
Short answer: the CarrierIQ takeaways for software vendors come down to two things. In a vendor-plus-platform stack, the party that decides what data to collect and whether to disclose it carries the privacy responsibility. And a too-broad indemnity can put the software vendor on the hook for the platform’s mistakes.
The CarrierIQ situation was a circus, but there are real things every software or SaaS company should take from it. Quick refresher: Carrier IQ made diagnostic software that mobile carriers like Sprint and AT&T embedded on roughly 150 million phones. In late 2011 a researcher claimed the software was logging keystrokes, and the internet exploded. Congress asked questions, class actions were filed, and the company spent years digging out (its assets were eventually acquired by AT&T in 2015).
1. Who Is Really at Fault, CarrierIQ or the Carriers?
CarrierIQ was the software provider. The carriers licensed its software and put it on the phones they sold to consumers. Two questions drove the controversy: what monitoring actually happened on the phones, and whether it was disclosed to users. Both of those sit with the carriers, not the software vendor. The carriers decided what to collect and transmit, and the carriers had the obligation to disclose those activities to their customers. At the time, TechCrunch landed on exactly that view (“Don’t Blame The IQ, Blame The Carrier”). The lesson for a vendor: know where in the stack the data decisions are actually made, because that is where the privacy responsibility lives, and design your disclosures and your contract accordingly. Getting ahead of this is exactly what Privacy by Design is for.
2. What Does the Indemnity Say?
Here is where it gets dangerous for the software vendor. Most software and SaaS providers should be giving only an infringement indemnity, not a broad general indemnity (here is the background on why). If CarrierIQ signed an indemnity covering “their use of the software” or anything “arising out of CarrierIQ’s performance,” they could be on the hook for millions in legal fees, fines, and judgments, even though the carriers made the calls that caused the problem. That is how a single over-broad indemnity clause turns someone else’s scandal into your bet-the-company lawsuit.
CarrierIQ Takeaway FAQs.
Why did the software vendor take the public blame? Because its name was on the software. Public blame follows the brand, but legal liability follows the contract and the conduct. You cannot fully control the first, which is exactly why you have to control the second.
What indemnity should a SaaS or software vendor give? As a starting position, an IP infringement indemnity tied to the software as delivered, and not much else. Resist “arising out of or relating to the software” formulations that sweep in how a customer or platform deploys it.
Does this still matter now? More than ever. Swap “carrier diagnostic software” for any embedded SDK, analytics layer, or AI component and the structure is identical: the party with its code in the stack gets named, and the party with the broad indemnity pays.
The Takeaway.
If you are a tech vendor, treat indemnities as a board-level risk, not boilerplate. A broad indemnity quietly transfers other people’s liability onto you, and it interacts directly with your overall liability cap (see What Does Your SaaS Agreement Liability Model Look Like?). Keep your indemnities narrow, tie them to your own conduct, and never agree to cover how a customer or platform deploys your software. And remember the privacy and indemnity issues are linked: the murkier the data practices in your stack, the more an aggressive indemnity can come back to bite you. Trust me on this one.
Resources:
- Indemnities: 4 Things You Should Know
- Privacy by Design: A Framework for SaaS and Software Vendors
- What Does Your SaaS Agreement Liability Model Look Like?
Disclaimer:
This post is for informational and educational purposes only, and is not legal advice. You should hire an attorney if you need legal advice, which should be provided only after review of all relevant facts and applicable law.
Discover more from Aber Law Firm
Subscribe to get the latest posts sent to your email.