Procurement, samples and ongoing supply
Evaluation licenses and NDAs for dataset samples
Quick answer
A trial data license agreement gives your team a limited, time-boxed right to test a supplier's dataset sample before committing to a full license, and the mutual NDA beside it decides what each side keeps secret. Published evaluation grants are often revocable and evaluation-only, so read silence as "no training." Make the grant list every test you plan, including any fine-tuning experiment, and state what happens to checkpoints, metrics and copies when the trial ends.
By SourceX Editorial · Updated
Trial license, NDA or both: what each document controls
The trial license sets what you may do with the sample; the NDA sets what each party may disclose about the other's confidential information, which for a buyer includes the evaluation results. Most sample reviews need both, and some suppliers put them in one document.
| Paper you are offered | What it controls | Published example | Gap a buyer has to close |
|---|---|---|---|
| Sample-data evaluation license | Use of the sample | NVIDIA's sample data license grants a limited, non-exclusive, revocable, non-transferable, non-sublicensable right solely to evaluate and test NVIDIA technologies, and bars other uses and redistribution [1] | Purpose tied to the licensor's products; nothing protects your findings |
| Combined trial license and mutual NDA | Use of the sample plus two-way confidentiality | One data vendor's Trial Data License and Mutual Non-Disclosure Agreement covers a subscriber evaluating the licensor's data and binds both sides to confidentiality [2] | Check that your side's confidential information includes results and model plans |
| Marketplace trial subscription | Click-through access to a reduced product | The marketplace's standard trial terms apply | Little room to negotiate; the slice may not match what you would buy |
| Mutual NDA on its own | Disclosure only | Common first paper in any deal | Use is often limited to "evaluating the proposed transaction," which does not clearly cover running models |
Insist on a mutual NDA: testing reveals your use case, the base models you tune and results showing what the data is worth to you, all of which matter in the price negotiation.
This page covers access before purchase. Fees and conversion credits are in paid data pilot terms; a license whose lasting purpose is testing your models is covered in evaluation-only data license terms and SourceX's answer to can I license data for evaluation only? If a holder will not release records at all, see sample routes for sensitive data.
Define "evaluation" as the activities your team will run
Replace "solely for evaluation" with a defined list of activities, because that phrase does not clearly cover fine-tuning, building a retrieval index or sending records to a hosted model API. A right to evaluate the licensor's technologies [1] is not a right to measure what the data does for your model, so write the purpose as "evaluating the sample to decide whether to license the dataset" and list the activities.
| Activity | What it leaves behind | Term to ask for |
|---|---|---|
| Profiling, schema validation, duplicate checks | Statistics, hash lists | Permitted; statistics and hashes survive the trial |
| Manual review, including residual-identifier spot checks | Notes that quote records | Named roles, contractors under written confidentiality; quotations deleted with the sample |
| Embedding and retrieval tests | Vector index, chunk store | Permitted inside the evaluation environment; index deleted at the end |
| Scoring existing models with sample records as prompts | Request logs at your inference provider | Name each provider, or commit to self-hosted inference |
| Supervised fine-tuning or LoRA adapter runs | Checkpoints, adapters, optimizer states | Internal experiments only, with the checkpoint's fate written down (next section) |
| Ablations mixing the sample with your own data | Mixed training sets | Permitted; mixed sets purged of sample rows at the end |
| Synthetic data generated from the sample | New records derived from licensed ones | Excluded unless agreed in writing |
Name the environment too: cloud account, storage location and roles with access. NVIDIA's license also forbids circumventing encryption, digital rights management or authentication mechanisms [1], so keep your pipeline from stripping such controls. The test plan behind this list belongs in your sample request.
Can you train on a data sample? Only under an explicit experiment right
You can train on a data sample only if the trial license grants that right in words. Treat a silent or evaluation-only grant as a prohibition, and negotiate a narrow right to run internal fine-tuning experiments whose checkpoints cannot reach production.
Suppliers resist because weights can carry training text. Carlini and colleagues extracted hundreds of verbatim training sequences from GPT-2, including contact details, code and UUIDs [3], and Nasr and colleagues recovered thousands of training examples from aligned production models such as ChatGPT [4]. A checkpoint tuned on sample records may hold some of them, and the supplier cannot inspect your weights. For EU personal data, a law-firm summary of EDPB Opinion 28/2024 reports that whether a model trained on personal data is anonymous must be assessed case by case [5].
Regulators can reach models too: the FTC's 2021 Everalbum order required deletion of models and algorithms developed with users' photos and videos [6]. That order concerned misleading users, not a license breach, but it explains why supplier counsel treats checkpoints as derived material. A workable experiment right has four parts:
- Scope: SFT or adapter runs on named base models in the named environment; no deployment, serving, distillation or use of outputs as training data.
- Traceability: each run logged against the sample version and record IDs.
- Fate: checkpoints, adapters and optimizer states deleted at the end of the window, or kept under a full license signed within an agreed conversion period; see derivative and successor model rights.
- What you keep: metrics, loss curves, outputs on your own test sets, configs and hyperparameters.
Do not let a trial checkpoint drift into a release. As of October 2026, California's AB 2013 requires developers of generative AI systems offered to Californians to post training-data documentation (first due 1 January 2026), including whether datasets were purchased or licensed and whether they include personal information [10]. In the EU, general-purpose AI model providers must publish a training-content summary under Article 53(1)(d) of the AI Act [11]. A sample that reached a shipped model could need disclosure and would have been used beyond its license; the grant you need instead is a fine-tuning-only data license.
Who owns the results, the feedback and what people remember
State that evaluation results belong to you and survive the trial whether or not you buy, and limit what the supplier may do with your feedback. Define results as metrics, error analyses, aggregate statistics, scripts, the evaluation harness and the decision memo, and keep verbatim records out of retained reports. If a supplier asks for a license to your feedback, accept data-quality feedback that helps fix the dataset, but bar attribution, publicity and disclosure of your model metrics to other prospects.
Some technology NDAs include a residuals clause, which lets a recipient use information retained in unaided memory. Exclude records and derived artifacts from it on both sides: a supplier will read a buyer-side residuals right as covering weights, and a supplier-side one could carry your findings to the next prospect.
The NDA's carve-out for independently developed information matters if you later license similar data elsewhere, so keep the sample in an isolated environment with access logs that show which teams saw it.
Personal data in the sample brings statutory terms with it
If the sample contains personal information, the trial agreement has to carry the obligations the law attaches to that data, and those can be stricter than anything in the commercial draft.
- California deidentified data. Under the CCPA, information counts as deidentified only if the business, among other conditions, publicly commits not to reidentify it and contractually obligates any recipients to comply with the definition [7]. A supplier relying on that status needs no-reidentification and use-in-deidentified-form clauses in the sample terms.
- HIPAA limited data sets. A limited data set remains protected health information, may be used only for research, public health or health care operations, and requires a data use agreement that limits use, restricts further disclosure, requires safeguards and reporting, and prohibits identifying or contacting individuals [8]. Whether commercial model development fits those purposes is a question for counsel; see limited data sets and DUAs for AI development and data license vs data use agreement.
- Financial records under Regulation P. A company receiving nonpublic personal information from a nonaffiliated financial institution under one of the rule's exceptions may use it only for the purpose for which it was received, even if it is not a financial institution [9].
Check that the sample carries no more identifiers than the full-delivery specification. When SourceX sources a dataset, names, emails, phone numbers and account numbers are removed or replaced before delivery and the method is recorded, and health records must meet HIPAA de-identification (Safe Harbor or Expert Determination) first. No de-identification method is perfect, so keep the no-reidentification clause either way.
Revocation, the evaluation window and the wind-down
Trial access is often revocable at the licensor's discretion, so fix an evaluation window, require notice before revocation except for breach, and define the wind-down for every copy and derived artifact. NVIDIA's grant is revocable [1]; an experiment cut off halfway proves nothing.
Size the window from your test plan, extendable by written notice, and list what the wind-down covers, because "all copies" is unverifiable:
- Raw files in object storage, local disks and notebooks
- Tokenized or preprocessed caches and mixed training sets
- Vector indexes and chunk stores
- Checkpoints, adapters and optimizer states not converted under a full license
- Experiment-tracking logs that store sample rows or model outputs quoting them
- Request logs at any named inference provider
- Backups, allowed to expire on their normal rotation while confidentiality continues
Close with a signed certificate naming those locations; deletion certificates for full contracts are covered in exiting a data contract. If you do license the dataset, decide whether sample records become held-out evaluation items and flag their record IDs, as in SourceX's guide to contamination checks for licensed evaluation data.
Illustrative term sheet: opening asks and fallbacks
Send a term sheet with the test plan so the supplier answers each point first.
Illustrative example: invented to show structure; it does not describe an available dataset. Not legal advice; adapt with counsel.
| Term | Buyer opening ask | Acceptable fallback | Walk-away signal |
|---|---|---|---|
| Purpose | Evaluate the sample to decide whether to license the dataset | Same purpose with a closed list of activities | Purpose tied to evaluating the supplier's own products |
| Activities | Profiling, review, retrieval tests, model scoring, internal fine-tuning experiments | All except fine-tuning, with a larger sample for the other tests | "Evaluation" left undefined |
| Checkpoints | Kept if a full license is signed within the conversion period, otherwise deleted | Deleted at the end, certified | Deletion of base models that were only scored on the sample |
| Results | Buyer owns all results; they survive termination | Buyer owns results; retained reports quote no records | Supplier owns or may publish results |
| Confidentiality | Mutual; covers use case, model plans and results | Mutual, with a shorter term for buyer information | One-way |
| Feedback and residuals | No feedback owed; no residuals clause | Unattributed data-quality feedback; residuals exclude records and weights | Feedback license with publicity rights |
| Window and revocation | Fixed window; revocation only for uncured breach | Revocation on written notice with time to wind down | Revocable at will mid-experiment |
| Deletion | Certified deletion of listed artifacts; backups expire on rotation | Certification within a set number of days | "All copies" certification with no list |
For fine-tuning, a definition like this gives both sides concrete text to edit:
Illustrative example: invented to show structure; it does not describe an available dataset. Not legal advice; adapt with counsel.
"Fine-Tuning Experiment" means training adapters or weights of a Licensee
model on the Sample, alone or mixed with Licensee data, inside the
Evaluation Environment, where the resulting checkpoints are not deployed,
served to any user, distilled into another model, or used to generate
training data. Licensee will delete such checkpoints within [X] days after
the Evaluation Period ends unless a Dataset License executed by the parties
covers them.
Review order for trial paper on the buyer side
Route trial paper to each reviewer once, in this order:
- ML or data lead writes the test plan: activities, base models, environment and sample size per test.
- Data partnerships lead sends the plan and term sheet before the sample ships.
- Counsel reviews grant, confidentiality, results, residuals and conversion against the AI training data licensing guide.
- Privacy checks statutory terms and compares the sample's fields with the full-delivery specification.
- Security confirms the evaluation environment, access logging and deletion method.
- ML lead certifies the wind-down; counsel files the certificate.
These steps sit inside the wider AI training data procurement lifecycle; SourceX's guide to running a data pilot with a supplier covers what follows, and AI data license terms explained summarizes full-license terms. If you source through SourceX, describe your planned tests in a data request on the SourceX buyer page. SourceX prepares diligence materials on source, rights, preparation and allowed use for each dataset, and nothing is delivered until an agreement is executed and the supplier approves the terms.
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
Planning to test a dataset sample before you license it?
Describe the dataset you need and the tests you plan for a sample. SourceX looks for US companies that hold that data, checks the data and the supplier's licensing permissions, and manages the license and delivery; nothing is contracted until a supplier agrees, and a request does not guarantee a matching dataset. Start a data request with SourceX.
Sources
- NVIDIA, "NVIDIA Sample Data License for Evaluation (2026.01.19)" (2026). https://developer.download.nvidia.com/licenses/nvidia-sample-data-license-for-evaluation-2026.01.19.pdf
- New Constructs, "Trial Data License Agreement and Mutual Non-Disclosure Agreement (TDLA Mutual NDA General)" (2024). https://www.newconstructs.com/wp-content/uploads/2024/10/New-Constructs-TDLA-Mutual-NDA-General.pdf
- Carlini et al. (USENIX Security 2021), "Extracting Training Data from Large Language Models" (2021). https://www.usenix.org/conference/usenixsecurity21/presentation/carlini-extracting
- Nasr et al. (ICLR 2025), "Scalable Extraction of Training Data from Aligned, Production Language Models" (2025). https://proceedings.iclr.cc/paper_files/paper/2025/hash/cce0e917b050208170151f77b497fc71-Abstract-Conference.html
- CMS (law-firm summary of EDPB Opinion 28/2024), "EDPB Opinion 28/2024: key takeaways on processing personal data in the context of AI models". https://cms.law/en/int/legal-updates/edpb-opinion-28-2024-key-takeaways-on-processing-personal-data-in-the-context-of-ai-models
- U.S. Federal Trade Commission, "FTC Finalizes Settlement with Photo App Developer Related to Misuse of Facial Recognition Technology" (2021). https://www.ftc.gov/news-events/news/press-releases/2021/05/ftc-finalizes-settlement-photo-app-developer-related-misuse-facial-recognition-technology
- California Legislature, "California Civil Code section 1798.140 (California Consumer Privacy Act definitions)". https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.140
- eCFR (Office of the Federal Register / HHS), "45 CFR 164.514(e): Limited data set and data use agreements". https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
- Consumer Financial Protection Bureau, "12 CFR 1016.11: Limits on redisclosure and reuse of information (Regulation P)". https://www.consumerfinance.gov/rules-policy/regulations/1016/11/
- California Legislature, "AB-2013 Generative artificial intelligence: training data transparency (Chapter 817, Statutes of 2024)" (2024). https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- European Commission, AI Act Service Desk, "AI Act Article 53: Obligations for providers of general-purpose AI models". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.