Skip to content

Leadership and readiness

Documents to gather before a data licensing review

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Before a data licensing review, gather four groups of documents: corporate authority records, customer and partner contracts, vendor and acquisition agreements, and employee and privacy documents. Together they show who owns the records, what restricts their use, what people were told and who can approve a license. Index them internally and share nothing until scope is agreed.

Key takeaways

  • Contracts decide rights, privacy notices show what people were told, and authority records decide who can sign.
  • Collect template versions by effective date, because the terms behind older records may differ from today's.
  • Acquired companies bring their own contracts, notices and system terms that still govern their records.
  • An index listing owner, location and date range for each document saves more time than the documents alone.
  • No documents need to be shared during an initial fit check.

What the review needs to answer#

A data licensing review needs to answer four questions: who owns the records, what restricts their use, what the people in them were told, and who can approve a license. The documents below are the evidence for each answer, grouped by where they usually live.

Gathering them early is one of the simplest ways to shorten the review. Counsel can only clear a record family as fast as the contracts and notices behind it can be found, and a missing document usually means a record family waits rather than moves.

Corporate authority documents#

Corporate authority documents show which entity holds the records and who may bind it. They matter most in groups with several entities, past acquisitions or investors with consent rights.

Groups with a holding company should note which entity signs customer contracts and which one pays for the systems. The two are often different, and the entity that holds the customer relationship may be the one whose approval the license needs.

Corporate authority documents
DocumentWhy it mattersWhere to find it
Entity chart and formation documentsShows which entity owns each system and its recordsCorporate secretary or outside counsel
Bylaws or operating agreementSets who can sign agreements and what needs board approvalMinute book
Investor agreements and consentsInvestors may hold consent rights over licenses of intellectual propertyCFO and financing files
Credit agreementCovenants can restrict licensing or transfers of assetsCFO or lender portal
Board resolutions on data or AIRecords earlier decisions and any limits already setBoard materials

Customer and partner contracts#

Customer and partner contracts are where most licensing restrictions live. Confidentiality, data use, deletion and ownership terms decide which records can be licensed and which must be carved out.

Start with every version of the standard customer terms, dated so you know which version applied to records from which period, then add negotiated agreements for the largest or most sensitive customers. Data processing agreements, statements of work and NDAs belong in the same folder, because they often override the main agreement on exactly the points that matter.

  • Standard terms of service and master agreements, every version with its effective date.
  • Negotiated agreements with material deviations from the template.
  • Data processing agreements and security addenda.
  • Statements of work and engagement letters that assign deliverables.
  • NDAs from pilots, partnerships and deals that never closed.
  • Reseller, referral and channel partner agreements.
  • Settlement agreements with customers that carry confidentiality terms.

Vendor, system and acquisition documents#

Vendor and acquisition documents show whether the systems holding your records, and the companies you bought, came with conditions attached. They are easy to overlook because they sit with IT, procurement or deal files rather than legal, and they explain many surprises late in a review.

Vendor, system and acquisition documents
DocumentWhy it mattersWhere to find it
Subscription terms for each system of recordExport rights, data use terms and what happens at cancellationIT, procurement or the vendor admin console
Outsourcing and managed service agreementsThird parties may have created or still hold some recordsProcurement or the COO
Purchase agreements for acquired companiesConfirms which records and contracts transferred, and any limitsDeal counsel or the CFO
Transition services agreementsMay govern records still held by a former ownerDeal files
Third-party content and open source licensesEmbedded material may carry its own termsEngineering or legal
Cyber and professional liability insurance policiesShows how a data-related claim would be handled and what notice the insurer expectsCFO or insurance broker

Employee and privacy documents#

Employee and privacy documents show what employees, customers and other individuals were told about how their information would be used. Collect historical versions, because a notice that changed recently does not describe what people were told when older records were created.

Former employees matter too. Messages in Slack, email and project tools were written under the policies in force at the time, so keep the handbook and acceptable-use versions that covered each period, not only the current ones.

  • Public privacy notices, every version with its effective date.
  • Employee handbook, acceptable-use policy and monitoring policy.
  • Employee confidentiality and invention assignment agreements.
  • Employee privacy notices, where the company issues them.
  • Records retention schedule and any deletion logs.
  • Data maps or records of processing, if they exist.
  • Consent records and opt-out lists.
  • Incident and breach records involving the systems in scope.
  • Legal hold notices and the matters they cover.

How to organize the document set#

An indexed document set beats a shared drive full of files. For each document, record its title, version or effective date, the entity it binds, the record families it affects, its owner and where the original is kept.

Keep the index separate from the documents and keep the documents inside the company. Much of a first review can run from the index and from counsel reading files internally; outside parties see specific documents later, under confidentiality terms, and only where they need to.

Mark gaps openly. A row that says a privacy notice from a given period could not be found is more useful than silence, because counsel can plan around a known gap but not around an unknown one.

Illustrative: a structural engineering firm builds its set#

Illustrative: a fictional structural engineering firm is considering licensing RFI responses, design review comments and internal QA checklists from Deltek Vantagepoint, Bluebeam sessions and Procore projects. The managing principal asks the operations director and outside counsel to assemble the document set before any export is discussed.

The set shows that the firm's standard client agreements give clients ownership of drawings and specifications but leave the firm its internal review notes and methods. A few public-sector clients' contracts restrict reuse entirely, so those projects are carved out. A smaller firm acquired some years earlier used different terms, which counsel reviews separately. The rights review starts with every answer already on file, and the principal approves a scope built only on documented rights.

How SourceX uses the documents#

Nothing needs to be shared during the SourceX initial assessment, which runs on metadata only. Once a supplier decides to proceed, the documents support the Rights step of the SourceX five-step transaction and become the basis of the SourceX Evidence Packet: provenance, licensing rights, permitted use, privacy record and release authorization.

Documents that are hard to find usually signal a record family that will take longer to clear, which is worth knowing before scope is set rather than after.

Frequently asked questions

Do we need to collect every customer contract?

Usually not. Start with every version of the standard terms and the negotiated agreements with material deviations, especially for large customers and those in sensitive industries. Counsel can then decide whether the remaining contracts need individual review or are covered by the template analysis.

What if we cannot find older privacy notices?

Check the website's content management history, archived copies of the site, old marketing files and the legal team's email. If a version cannot be found, record the gap in the index. Counsel may treat records from that period more conservatively.

Who should own gathering the documents?

One coordinator, often in legal or operations, with named owners for each group: the CFO for financing documents, IT for system terms and HR for employee materials. Without a coordinator, the review waits on the slowest unassigned item, and owners rarely volunteer documents nobody asked for.

How far back do the documents need to go?

As far back as the records you might license. If the oldest tickets or job records you would include come from a particular year, the contracts, notices and policies in force that year are the ones that govern them.

Should we send these documents to a prospective buyer?

Not at the start. Buyers rely on the supplier's representations and the evidence prepared for the license, not on raw contract files. Specific documents may be shared later under confidentiality terms if a buyer's diligence genuinely needs them, and counsel should decide what leaves the company.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify