Software companies
Asset sale of a software company: which customer data rights transfer?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
In an asset sale of a software company, customer data rights transfer only with the customer contracts that are validly assigned, and the buyer gets exactly what the seller could do under each one. Anti-assignment clauses, DPAs and privacy notices decide whether consent is needed. Contracts that are not assigned leave their data rights, and their customers' data, behind.
Key takeaways
- Rights to use customer data are contract rights, so they move only when the customer contract is assigned.
- An assigned contract carries its limits with it, including use restrictions and any aggregated data clause.
- Anti-assignment clauses often require customer consent in an asset deal, even where a stock deal often would not.
- Vendor-owned records such as code, tickets and internal docs transfer as purchased assets, subject to confidentiality duties.
- A customer that withholds consent stays with the seller, which must then serve, return or delete that customer's data.
The rule: data rights follow the assigned contract#
In a software asset sale, customer data rights follow the customer contracts that are assigned to the buyer. The seller usually never owned its customers' data; it held permission to process it under the master agreement, order forms and data processing addendum. Vendor terms often say so directly: Zendesk's data processing agreement, for example, states that Zendesk claims no ownership interest in the service data it processes.
So a buyer cannot acquire customer data as a free-standing asset. It acquires the seller's contractual position, if each contract is validly assigned, and with it exactly the permissions and limits the seller had. A contract that limits use to providing the service still limits the buyer after closing.
What transfers and what stays behind#
What transfers in a software asset sale depends on whether an item is a contract right or a business asset. Contract rights need assignment; business assets pass under the asset purchase agreement, carrying whatever confidentiality duties attach to their contents.
| Item | How it transfers | What to check |
|---|---|---|
| Customer contracts: MSA and order forms | By assignment, sometimes with customer consent | Anti-assignment and change-of-control clauses |
| Rights to process customer data | Only with the assigned contract | Use restrictions, DPA terms, sub-processor commitments |
| Aggregated or usage data rights | Only as granted in each assigned contract | Purpose limits, such as improving the service only |
| Aggregated datasets already created | As seller assets, if the contract allowed creating and keeping them | Whether the right survives assignment or termination |
| Source code, Jira, GitHub, internal docs | As purchased assets | Customer confidential information and third-party code inside |
| Support tickets and CRM history | As purchased business records | Customer personal data and confidentiality duties |
| Data of customers whose contracts are not assigned | Does not transfer | The seller's return or deletion obligations |
Reading anti-assignment clauses in SaaS contracts#
Anti-assignment clauses in SaaS contracts decide whether the seller can hand a customer contract to the buyer without asking. The wording varies widely, and one product can carry several patterns across its customer base, especially where large customers negotiated their own paper.
The carve-out matters most in a product-line sale. Selling one product is often not a sale of substantially all assets, so the successor exception may not apply, and each customer on that product may need to consent. Customer-favorable contracts sometimes add a termination right on assignment, which turns a consent request into a renewal negotiation.
Third-party licenses inside the product have their own clauses. A license limited to the licensee's internal operations or its affiliates can leave a divested product outside the license once it leaves the group.
| Clause pattern | Effect in an asset sale | Typical next step |
|---|---|---|
| No assignment without consent | The customer must agree before the contract moves | Request consent and plan for refusals |
| Consent not to be unreasonably withheld | The customer must agree but needs a reason to refuse | Request consent with information about the buyer |
| Successor carve-out for a sale of substantially all assets | May not cover the sale of a single product line | Check whether the deal fits the wording |
| Free assignment to affiliates or successors | The contract moves without consent | Send notice if the contract requires it |
| Termination right on assignment | The customer may exit instead of consenting | Treat it as a renewal conversation |
| No clause at all | Depends on governing law and the nature of the services | Ask counsel before assuming |
Checklist for customer data in an asset deal#
A customer data checklist keeps the asset purchase agreement aligned with what each customer contract actually allows. Work through it before signing, because consent requests and fallbacks take longer than closing mechanics.
- Inventory every customer contract on the product, including the DPA and any security addendum.
- Classify each assignment clause: free, consent required, successor carve-out or termination right.
- Record each contract's data use limits, aggregated data rights and any AI or machine learning terms.
- Check DPAs and privacy notices for notice duties when the processor or a sub-processor changes.
- Plan consent requests, a fallback for refusals and a deadline aligned with any transition services period.
- Decide what happens to the data of customers who do not consent, and document return or deletion.
- Confirm that third-party software and data licenses inside the product can be assigned to the buyer.
Does the buyer get the right to train on or license customer data?#
A buyer gets the right to train on or license customer data only if the assigned contracts already granted it. Most B2B SaaS agreements restrict use to providing and supporting the service, and assignment does not widen that scope.
Changing the terms after closing is a separate step with its own risk. Customers who accepted terms under one owner may object to new uses, and privacy laws such as the GDPR and US state privacy laws may apply wherever personal data is involved. Treat any new AI use as a permission still to be obtained, not something the purchase price bought.
Vendor-owned records are different. Source code, engineering tickets and internal product discussions are business assets that do transfer, and they can be candidates for licensing once confidential customer details are removed.
Distressed sales and privacy promises#
Distressed asset sales add a privacy layer when the software collected consumers' details. Under 11 U.S.C. 363(b)(1), if a debtor's privacy policy prohibited transferring personally identifiable information to unaffiliated persons, the trustee generally cannot sell it unless the sale fits that policy or, after a consumer privacy ombudsman is appointed and notice and a hearing are held, the court approves it.
Regulators have also asked buyers to honor earlier promises. In the RadioShack bankruptcy, the FTC recommended in May 2015 that customer data not be sold as a standalone asset, and that any transfer be limited to a buyer in substantially the same line of business willing to be bound by RadioShack's privacy policy.
Illustrative: a product line sold out of a larger software company#
Illustrative: a fictional workflow software company sells its inspection scheduling product for property inspectors to a vertical software acquirer in an asset deal. The product has customers on negotiated contracts and on click-through terms, plus years of Jira, GitHub and Zendesk history.
Counsel finds that the click-through terms allow assignment to any successor to the product, while the negotiated contracts require consent. Most consents come back; two customers decline and leave at the end of their terms, and the seller deletes their data and certifies it. No contract allowed training, so the buyer's planned AI feature needs new opt-in terms.
The engineering and support history transfer as business records. The buyer later reviews them for licensing, removing customer names and personal details first.
How SourceX treats acquired customer data#
SourceX treats rights as the second step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. For an acquired product, the rights review traces each record class to the contract or purchase document that conveys it, and customer content is excluded unless the customer contract permits the use. The SourceX Evidence Packet then records the chain of title, permitted use and release authorization for anything licensed.
Every deal is assessed on its own documents. Assignment, privacy and bankruptcy rules vary, so the analysis is done with counsel.
Frequently asked questions
Is a stock sale simpler for customer data?
Often, because the contracting entity does not change, so customer contracts stay with the same party. Change-of-control clauses can still give customers notice or termination rights, and the new owner still cannot widen data use beyond the existing terms without customer agreement.
Can the seller keep a copy of customer data after closing?
Usually only what the contracts, the transition services agreement and the law allow, such as records needed for tax or legal holds. Keeping copies for other uses can breach the assigned contracts. Spell out retention and deletion in the asset purchase agreement.
Do sub-processor notices apply in an asset sale?
They can. A new legal entity processing customer data may count as a new processor or a change of sub-processor under a DPA, which can trigger notice and sometimes an objection right. Check each DPA's wording and build the notices into the closing plan.
How does purchase accounting treat customer data?
Under ASC 805, acquired intangible assets are recognized separately from goodwill when they arise from contractual or legal rights or are separable, and the guidance's examples list databases and customer lists. How customer-related data is valued is a question for the buyer's accountants and valuation advisers.
What if customer contracts say nothing about assignment?
Silence does not always mean free assignment. Default contract law, the governing law clause and the nature of the services all matter, and personal data duties apply either way. Counsel should review silent contracts as carefully as those with explicit clauses.
Sources
- Zendesk's Data Processing Agreement states that Zendesk claims no ownership interest in the Service Data it processes under the agreement. Source
- Under 11 U.S.C. §363(b)(1), if a debtor disclosed to individuals a policy prohibiting transfer of personally identifiable information to unaffiliated persons and that policy is in effect when the case commences, the trustee may not sell or lease that information unless the sale is consistent with the policy or, after appointment of a consumer privacy ombudsman under §332 and notice and a hearing, the court approves it after finding no showing that the sale would violate applicable nonbankruptcy law. Source
- In a May 2015 letter to the RadioShack consumer privacy ombudsman, publicized by the FTC on May 18, 2015, FTC Bureau of Consumer Protection Director Jessica Rich recommended that customer data not be sold as a standalone asset and be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy and to obtain consumers' affirmative consent before making material changes. Source
- Under ASC 805, an intangible asset acquired in a business combination is recognized separately from goodwill if it arises from contractual or legal rights or is separable, and the Codification's illustrative examples list databases, including title plants, among technology-based intangible assets and customer lists among customer-related intangible assets. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.