Private equity and portfolios
Acquiring a company that already licenses its data: what to check
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
When acquiring a company that already licenses its data, check seven things before signing: what was licensed, the permitted use, any exclusivity, how the license revenue is earned and renewed, deletion and audit duties, change-of-control and assignment terms, and limits on who the target may license to next. Affiliate definitions deserve special attention.
Key takeaways
- Read every data license for scope, permitted use, exclusivity and term before treating its revenue as recurring.
- Affiliate definitions can extend a target's licensing restrictions to the acquirer's other portfolio companies after closing.
- Change-of-control clauses may require consent or let the licensee exit when the target is sold.
- Deletion, audit and survival clauses decide which obligations continue after a license ends.
- Ask for a provenance record for each licensed package showing source, rights and who approved release.
Why an existing data license changes the diligence plan#
An existing data license changes the diligence plan because it is both an asset and a set of continuing obligations. The target may have income from it, a buyer relationship and a working preparation process. It may also have granted rights that limit what a new owner can do with the same records.
Data licenses are newer than most commercial contracts in a data room, so they are often drafted from scratch or from the buyer's template. That makes them less predictable than a standard customer agreement. Read each one in full rather than relying on the CIM summary, and bring counsel in early; the points below are general information, and every agreement and deal differs.
The buy-side checklist#
The buy-side checklist covers seven items, each tied to specific clauses. Work through it for every license, data sharing agreement and AI-related data arrangement the target has signed, including ones described as pilots or evaluations.
| Item | What to read | Question to answer | Red flag |
|---|---|---|---|
| Scope | Grant clause, data description, delivery schedules | Which record families, date ranges and entities were licensed? | Vague descriptions such as all company data |
| Permitted use | Use restrictions, field-of-use clause | What may the licensee do with the records? | Unrestricted use, or rights to resell or sublicense |
| Exclusivity | Exclusivity and non-compete clauses | Is the target barred from licensing similar records elsewhere? | No end date, or a broad definition of similar data |
| Revenue terms | Fees, milestones, renewal and refund clauses | Is income one-time, milestone-based or recurring? | Refunds tied to open-ended data quality claims |
| Deletion and audit | Term, termination, survival and audit clauses | What must the licensee delete, and can the target verify it? | No deletion duty and no audit right |
| Change of control | Assignment and change-of-control clauses | Does the acquisition need consent or allow termination? | Licensee may terminate or renegotiate on a sale |
| Limits on the licensor | Covenants, most-favored terms, competitor clauses | Has the target agreed not to license to certain parties? | Restrictions that also bind affiliates |
Scope and exclusivity: what has already been given away#
Scope and exclusivity clauses show what the target has already given away. A well-drafted license names the record families, systems, date ranges and legal entity, so it is clear what was delivered and what remains free to license. A loose one describes data in general terms that a licensee could later read broadly.
Pay particular attention to affiliate definitions. If the target agreed that it and its affiliates will not license similar records to others, the acquirer's other portfolio companies could arguably become affiliates at closing. Whether that reading holds depends on the drafting, so flag any affiliate language for counsel and, where it matters, seek an amendment before signing.
How to read license revenue in a quality of earnings review#
License revenue should be read through its contract terms, not through where it sits in the income statement. A single fee for a delivered package behaves differently from a multi-year agreement with scheduled refreshes, and a milestone payment that depends on buyer acceptance carries more risk than one already earned.
How the revenue is recognized depends on those terms and is a question for the target's accountants and the buyer's quality of earnings provider, typically under ASC 606. For valuation, separate contracted renewals from one-time deliveries, and do not assume a repeat license unless a renewal is written into the agreement.
- One-time delivery fees: treat as non-recurring unless a refresh schedule is contracted.
- Contracted refreshes: recurring only for the committed term.
- Milestone payments: check the acceptance criteria and who decides acceptance.
- Refund or credit clauses: check the triggers, such as disputes over data quality or completeness.
Deletion duties, audit rights and what survives termination#
Deletion and survival clauses decide what continues after a license ends. Some licenses require the buyer to delete the records and certify deletion; others allow models already trained on the records to stay in use. Neither is wrong, but the acquirer should know which applies before describing the asset to its lenders or to a future buyer.
Check whether the target has ever exercised an audit right or received a deletion certificate. An untested right still has value, but a documented certificate is stronger evidence in the next diligence process, and it shows the target actually tracks its obligations.
Change of control and assignment#
Change-of-control and assignment clauses determine whether a license survives the deal unchanged. Some agreements require the licensee's consent before assignment, some let either party terminate if the other is acquired by a competitor, and some are silent. In a stock purchase the license usually stays with the target, but change-of-control language can still apply.
Ask the target which licensees must be notified, which must consent and whether any licensee gains a right to renegotiate. Put those steps on the closing checklist with an owner for each, so they do not surface after signing.
- List every data license, data sharing agreement and evaluation agreement with its counterparty and term.
- Mark each one as consent required, notice required or silent on change of control.
- Note any termination or renegotiation right triggered by the sale itself or by the acquirer's identity.
- Assign an owner and a sequence for each notice or consent request, and keep copies of responses in the closing set.
Illustrative: a fleet maintenance software target with one license#
Illustrative: a fictional fleet maintenance software company licensed a prepared package of support tickets, engineering issues and release notes to an AI developer. The sponsor's deal team finds the grant clearly limited to those records and dates, with a field-of-use limit that excludes fleet management products.
Two issues surface. The exclusivity clause bars the target and its affiliates from licensing support records to other developers during the term, which would reach a sister company in the sponsor's portfolio. And the license fee was a single payment that the CIM presented next to subscription revenue.
The sponsor asks the target to obtain an amendment narrowing the affiliate definition before closing, and models the fee as non-recurring. Because the target kept a delivery record and an approval memo, confirming what left the company takes a document review rather than a forensic exercise.
How SourceX documents licenses for diligence#
SourceX records each licensed package in a SourceX Evidence Packet: provenance, licensing rights, permitted use, the privacy record and release authorization. For an acquirer, that packet answers the scope, use and approval questions above without reconstructing them from email threads.
Public provenance vocabularies point the same way. The Data & Trust Alliance's Data Provenance Standards group dataset metadata into Source, Provenance and Use, and the Use group includes elements such as license to use, intended data use and consent documentation location. A target that documents its licenses in comparable terms is far easier to diligence.
Frequently asked questions
Should an existing data license raise or lower the valuation?
It can do either. A well-scoped, non-exclusive license with clean documentation shows that the records have buyers and that the company can deliver. A broad or exclusive license may limit future options. Value it on its contract terms and on what remains available to license, not on the headline fee.
What if the target cannot produce the license schedules?
Treat it as a material gap. Without the schedules, no one can confirm what was delivered or which uses were permitted. Ask for delivery records, correspondence and approval memos, and discuss protections such as a specific indemnity with counsel if the gap cannot be closed before signing.
Do we need to tell the licensee about the acquisition?
Only if the agreement requires notice or consent, or a change-of-control clause gives the licensee rights. Some agreements say nothing on the point. Counsel should confirm the requirement for each license, and the closing checklist should record who notifies whom.
Can we expand the target's licensing program after closing?
Often, if the existing licenses leave room. Check exclusivity, field-of-use and most-favored terms first, then confirm rights for any new record families. New packages from the target or from sister companies each need their own rights review and supplier approval.
How do we check that personal data was handled properly in past deliveries?
Ask for the privacy record for each delivery: what was removed or replaced, how preparation was checked and who approved release. If no record exists, review a written description of the preparation steps with privacy counsel before relying on the license in the deal model.
Sources
- The Data & Trust Alliance's Data Provenance Standards (version 1.0.0 specification) define dataset metadata in three groups: Source, Provenance and Use. Source
- The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
Related resources
- QuestionData licensing vs data selling: what's the difference?
- InsightCan roofing contractors sell their data to AI companies?
- InsightCustomer complaint logs: what AI learns from how you resolve them
- InsightWho has authority to license a dissolved company's data?
- SolutionData monetization: earning revenue from data you already have
- IndustryHealthcare administration data
See if your company qualifies
A short company assessment. No data uploads are needed.