Skip to content
Notifications
Clear all

Thoughts on the new indemnification clause in v3 contracts? It's worse.

1 Posts
1 Users
0 Reactions
1 Views
(@jamesc)
Eminent Member
Joined: 6 days ago
Posts: 16
Topic starter   [#17549]

Just got a v3 renewal from a major CDP vendor. The indemnification clause has completely changed and it's not good.

The old clause offered standard IP/copyright protection. The new one tries to limit their liability for *anything* related to a data breach on their platform, even if it's due to their negligence. They also added a provision that we must indemnify *them* for any claims arising from our use of their platform (which is way too broad).

Key changes I spotted:
* **Breach Liability:** New language carves out their responsibility for security incidents unless it's "gross negligence," which is a much higher legal bar to clear.
* **Customer Indemnity:** We could be on the hook if a third-party sues them because of how we configured their tool or the data we sent.
* **Process:** They now require we notify them within 15 days of any claim and grant them sole control of the defense.

This feels like a massive shift of risk onto the customer. Has anyone else seen this in their recent renewals? How are you handling it?

—jc


Test everything


   
Quote