Skip to content

Software companies

Asset sale of a software company: which customer data rights transfer?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

In an asset sale of a software company, customer data rights transfer only with the customer contracts that are validly assigned, and the buyer gets exactly what the seller could do under each one. Anti-assignment clauses, DPAs and privacy notices decide whether consent is needed. Contracts that are not assigned leave their data rights, and their customers' data, behind.

Key takeaways

  • Rights to use customer data are contract rights, so they move only when the customer contract is assigned.
  • An assigned contract carries its limits with it, including use restrictions and any aggregated data clause.
  • Anti-assignment clauses often require customer consent in an asset deal, even where a stock deal often would not.
  • Vendor-owned records such as code, tickets and internal docs transfer as purchased assets, subject to confidentiality duties.
  • A customer that withholds consent stays with the seller, which must then serve, return or delete that customer's data.

The rule: data rights follow the assigned contract#

In a software asset sale, customer data rights follow the customer contracts that are assigned to the buyer. The seller usually never owned its customers' data; it held permission to process it under the master agreement, order forms and data processing addendum. Vendor terms often say so directly: Zendesk's data processing agreement, for example, states that Zendesk claims no ownership interest in the service data it processes.

So a buyer cannot acquire customer data as a free-standing asset. It acquires the seller's contractual position, if each contract is validly assigned, and with it exactly the permissions and limits the seller had. A contract that limits use to providing the service still limits the buyer after closing.

What transfers and what stays behind#

What transfers in a software asset sale depends on whether an item is a contract right or a business asset. Contract rights need assignment; business assets pass under the asset purchase agreement, carrying whatever confidentiality duties attach to their contents.

What transfers and what stays behind
ItemHow it transfersWhat to check
Customer contracts: MSA and order formsBy assignment, sometimes with customer consentAnti-assignment and change-of-control clauses
Rights to process customer dataOnly with the assigned contractUse restrictions, DPA terms, sub-processor commitments
Aggregated or usage data rightsOnly as granted in each assigned contractPurpose limits, such as improving the service only
Aggregated datasets already createdAs seller assets, if the contract allowed creating and keeping themWhether the right survives assignment or termination
Source code, Jira, GitHub, internal docsAs purchased assetsCustomer confidential information and third-party code inside
Support tickets and CRM historyAs purchased business recordsCustomer personal data and confidentiality duties
Data of customers whose contracts are not assignedDoes not transferThe seller's return or deletion obligations

Reading anti-assignment clauses in SaaS contracts#

Anti-assignment clauses in SaaS contracts decide whether the seller can hand a customer contract to the buyer without asking. The wording varies widely, and one product can carry several patterns across its customer base, especially where large customers negotiated their own paper.

The carve-out matters most in a product-line sale. Selling one product is often not a sale of substantially all assets, so the successor exception may not apply, and each customer on that product may need to consent. Customer-favorable contracts sometimes add a termination right on assignment, which turns a consent request into a renewal negotiation.

Third-party licenses inside the product have their own clauses. A license limited to the licensee's internal operations or its affiliates can leave a divested product outside the license once it leaves the group.

Reading anti-assignment clauses in SaaS contracts
Clause patternEffect in an asset saleTypical next step
No assignment without consentThe customer must agree before the contract movesRequest consent and plan for refusals
Consent not to be unreasonably withheldThe customer must agree but needs a reason to refuseRequest consent with information about the buyer
Successor carve-out for a sale of substantially all assetsMay not cover the sale of a single product lineCheck whether the deal fits the wording
Free assignment to affiliates or successorsThe contract moves without consentSend notice if the contract requires it
Termination right on assignmentThe customer may exit instead of consentingTreat it as a renewal conversation
No clause at allDepends on governing law and the nature of the servicesAsk counsel before assuming

Checklist for customer data in an asset deal#

A customer data checklist keeps the asset purchase agreement aligned with what each customer contract actually allows. Work through it before signing, because consent requests and fallbacks take longer than closing mechanics.

  • Inventory every customer contract on the product, including the DPA and any security addendum.
  • Classify each assignment clause: free, consent required, successor carve-out or termination right.
  • Record each contract's data use limits, aggregated data rights and any AI or machine learning terms.
  • Check DPAs and privacy notices for notice duties when the processor or a sub-processor changes.
  • Plan consent requests, a fallback for refusals and a deadline aligned with any transition services period.
  • Decide what happens to the data of customers who do not consent, and document return or deletion.
  • Confirm that third-party software and data licenses inside the product can be assigned to the buyer.

Does the buyer get the right to train on or license customer data?#

A buyer gets the right to train on or license customer data only if the assigned contracts already granted it. Most B2B SaaS agreements restrict use to providing and supporting the service, and assignment does not widen that scope.

Changing the terms after closing is a separate step with its own risk. Customers who accepted terms under one owner may object to new uses, and privacy laws such as the GDPR and US state privacy laws may apply wherever personal data is involved. Treat any new AI use as a permission still to be obtained, not something the purchase price bought.

Vendor-owned records are different. Source code, engineering tickets and internal product discussions are business assets that do transfer, and they can be candidates for licensing once confidential customer details are removed.

Distressed sales and privacy promises#

Distressed asset sales add a privacy layer when the software collected consumers' details. Under 11 U.S.C. 363(b)(1), if a debtor's privacy policy prohibited transferring personally identifiable information to unaffiliated persons, the trustee generally cannot sell it unless the sale fits that policy or, after a consumer privacy ombudsman is appointed and notice and a hearing are held, the court approves it.

Regulators have also asked buyers to honor earlier promises. In the RadioShack bankruptcy, the FTC recommended in May 2015 that customer data not be sold as a standalone asset, and that any transfer be limited to a buyer in substantially the same line of business willing to be bound by RadioShack's privacy policy.

Illustrative: a product line sold out of a larger software company#

Illustrative: a fictional workflow software company sells its inspection scheduling product for property inspectors to a vertical software acquirer in an asset deal. The product has customers on negotiated contracts and on click-through terms, plus years of Jira, GitHub and Zendesk history.

Counsel finds that the click-through terms allow assignment to any successor to the product, while the negotiated contracts require consent. Most consents come back; two customers decline and leave at the end of their terms, and the seller deletes their data and certifies it. No contract allowed training, so the buyer's planned AI feature needs new opt-in terms.

The engineering and support history transfer as business records. The buyer later reviews them for licensing, removing customer names and personal details first.

How SourceX treats acquired customer data#

SourceX treats rights as the second step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. For an acquired product, the rights review traces each record class to the contract or purchase document that conveys it, and customer content is excluded unless the customer contract permits the use. The SourceX Evidence Packet then records the chain of title, permitted use and release authorization for anything licensed.

Every deal is assessed on its own documents. Assignment, privacy and bankruptcy rules vary, so the analysis is done with counsel.

Frequently asked questions

Is a stock sale simpler for customer data?

Often, because the contracting entity does not change, so customer contracts stay with the same party. Change-of-control clauses can still give customers notice or termination rights, and the new owner still cannot widen data use beyond the existing terms without customer agreement.

Can the seller keep a copy of customer data after closing?

Usually only what the contracts, the transition services agreement and the law allow, such as records needed for tax or legal holds. Keeping copies for other uses can breach the assigned contracts. Spell out retention and deletion in the asset purchase agreement.

Do sub-processor notices apply in an asset sale?

They can. A new legal entity processing customer data may count as a new processor or a change of sub-processor under a DPA, which can trigger notice and sometimes an objection right. Check each DPA's wording and build the notices into the closing plan.

How does purchase accounting treat customer data?

Under ASC 805, acquired intangible assets are recognized separately from goodwill when they arise from contractual or legal rights or are separable, and the guidance's examples list databases and customer lists. How customer-related data is valued is a question for the buyer's accountants and valuation advisers.

What if customer contracts say nothing about assignment?

Silence does not always mean free assignment. Default contract law, the governing law clause and the nature of the services all matter, and personal data duties apply either way. Counsel should review silent contracts as carefully as those with explicit clauses.

Sources

  • Zendesk's Data Processing Agreement states that Zendesk claims no ownership interest in the Service Data it processes under the agreement. Source
  • Under 11 U.S.C. §363(b)(1), if a debtor disclosed to individuals a policy prohibiting transfer of personally identifiable information to unaffiliated persons and that policy is in effect when the case commences, the trustee may not sell or lease that information unless the sale is consistent with the policy or, after appointment of a consumer privacy ombudsman under §332 and notice and a hearing, the court approves it after finding no showing that the sale would violate applicable nonbankruptcy law. Source
  • In a May 2015 letter to the RadioShack consumer privacy ombudsman, publicized by the FTC on May 18, 2015, FTC Bureau of Consumer Protection Director Jessica Rich recommended that customer data not be sold as a standalone asset and be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy and to obtain consumers' affirmative consent before making material changes. Source
  • Under ASC 805, an intangible asset acquired in a business combination is recognized separately from goodwill if it arises from contractual or legal rights or is separable, and the Codification's illustrative examples list databases, including title plants, among technology-based intangible assets and customer lists among customer-related intangible assets. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify