The five vendor contract clauses most likely to produce disputes are indemnification, liability caps, auto-renewal, termination rights, and intellectual property ownership. If you sign a vendor agreement without reviewing these five areas, you are accepting risk that the vendor’s lawyer specifically designed to shift onto your company, risk that may not become apparent until the vendor relationship deteriorates and you discover the contract favors the vendor on every material term.

That is the short version. The rest of this guide breaks down each red flag, explains what to look for in your existing and future vendor agreements, and identifies the provisions that separate a contract protecting your business from one protecting only the vendor.

The Five Clauses That Create the Most Vendor Disputes

Most vendor agreements are drafted by the vendor’s attorneys, which means the default terms favor the vendor. That is not unusual or improper, but it does mean that every clause below will require your attention before signing.

Indemnification

An indemnification clause moves the cost of a claim, including the cost of defending it, from one party to the other. The Minnesota Supreme Court has described the language such a provision needs as language that shifts “the economic risk and costs of defending against claims related to that contract from the indemnitee to the indemnitor.” Dewitt v. London Road Rental Center, Inc., 910 N.W.2d 412, 416 (Minn. 2018).

The usual trigger is a third party suing, but the clause can also be written to reach a claim brought by the other contracting party. In 2025 the Minnesota Supreme Court applied Dewitt’s standard to an indemnification clause running against the injured member who signed the form, reading the clause as shifting liability back to the injured party and producing the same result as an exculpatory provision, which barred his conservator’s claims of ordinary negligence against the business (Lund v. Calhoun Orange, Inc., No. A23-0149 (Minn. May 21, 2025)). Read a vendor’s indemnity clause as a possible release of your own claims, not only as an allocation of third-party claims.

In a well-drafted vendor agreement, indemnification is mutual: the vendor indemnifies you for claims arising from the vendor’s negligence or breach, and you indemnify the vendor for claims arising from your misuse of the vendor’s product or service. That fault-based split matches what Minnesota courts apply when a clause does not clearly say otherwise.

The split carries a limit worth knowing before you sign. Minnesota strictly construes indemnity clauses, so to shift liability for a party’s own negligence the contract must include an “express provision” that “indemnif[ies] the indemnitee for liability occasioned by its own negligence; such an obligation will not be found by implication.” Dewitt v. London Road Rental Center, Inc., 910 N.W.2d 412, 417 (Minn. 2018). Dewitt is itself a vendor-agreement case, decided on a rental company’s standard form, so the test applies directly to the paper on your desk. Broad wording such as “any and all claims” does not get there. Limiting language inside the clause matters: if limiting words put the “scope of indemnity in question,” the contract’s language is equivocal and the clause is unenforceable under strict construction, and in that circumstance “each tortfeasor accept[s] responsibility for damages commensurate with its own relative culpability.”

That demanding standard now reaches the clauses sitting next to the indemnity. The Minnesota Supreme Court held in 2022 that “both indemnity clauses and exculpatory clauses are subject to the same standard of strict construction” (Justice v. Marvel, LLC, 979 N.W.2d 894 (Minn. 2022)), so the limitation-of-liability and waiver language in the same vendor form is read the same way, and a release of “any and all claims” does not reach the drafter’s own negligence without a clear and unequivocal statement.

For one large category of vendor agreements the fault-based split is compulsory rather than merely well drafted. An indemnification agreement contained in, or executed in connection with, a building and construction contract is unenforceable except to the extent the underlying injury or damage is attributable to the negligent or otherwise wrongful act or omission, including breach of a specific contractual duty, of the promisor or the promisor’s independent contractors, agents, employees, or delegatees, or the indemnity is an owner’s, a responsible party’s, or a governmental entity’s agreement to indemnify a contractor with respect to strict liability under environmental laws (Minn. Stat. § 337.02). The 2023 Legislature added “defend” to the statutory definition of an indemnification agreement, so the bar now reaches defense costs as well, for agreements entered into on or after May 25, 2023 (Minn. Stat. § 337.01, subd. 3, as amended by Laws of Minnesota 2023, ch. 53, art. 7, §§ 4, 6). That ceiling applies only to contracts for the design, construction, alteration, improvement, repair, or maintenance of real property, highways, roads, or bridges, and not to contracts for maintenance or repair of machinery or equipment used in a production process (Minn. Stat. § 337.01, subd. 2). For software, staffing, logistics, marketing, and similar vendor agreements, indemnity scope is a negotiating question rather than a statutory one.

Red flags to watch for:

  • One-sided indemnification. The vendor requires you to indemnify the vendor but does not offer reciprocal indemnification for the vendor’s own errors or omissions.
  • Broad indemnification triggers. Language requiring you to indemnify the vendor for “any and all claims arising out of or related to” the agreement, which could sweep in claims caused entirely by the vendor’s conduct.
  • Capped indemnification obligations. Some vendors propose capping their indemnification obligations at the same low amount as the general liability cap. Where the contract is one for the sale of goods, Minnesota’s Uniform Commercial Code permits that allocation: “Consequential damages may be limited or excluded unless the limitation or exclusion is unconscionable. Limitation of consequential damages for injury to the person in the case of consumer goods is prima facie unconscionable but limitation of damages where the loss is commercial is not.” (Minn. Stat. § 336.2-719, subd. (3).) For a services or software agreement, the common law governs instead, as the next section explains. Whether indemnification stays inside the cap is a negotiating point either way. Because indemnification answers claims arising from the indemnifying party’s own conduct, buyers commonly ask that indemnification be carved out of the general cap or given a separate, higher cap.

Limitation of Liability

Nearly every vendor agreement contains a limitation of liability clause. The question is not whether the vendor will attempt to limit its liability (it will) but whether the cap is commercially reasonable.

Start with which body of law governs the cap, because that turns on what you are buying. Article 2 of the Uniform Commercial Code applies to transactions in goods, and in a single transaction combining a sale of goods with services or a license of something other than goods it applies only to the extent Minn. Stat. § 336.2-102 provides: where the sale-of-goods aspects do not predominate, only the provisions relating primarily to those goods aspects apply. A hardware, equipment, or supply contract is a goods contract. A software subscription, consulting engagement, managed-services contract, or marketing agreement is a contract for non-goods, and the Minnesota Supreme Court states the consequence plainly: “The common law governs contracts for non-goods.” (Vermillion State Bank v. Tennis Sanitation, LLC, 969 N.W.2d 610 (Minn. 2022).) Minnesota classifies a contract covering both by its predominant purpose, and that classification is a question of law for the court.

Bundled agreements that include a sale of goods, such as equipment sold with installation and maintenance or hardware sold with a software license, now run through a statutory rule. A “hybrid transaction” means a single transaction involving a sale of goods and the provision of services, a lease of other goods, or a sale, lease, or license of property other than goods (Minn. Stat. § 336.2-106, subd. (5), as amended by Laws 2024, ch. 93, art. 2, § 2). A services-only or subscription-only deal is therefore never a hybrid transaction. Where the goods aspects do not predominate, only the Article 2 provisions relating primarily to those goods aspects apply; where they do predominate, Article 2 applies but other law still reaches the non-goods aspects. A transaction validly entered into before August 1, 2024, and the rights, duties, and interests flowing from it, may be terminated, completed, consummated, or enforced as though the 2024 amendments had not taken effect, except as sections 336.0A-301 to 336.0A-306 provide (Minn. Stat. § 336.0A-201).

Where Article 2 does govern, the agreement may limit or alter the measure of damages recoverable, including limiting your remedies to return of the goods and repayment of the price or to repair and replacement of nonconforming goods or parts (Minn. Stat. § 336.2-719, subd. (1)(a)). Two adjacent subsections give you concrete drafting checks. A contractual remedy is optional and cumulative with the Code’s remedies unless the agreement expressly makes it exclusive, in which case it is the sole remedy, so the phrase “sole and exclusive remedy” is what actually shuts off your other remedies. And where circumstances cause an exclusive or limited remedy to fail of its essential purpose, you may pursue the remedies the chapter otherwise provides (Minn. Stat. § 336.2-719, subd. (1)(b), (2)).

Do not read that escape hatch too broadly. Minnesota tests the two clauses separately: a separately stated consequential-damages exclusion is judged on its own and survives unless it is unconscionable. The Minnesota Supreme Court treats a repair-or-replace remedy and a consequential-damages exclusion as “discrete and independent contractual provisions” and enforced the exclusion even after a jury found the limited remedy had failed, where both sides were merchants of comparable bargaining power and the loss was commercial (International Financial Services, Inc. v. Franz, 534 N.W.2d 261, 269 (Minn. 1995)). The Eighth Circuit applied that rule to a Minnesota supply contract in 2022 (Far East Aluminium Works Co. v. Viracon, Inc., 27 F.4th 1361 (8th Cir. 2022)). Franz reserved consumer transactions in commonplace products from its holding, and the exclusion reaches only consequential damages: the cost of putting the offending product in place remains a recoverable direct damage.

Note also the correct rule on unconscionability, which is easy to overstate. Consequential damages may be limited or excluded unless the limitation or exclusion is unconscionable, and the same subsection adds that a limitation of consequential damages for injury to the person in the case of consumer goods is prima facie unconscionable “but limitation of damages where the loss is commercial is not” (Minn. Stat. § 336.2-719, subd. (3)). In a business-to-business contract for the sale of goods your loss is commercial, so the exclusion carries no presumption of unconscionability and you carry the burden. The general unconscionability provision does not make an offending clause automatically void either: a court “may refuse to enforce the contract, or it may enforce the remainder of the contract without the unconscionable clause, or it may so limit the application of any unconscionable clause as to avoid any unconscionable result” (Minn. Stat. § 336.2-302). Negotiate the cap and its carve-outs before signing rather than counting on a court to strike the clause later.

Liability Cap Structure Risk Level When Acceptable
Fees paid in prior 1 month High Rarely, leaves you with minimal recovery for significant losses
Fees paid in prior 12 months Moderate Acceptable for many routine vendor relationships
Fees paid in prior 24 months or $1M–$5M floor Lower Appropriate for vendors handling critical operations or sensitive data
Uncapped (for specific carve-outs) Lowest Standard for indemnification, confidentiality breaches, willful misconduct, IP infringement

Red flags to watch for:

  • Liability capped at a single month of fees. If you pay a vendor $5,000 per month and the vendor causes $200,000 in damages, a one-month cap limits your recovery to $5,000.
  • No carve-outs. A well-negotiated agreement excludes certain categories of liability from the cap, typically indemnification, confidentiality breaches, willful misconduct, and intellectual property infringement.
  • Exclusion of all consequential damages. Many vendors attempt a blanket exclusion of consequential, incidental, and indirect damages. Lost profits and business-interruption costs are the classic category such an exclusion sweeps away, because the Code places in the consequential category “any loss resulting from general or particular requirements and needs of which the seller at the time of contracting had reason to know and which could not reasonably be prevented by cover or otherwise” (Minn. Stat. § 336.2-715, subd. (2)). The exclusion does not reach direct damages such as the difference in value of what was delivered or the cost to cover.

Auto-Renewal

Auto-renewal clauses are not inherently problematic, but they become a red flag when the notice window for cancellation is narrow and the renewal term is long. No general Minnesota or federal automatic-renewal statute reaches a business-to-business vendor agreement, and the one commercial exception is covered below, so your protection is your own calendar.

Do not rely on an older statement that Minnesota imposes no statutory limit on auto-renewal clauses. Minnesota now has an automatic-renewal statute, effective January 1, 2025 and applicable to contracts entered into, modified, or renewed on or after that date (Laws of Minnesota 2024, ch. 114, art. 3, §§ 55 to 62), imposing disclosure, confirmation, annual notice, and easy-cancellation duties and making certain terms void. It governs only an “indefinite subscription agreement,” meaning a subscription or purchasing agreement “between a seller and a consumer in Minnesota” that is “subject to automatic renewal or continuous service,” and it defines “consumer” as “any individual who seeks or acquires, by purchase or lease, any goods, services, money, or credit for personal, family, or household purposes” (Minn. Stat. § 325G.56, subds. 4, 6). Your company is not a consumer, so the statute governs the subscriptions you sell to individuals rather than the vendor contracts you sign as a business.

Federal law adds nothing of general application. The Eighth Circuit, the federal appeals court covering Minnesota, vacated the Federal Trade Commission’s amended Negative Option Rule in its entirety on July 8, 2025, holding that “the Commission failed to follow procedural requirements under § 22 of the Federal Trade Commission Act” (Custom Communications, Inc. v. Federal Trade Commission, No. 24-3137 (8th Cir. July 8, 2025)). The prenotification rule remains in force, and it reaches only plans that periodically ship goods and merchandise to subscribers (16 C.F.R. § 425.1). The internet negative-option consent rules of the Restore Online Shoppers’ Confidence Act remain as well (15 U.S.C. § 8403).

Two boundaries matter. Minnesota does police nonrenewal in some commercial relationships: unless the failure to renew is for good cause and the sales representative has failed to correct the reasons for termination, a manufacturer, wholesaler, assembler, or importer must give at least 90 days’ advance written notice before failing to renew a sales representative agreement (Minn. Stat. § 325E.37, subd. 3). And if your company sells subscriptions to individuals for personal, family, or household use, you are the regulated seller. A material change made without clear and conspicuous advance notice and termination instructions “is void and unenforceable” (Minn. Stat. § 325G.57, subd. 3), and several vendor categories are exempt entirely, including alarm and low-voltage contractors, utilities, telecommunications, insurers, and securities firms (Minn. Stat. § 325G.62).

Red flags to watch for:

  • Short cancellation windows. A clause requiring 90 days’ written notice of non-renewal, combined with annual auto-renewal, creates a narrow window that is easy to miss.
  • Renewal at increased pricing. Some contracts auto-renew at a higher rate or at “then-current pricing,” which the vendor can set unilaterally.
  • Multi-year renewal terms. A contract that auto-renews for successive one-year terms is less concerning than one that auto-renews for successive three-year terms.

Build a contract renewal calendar into your compliance tracking system. If you use a compliance calendar for state filings and tax deadlines, add vendor contract renewal dates to the same system with reminders set 120 days before each cancellation deadline.

Termination for Convenience

Every vendor agreement addresses termination for cause, the right to end the contract if the other party materially breaches. The Minnesota Supreme Court defined that trigger expressly for the first time in 2024: a “material breach” is a breach that goes to the essence of the parties’ agreement, “affect[ing] the purpose of the contract in . . . [a] vital way” (Kuhn v. Dunn, 8 N.W.3d 633 (Minn. 2024)). A minor or technical lapse does not justify ending the contract, and terminating for a non-material breach is itself a breach. Materiality is measured against what you bargained for rather than money lost, so a violation of a consent, assignment, or change-of-control provision can be material even though the vendor keeps delivering and billing normally.

Fewer agreements include termination for convenience, which is the right to end the relationship without having to prove a breach occurred. Minnesota’s Uniform Commercial Code draws that line for contracts involving goods: “termination” occurs “when either party pursuant to a power created by agreement or law puts an end to the contract otherwise than for its breach,” and on termination all obligations still executory on both sides are discharged, but any right based on prior breach or performance survives (Minn. Stat. § 336.2-106, subd. (3)). Invoices for work already delivered and claims from an existing breach therefore carry through. The label in your exit notice matters, because “’[c]ancellation’ occurs when either party puts an end to the contract for breach by the other and its effect is the same as that of ’termination’ except that the canceling party also retains any remedy for breach of the whole contract or any unperformed balance” (Minn. Stat. § 336.2-106, subd. (4)). A party exiting for convenience gives that up.

Red flags to watch for:

  • No termination for convenience. If the contract lacks this provision, you may be locked in for the full term even if the vendor’s service quality declines or your business needs change.
  • Asymmetric termination rights. The vendor can terminate for convenience on 30 days’ notice, but you cannot terminate without demonstrating cause.
  • Excessive early termination fees. Some agreements allow termination for convenience but impose a penalty equal to all fees remaining in the contract term, which effectively eliminates the right.

Intellectual Property Ownership

When a vendor creates work product on your behalf (software, designs, marketing content, data analyses) the contract must specify who owns that work product. Without clear language, ownership disputes can arise under both copyright law and contract law. Copyright “vests initially in the author or authors of the work” (17 U.S.C. § 201, subd. (a)), and outside the work-for-hire rules discussed below, the author is the vendor that created it. Paying the invoice does not by itself move the copyright.

Copyright is also divisible, so a vendor IP clause is not an all-or-nothing choice: any of the exclusive rights comprised in a copyright may be transferred and owned separately (17 U.S.C. § 201, subd. (d)(2)), which is how a fair clause gets negotiated when the vendor needs to reuse its underlying tools and you need full rights in the deliverable. And if you commission a contribution to a collective work without an express transfer, you are presumed to have acquired only the privilege of reproducing and distributing that contribution as part of that particular collective work, any revision of it, and any later collective work in the same series (17 U.S.C. § 201, subd. (c)).

Red flags to watch for:

  • Vendor retains all IP rights. The vendor owns everything it creates, and you receive only a license to use it. If the relationship ends, you may lose access to work product you paid for.
  • No assignment language. A work-for-hire clause and an assignment are not substitutes, and for vendor deliverables the difference is usually decisive. Under 17 U.S.C. § 101, a specially ordered or commissioned work becomes a “work made for hire” only if it falls within one of nine enumerated categories and “the parties expressly agree in a written instrument signed by them that the work shall be considered a work made for hire.” The Supreme Court held that a hiring party’s control over an independent contractor does not convert the contractor’s work into a work for hire, and that “only enumerated categories of commissioned works may be accorded work for hire status” (Community for Creative Non-Violence v. Reid, 490 U.S. 730 (1989)). Custom software, source code, logos, and websites are not on that list, so ownership reaches you only through a signed written transfer (17 U.S.C. § 204). Patent rights move by their own mechanism: applications for patent, patents, or any interest in them are “assignable in law by an instrument in writing” (35 U.S.C. § 261). The present assignment is the load-bearing clause, and work-for-hire language standing alone is the red flag. A well-drafted clause states both, so the assignment operates whenever the work-for-hire designation does not.
  • License restrictions that limit your use. Even if you receive a license, check whether it is exclusive or non-exclusive, perpetual or terminable, and whether it survives termination of the agreement.

Two of the nine work-for-hire categories sound broad enough that a buyer may assume its deliverable qualifies, and the statute narrows both. A “supplementary work” is one prepared for publication as a secondary adjunct to another author’s work, and an “instructional text” is one prepared for publication for use in systematic instructional activities. Both turn on preparation for publication, which most commissioned business work product is not. A “compilation” qualifies only where materials or data “are selected, coordinated, or arranged in such a way that the resulting work as a whole constitutes an original work of authorship,” so a raw data extract is not one, and “computer program” is defined separately in the same section and appears nowhere among the nine (17 U.S.C. § 101).

A novation or contract amendment may be necessary to correct IP ownership terms in an existing vendor relationship, but the better practice is to negotiate these terms before execution.

Liability and Insurance Requirements

A limitation of liability clause is only as useful as the vendor’s ability to pay a claim. Insurance requirements bridge that gap by ensuring the vendor has financial backing for its contractual obligations.

What Your Vendor Agreement Should Require

Every vendor agreement should include an insurance requirements provision specifying coverage types and minimums. For a broader discussion of the insurance policies every employer needs, see our separate guide, the principles below apply specifically to what you should require from your vendors:

Coverage Type Typical Minimum When Required
Commercial general liability $1M per occurrence / $2M aggregate All vendor agreements
Professional liability (errors & omissions) $1M per occurrence Vendors providing professional services or consulting
Cyber liability / data breach $1M–$5M Vendors with access to your systems or data
Workers’ compensation Statutory limits Vendors with employees working on your premises
Commercial auto $1M combined single limit Vendors operating vehicles on your behalf

Additional Insured Endorsements

Require the vendor to name your company as an additional insured on its commercial general liability and umbrella policies. This is not a request for the vendor to purchase insurance on your behalf, it is a standard endorsement that extends the vendor’s existing coverage to claims against your company arising from the vendor’s work, subject to that policy’s own limits and exclusions.

Know what the blanket additional insured endorsement construed in Minnesota’s leading case did and did not do. Minnesota reads it as a vicarious liability provision: it responds only “[i]f, and only to the extent that, the injury or damage is caused by acts or omissions of” the vendor in performing its work, and the customer “does not qualify as an additional insured with respect to the independent acts or omissions of” the customer (Engineering & Construction Innovations, Inc. v. L.H. Bolduc Co., 825 N.W.2d 695, 706, 709-10 (Minn. 2013)). A customer found negligent on its own, or whose vendor is found not negligent, recovers nothing under the endorsement. Trigger wording varies from form to form, so read your own endorsement rather than relying on the certificate. The underlying policy’s exclusions travel with the endorsement, so a certificate of insurance proves little: ask for the endorsement form and the policy exclusions.

When the vendor’s work is construction, the statutory ceiling reaches insurance too. A provision requiring a party to provide insurance coverage to one or more other parties for the negligence or intentional acts or omissions of any of those other parties “is against public policy and is void and unenforceable,” while a provision requiring the vendor to provide or obtain coverage for your vicarious liability, or liability imposed by warranty, arising out of the vendor’s acts or omissions remains valid (Minn. Stat. § 337.05, subd. 1(b), (d)).

Red flags to watch for:

  • No insurance requirements at all. A surprising number of vendor agreements (particularly templates provided by smaller vendors) omit insurance provisions entirely.
  • Self-insurance without financial backing. Some vendors claim to be “self-insured” without demonstrating the financial reserves to support that claim.
  • No annual certificate requirement. The contract should require the vendor to provide updated certificates of insurance annually and within 30 days of any policy change.

Hall PC regularly reviews vendor agreements where the insurance provisions are either missing or inadequate to cover the scope of work the vendor is performing. This is one of the most straightforward issues to fix during contract negotiation, vendors expect to receive insurance requirement requests.

Data Security and Confidentiality Provisions

If your vendor will access, store, or process any of your company’s data (customer information, financial records, employee data, trade secrets) the vendor agreement must address data security with specificity, not generalities.

Required Data Security Provisions

Minnesota’s data breach notification statute imposes two different duties, and the vendor’s is the one people miss. A business that conducts business in Minnesota and owns or licenses data containing personal information must notify each Minnesota resident whose unencrypted personal information an unauthorized person acquired, or is reasonably believed to have acquired, “in the most expedient time possible and without unreasonable delay.” A business that maintains personal information it does not own, which is your vendor’s position, must instead notify the owner or licensee “immediately following discovery” (Minn. Stat. § 325E.61, subd. 1). That vendor duty sits in subdivision 1(b). Minnesota sets no fixed 30, 45, or 60 day deadline and requires no notice to the Attorney General, whose role is enforcement: “The attorney general shall enforce this section and section 13.055, subdivision 6, under section 8.31.” (Minn. Stat. § 325E.61, subd. 6.)

Three more features of that statute belong in your vendor negotiation. “Any waiver of the provisions of this section and section 13.055, subdivision 6, is contrary to public policy and is void and unenforceable,” so a vendor clause disclaiming or narrowing breach-notice duties does not work and its real danger is the false comfort it gives (Minn. Stat. § 325E.61, subd. 3). When more than 500 persons must be notified, all nationwide consumer reporting agencies must be notified within 48 hours, which is the operational reason your contract needs a fast, specific breach-scope reporting duty rather than “promptly” or “as required by law” (Minn. Stat. § 325E.61, subd. 2). And a vendor that is a financial institution as defined by the Gramm-Leach-Bliley Act sits outside the section entirely, so your contract has to supply the notice duty (Minn. Stat. § 325E.61, subd. 4).

If you accept payment cards, a second statute applies, commonly called the Plastic Card Security Act and formally headed “Access Devices; Breach of Security.” You may not retain the card security code data, the PIN verification code number, or the full contents of any magnetic stripe track once a transaction is authorized; there is no general grace period, and the only window is 48 hours, applying solely to PIN debit transactions (Minn. Stat. § 325E.64, subd. 2). The prohibition reaches only those three data categories, not the card account number, cardholder name, or expiration date.

Retention alone creates no damages claim. Liability attaches only when a violation is joined by a security breach, and the reimbursement runs to the financial institution that issued the affected cards, covering card cancellation and reissuance, account closures and reopenings, cardholder refunds, and cardholder notification, plus damages the institution paid injured cardholders, with the remedies stated to be cumulative (Minn. Stat. § 325E.64, subd. 3). A vendor indemnity drafted to cover only “statutory penalties” therefore leaves you exposed. A federal district court applied the section to a Minnesota company’s out-of-state transactions and allowed a derivative negligence per se claim to proceed, though as a district-court decision it is persuasive rather than controlling (In re Target Corp. Customer Data Security Breach Litigation, 64 F. Supp. 3d 1304, 1313 (D. Minn. 2014)).

The Minnesota Consumer Data Privacy Act (MCDPA) adds another layer, but not for every business. It applies only to legal entities that conduct business in Minnesota or produce products or services targeted to Minnesota residents and that either control or process personal data of 100,000 or more consumers in a calendar year (excluding data handled solely to complete a payment transaction) or derive over 25 percent of gross revenue from the sale of personal data while handling data of 25,000 or more consumers (Minn. Stat. § 325M.12, subd. 1(a)). Subdivision 2 then removes 21 categories, including small businesses as the U.S. Small Business Administration defines them, government entities, tribes, banks and credit unions, insurers, HIPAA and Gramm-Leach-Bliley data, Fair Credit Reporting Act and FERPA data, payment-only transactions retaining no consumer data, and job-applicant, employee, owner, officer, and contractor records (Minn. Stat. § 325M.12, subd. 2). “Consumer” is limited to a Minnesota resident acting only in an individual or household context, so ordinary business-to-business vendor data sits outside the Act (Minn. Stat. § 325M.11). If you are below both thresholds or inside an exclusion, the Act imposes no processor-contract duty on you at all.

Even an excluded small business keeps one duty: it “must not sell a consumer’s sensitive data without the consumer’s prior consent” (Minn. Stat. § 325M.17). That is the one vendor-contract term a small-business reader should still insist on.

If your business is in scope, Minn. Stat. § 325M.13 requires a binding written contract with each processor, and the list is longer than most vendor forms carry. Paragraphs (c) and (e) each require the contract to set out five descriptive elements (the processing instructions, the nature and purpose of the processing, the type of personal data, the duration, and both parties’ rights and obligations), and they impose five affirmative processor duties: a confidentiality duty binding each person who processes the data; subcontracting only after you have an opportunity to object and only under a written contract passing the obligations down; deletion or return of all personal data at your choice when the services end unless retention is required by law; production on reasonable request of all information necessary to demonstrate compliance; and cooperation with reasonable assessments and inspections, which the vendor may satisfy instead through an annual independent assessment at its own expense. Paragraph (d) separately requires both parties to implement risk-appropriate technical and organizational security measures and to allocate responsibility for them clearly. These requirements took effect July 31, 2025 (Laws 2024, ch. 121, art. 5, §§ 5, 14).

That effective date carries one exception: postsecondary institutions regulated by the Office of Higher Education are not required to comply until July 31, 2029 (Laws 2024, ch. 121, art. 5, § 14).

Two further paragraphs answer the questions that follow. No contract may relieve a controller or a processor “from the liabilities imposed on a controller or processor by virtue of the controller’s or processor’s roles in the processing relationship,” so a vendor’s limitation-of-liability or indemnity language does not move statutory data-privacy exposure (Minn. Stat. § 325M.13). And the label the contract uses does not control: determining whether a person acts as a controller or a processor “is a fact-based determination that depends upon the context in which personal data are to be processed,” and a vendor that begins determining the purposes and means of processing becomes a controller with the full set of controller duties. That is why broad vendor data-use rights covering analytics, product improvement, model training, or resale are worth catching before you sign.

Essential data security terms:

  • Specific technical safeguards. Require encryption at rest and in transit, role-based access controls, multi-factor authentication for administrative access, and regular vulnerability assessments. Avoid accepting vague commitments to “commercially reasonable security measures” without defining what that means.
  • Breach notification timeline. Specify that the vendor must notify you of any actual or suspected breach within 24 to 72 hours. The contract should also define what constitutes a “breach”, unauthorized access, unauthorized disclosure, and loss of data should all trigger notification.
  • Prohibition on secondary data use. Prohibit the vendor from using your data for analytics, benchmarking, machine learning training, or any purpose other than performing the contracted services, unless you provide separate written authorization.
  • Subcontractor controls. If the vendor uses subcontractors who will access your data, the contract should require the vendor to impose equivalent security obligations on those subcontractors and to notify you before engaging new subcontractors.
  • Audit rights. Reserve the right to audit the vendor’s security practices annually or upon reasonable request. Vendors with SOC 2 Type II or ISO 27001 certifications can satisfy this requirement by providing current audit reports.

Confidentiality Provisions

A separate confidentiality clause (or a standalone NDA executed alongside the vendor agreement) should define what constitutes confidential information, establish the duration of confidentiality obligations (which should survive termination), and restrict the vendor’s ability to disclose your information to third parties.

If you are evaluating how payment disputes intersect with vendor data obligations, separate the two sources of duty. Statutory obligations do not depend on payment: no contract may relieve a processor of the liabilities its role imposes under the MCDPA (Minn. Stat. § 325M.13), and a vendor that maintains personal information it does not own must notify you of a breach immediately following discovery, with any waiver of that duty void as against public policy (Minn. Stat. § 325E.61, subd. 1(b), subd. 3). Trade secret protection runs independently as well: a vendor that acquired trade secret information under circumstances giving rise to a duty to maintain its secrecy misappropriates it by disclosing or using it without consent, whether or not your invoices are current (Minn. Stat. § 325C.01, subd. 3).

Contractual confidentiality is different, and this is where a common assumption fails. Minnesota treats a material breach as “[a] breach of contract that is significant enough to permit the aggrieved party to elect to treat the breach as total (rather than partial), thus excusing that party from further performance and affording it the right to sue for damages” (BOB Acres, LLC v. Schumacher Farms, LLC, 797 N.W.2d 723, 728 (Minn. Ct. App. 2011)), so a vendor facing nonpayment can argue that its remaining contract duties are excused. Confidentiality carries through a billing dispute because the agreement makes it survive. Confirm that the survival clause names confidentiality and data security and states that those duties are independent of payment, rather than assuming that withholding payment leaves them intact.

Termination Rights and Exit Planning

The most overlooked section of most vendor agreements is the exit. Business owners focus on what the vendor will deliver and what it will cost, but rarely examine what happens when the relationship ends.

Transition Assistance

The contract should require the vendor to provide reasonable transition assistance for a defined period after termination, typically 30 to 90 days. This assistance should include:

  • Data export in usable formats. The vendor must provide your data in a standard, machine-readable format (CSV, JSON, XML, or the format used by your replacement vendor), not a proprietary format that requires the departing vendor’s software to read.
  • Knowledge transfer. For vendors providing managed services, the contract should require documentation of configurations, processes, and access credentials necessary for a successor vendor to assume the work.
  • Continued service during transition. The agreement should specify that the vendor will continue performing services at the same service level during the transition period, even if the termination was contentious.

Data Return and Destruction

At the end of the vendor relationship, you need your data back and you need assurance that the vendor has not retained copies.

What the contract should require:

  • Return of all company data within 30 days of termination.
  • Certification of data destruction: a written attestation from an officer of the vendor confirming that all copies of your data (including backups) have been permanently destroyed.
  • Deletion of data from subcontractor systems on the same timeline.

Wind-Down Financial Terms

Termination provisions should also address the financial mechanics of ending the relationship:

  • Prorated refunds. If you prepaid for an annual term and terminate mid-year, the contract should specify how unused fees are refunded.
  • Final invoicing deadlines. Require the vendor to submit any final invoices within 30 to 60 days of termination. Without a deadline, vendors may submit surprise invoices months after the relationship ended.
  • Survival clauses. Confirm which provisions survive termination. At minimum, confidentiality, indemnification, limitation of liability, and data security obligations should survive.

For vendor relationships involving physical assets, similar exit-planning principles apply, the commercial lease audit checklist addresses parallel concerns for property-related vendor and landlord relationships.

Putting It All Together: The Vendor Agreement Review Framework

Before signing any vendor agreement, work through this framework:

Step 1: Read the entire agreement. This sounds obvious, but many business owners sign vendor agreements without reading past the pricing section. Every clause discussed in this guide is typically buried in the “General Terms” or “Legal Terms” section that follows the scope of work and pricing.

Step 2: Identify the five high-risk clauses. Locate the indemnification, limitation of liability, auto-renewal, termination, and IP ownership provisions. If any of these clauses is missing, that is itself a red flag, because silence hands the question to background law. The gap-fillers do not uniformly favor the vendor, though. A damages cap exists only because the parties wrote one, so an agreement with no limitation-of-liability clause leaves the vendor exposed to the full Article 2 remedy set (Minn. Stat. § 336.2-719, subd. (1)), including your consequential damages (Minn. Stat. § 336.2-715). Where a merchant sells goods of that kind, the implied warranty of merchantability applies “[u]nless excluded or modified,” so silence keeps it (Minn. Stat. § 336.2-314, subd. (1)). Omitting an auto-renewal clause helps you, because no default rule renews a contract. Omitting a termination clause pulls in the rule that a goods contract providing for successive performances but indefinite in duration “may be terminated at any time by either party” unless otherwise agreed, on reasonable notification received by the other party, which protects both sides (Minn. Stat. § 336.2-309, subd. (2)-(3)). IP ownership is the one clause where the warning holds, because copyright vests initially in the author (17 U.S.C. § 201). Indemnification is genuinely mixed. These Article 2 gap-fillers govern contracts for the sale of goods; a services-only agreement is filled by common-law rules. The real lesson is that silence produces an unpredictable, clause-by-clause outcome neither side chose.

Step 3: Compare against the tables above. Use the liability cap and insurance requirement tables in this guide as benchmarks. If your vendor’s terms fall in the “high risk” column, those provisions need negotiation.

Step 4: Check data security provisions. If the vendor will access any of your data, confirm that the agreement includes the specific protections outlined in the data security section above.

Step 5: Review termination and exit terms. Confirm that you have termination for convenience, that data return obligations are specified, and that transition assistance is addressed.

Step 6: Engage counsel for high-value agreements. For vendor relationships exceeding $50,000 annually, or any vendor with access to sensitive data, a contract review by an attorney is a cost-effective way to identify risks that are not obvious to non-lawyers.

Aaron Hall and the attorneys at Hall PC work with business owners across Minnesota to review and negotiate vendor agreements as part of the Legal Operating System™ approach to proactive legal infrastructure. The goal is not to create adversarial vendor relationships, it is to ensure that the contract accurately reflects the deal both parties intend.

What are the biggest red flags in a vendor contract?

The five clauses most likely to produce disputes are indemnification, limitation of liability, auto-renewal, termination for convenience, and intellectual property ownership. Any of these clauses can shift significant financial risk onto your business if you do not negotiate them before signing.

Should vendor contracts require proof of insurance?

Yes. Every vendor agreement should require the vendor to maintain general liability, professional liability, and (where applicable) cyber liability insurance at specified minimum coverage amounts. The contract should also require your business to be named as an additional insured and should obligate the vendor to provide certificates of insurance annually.

What should a vendor contract say about data security?

The contract should require the vendor to implement specific technical safeguards (encryption, access controls, and secure data transfer) rather than vague promises of ‘reasonable security.’ It should also include breach notification timelines, data return or destruction obligations at termination, and restrictions on secondary use of your data.

How much notice should a vendor contract require for termination?

Termination notice periods typically range from 30 to 90 days, depending on the complexity of the services. More important than the notice period itself is whether the contract includes termination for convenience, the right to end the relationship without proving the vendor breached the agreement.

Can a vendor limit its liability to the fees paid in the last month?

A vendor can propose any liability cap, but that does not mean you should accept it. A cap limited to one month of fees may leave you unable to recover meaningful damages if the vendor causes a significant loss. Push for a cap of 12 to 24 months of fees, with carve-outs that exclude indemnification obligations, confidentiality breaches, and willful misconduct from the cap entirely.

What is an auto-renewal clause and why is it a problem?

An auto-renewal clause automatically extends the contract for successive terms unless one party provides written notice of non-renewal within a specified window, often 30 to 90 days before the current term expires. The problem is that businesses frequently miss the cancellation window and remain locked into contracts they intended to end, sometimes at increased pricing.