Software companies
Does an aggregated data clause let a SaaS company license data to AI developers?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
An aggregated data clause rarely lets a SaaS company license customer data to AI developers. Most such clauses allow combined, de-identified statistics for running, improving or benchmarking the service, not record-level text shared with third parties. Check five words: aggregated, de-identified, derived, purpose and third parties; if any is narrow, treat the data as out of scope.
Key takeaways
- Aggregated usually means combined across customers into statistics, which is not the record-level text AI developers want.
- A contract's definition of de-identified does not replace how privacy laws that may apply define it.
- Purpose language such as improving the services rarely stretches to licensing to an outside developer.
- The DPA and the order-of-precedence clause can override a broad aggregated data clause in the main agreement.
- The company's own engineering and support records are usually a cleaner route than stretching the clause.
What does a typical aggregated data clause permit?#
A typical aggregated data clause permits the SaaS vendor to compile data from customer use into combined, de-identified form and use it to operate, improve and benchmark the service. Many clauses also say the vendor owns the resulting aggregated data and may keep using it after the agreement ends.
Clauses like this were mostly written for dashboards, industry benchmarks and product analytics. As interest in AI training data has grown, vendors increasingly look to these carve-outs as a possible route for AI use, which is exactly why they deserve a close read rather than an assumption.
The clause usually sits in a section about data rights or usage data, away from the confidentiality and DPA terms that limit it. Reading it in isolation is the most common mistake general counsel see in internal proposals.
Five words to check in an aggregated data clause#
Five words in an aggregated data clause decide most of what it permits. Read each in its defined form, because the definitions section often narrows the plain meaning considerably.
As a checklist, the clause supports an AI license only if every answer below is broad. One narrow answer is enough to take customer records out of scope.
- Aggregated covers the specific records, not just statistics about them.
- De-identified is defined at least as strictly as the privacy laws that may apply.
- Derived data includes the content a licensee wants, not only usage metrics.
- Purpose extends beyond the vendor's own service.
- Third-party disclosure or commercialization is expressly allowed.
| Word or phrase | What it usually permits | What to watch for |
|---|---|---|
| Aggregated | Data combined across customers or users into totals, averages or trends | Whether individual records, even without names, can count as aggregated at all |
| De-identified or anonymized | Data that cannot reasonably identify a customer or individual | Whether the definition matches privacy laws that may apply, and who certifies it |
| Derived from or generated by | Data the vendor creates from use of the service, such as metrics | Whether customer content itself, or only metadata about use, falls inside |
| Purpose | Operating, improving, securing or benchmarking the service | Any lawful purpose is broad; improving the services is not licensing |
| Third parties | Sharing or publishing results with others | Silence on sharing, or sharing only in aggregated reports |
Why does record-level text usually fall outside the clause?#
Record-level text usually falls outside an aggregated data clause because a de-identified support ticket, document or message is still an individual record, not an aggregate. Removing names changes who is identifiable; it does not combine the record with others.
AI developers usually want exactly these individual records: a ticket and its resolution, a document and its revisions, a request and the approval that followed. That mismatch is why aggregated data clauses, read carefully, rarely answer the licensing question for customer content.
Some proposals try to bridge the gap by pooling records from many customers and calling the pool aggregated. A pool of individual tickets is still a set of individual tickets: in most clauses the word describes the output of combining data, not the size of a collection. Test any such reading against the definition, not the label.
How do the DPA and privacy law interact with the clause?#
The data processing agreement often controls over the main agreement for personal data, and it usually limits processing to the customer's documented purposes. Check the order-of-precedence clause: if the DPA wins for personal data, a broad aggregated data clause in the main agreement may not reach any record that contains it.
Privacy laws such as GDPR and CCPA set their own standards for anonymized or de-identified data, often with conditions beyond removing names. A contract can promise de-identification, but whether the result falls outside a privacy law is assessed against that law, deal by deal, with counsel.
Confidentiality terms add a third layer. Customer business information, such as pricing, volumes or supplier lists, can stay confidential even when no person is identifiable.
What can an aggregated data clause support?#
An aggregated data clause can support genuine aggregates: benchmarks, distributions and trend data that describe many customers without exposing any one. Examples include resolution-time distributions by ticket category or feature adoption curves by industry, provided the purpose and third-party language allow sharing them.
Interest in such statistics from AI developers is narrower than interest in records, but they can inform evaluation design or market context. They also carry the lowest customer exposure, which makes them a reasonable add-on to a package built from company-owned records.
Build aggregates conservatively. Small groups can expose a single customer, so set minimum group sizes, suppress rare categories, and check whether a benchmark could reveal one large customer's figures. Record those choices in the privacy file alongside the clause reading.
Illustrative: a procurement software company reads its clause#
Illustrative: a fictional procurement software company assumes its master subscription agreement allows licensing because it grants the company ownership of aggregated data. Its general counsel reads the clause against the five words.
Aggregated is defined as data combined across customers so that no customer is identifiable. Purpose is limited to improving and marketing the service. The DPA, which controls for personal data, limits processing to providing the service. Purchase requisitions, supplier messages and approval comments are individual records, so they fall outside.
The company concludes that customer procurement records are out of scope, and notes that even its category-level spend benchmarks would need a broader purpose clause before they could be licensed. It proceeds instead with its own support escalation notes and engineering history. The general counsel files a short memo explaining the reading so the question does not resurface with each new inquiry.
How SourceX approaches aggregated data rights#
SourceX reviews aggregated data clauses in the Rights step of the SourceX five-step transaction, together with the DPA, confidentiality terms and any order-of-precedence language. Where a clause does not clearly cover both the records and the use, the default is to exclude them.
The SourceX Evidence Packet records the licensing rights relied on, including the clause text and how it was read, so a licensee can see why each record family is in scope and the supplier can see what it approved.
Frequently asked questions
Can we amend the clause to cover AI licensing going forward?
Possibly. An amended clause would normally reach only data collected after customers accept it, so past records stay under the old wording. Altering data use terms without clear notice also invites customer complaints and regulator scrutiny, so plan any amendment, and how it is announced, with counsel.
Does usage data fall under the aggregated data clause?
Often it is defined separately, as data about how customers use the service rather than what they put into it. Usage data can be broader in scope, but it may still include personal data and still sit under the DPA. Read both definitions together before relying on either.
Does owning aggregated data mean we can sell it?
Ownership language helps, but other clauses can still restrict use, including confidentiality, purpose limits and the DPA. Owning a compiled dataset does not override obligations attached to the inputs it was built from.
What if customers signed different versions of our terms?
Then the answer differs by customer. Map which version each customer signed, and treat the narrowest version as the baseline unless records can be reliably separated by contract version. Enterprise customers with negotiated paper often have the narrowest language.
Who should read the clause before anyone talks to a licensee?
Counsel who knows the full agreement set, including the DPA and any negotiated enterprise terms. A product or sales leader reading only the data rights section will usually overestimate what it allows.
Does a no AI training clause in some contracts change the analysis?
Yes, for those customers. An express prohibition overrides any broader reading of the aggregated data clause in that agreement, and many order-of-precedence clauses give negotiated terms priority over standard ones. Flag those customers early and exclude their data from every scope, including aggregates if the prohibition reaches them.
Related resources
- IndustryLegal data
- QuestionDo AI labs buy legal documents?
- InsightDo you need a DPA when licensing de-identified data?
- InsightIs an AI data buyer a controller, a processor or a third party?
- InsightData licensing partner vs law firm vs doing it yourself
- SolutionData partnerships between businesses and AI developers
See if your company qualifies
A short company assessment. No data uploads are needed.