Skip to content

Private equity and portfolios

Group data licensing policy template for holding companies

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A group data licensing policy template for a holding company sets the rules every operating company follows before licensing records outside the group: scope, approval thresholds, prohibited data, privacy preparation and recordkeeping. The most useful rule is to escalate by risk feature rather than size, sending exclusivity, cross-company bundles and recently acquired records to the holdco.

Key takeaways

  • A group policy allocates licensing authority between the holdco and each operating company; it does not replace each company's own process.
  • Approval thresholds work best when they escalate on deal features such as exclusivity, bundling and acquisition status, not on size alone.
  • The prohibited data list belongs at group level so acquired companies get an answer from the day they join.
  • Samples, pilots and data traded for vendor credits are licenses in substance and belong inside the policy's scope.
  • One group license register, fed by each company, answers later questions from lenders and acquirers in one place.

What does a group data licensing policy decide?#

A group data licensing policy decides which licensing calls each operating company makes on its own and which ones the holding company reserves. A single-company policy answers when and how records may be licensed; a group policy adds a second layer that allocates authority between the holdco and its subsidiaries.

Many software holding groups run decentralized business units, so the policy should be short and set floors rather than procedures. Each operating company can keep its own intake, counsel and signer, as long as it applies the group's prohibited data list, preparation standard and escalation triggers.

Write the policy after the first one or two fit checks, not before. Early requests show which questions actually arise: whether a unit can sign alone, what happens to records from a company the group just acquired, and who answers when a buyer wants support histories from several products at once.

The template, section by section#

The template below has ten sections, and the third column shows where authority usually sits in a decentralized group. Adjust that column to match how much autonomy your business units already have over contracts, pricing and customer terms.

Keep each section to a few sentences in the policy itself. Detail such as intake forms, review checklists and register fields can live in attached schedules that holdco counsel updates without re-adopting the whole policy.

The template, section by section
Policy sectionWhat it statesUsually set by
Purpose and scopeWhich entities and which outbound transactions the policy coversHoldco
DefinitionsRecords, customer content, samples, license, counterparty and supplier entityHoldco
Roles and authorityPolicy owner, each company's authorized signer and holdco reviewersHoldco
Approval thresholdsWhich deal features escalate a license to the holdcoHoldco
Prohibited dataRecords no group company may license, whatever the termsHoldco
Privacy preparationThe minimum preparation before any record or sample leavesHoldco sets the floor; each company runs it
Rights reviewCustomer contracts, product terms, vendor terms and notices checked per packageOperating company, with holdco counsel on escalations
Counterparty rulesCompetitors, group customers and related parties that need reviewHoldco
RecordkeepingRequired entries in the group license registerHoldco template; each company enters
Exceptions and reviewHow exceptions are granted and when the policy is revisitedHoldco

Scope: which entities, records and deals the policy covers#

The scope clause should name every entity the policy binds and say how a newly acquired company comes under it. A workable rule is that an acquired company's people are bound from closing, but its records stay out of licensing scope until its rights review is complete.

Define the covered transactions broadly. Signed licenses are the obvious case, but samples sent to a prospective buyer, pilot exports, records shared with an AI vendor in exchange for credits or discounts, and research collaborations all move records outside the group and belong in scope.

Then say what the policy does not cover, so it does not collide with other documents. Customer content processed inside a hosted product is governed by that product's terms. Staff use of AI tools belongs in an acceptable use policy, and records shared with service providers for the group's own operations follow vendor management rules.

Sample approval thresholds (illustrative)#

Approval thresholds work best when they escalate on risk features rather than on deal size alone. The table is an illustrative sample for a decentralized software holdco; a group that also wants a value threshold should set its own figure with the group CFO.

Notice matters as much as approval. Even routine licenses should reach holdco counsel before signature, so the group can spot two units negotiating with the same counterparty on inconsistent terms or granting overlapping rights.

Sample approval thresholds (illustrative)
Deal featureWho approvesWhy it escalates
Non-exclusive license of company-owned operational records with standard preparationOperating company CEO and signer, with notice to holdco counselRoutine risk the unit can judge
Any exclusivity, including field-limited or time-limited exclusivityHoldco general counsel and group CFOCan constrain other units and surfaces in exit diligence
Records from a company still inside its post-acquisition rights reviewHoldco general counselLegacy contracts and notices are not yet mapped
A package combining records from more than one operating companyHoldco, with a separate schedule signed by each supplier entityEach entity has its own rights and its own signer
Counterparty is a group customer, a competitor or a related partyHoldco general counselCommercial and conflict risk across units
License needs lender, investor or board consentGroup CFO and holdco general counselConsents sit above the operating company
Request touches customer content in a hosted productNot approvable without the customer's written permissionCustomer content is not the group's to license

Prohibited data: the group-wide list#

The prohibited data list names records no group company may license, regardless of counterparty, terms or preparation. Holding it at group level stops each unit from relitigating the same questions and gives acquired companies a clear answer immediately.

  • Customer content stored in or processed by a group product, unless the customer has given written permission for that specific use.
  • Third-party data received under a license that bars redistribution, such as purchased data feeds or partner catalogs.
  • Credentials, API keys, encryption keys and security configurations, wherever they appear in tickets, repositories or chat.
  • Privileged communications with counsel and any records under a legal hold.
  • Sensitive personal data, including health details, financial account numbers, government identifiers, and candidate or personnel files.
  • Export-controlled technical data and customer-owned designs or deliverables.
  • Records of a company in an active sale process, unless deal counsel has signed off.

Privacy preparation and the group license register#

The privacy preparation section sets a floor every company must meet before any record leaves, samples included: personal and confidential details removed, automated detection followed by human review, and a written record of the methods used and what was excluded. Units may go further; none may go lower.

The recordkeeping section makes the holdco the keeper of one license register for the whole group. Published standards help define its fields. The Data & Trust Alliance's Data Provenance Standards group dataset metadata into Source, Provenance and Use, and the Use group includes confidentiality classification, consent documentation location, privacy-enhancing technologies applied and license to use.

A register held at group level lets counsel answer an acquirer's or lender's question from one table instead of searching each unit's shared drives. Require each company to enter at least the following before release.

  • Supplier entity and authorized signer.
  • Counterparty, permitted use and any exclusivity.
  • Record families, systems of origin and date ranges included.
  • Preparation methods applied and the named reviewer.
  • Consents obtained and when they were given.
  • Term, renewal, deletion or return obligations, and where the signed contract is stored.

Illustrative: a vertical software holdco adopts the policy#

Illustrative: a fictional holding company owns eight vertical software businesses, including products for marina operators, pest control routing and commercial printers' estimating. Its general counsel drafts the group policy after the marina unit receives an inquiry about its Zendesk support history and the Jira issues linked to it.

Under the policy, the marina unit's CEO approves a non-exclusive license of prepared support and engineering records, with notice to holdco counsel. Customer content stored in the marina product stays out entirely; only the unit's own ticket conversations and fix histories are in scope.

Later, a second request asks for support records from three units in one package, and the thresholds send it to the holdco. Counsel approves two units under separate schedules and holds back the pest control business, acquired recently and still inside its rights review, until its legacy customer terms are mapped.

How SourceX works inside a group policy#

SourceX runs each package as a separate transaction for the supplier entity, which fits a policy that keeps authority with operating companies. The SourceX five-step transaction maps onto the template: Supply to scope, Rights to the rights review and prohibited data list, Preparation to the privacy floor, Approval to the thresholds and signer, and Delivery to the register.

Each release produces a SourceX Evidence Packet covering provenance, licensing rights, permitted use, the privacy record and release authorization. Those fields can feed the group license register directly, so holdco counsel sees the same record the operating company approved.

Frequently asked questions

Should each operating company formally adopt the group policy?

Usually yes, or at least its authorized officers should acknowledge it. The operating company is the supplier and signs each license, so the policy binds it most clearly when adopted through that entity's own governance. Counsel can advise on the cleanest route, especially where minority shareholders or founders still hold equity.

Does the group policy replace each company's own licensing policy?

No. The group policy sets the floor. An operating company can keep a more detailed policy of its own, with its own intake form and reviewers, as long as nothing in it is looser than the group rules on prohibited data, preparation and escalation.

How should the policy treat AI vendors that offer credits for data?

As a license. Any arrangement where records leave the group in exchange for credits, discounts, equity or free features should go through the same scope, rights, preparation and approval steps as a cash license, and it should be entered in the register.

Who should own the group policy?

Holdco general counsel usually owns it, with the group CFO as co-owner for consents, revenue and reporting. A named owner matters most when a newly acquired company joins, because someone has to decide when its records come into licensing scope.

Can a group policy override a customer contract?

No. Customer contracts and product terms that restrict use of records control for that customer, whatever the group policy allows. The policy should require the rights review to check those terms and should never be read as permission to license what a contract forbids.

Sources

  • The Data & Trust Alliance's Data Provenance Standards define dataset metadata in three groups, Source, Provenance and Use; the Use group includes confidentiality classification, consent documentation location, privacy-enhancing technologies applied and license to use. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify