Rights and contracts
Data sharing agreement vs data license agreement: which do you need?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A data sharing agreement governs records two parties exchange for a shared purpose, usually without payment, while a data license agreement grants a paying licensee defined rights to use data the licensor keeps owning. If an AI developer will pay to train or evaluate models on your records, use a data license agreement with an explicit training scope.
Key takeaways
- Choose the agreement by purpose: sharing serves a joint or regulated purpose, licensing serves another party's paid use.
- A data license keeps ownership with the licensor and spells out exactly what the licensee may do.
- Sharing templates rarely address model training, trained models, deletion after training or exclusivity.
- A data processing agreement is a different tool again: it governs a vendor handling personal data on your instructions.
- The title of the document matters less than its terms, so read what the grant actually allows.
How do the two agreements differ?#
A data sharing agreement and a data license agreement differ mainly in purpose and in who benefits. A sharing agreement sets rules for an exchange that serves a common goal, such as a joint project or a reporting flow between affiliates. A license grants one party the right to use another party's data for its own purposes, usually for a fee.
The difference shows up in nearly every major term, from payment to what happens when the relationship ends.
| Dimension | Data sharing agreement | Data license agreement |
|---|---|---|
| Purpose | A defined shared purpose, often mutual | The licensee's own use within a granted scope |
| Payment | Often none, or cost recovery | License fees, milestones or revenue share |
| Rights granted | Access and use limited to the shared purpose | A defined grant: which uses, which models, which entities |
| Ownership | Each party keeps what it contributes | Licensor keeps ownership; licensee holds a license |
| Core obligations | Security, confidentiality and purpose limits on both sides | Permitted use, prohibited uses, deletion, verification, confidentiality |
| Ending | Return or destroy the shared data | Delete copies and settle what happens to anything built with the data |
| Typical parties | Partners, affiliates, research collaborators | A data supplier and an AI developer or other commercial user |
Where data use, transfer and processing agreements fit#
Data use, data transfer and data processing agreements are related documents with narrower jobs. Lawyers sometimes reach for whichever template is closest to hand, which is how an AI licensing deal ends up on a research-style form.
An AI developer that trains on licensed records decides its own purposes, so it is generally not acting as your processor. Whether a processing agreement is still needed depends on whether any personal information remains after preparation, which counsel assesses for each package.
| Agreement | Typical setting | What it mainly controls |
|---|---|---|
| Data use agreement | Research access to a dataset held by an institution | Who may use the data, for which study, under which safeguards |
| Data transfer agreement | Moving a dataset between organizations or countries | Custody, transfer conditions and onward transfers |
| Data processing agreement | A vendor handles personal data on your behalf | Processing on instructions, security, subprocessors, help with rights requests |
| Data sharing agreement | Ongoing exchange for a common purpose | Mutual purpose limits and safeguards |
| Data license agreement | Paid use of data by another party for its own purposes | Grant of rights, fees, restrictions, deletion and liability |
Why a sharing template falls short for AI training#
A sharing template falls short for AI training because it was written for exchanges where both sides use data for an agreed purpose and then stop. Model development raises questions those templates never anticipated, and silence on them usually favors the party holding the data afterward.
- No grant language for pretraining, fine-tuning or evaluation, so the scope of use is left to interpretation.
- Silence on trained models, including whether a model must be deleted or may be kept after the term.
- Return-or-destroy clauses that ignore backups, derived datasets and training copies.
- Mutual obligations that assume each side shares data, which blurs who the licensor is.
- No exclusivity, fee, payment timing or verification terms.
- No ban on re-identifying individuals or reconstructing confidential records from outputs.
Clauses an AI data license agreement needs, from the supplier side#
An AI data license agreement needs clauses that state, in writing, what the licensee may build and what happens to the data afterward. The table reads like an annotated term sheet: each clause, the question it settles and a reasonable opening position for the company supplying the records.
These are starting points, not fixed answers. Each clause is negotiated deal by deal, and the right position depends on what the records contain and how sensitive they are.
| Clause | Question it settles | Supplier-side opening position |
|---|---|---|
| Grant and training scope | Pretraining, fine-tuning, evaluation or all three, and for which models | Name the permitted activities and the licensee's own models; anything not named is excluded |
| Licensee entities | Which legal entities and contractors may touch the data | Named licensee and listed affiliates; contractors only under written flow-down; no sublicensing |
| Trained models and outputs | Who owns trained models and what happens to outputs that reproduce records | Licensee owns the models it trains; outputs that reproduce records or confidential details are restricted |
| Prohibited uses | Which uses are off limits whatever the grant says | A short enumerated list tied to the risks in the records |
| Retention and deletion | When copies are deleted and how deletion is confirmed | Delete training copies and derived datasets at term end with a written certificate; state how models are treated |
| Verification | How the supplier checks compliance | Periodic officer attestation, with audit only for cause |
| Exclusivity | Whether the supplier can license the same records to others | Non-exclusive by default; any exclusivity narrow by field and period and priced separately |
| Fees and payment | Amounts, structure and payment triggers | Fixed fees, milestones or revenue share, with payment tied to delivery or acceptance rather than model results |
| Warranties, caps and indemnities | What each side promises and up to what limit | Warrant authority, conformity and documented preparation; qualify rights warranties by knowledge; cap liability |
When a data sharing agreement is the right tool#
A data sharing agreement is the right tool when no one is paying for use and both parties serve the same purpose. Examples include sending service records to a franchisor under a reporting obligation, exchanging quality data with a key supplier to fix a recurring defect, or giving an affiliate access to a shared support history.
Early evaluation by a prospective AI buyer is a middle case. Small samples shared before a deal are usually covered by a nondisclosure agreement plus a short evaluation license that limits use to assessing fit and requires deletion if no deal follows. A sharing template is rarely the right form for that step either.
Illustrative: a software company converts a buyer's draft#
Illustrative: a fictional vertical software company that sells dispatch software to towing operators receives a first draft from a prospective AI buyer titled Mutual Data Sharing Agreement. The records in scope are Intercom conversations linked to Linear issues and changelog entries.
The general counsel notices that the draft lets the recipient use shared data for any purpose related to its business, imposes identical duties on both sides and requires return of data only on request. Nothing addresses training, trained models or verification.
Counsel responds with a license structure: a grant limited to training and evaluating the buyer's own models, a ban on re-identification and redistribution, deletion of training copies at term end with a written certificate, and fees tied to delivery. The company keeps its original sharing template for a separate integration project with a reseller.
How SourceX structures the paperwork#
SourceX treats every transaction as a license, not a sale: the supplier keeps ownership and the buyer receives defined rights. In the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery), the Rights step establishes which uses the supplier is able to grant, and the Approval step is where the supplier signs off on the permitted use before the contract is executed.
The SourceX Evidence Packet then carries that permitted use next to the package's provenance, licensing rights, privacy record and release authorization, so the contract and the documentation describe the same scope. SourceX's own rights in a deidentified dataset are set out in the signed supplier agreement.
Frequently asked questions
Can one agreement cover both sharing and licensing?
It can, but it rarely helps. Combining a mutual exchange with a paid license blurs who the licensor is, which duties run in which direction and which data the fees cover. Separate documents, or a license with a clearly separated schedule for any mutual exchange, are easier to negotiate and to check later.
Is a data license the same as selling data?
No. Under a license the company keeps ownership of its records and grants defined rights for a defined term. A sale transfers ownership. People often search for selling data, but AI training arrangements are commonly structured as licenses with use limits and deletion terms.
Do we need an NDA before negotiating a data license?
Usually, if samples, schema descriptions or commercial terms will be exchanged. The NDA protects the discussion; the license governs the data once a deal is signed. Metadata-only conversations, such as describing systems and years of history, can often happen before an NDA is in place.
Who usually drafts the first version?
AI buyers often send their own paper, which tends to favor broad use rights and strong supplier warranties. A supplier can respond with its own outline or term sheet to set the structure first. Whichever draft is used, review the grant, deletion and warranty clauses closely.
Does the title of the agreement matter legally?
Courts and counterparties generally look at what the terms say, not at the title. A document labeled as a data sharing agreement that grants broad use rights for a fee works as a license. The title still shapes expectations during negotiation, so an accurate label helps.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.