Rights and contracts
Do data rights transfer in an asset purchase?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Data rights transfer in an asset purchase only to the extent the purchase agreement lists the records as acquired assets and the seller could lawfully pass them on. Three checks decide it: whether the underlying contracts were assigned, whether the privacy notices allowed transfer in a sale, and whether required customer or vendor consents were obtained.
Key takeaways
- An asset buyer receives only the data assets the agreement names and the seller had the right to transfer.
- Records tied to a contract, such as customer data hosted under a SaaS agreement, follow that contract and its assignment clause.
- Personal information stays subject to the promises made when it was collected, even after closing.
- A stock purchase usually leaves records and contracts with the same legal entity, so the analysis differs.
- Licensing acquired records later depends on a documented chain of title from collection through closing.
How data moves in an asset purchase#
Data moves in an asset purchase the same way any other asset does: only if the purchase agreement lists it, and only to the extent the seller owned it or held a transferable right to it. Definitions such as books and records, business data, customer lists and intellectual property do the work, and the excluded assets schedule often takes some of it back.
Software acquirers buying a vertical SaaS business through an asset deal face a specific complication. Much of the most useful data, such as support tickets, product usage logs and the content customers entered, was held under customer agreements rather than owned outright. Those rights move only if the customer agreements move.
| Question | Asset purchase | Stock purchase | Merger |
|---|---|---|---|
| Who holds the records after closing? | The buyer entity, for listed assets | The same company, under new ownership | The surviving entity |
| Do customer contracts need assigning? | Yes, contract by contract | Usually no, the party is unchanged | Depends on structure and contract wording |
| Do anti-assignment clauses bite? | Yes, consents may be needed | Only if a change-of-control clause applies | Sometimes, courts differ |
| Do privacy promises carry over? | Yes, they follow the personal information | Yes, the same entity made them | Yes |
Check one: were the contracts and data assignable?#
Assignability is the first check because data held under a contract can only transfer with that contract. Customer agreements often prohibit assignment without consent, sometimes with an exception for a sale of substantially all of the business. Where the seller acted as a processor or service provider for customer data, the customer's rights in that data usually continue unchanged after the sale.
Vendor accounts are the second half of the question. Subscriptions to Zendesk, Jira, Salesforce or HubSpot may not transfer without the vendor's agreement, and history stored only in a vendor account is lost if the account closes before an export. Transition services agreements often cover the gap, but only for a limited period.
Check two: what did the privacy notices promise?#
Privacy notices decide what an acquirer may do with personal information, because the promises made at collection travel with the data. Most modern notices include language allowing transfer in a merger, acquisition or sale of assets. Older notices, or notices that promised never to share data, can limit both the transfer and later uses.
Several state privacy laws treat a transfer in a merger or acquisition differently from a sale of personal information, but they generally expect the acquirer to keep using the data consistently with the original notice or give fresh notice before a materially different use. Licensing records to an AI developer is likely to count as a new use, so check whether de-identification or updated notice is needed for the records in scope.
Check three: which consents were required and obtained?#
Consents are the third check, and the disclosure schedules show which ones the seller expected to need. Compare the list of contracts requiring consent with the consent letters actually delivered at closing. Contracts listed as not assigned, or assigned under a hold-in-trust arrangement, may carry data the buyer cannot treat as its own.
A general counsel reviewing an acquired company before any licensing should pull a standard set of closing documents. Most of them sit in the deal's closing binder, but the archived privacy notices and negotiated customer exceptions are often missing and worth requesting early.
- Asset purchase agreement, including the purchased and excluded asset definitions.
- Disclosure schedules listing contracts, consents and known data restrictions.
- Bill of sale, IP assignment agreement and assignment and assumption agreement.
- Consent letters from customers, vendors and any other counterparties.
- Transition services agreement covering system access and exports.
- Archived privacy notices and terms of service from each period of collection.
- Customer contract templates and any negotiated data-use or confidentiality exceptions.
Which record families rarely transfer cleanly?#
Some record families rarely transfer cleanly because they were never fully the seller's to begin with or because they carry obligations to people outside the deal. Flag them during integration, not when a license is on the table, so exports and permissions can be fixed while the seller's team is still reachable.
| Record family | Why the transfer is often incomplete | What to check |
|---|---|---|
| Content customers uploaded or entered | Owned by customers and licensed to the seller only to provide the service | Customer agreement data clauses and consents |
| Former employees' email and chat | Mixes business records with personal and sometimes privileged messages | Retention policy, employee notices and privilege review |
| Source code | May include open-source components and third-party code with their own licenses | Dependency inventory and contributor agreements |
| Data pulled through integrations | Governed by the API terms of the third-party platform | Integration and marketplace terms |
| Records of a carved-out division | Shared systems may hold data the seller kept | Excluded assets schedule and data separation steps |
What this means for licensing acquired records to AI developers#
Licensing acquired records requires the acquirer to show a chain of title: how each record was collected, under what terms, and how it passed to the current owner. An AI developer's diligence will ask for exactly that, and gaps usually shrink the licensable scope rather than ending the conversation.
The purchase price allocation is a useful starting point. Under ASC 805, acquired intangibles that arise from contractual or legal rights or are separable are recognized apart from goodwill, and the guidance's examples include databases and customer lists. If the deal team valued a database or customer list, the allocation report shows what the acquirer believed it bought, though it does not prove the right to license it.
Two further points come up often. First, the seller may have kept copies of the data for tax, legal or wind-down purposes, which matters if a buyer wants exclusivity. Second, the purchase agreement's data representations and their survival period determine whether the acquirer has any recourse if a restriction surfaces later.
Illustrative example: a software acquirer buys a field inspection product#
Illustrative: a fictional vertical software holding company buys the assets of a small business that sells inspection scheduling software to elevator contractors. The purchased assets include the code repository, Jira and Zendesk history and the HubSpot CRM. A year later the group considers licensing support tickets linked to engineering fixes.
The general counsel finds that the agreement listed business data and books and records as purchased assets, that most customer agreements allowed assignment in a sale of the business, and that a few enterprise customers required consent and declined. The old privacy notice covered transfer in a sale but said nothing about third-party licensing. The group licenses engineering records and de-identified tickets only from assigned customers, excludes the rest and files a chain-of-title memo with the package.
How SourceX approaches acquired records#
SourceX asks for the acquisition documents at the Rights step of the SourceX five-step transaction, because provenance for acquired records runs through the closing binder. Records whose transfer cannot be shown are carved out before preparation begins.
The SourceX Evidence Packet then records the provenance of each record family, including the acquisition, together with licensing rights, permitted use, the privacy record and release authorization from the current owner.
Frequently asked questions
Does a books and records definition include support tickets and CRM history?
Often, because such definitions tend to be broad, but read the exact wording and the excluded assets schedule. Some agreements exclude records the seller must keep, data held for customers or records in systems that were not transferred. When in doubt, the closing deliverables show what actually moved.
Can the seller keep a copy of the data after closing?
Sellers commonly keep copies for tax, legal and accounting purposes, and the agreement may allow it. A covenant limiting the seller's use of those copies protects the buyer, and it matters if a later data license promises exclusivity.
What if the seller only processed the data for its customers?
Data processed for customers generally remains the customers' data. The acquirer steps into the service relationship but usually gains no broader right to reuse that content, so licensing it would need customer permission or a contract term that already grants it.
Is a bankruptcy asset sale different?
Yes. Under 11 U.S.C. §363(b)(1), if the debtor's privacy policy prohibited transferring personal information to unaffiliated parties, the trustee generally may not sell it unless the sale is consistent with that policy or the court approves it after a consumer privacy ombudsman is appointed. In the 2015 RadioShack case, the FTC recommended that customer data go only to a buyer in substantially the same line of business that agreed to be bound by the original privacy policy. Keep the sale order and any ombudsman findings with your provenance file.
Do we need new consent to license acquired data for AI?
Sometimes. It depends on the customer contracts, the privacy notices in force at collection and whether the records will be de-identified. Counsel should assess this for the specific records and buyer rather than relying on the acquisition alone.
Sources
- Under 11 U.S.C. §363(b)(1), if a debtor disclosed a policy prohibiting transfer of personally identifiable information to unaffiliated persons, the trustee may not sell it unless the sale is consistent with the policy or the court approves it after appointment of a consumer privacy ombudsman and notice and a hearing. Source
- In 2015 the FTC recommended that RadioShack customer data be transferred only to a buyer in substantially the same line of business that agrees to be bound by RadioShack's privacy policy. Source
- Under ASC 805, an acquired intangible asset is recognized separately from goodwill if it arises from contractual or legal rights or is separable, and the examples list databases and customer lists. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.