Skip to content

Getting started

Can you change your terms to cover data you already collected?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Changing your terms generally cannot cover data you already collected. New terms usually govern future collection, while using older data in a materially new way, such as licensing it for AI training, typically calls for affirmative consent. Rule: treat a retroactive terms change for AI training as a consent project, or license de-identified records that may fall outside earlier promises.

Key takeaways

  • New terms generally govern data collected after they take effect, not records gathered under earlier promises.
  • The FTC has long treated material retroactive changes to data practices without affirmative express consent as potentially unfair or deceptive.
  • B2B contracts usually require a signed amendment; updating a website page rarely changes them.
  • Data you process for customers as a service provider is often not yours to license, whatever your own terms say.

Why old data is governed by old promises#

Old data is governed by old promises because customers, users and employees shared it on the terms in force at the time. A privacy policy, customer contract or employee notice describes the uses they could expect, and a later update cannot change what they agreed to when they handed the information over.

That is why counsel usually starts by mapping record periods to the terms in force for each one. A help desk archive spanning many years may sit under several versions of a privacy policy and several MSA templates, each with different language about use, improvement and sharing.

The question for licensing is therefore not only what your terms say today, but what they said when each record was created and whether the proposed use fits within that.

What have US regulators said about retroactive changes?#

US regulators, led by the FTC, have long taken the position that a company making a material retroactive change to how it uses personal data it already collected generally needs affirmative express consent, not just an updated notice. On February 13, 2024, FTC staff applied that position to AI in a business guidance post titled 'AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive'. It warned that a company adopting more permissive data practices, such as using consumers' data for AI training, and telling consumers only through a surreptitious, retroactive change to its terms or privacy policy may be engaging in unfair or deceptive practices. It is staff guidance, not a rule, but it signals how the agency views these changes.

Public reaction can move faster than regulators. In August 2023, after backlash over earlier terms changes, Zoom added language to its terms stating it would not use audio, video or chat customer content to train its AI models without consent. Vague AI clauses carry a trust cost even when they are lawful.

State privacy laws point the same way. California's law, for example, generally expects personal information to be used for purposes that were disclosed and are compatible with the context in which it was collected. Where a new use falls outside that, notice alone may not be enough.

None of this decides a particular case. How a regulator views a change depends on the original promises, the type of data and how the change was communicated, which is why it is assessed deal by deal with counsel.

A rule of thumb by data type helps sort records before counsel looks at the details. The right-hand column matters most, because some records cannot be brought into scope by any change to your own terms.

Most archives contain several of these rows at once. A single Zendesk instance can hold consumer tickets, business customers' tickets and conversations you handle on a client's behalf, each with a different answer.

Notice, consent or not possible: a rule of thumb by data type
Data typeNotice may be enough whenAffirmative consent usually needed whenOften not possible when
Consumer data from your website or appThe new use was already disclosed, or the data is de-identified before usePersonal information is used for a materially new purpose such as AI trainingOriginal promises ruled the use out and consent cannot be obtained
B2B customer data you controlThe contract already permits the useThe contract is silent or limits use; a signed amendment is the usual routeThe customer refuses or the contract bars the use outright
Data you process for customers as a service providerRarely; the customer usually decides useThe customer must authorize it, usually by contractYour agreement limits you to processing on the customer's instructions
Employee records and communicationsThe use fits notices given to employees and records are de-identifiedIdentifiable content is used for a new external purposeRecords contain privileged or highly sensitive material
Records from an acquired companyThe acquired company's own terms already permitted the useIts terms were narrower than yoursIts promises excluded transfer or new uses

Why B2B contracts rarely change by notice#

B2B contracts rarely change by notice because most MSAs require amendments in a signed writing, and many customers negotiated their own data clauses. Posting updated online terms does little for a customer whose order form says the negotiated agreement controls.

Data processing agreements add another layer. If you act as a service provider or processor, the DPA usually limits you to processing customer data on the customer's instructions, and using that data for your own licensing may fall outside what the agreement allows. Customer-owned data clauses in SaaS contracts often say the same thing more bluntly.

The workable path is usually prospective: add clear, specific language at renewal for data created from then on, through an opt-in or a negotiated clause, and treat historical records separately.

Options when old records are out of scope#

Options when old records are out of scope fall into four groups, and most licensing programs combine them. None involves rewriting history.

Whatever mix you choose, record the rights basis for each record period. A buyer will ask, and a clear answer is what separates a licensable package from an argument.

  • Seek affirmative consent for historical records from the customers whose data matters most, through a signed amendment.
  • License only de-identified records, with personal information and customer-identifying details removed, after counsel confirms the approach.
  • Limit scope to internal records the company clearly controls, such as engineering issues, internal discussions and process documents.
  • Update terms prospectively so that future records are created under clear permissions.

Illustrative: a software company narrows scope instead of changing terms#

Illustrative: a fictional company that sells inspection software to commercial building owners wants to license support conversations and engineering records. Its privacy policy says customer information is used to provide and improve the service, and its MSA states that customers own customer data.

Counsel concludes that updating the online terms would not reach historical support conversations governed by the MSA. The company instead licenses its Jira issues, code review discussions and internal postmortems after removing customer names and account details, and asks a group of long-standing customers to sign an amendment covering their de-identified tickets.

At the next renewal cycle, the MSA template gains a specific, opt-in clause on de-identified use of support records for licensing. Future tickets will have a clear rights basis; past tickets are licensed only where an amendment exists.

How SourceX handles terms that changed over time#

SourceX handles changing terms in the Rights step of the SourceX five-step transaction by reviewing the terms in force for each record period and system. Records whose rights basis is unclear are left out or held until counsel resolves them.

The SourceX Evidence Packet records licensing rights and permitted use period by period, next to provenance, the privacy record and release authorization, so supplier and buyer can both see which promises cover which records.

Frequently asked questions

Does a continued-use clause make new terms apply to old data?

Rarely for a materially new use of data already collected. Continued use may show assent to updated terms going forward, but regulators have been skeptical of treating it as consent to new uses of past data, and courts look closely at whether notice was clear. Counsel should assess how your terms were presented.

Can we email customers and treat silence as consent?

Treating silence as consent is risky for materially new uses. Affirmative consent generally means a clear, active choice, such as a signature, a checkbox or a reply agreeing to the change. An email notice is still useful to inform customers, but it is weak evidence of agreement.

Do updated terms cover records created after the change?

Generally yes, if the update was clearly communicated and properly accepted under your contracts and applicable law. That is why prospective updates matter even when historical records stay out of scope: they make future records far easier to license.

Is de-identification a reliable workaround?

It can be part of the answer, because many privacy promises concern personal information, but it is not automatic. Confidentiality clauses in B2B contracts can cover business information even after names are removed, and de-identification must meet legal conditions. Counsel should confirm the approach for each record type.

Does the same reasoning apply to employee Slack messages and email?

Employee communications raise their own questions. Many employers have policies saying work systems belong to the company, but those policies were usually written for security and monitoring, not for licensing to outside developers. Employee notices, state privacy rules and any union agreements may matter, so de-identification and counsel review are usually needed.

What should a forward-looking AI clause say?

It should be specific and prominent: which records, which uses such as licensing or AI training, whether data is de-identified first, and how a customer can opt in or out. Vague language about improving services is a common source of later disputes, so plain wording helps both sides.

Sources

  • On February 13, 2024, FTC staff warned that a company adopting more permissive data practices, such as using consumers' data for AI training, and informing consumers only through a surreptitious, retroactive change to its terms or privacy policy may be engaging in unfair or deceptive practices. Source
  • On August 7, 2023, after backlash over March 2023 changes to its terms, Zoom added to its Terms of Service that it will not use audio, video or chat Customer Content to train its AI models without consent. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify