Skip to content

Data licensing for AI training

Master data license agreements and order forms for recurring AI data purchases

Quick answer

A master data license agreement (MDLA) is a framework contract that fixes the terms you never want to renegotiate (rights grant definitions, warranties, indemnity, liability, audit, security, deletion) and lets each new dataset be added through a short order form or schedule that states only what changes: the records, permitted uses, term, fees and delivery. For AI training data bought repeatedly from one supplier, it turns each purchase into a short paperwork exercise instead of a fresh negotiation.

By SourceX Editorial · Updated

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

Why recurring AI data purchases need a master agreement

A master agreement pays off once you expect a second dataset, a refresh, or a renewal from the same supplier. Without one, every purchase reopens indemnity caps, warranty wording and training-rights definitions, and the contracts drift apart so that one dataset may be deletable on termination while another is not. Published market-data contracts already use this structure: Cox Automotive's MDLA licenses data ordered through Order Forms that incorporate data-specific terms by reference [1], and Nodal Exchange gives every licensee one standard set of master terms combined with Order Forms and Schedules [2]. A negotiated example, the Tradeweb and Refinitiv MDLA effective November 2023, is public as an SEC exhibit and is worth reading for its drafting conventions [3].

AI deals add pressure the market-data templates do not address. Large licensing programs are multi-year and multi-party: Reddit's S-1 disclosed January 2024 data licensing arrangements with an aggregate transaction price of $203.0 million and terms of two to three years [5]. Over that span you will add datasets, change permitted uses (say, from fine-tuning to pre-training) and adjust delivery, and the master is where those changes stay consistent. For a single one-off purchase, a standalone license built from a data license term sheet is usually enough.

What belongs in the master and what belongs in each order form

The master holds everything that should be identical across datasets, and the order form holds everything that describes one dataset. A useful test: if a term would be embarrassing to have differ between two datasets from the same supplier, it belongs in the master. Definitions in particular ("Licensed Data," "Model," "Derivative," "Output," "Training") must live in the master so that each order form inherits the same meaning; see writing the AI training rights grant for the definitions themselves.

Illustrative example: invented to show structure; it does not describe an available dataset.

TermMaster agreementOrder form or dataset schedule
Definitions (Licensed Data, Model, Output, Derivative)Yes, onceReferences master; adds dataset-specific terms only
Rights grant frameworkMenu of use tiers (eval, fine-tuning, pre-training, RAG)Selects the tier(s) for this dataset
Warranties on provenance and consentsBaseline warrantiesDataset-specific representations (for example, consent basis for call recordings)
IP indemnity and liability capsCap structure and super-capsFee amount that feeds the cap formula
Audit and usage reportingProcedure, notice, frequency, cost allocationAny reporting metric unique to the dataset
Security and access controlsBaseline controlsExtra controls for sensitive categories
Deletion, return and model retentionDefault rule on terminationExceptions, if any, stated explicitly
Records, fields, volume, formatNoYes: schema, file format, record counts, sample reference
Term, refresh cadence, delivery methodDefault frameworkSpecific start date, end date, cadence, channel
Fees and paymentInvoicing and tax mechanicsPrice, payment schedule

Two items need special care. Liability caps are often calculated as a multiple of fees, so state in the master whether the cap is per order form or aggregate across all orders; liability caps and super-caps covers the trade-offs. Model retention after termination should be a master-level rule, because a model trained on three datasets cannot be unwound per schedule; see what happens to trained models when a data license ends.

How to set the order of precedence

The order of precedence clause decides which document wins when the master and an order form conflict, and it should let order forms override the master only where they say so expressly. One workable pattern is: (1) the order form, only for terms it identifies as overriding a named master section; (2) the master agreement; (3) data-specific additional terms or data policies; (4) the order form's remaining content. Cox's structure, where data-specific terms are incorporated into the agreement by reference, shows why this matters: incorporated supplier policies can change, so pin them to a dated version [1].

Failure modes to draft against:

  • Silent override. An order form says "Licensee may use the Data for internal research only," narrowing a pre-training grant without referencing the master. Require express override language naming the clause number.
  • Floating policy links. The master incorporates "Supplier's Data Use Policy at [URL] as updated from time to time." Fix the version and date, or require notice and a right to reject changes for existing orders.
  • Orphaned order forms. An order form signed after the master expires. State whether the master survives for active orders.
  • Click-through terms at delivery. A portal or listing presents its own terms when you download. Say in the master that delivery-platform terms do not amend the license.

Adding new datasets without renegotiating

New datasets go in cleanly when the master pre-negotiates a menu of use tiers and the order form only picks from it. Define three or four permitted-use tiers in the master, each with its own warranty and indemnity profile: evaluation only, fine-tuning, pre-training, and retrieval or RAG grounding. A new order form then states "Permitted Use: Tier 2 (Fine-tuning)" and inherits everything else. If a dataset needs rights outside the menu, that order form is the only document reopened; see pre-training data license rights and fine-tuning-only data licenses for what each tier should grant.

Include a short change-order mechanism for refreshes: same dataset, new delivery period, same schema, signed by both parties without legal review if fees stay within a pre-approved band. For deliveries that repeat on a cadence, coordinate with your ongoing data supply agreement structure and decide whether each delivery is an incremental or a full refresh. If data moves through a cloud sharing channel such as Snowflake listings with cross-region auto-fulfillment, name that channel in the order form rather than the master, because it can change per dataset [7].

Illustrative example: invented to show structure; it does not describe an available dataset.

order_form: "No. 004 under Master Data License Agreement dated 2026-03-02"
dataset_name: "Field service work orders, HVAC, 2019-2025"
records: "approx. 410,000 work orders; fields per Schema Annex A (v1.2)"
format: "JSON Lines, UTF-8, one work order per line; attachments as PDF"
permitted_use_tier: "Tier 2 - Fine-tuning (Master s.3.2)"
additional_restrictions: "No use of technician free-text notes for RAG retrieval"
deidentification: "Customer names, phones, emails, account numbers replaced with tokens; method memo attached as Annex B"
term: "24 months from first delivery"
refresh: "Quarterly incremental deliveries; change orders per Master s.9.4"
delivery: "Private access-controlled bucket; no email transfer"
fees: "Per Fee Annex; cap basis per Master s.12.1 (aggregate across Orders)"
overrides_master: "None"

Keeping deletion, audit and security consistent across schedules

Deletion, audit and security terms belong in the master because inconsistency across schedules quickly makes a multi-dataset relationship unmanageable. If Order Form 1 requires deletion of raw data in 30 days and Order Form 3 says 90, your data engineering team ends up tracking per-file retention clocks in a shared training corpus. Set one default in the master, allow exceptions only by express override, and require the supplier to accept a single deletion certificate covering all orders; deletion and return clauses has drafting detail.

Audit works the same way. Some market-data licensors handle audit procedure at the master level; for example, SIX publishes a separate audit code of practice that accompanies its MDLA [4]. For AI data, agree once on notice period, frequency, auditor independence, confidentiality of model weights and training logs, and who pays if an audit finds under-reporting; audit and usage-reporting rights covers the reporting metrics. Security baselines (encryption at rest, access logging, named-user access) sit in the master, with stricter controls added per order for sensitive categories such as health or financial records.

When the master is the wrong vehicle

A data license master is the wrong vehicle when the data is regulated in a way that requires a specific instrument. Health data may need a HIPAA business associate agreement or a limited data set data use agreement rather than, or alongside, a commercial license; see business associate agreement or data license and HIPAA limited data sets and data use agreements. Law-firm guidance also distinguishes licenses, which pre-authorize uses, from negotiated data use agreements, and the right label depends on who controls the data and why [6]; see data license vs data use agreement.

Samples for evaluation are another case. An evaluation agreement or NDA can sit outside the master so procurement can test data before signing; see evaluation licenses and NDAs for dataset samples. If you buy from many suppliers rather than repeatedly from one, the coordination problem shifts to vendor management; SourceX's guide to managing many data suppliers addresses that. If you want operational data from US companies sourced and licensed for you, start with the SourceX buyer request.

Buyer checklist before signing an MDLA

Run this checklist against the draft master before the first order form is executed.

  • Definitions of Model, Output, Derivative and Training live only in the master.
  • Permitted-use tiers are defined, each with its own warranty and indemnity profile.
  • Order of precedence requires express, clause-numbered overrides.
  • Incorporated policies are pinned to a dated version.
  • Liability cap basis states per-order or aggregate.
  • Model retention after termination is a single master-level rule.
  • One deletion standard and one certificate process cover all orders.
  • Audit procedure, frequency and cost allocation are set once.
  • Master survives for active order forms after its own expiry.
  • Delivery-platform click-through terms cannot amend the license.
  • A change-order route exists for refreshes within a pre-approved fee band.

Use the AI data license negotiation checklist for fallback positions on each clause, and the licensing cluster hub for the wider set of rights topics.

Buying recurring datasets under one framework

SourceX sources operational datasets from US companies on request and manages the commercial process, including licensing agreements and ongoing purchases. Every dataset is rights-reviewed and delivered under a license defining records, uses, term and delivery, and nothing is contracted until the supplying company agrees. For more on how terms are handled, see data partnership terms, then describe the recurring datasets you need.

Frequently asked questions

Is an MDLA the same as an MSA with statements of work?

The architecture is the same: master terms plus short transactional documents. The difference is content, because an MDLA centers on a rights grant, data warranties and post-termination model treatment rather than services, acceptance and personnel.

Should each order form have its own liability cap?

It can, but decide deliberately. A per-order cap keeps exposure proportional to each dataset's fee, while an aggregate cap across orders is simpler to administer and may be higher overall. State the choice in the master.

Can a supplier change master terms for existing orders?

Only if the master allows it. Ask that amendments to the master apply to existing order forms only with your written consent, and that incorporated policies are fixed to a dated version.

Sources

  1. Cox Automotive, "Master Data License Agreement" (2022). https://www.coxautoinc.com/terms/wp-content/uploads/sites/3/Master-Data-License-Agreement.pdf
  2. Nodal Exchange, "Master Data Agreement". https://www.nodalexchange.com/wp-content/uploads/Master-Data-Agreement-FINAL.pdf
  3. U.S. Securities and Exchange Commission (EDGAR), "Exhibit 10.36, Master Data License Agreement (Tradeweb and Refinitiv)" (2024). https://www.sec.gov/Archives/edgar/data/0001758730/000175873024000025/twm-2023x12x31xexx1036.htm
  4. SIX Group, "SIX Exfeed MDLA Audit Code of Practice". https://www.six-group.com/dam/download/market-data/exfeed/agreements-mdla/six-exfeed-mdla-audit-code-of-practice.pdf
  5. U.S. Securities and Exchange Commission (EDGAR), "Reddit, Inc. Form S-1" (2024). https://www.sec.gov/Archives/edgar/data/1713445/000162828024006294/reddits-1q423.htm
  6. Mayer Brown, "Data licensing tips and tactics" (2018). https://www.mayerbrown.com/zh-hans/insights/publications/2018/05/data-licensing-tips-and-tactics
  7. Snowflake, "Auto-fulfillment for listings". https://docs.snowflake.com/en/collaboration/provider-listings-auto-fulfillment

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data