Skip to content

AI data market

Data rights in M&A due diligence: what buyers now check because of AI

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

In M&A due diligence, buyers now check where a target's data came from, what rights it holds to use and license it, which AI tools have touched customer data, and whether it has already licensed records or trained models on them. The working rule: every data use should trace to a contract, notice or license the target can produce.

Key takeaways

  • Diligence requests now cover inbound data sources, outbound data licenses and internal AI use, not only privacy and security.
  • Customer contracts decide whether a target's use of customer data for AI features or licensing was permitted.
  • Outbound licenses are reviewed for exclusivity, term, permitted use, change of control and deletion.
  • Sellers who can produce a data inventory and a rights map answer most requests before they are asked.
  • Unresolved data issues tend to become specific indemnities, escrows or closing conditions.

What do acquirers check about data rights now?#

Acquirers now check data rights in three directions: data coming into the target, data the target uses internally, including with AI tools, and data going out under licenses or partnerships. Privacy and security used to dominate this workstream; AI has added questions about training, model use and licensing.

Operating partners and general counsel see the pattern from both sides. As buyers, they want to know the target can keep doing what it does with data after closing. As sellers, they need to show it with documents rather than assurances.

The questions arrive earlier than they used to. Some buyers raise data and AI topics in the first management meeting, because the answers can change how they view the target's product roadmap, its customer relationships and the work needed after closing.

What is on the core data rights diligence checklist?#

The core data rights checklist covers nine areas that now commonly appear in the data and AI sections of diligence request lists. Not every item applies to every target; a field service company and a vertical SaaS platform will weight them differently.

Answering these items is easier when one person owns the response and every answer points to a document. Verbal assurances in a management meeting do not survive the confirmatory phase.

What is on the core data rights diligence checklist?
AreaWhat buyers requestRed flag
Data inventorySystems, record families, owners and date rangesNo one can describe where key records live
Inbound sourcesOrigin and terms of purchased, scraped or partner-supplied dataScraped or third-party data with no license on file
Customer contractsData use, aggregated data and confidentiality clauses by customer tierAI features or licensing the contracts do not permit
Privacy noticesCurrent and past notices mapped to each data useUses that began after the notice was last updated
Internal AI useAI vendors that process customer data, and their termsCustomer data sent to tools that may train on it
Outbound data licensesEvery license, pilot and design partnership involving recordsPerpetual or exclusive grants, or no deletion terms
IP and authorshipEmployee and contractor IP assignments; open-source policyContractors who created code or content without assignment
Retention and deletionRetention schedule and evidence that it is followedArchives kept indefinitely, or purges just before the process
Incidents and requestsBreach history and handling of deletion requestsDeletion requests not honored in archives or licensed copies

How outbound data licenses are reviewed#

Outbound data licenses are reviewed like any material contract, with extra attention to what the buyer can do with the records after closing. A clean, non-exclusive license with a fixed term reads as revenue; a vague one reads as risk.

  • Exclusivity: whether any field, record family or buyer category is locked up, and for how long.
  • Permitted use: training, evaluation or both, and whether redistribution is barred.
  • Term, renewal and termination rights, including what happens on a change of control.
  • Assignment: whether the license can move with the business without the licensee's consent.
  • Deletion: what the licensee must delete at the end and whether it certifies deletion.
  • Warranties and indemnities the target gave about rights and privacy, and their caps.
  • Revenue recognition: how license fees were recognized and over what period, which the buyer's accountants will test.

Provenance records that answer questions early#

Provenance records answer diligence questions early because they show where each dataset came from and what it may be used for. They matter most for any dataset the target licensed out or used to train its own models.

Published standards offer a ready-made structure. The Data & Trust Alliance's Data Provenance Standards sort dataset metadata into Source, Provenance and Use groups, and the Use group covers points such as confidentiality classification, where consent documentation is kept, license to use and intended data use. A target need not adopt the standard formally; records organized along those lines simply answer diligence requests faster.

In practice, a short datasheet per dataset is enough: what it contains, which systems and years it came from, which contracts and notices govern it, what was removed during preparation, and who approved its use or release. Keep each datasheet next to the related license, so counsel can read them together.

AI representations and warranties buyers ask for#

AI representations and warranties extend the usual data and IP reps to cover training and model use. Wording is negotiated deal by deal, but the topics are becoming familiar to deal counsel, and sellers can prepare the support for each in advance.

AI representations and warranties buyers ask for
Rep topicWhat it coversSeller preparation
Training data rightsThe target had rights to all data used to train its modelsList of training datasets with sources and terms
Customer data useCustomer data was used only as contracts and notices allowRights map by customer group and notice version
Outbound licensingAll data licenses are disclosed and in good standingComplete license schedule with delivery and deletion records
AI tool useThird-party AI tools were used under terms that protect confidential dataVendor list with data-use settings and agreements
Compliance with AI and privacy lawsNo known violations or pending claimsCounsel's review of the laws that may apply, by jurisdiction

What should sellers put in the data rights folder of the data room?#

Sellers should put the documents behind every data answer into one data rights folder, so buyer's counsel can test claims without a round of follow-up requests. Building it before the process starts also shows the seller where its own gaps are.

  • Data inventory: systems, record families, owners, date ranges and export routes.
  • Customer contract matrix: data use, aggregated data and confidentiality clauses by customer tier and paper version.
  • Privacy notice archive: each version with its effective dates.
  • AI vendor register: tools that touch customer or employee data, their terms and their data-use settings.
  • Outbound license schedule: every license, pilot and design partnership, with delivery logs and deletion certificates.
  • IP assignment register: employee and contractor agreements, with gaps flagged.
  • Request and incident log: deletion requests, how they reached archives and licensed copies, and any breaches.

Illustrative: a platform acquisition finds a loose design partnership#

Illustrative: a fictional buy-and-build platform is acquiring a vertical SaaS company that serves property managers. Diligence shows the target shared support transcripts and work-order histories with an AI startup under a design partner agreement. The agreement's feedback clause let the startup use anything shared to improve its products, with no deletion obligation.

Buyer's counsel asks for the agreement to be fixed before signing. The target negotiates an amendment requiring the startup to delete the records and confirm in writing that they were not used to train models offered to others, then updates its license schedule. The buyer accepts the amended position with a specific representation covering the matter rather than a broader indemnity.

How does SourceX support sellers in diligence?#

SourceX supports sellers by producing a SourceX Evidence Packet for every package licensed through the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. The packet records provenance, licensing rights, permitted use, the privacy record and release authorization, which lines up with what buyer's counsel asks in a data rights review.

For portfolio owners preparing companies for sale, the same discipline applies before any license is signed: inventory first, rights map second, and the supplier's approval recorded at each step.

Frequently asked questions

Does an existing data license reduce a target's value?

Not usually by itself. A documented, non-exclusive license with a fixed term and deletion terms can read as ordinary revenue. Exclusive, perpetual or poorly documented grants are what concern buyers, because they limit post-closing options and can hide privacy or rights problems.

Who should run the data rights workstream?

Buyer's counsel usually leads, with privacy counsel, IT diligence and the operating partner contributing. On the sell side, the general counsel or outside counsel coordinates answers, while the CTO or COO supplies the inventory. Agree early who owns the license schedule, because it touches legal, finance and engineering.

Do buyers ask to see the licensed data itself?

Rarely in full. Most diligence relies on contracts, inventories, schemas, delivery logs and deletion records. A buyer may ask for samples or a supervised demonstration for an important dataset, but sharing licensed records with a bidder can breach confidentiality terms, so check the license first.

Does representation and warranty insurance cover AI data issues?

Policies differ. Known issues found in diligence are commonly excluded, and some policies narrow coverage for data, privacy or AI matters. Ask the broker how the policy treats training data rights and outbound licenses, and expect issues found in diligence to be handled through specific deal terms instead.

What if the target trained its own product features on customer data?

Buyers will ask which data was used, under which contract terms and notices, and whether customers could opt out. If the contracts allowed only providing the service, the buyer may require remediation, such as retraining without certain data or obtaining consents, before or after closing. Counsel assesses this case by case.

Sources

  • The Data & Trust Alliance's Data Provenance Standards (version 1.0.0) define dataset metadata in three groups: Source, Provenance and Use. Source
  • The Use group of the Data Provenance Standards includes elements for confidentiality classification, consent documentation location, license to use and intended data use. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify