the governing law and jurisdiction. English law and the courts of England and Wales are the default for most UK software contracts, but some vendors prefer arbitration or a foreign forum. That choice affects cost and speed if a dispute arises.

Common questions

What is a liability cap in a UK software contract? It is the maximum sum the vendor will pay for claims under the contract, usually a multiple of fees paid in a defined period or a fixed amount.

Can a vendor cap liability for a data protection breach? Yes, unless the contract carves data protection breaches out of the cap. Whether the cap applies is a negotiation point, and the answer changes the vendor's risk and your remedy.

Do I need a separate data processing agreement? Usually yes if the vendor processes personal data for you. It can be a schedule to the main contract, but it must contain the terms required by UK GDPR.

Are service credits the same as compensation? No. A service credit is a discount against fees. It does not cover lost sales or other losses unless the contract says so.

How much notice do I need to give to exit? It depends on the contract. Check the renewal clause and the notice period, and diarise the deadline well before it falls.

What happens to my data when the contract ends? The contract should require return or deletion within a set period, in a usable format, with confirmation. Check backups and analytics copies too.

More in Rules and ethics

Rules and ethics

How HMRC's Making Tax Digital rules change what UK seller software must calculate

Marketplace seller tools must now calculate UK VAT, MTD for Income Tax quarterly updates and marketplace-facilitator VAT, with exact fields and figures.

Rules and ethics

Post-Brexit customs and IOSS for British sellers shipping to the EU

Seller software must encode customs declarations, IOSS, Union One-Stop Shop, rules of origin and XI EORI for UK sellers shipping to the EU and Northern Ireland.

Tools and providers

Belfast and the dual market, seller software for UK and EU trade from Northern Ireland

Seller software for Belfast traders must handle the Windsor Framework green lane, XI EORI numbers, dual VAT registration and Irish Sea freight in one flow.

Tools and providers

Which Scottish delivery surcharges must seller software model by region?

Seller software must model Royal Mail and Parcelforce zonal pricing, Highland and island surcharges and carrier coverage gaps by postcode area.