Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The general liability cap is set at twelve months of fees paid. For claims arising from Atlassian's unauthorized disclosure of Customer Data caused by a breach of its security program obligations, a higher cap applies: two times fees paid during the preceding twelve months or US$5,000,000, whichever is lower.
This analysis describes what Loom's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes the financial ceiling on Atlassian's liability for data security failures, with the Special Claims cap creating a specific recovery ceiling for unauthorized Customer Data disclosures that may be substantially lower than actual damages for high-value enterprise data incidents.
Under this clause, Customer's financial recovery from Atlassian for a security breach resulting in unauthorized Customer Data disclosure is capped at two times the fees paid in the prior twelve months or US$5,000,000, whichever is less; Customer payment obligations are explicitly excluded from the general liability cap.
Cross-platform context
See how other platforms handle Tiered Liability Cap with Special Claims and similar clauses.
Compare across platforms →Monitoring
Loom has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Except for Excluded Claims or Special Claims, to the maximum extent permitted by Law, each party's entire liability arising out of or related to this Agreement will not exceed in aggregate the amounts paid to Atlassian for the Products, Support and Advisory Services giving rise to the liability during the twelve (12) months preceding the first event out of which the liability arose. Customer's payment obligations under Sections 10.1 (Fees) and 10.2 (Taxes) are not limited by this Section 14.2. For Special Claims, Atlassian's aggregate liability under this Agreement will be the lesser of: (a) two times (2x) the amounts paid to Atlassian for the Products, Support and Advisory Services giving rise to the Special Claim during the twelve (12) months preceding the first event out of which the Special Claim arose, and (b) US$5,000,000. "Special Claims" means any unauthorized disclosure of Customer Data or Customer Materials caused by a breach by Atlassian of its obligations in Section 4.2 (Security Program).Excerpt from Loom's Terms of Service
1. REGULATORY LANDSCAPE: Contractual liability caps for data breaches interact with GDPR Article 82 liability provisions for EU customers, which establish data subject rights to compensation that cannot be waived by contract between controllers and processors. The cap does not affect Atlassian's regulatory obligations under GDPR or applicable breach notification laws; it governs only the contractual relationship between Atlassian and the Customer. For US customers, state breach notification laws and HIPAA civil monetary penalties operate independently of contractual caps. 2. GOVERNANCE EXPOSURE: High for enterprise customers with significant data assets in Atlassian Cloud Products. The Special Claims cap of 2x fees or US$5,000,000 may be substantially less than actual damages arising from a large-scale data breach, particularly for organizations storing sensitive business, personnel, or customer data. The Excluded Claims category, which removes Customer's Restrictions violations and confidentiality breaches from the general cap entirely, creates asymmetric exposure favoring Atlassian for certain claim types. 3. JURISDICTION FLAGS: EMEA customers governed by Irish law should evaluate whether Irish or EU law places mandatory floors on liability for data breaches that may limit the enforceability of this cap in certain circumstances. California courts have, in some commercial contexts, scrutinized limitation of liability clauses for unconscionability, though enforceability in B2B enterprise agreements is generally more robust. The US$5,000,000 absolute ceiling may be disproportionately low for large enterprise customers whose annual Atlassian spend is substantially below the threshold at which 2x fees would exceed that ceiling. 4. CONTRACT AND VENDOR IMPLICATIONS: Enterprise procurement teams should model the maximum recovery available under the Special Claims cap relative to the value of Customer Data stored in Atlassian Cloud Products when assessing risk exposure. Organizations may wish to negotiate higher caps or cyber liability insurance requirements as part of enterprise agreements. The Excluded Claims carve-out should be reviewed to confirm that Customer's own liability exposure for Restrictions violations is understood and managed through acceptable use controls. 5. COMPLIANCE CONSIDERATIONS: Risk management teams should assess whether the Special Claims cap is adequate relative to the Customer's own breach notification, regulatory penalty, and third-party liability exposure in the event of an Atlassian-caused data incident. Insurance programs should be evaluated to confirm that gaps between the contractual cap and total potential breach costs are addressed. Legal teams should note that the cap applies only to claims arising from Atlassian's breach of Section 4.2 (Security Program); data incidents caused by other Atlassian failures may fall under the lower general cap.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes the financial ceiling on Atlassian's liability for data security failures, with the Special Claims cap creating a specific recovery ceiling for unauthorized Customer Data disclosures that may be substantially lower than actual damages for high-value enterprise data incidents.
Under this clause, Customer's financial recovery from Atlassian for a security breach resulting in unauthorized Customer Data disclosure is capped at two times the fees paid in the prior twelve months or US$5,000,000, whichever is less; Customer payment obligations are explicitly excluded from the general liability cap.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Loom.