(1) whether damages for violations of confidentiality, privacy, and data security obligations are unlimited or capped by a limitation of liability or by a special limitation of liability devoted to these issues (i.e., a “super cap”), and
(2) whether the recommended service provider’s full hold-harm- less indemnity for third-party claims based on privacy and data security violations is unlimited or capped by a limitation of liability or by a super cap.