Skip to content

Rights and contracts

Data rights due diligence checklist for acquirers

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A data rights due diligence checklist tests whether a target company can actually use, license or transfer the records it holds. Group the review into four areas: ownership, contracts, privacy and existing licenses. The decision rule: count records as an asset only when you can trace who created them, under which terms, and what has already been granted.

Key takeaways

  • Owning a company does not mean owning every record in its systems; customer, vendor and employee terms can limit use.
  • Review four areas in order: ownership, contracts, privacy notices and consents, then existing licenses and AI permissions.
  • Prior exclusive licenses and vendor AI-training permissions can quietly remove value before closing.
  • Turn each finding into a deal response: a specific representation, an indemnity, a closing condition or a carve-out.
  • Keep the diligence file, because it becomes the starting evidence for any future data license.

What does data rights diligence check that IP diligence misses?#

Data rights diligence checks whether the target's operational records can be used for new purposes, including licensing them for AI training, and not only whether the target owns its software and trademarks. Standard IP diligence looks at patents, code ownership and registered marks. It rarely asks who controls the support tickets, CRM histories, job records or engineering discussions sitting in the target's systems.

That gap matters once an investment thesis counts data as part of the value. A target can own its product outright while its customer agreements forbid reuse of customer content, its privacy notice promises a narrow purpose, and a past vendor deal granted someone else rights to the same archive. Each of those facts changes what the records are worth after closing.

  • Ownership: which legal entity created and holds each record family, and whether any records belong to customers or clients.
  • Contracts: customer, vendor, partner and employee terms that restrict use, disclosure or transfer.
  • Privacy: what personal information the records contain, and which notices and consents covered its collection.
  • Existing licenses: data licenses, exclusivity grants and AI-training permissions already given to others.

Ownership: who actually holds the records?#

Ownership diligence confirms which entity created the records, which entity holds them today, and whether any third party has a competing claim. In roll-ups and carve-outs these are often three different answers, because records were created by a predecessor company, migrated into a parent's systems and stored in a vendor's cloud.

Ask for a record map before you ask for contracts. A one-page list of systems, the account holder for each, the years of history each holds and the record families inside them tells you where to aim document requests.

Ownership: who actually holds the records?
QuestionEvidence to requestRed flag
Which entity is the account holder for each system?Vendor invoices and admin console ownershipSystems billed to a founder, an affiliate or a former parent
Were records inherited from an earlier acquisition?Prior purchase agreement and asset schedulesAn asset purchase that excluded customer data or archives
Do any records belong to clients?Client contracts and statements of workDeliverables, designs or code owned by the client
Who created internal documents and code?Employee and contractor IP assignment agreementsContractors with no assignment on file
Can history still be exported?Export tests or vendor documentation for the plan in useArchives that exist only in a system scheduled for shutdown

Contracts: which agreements limit use of the records?#

Contract diligence finds the clauses that limit how records can be used, shared or transferred, and those clauses sit in more places than a standard material contracts list. Customer agreements and data processing addendums are the obvious start, but vendor terms of service, reseller agreements and NDAs signed during sales cycles can carry restrictions too.

Look for specific language rather than general confidentiality. The clauses that matter most are use restrictions tied to providing the service, bans on aggregation or benchmarking, deletion duties at contract end, anti-assignment terms triggered by a change of control, and newer clauses that prohibit training AI on customer content.

  • Customer MSAs and order forms: permitted use of customer content, rights in aggregated or de-identified data, AI-training bans.
  • Data processing addendums: processor-only roles, return and deletion obligations, subprocessor limits.
  • Vendor and SaaS platform terms: who may export, and whether the vendor itself may train on the data.
  • NDAs and partner agreements: confidential information received from others that now sits in email and shared drives.
  • Employee and contractor agreements: confidentiality, invention assignment and notices about monitoring of workplace communications.

Privacy: what was collected and under which notices?#

Privacy diligence establishes what personal information the records contain, what the target told people when it collected it, and which consents or opt-outs apply now. The answer decides whether records can be prepared for a new use or must stay tied to their original purpose.

Ask for every version of the privacy notice in force across the period the records cover, not just the current one. An older notice may describe narrower uses, and records collected under it can be harder to reuse. Call recordings and chat transcripts deserve separate review, because state recording-consent and wiretap rules may apply.

Industry metadata standards point at the same evidence. The Data & Trust Alliance's Data Provenance Standards include metadata elements for consent documentation location, license to use and intended data use, which is a useful prompt for what a later licensee of the records will ask the company to show.

Privacy: what was collected and under which notices?
AreaWhat to verifyWhy it matters
NoticesHistoric and current privacy notices with effective datesDefines the purposes people were told about
ConsentsRecording disclosures, marketing consents, opt-out logsShows what people agreed to and what they refused
Sensitive dataHealth, financial, biometric or children's data in free textUsually excluded or sent to specialist review
IncidentsBreach log, regulator letters, complaintsSignals weak controls over the same records
RequestsDeletion and access request logsDeleted individuals must stay out of any reuse

Existing licenses: what has already been granted to others?#

Existing license diligence identifies every party that already holds rights to the target's records, because a prior grant can narrow or block what you do next. Prior data licenses, research collaborations, data-sharing pilots and vendor arrangements all count, whether or not anyone called them licenses at the time.

Exclusivity is the clause to find first. An exclusive grant by field, record type, industry or term can block a new license to a different licensee. Next, check whether any software vendor the target uses has been permitted to train on its content, through a contract or an admin setting, since the same records may already be inside someone else's model.

Then turn to the target's own AI work. If the target trained or tuned its product's AI features on customer content, confirm the contract terms and notices that allowed it. US regulators have in some cases required companies to delete models and algorithms built on improperly collected data, so a weak answer here can touch the product, not just the archive.

  • Signed data licenses, research agreements and data-sharing pilots, with scope, term, exclusivity and deletion duties.
  • Exclusivity or first-refusal rights by field, record type, industry or territory.
  • Vendor terms or admin settings that let a software provider use the target's content to train or improve its models.
  • The target's own AI features: which customer content trained them, and under which contract terms and notices.
  • Employee use of outside AI tools with company records, and any policy that governs it.
  • Payments received for data, how they were recorded, and whether each signer had authority.

How to turn findings into deal terms#

Each data rights finding should map to a deal response, so the diligence work changes the purchase agreement rather than sitting in a memo. Most findings fall into a small set of responses, and counsel chooses among them deal by deal.

Data and AI representations in purchase agreements work best when diligence has already defined the record families they cover. A representation that the target has the right to use all data in its business is far weaker than one tied to a schedule of named systems.

Plan for insurance early. Representations and warranties insurance typically excludes issues the buyer already knew about from diligence, so a known data problem is usually handled through a specific indemnity, an escrow, a price adjustment or a carve-out rather than left to the policy.

How to turn findings into deal terms
FindingTypical deal response
Records owned by clients or a former parentCarve out of the data thesis; specific representation on ownership
Customer contracts with AI-training bansExclude affected records; list the contracts in the disclosure schedules
Narrow historic privacy noticeLimit reuse to de-identified records; pre-closing review by privacy counsel
Undisclosed exclusive data licenseClosing condition to obtain a waiver, or a specific indemnity
Customer contracts with change-of-control or anti-assignment clausesCustomer consents as closing deliverables, or carve the affected records out
Vendor permitted to train on contentPre-closing settings change and written confirmation from the vendor
Archive in a system scheduled for shutdownCovenant to preserve and export records before closing
Records under a litigation holdPreserve as required; keep them out of the data thesis until counsel clears them

Illustrative: a buy-and-build platform reviews a regional 3PL#

Illustrative: a fictional lower-middle-market sponsor is adding a regional third-party logistics company to its distribution platform. The thesis includes licensing de-identified order exception records, which live in the 3PL's WMS and a separate ticketing tool, alongside the platform's own records.

Diligence finds three issues. The ticketing tool is billed to the founder personally. Two large shipper contracts prohibit using shipper data for anything other than providing services. And the WMS vendor's terms let it use customer data to improve its own products. The sponsor requires the account transfer before closing, removes the two shippers' records from the data thesis and asks counsel to assess the vendor clause. The remaining exception history enters the post-closing plan with its limits written down.

How SourceX uses diligence evidence after closing#

SourceX starts a post-acquisition data license from the same questions diligence asks, using the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. A clean diligence file shortens the Rights step because the ownership map, contract schedule and notice history already exist.

For each package that proceeds, the SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. An acquirer can treat that packet as a continuation of its diligence file, so whoever buys the company later sees the same record.

Frequently asked questions

Should data rights diligence start before or after the LOI?

Light screening belongs before the letter of intent, because it can change the thesis. Ask early for the system map, the customer contract template and the privacy notice history. Contract-by-contract review usually follows in confirmatory diligence, once the record families that matter to the deal are known.

Who should run data rights diligence on the buyer side?

Usually deal counsel paired with a privacy specialist, supported by the operating partner or an IT diligence provider who can confirm which systems exist and what can be exported. The operating partner keeps the review tied to the value thesis, so effort goes to record families that actually matter.

Does an asset purchase change the data rights analysis?

Often, yes. In an asset purchase, records and contracts move only if they are listed and assignable, and some privacy notices or customer agreements limit transfer of personal information to a new owner. In a stock purchase the entity stays the same, but change-of-control clauses can still apply. Counsel assesses the structure deal by deal.

What if the target has already licensed data for AI training?

Treat the existing license as a material contract. Review its scope, exclusivity, term, deletion duties and payment history, and confirm who signed it. A well-documented prior license can support the thesis by showing buyer interest; a poorly documented one can create exposure to resolve before closing.

Does data rights diligence matter if we never plan to license the data?

Yes. The same review tells you whether the target's own AI features were built on customer content it had the right to use, whether privacy notices support current processing, and whether a vendor already trains on the archive. Those answers affect product risk and the next exit, not only a licensing thesis.

Can a seller prepare for data rights diligence in advance?

Yes. A seller can build a record map, collect historic privacy notices, list contracts with data restrictions and document any prior data licenses. That preparation shortens diligence and lowers the chance that data findings turn into last-minute deal terms.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify