Private equity and portfolios
Data assets in a sell-side data room: what to include
By SourceX Editorial · Updated
Short answer
A sell-side data room should include a dedicated data assets folder holding five things: a record inventory, rights evidence, a privacy record, any signed data licenses and their delivery logs. The rule that matters most: every claim the teaser makes about data should point to a document in that folder, or a buyer will discount it.
Key takeaways
- Give data assets their own folder rather than scattering evidence across IP, IT and commercial contract folders.
- A record inventory names systems, record families, date ranges and restrictions; it never contains raw records.
- Each signed data license needs a one-page summary of exclusivity, term, assignment and change-of-control terms.
- Delivery logs and deletion confirmations prove that past licenses were performed within their limits.
- Build the folder before launch so gaps are fixed on the seller's timetable, not the buyer's.
Why data assets need their own data room folder#
Data assets need their own data room folder because buyers may treat records, data rights and AI use as a diligence topic in their own right, separate from IT security and general intellectual property. When the evidence is spread across commercial contracts, IT policies and the IP schedule, the buyer's counsel has to rebuild the picture, and every gap becomes a question or a price adjustment.
A single folder also forces the seller to reconcile its own story. If the management presentation says the company holds many years of linked service records, the inventory in the folder should show which systems hold them and which date ranges can still be exported.
The folder index for data assets and licenses#
The folder index below covers what a buyer's counsel and technical advisers expect to find. Smaller companies can combine some folders; companies that have already licensed records to AI developers need all of them.
Cross-reference rather than duplicate. Customer contracts usually sit in the commercial folder already, so the rights evidence folder can hold a short memo that cites the relevant clauses and points to the full agreements.
| Folder | What goes in it | Who prepares it |
|---|---|---|
| Record inventory | Systems, record families, date ranges, approximate volumes, export routes and known restrictions | COO or IT lead with the owner of each system |
| Rights evidence | Customer contract clauses on data use, vendor platform terms, and the privacy and employee notices in force when records were collected | General counsel or outside counsel |
| Privacy record | What personal and confidential details were removed from licensed records, how, and who reviewed the result | Privacy lead or the preparation provider |
| Signed data licenses | Executed licenses, amendments, one-page term summaries and any open negotiations | General counsel with the CFO |
| Delivery logs | Delivery manifests, dates, approvals, file checksums and deletion or return confirmations | IT lead |
| Revenue and accounting | How license income was recognized and whether it repeats | CFO with the auditors |
| AI tools in use | Internal AI tools, the vendors behind them and the data those vendors can access | CTO or IT lead |
What a buyer-ready record inventory looks like#
A buyer-ready record inventory is a structured description of records, not a sample of them. It lets a buyer judge depth, linkage and restrictions without anyone handling personal or confidential information.
Keep the inventory in a spreadsheet with one row per system and record family. Buyers' advisers can then filter it and map it against their own integration plans, and the seller can update it as diligence questions arrive.
- System name and owner, such as Zendesk owned by the support director or NetSuite owned by the controller.
- Record family, such as support tickets, quotes, work orders, code reviews or quality reports.
- Date range that can still be exported, which may be shorter than the company's operating history.
- Approximate volume, stated as a range rather than a precise count.
- Linkage: whether records connect a request to the decision and the outcome.
- Known restrictions, such as client-owned deliverables, carve-outs in customer contracts or vendor export limits.
How to present rights evidence and the privacy record#
Rights evidence should show the terms under which records were collected, not only today's terms. A customer agreement signed years ago, an older privacy notice or a vendor contract that has since changed may still govern older records, so include the versions that applied at the time.
For the privacy record, a recognized vocabulary helps. The Data & Trust Alliance's Data Provenance Standards group dataset metadata into Source, Provenance and Use, and the Use group includes elements such as confidentiality classification, consent documentation location, privacy-enhancing technologies applied, license to use and intended data use. A seller does not need to adopt the standard, but describing licensed records in similar terms makes them easier for a buyer's technical advisers to assess.
Keep raw records, unredacted customer lists and credentials out of the data room. If a preferred bidder needs to inspect samples, use a later-stage clean room with prepared extracts and its own access log.
Summarizing signed data licenses for a buyer#
Signed data licenses should each come with a one-page summary, because a buyer reads them for obligations that survive the sale. The terms that change a buyer's view are few, and they should be easy to find without reading every clause.
| Term | What the buyer is checking |
|---|---|
| Exclusivity | Whether any record family or field of use is closed to future licensing |
| Term and renewal | Whether obligations run past the expected closing |
| Assignment and change of control | Whether the license transfers, needs consent or can be terminated on a sale |
| Continuing delivery | Whether the company owes refreshes or future exports |
| Permitted use | Whether the licensee may train, evaluate, resell or share the records |
| Deletion and audit | Whether the company can confirm the licensee's compliance |
| Warranties and indemnities | What the company promised about rights and privacy, and for how long |
Illustrative: a buyer's questions answered from the folder#
Illustrative: a fictional PE-backed provider of maintenance management software is preparing for sale. Earlier in the hold period it licensed prepared internal engineering tickets and code review history to an AI developer, with customer data in the product left out of scope. The deal partner asks the company to build a data assets folder before the process launches.
Building the folder surfaces one problem. The license summary shows exclusivity for engineering tickets in a narrow field of use, but the management presentation describes the whole engineering archive as available for future licensing. The company corrects the presentation and adds a note explaining the exclusivity scope.
When a bidder's counsel asks about the license, the answer is already in the folder: the term summary, the delivery manifest, the privacy record and the licensee's deletion confirmation for an earlier test extract.
How the SourceX Evidence Packet maps to the folder#
The SourceX Evidence Packet maps directly to a data room folder because it records the same five things a buyer checks: provenance, licensing rights, permitted use, the privacy record and release authorization. Companies that licensed records through the SourceX five-step transaction can file the packet for each license next to the signed agreement.
For companies that have not licensed anything yet, the metadata gathered for a SourceX fit check, such as systems, record families, date ranges and known restrictions, is the same information the record inventory needs, so the work serves both purposes.
Frequently asked questions
When should the data assets folder be built?
Build it before the process launches, ideally while the company prepares its quality of earnings work. That leaves time to fix gaps, such as a missing contract version or an unsigned deletion confirmation, without a buyer waiting. A folder assembled in response to diligence questions usually looks reactive and incomplete.
Does a company with no data licenses need this folder?
Yes, in a shorter form. A record inventory, rights evidence and a list of AI tools in use still help a buyer value the records and spot risks. The folder also shows that the company knows what it holds, which supports any data story in the management presentation.
Should a license still under negotiation be disclosed?
Usually it should appear, handled with care. Counsel will advise on how much detail to share and when, but a buyer that discovers an undisclosed negotiation late tends to question everything else in the folder. A short note on the counterparty type, record scope and status is a common approach.
Should bidders receive sample records?
Not in the general data room. Samples raise privacy and confidentiality risks and are rarely needed for a first view. If a preferred bidder needs to verify quality, provide prepared extracts in a controlled clean room with access logging, after the privacy work is complete.
How should license income appear in the financials?
Show it separately from core revenue, with a note on whether it is one-time or repeating and how it was recognized. Buyers often normalize income they consider non-recurring, so clarity up front avoids a debate during quality of earnings review. Ask your auditors how specific license terms affect recognition.
Who should own the data assets folder?
The portfolio company should own it, with one named coordinator, usually the general counsel or the COO, and the deal team checking it against the management presentation. Sponsor staff can push for completeness, but the people who run the systems and signed the contracts are the ones who can answer follow-up questions accurately.
Sources
- The Data & Trust Alliance's Data Provenance Standards (version 1.0.0 specification) define dataset metadata in three groups: Source, Provenance and Use. Source
- The Use group of the Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, license to use and intended data use. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.