Software companies
How to answer 'do you sell customer data?' in a security questionnaire
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Answer 'do you sell customer data?' with a scoped statement, not a reflex. If you license nothing, say no and state your limits on use. If you license only company records, say no, then name the records and how customer details are removed. If opted-in customer data is included, disclose the program, its consent basis and what customers control.
Key takeaways
- Questionnaire answers are often relied on in contracts, so treat each one as a representation.
- Some state privacy laws give 'sell' a broader meaning than everyday speech, so answer the substance, not the word.
- Licensing de-identified company records is a different activity from selling customer data, and the answer should say so.
- A blanket 'never' answer can block future programs and becomes inaccurate the day one starts.
- Keep one approved answer library and update it before any licensing program goes live.
Why is the question harder than it looks?#
The question is harder than it looks because 'sell' means different things to a procurement analyst, a privacy lawyer and a sales rep. Several US state privacy laws define a sale of personal information more broadly than a cash transaction, and enterprise customers now ask separately about AI training, sharing and subprocessors.
The safest approach is to answer the question behind the question. Customers want to know whether their records, or anything derived from them, could end up with someone else for a purpose they did not agree to. If your DPA makes you a processor or service provider, it often already restricts selling or sharing customers' personal information and using it for your own purposes, so the answer should restate those limits rather than invent new ones.
Answers also carry weight. Questionnaires such as the SIG, the CAIQ and customers' own forms are often attached to contracts or relied on during procurement, so an inaccurate 'no' can become a misrepresentation claim. This is general information, not legal advice; have counsel approve the final wording.
Which versions of the question will you see?#
The same concern appears in several forms, and each deserves a consistent answer. Map them once so the sales team does not improvise under deadline.
Notice that only the first row uses the word sell. A customer who reads a careful answer there and a loose one further down will spot the gap.
| Question wording | What the customer wants to know | What your answer should cover |
|---|---|---|
| Do you sell customer data? | Whether our data is monetized without us | Your customer data definition and any licensing of other records |
| Do you share customer data with third parties? | Who else touches our data | Subprocessors, purposes and legal requests |
| Do you use customer data to train AI or ML models? | Whether our content shapes your models | In-product models, opt-in status, de-identification |
| Do third parties train models on our data? | Whether our data reaches outside model developers | Model provider terms and any licensing program |
| Do you use aggregated or de-identified data? | Whether derived data escapes our contract | What is derived, how, and for which purposes |
Model answers for three scenarios#
The model answers below are starting points to adapt to your own contract definitions. Use your agreement's defined terms, such as Customer Data, exactly as written so the answer matches the paper.
Scenario three needs the most care. Describe the opt-in mechanism accurately, including what withdrawal does and does not affect, since data already delivered may remain with the licensee under the license terms.
- Scenario one, no licensing: 'We do not sell, rent, license or otherwise make Customer Data available to third parties for their own purposes. Customer Data is used only to provide, secure and support the service as described in our agreement and DPA, and is processed by the subprocessors listed on our website.'
- Scenario two, company records only: 'We do not sell or license Customer Data. We license certain company-owned operational records, such as internal engineering history and support resolution notes, to AI developers. Before release, customer names, contact details, account identifiers and content customers submit to the service are removed, and records of customers whose agreements restrict such use are excluded.'
- Scenario three, opted-in customer data: 'Customer Data is included in data licensing only for customers who have opted in under a separate written agreement. For participating customers, personal information is removed before release, and a customer may withdraw from future deliveries by written notice. Customer Data of non-participating customers is not included.'
What records must back each answer?#
Each answer is only as good as the records behind it. Before publishing an answer, confirm that someone can produce the supporting documents if a customer asks a follow-up question.
Keep the answer library, trust center and privacy policy in step. A customer who reads one statement on your website and a different one in a questionnaire will ask why, and the inconsistency can stall a renewal.
| Scenario | Records to keep | Who signs off |
|---|---|---|
| No licensing | Data use policy, subprocessor list, DPA template | General counsel and security lead |
| Company records only | Scope note, de-identification record, list of excluded restricted customers | General counsel and CTO |
| Opted-in customer data | Signed opt-in agreements, withdrawal log, delivery records per customer | General counsel, CTO and CEO |
Mistakes that turn an answer into a liability#
Most problem answers were written quickly by someone trying to close a deal. Check your current library for the patterns below.
Fixing these is mostly a matter of ownership. One person approves every change to data use answers, each answer cites the policy or contract clause it relies on, and a dated version history shows what customers were told and when.
- Absolute language such as 'never' or 'under no circumstances' that rules out programs you may later run.
- Answering for the operating company while an affiliate holds and licenses records.
- Ignoring de-identified or derived data, which many customers now ask about directly.
- Letting sales edit approved answers for a single prospect without legal review.
- Leaving the library unchanged after a licensing program starts.
- Naming a licensee when the license terms make its identity confidential.
Illustrative: a contract management software company updates its library#
Illustrative: a fictional contract lifecycle software company decides to license its engineering history and de-identified support resolutions. Its answer library still says the company 'never shares any data with third parties,' a sentence a sales engineer added years earlier.
The general counsel replaces it with the scenario two answer, lists the exclusions and adds a short data use statement to the trust center. Customers whose enterprise riders prohibit secondary use are removed from the support data scope before preparation begins.
When an enterprise customer's security team asks a follow-up, counsel sends the scope note and the exclusion confirmation for that account. The renewal proceeds without a redline on data use.
How SourceX helps keep answers accurate#
SourceX helps by turning the scope of each license into a written record rather than a recollection. In the Rights step of the SourceX five-step transaction, record families are classified as company records or customer data, and anything the contracts do not clearly cover is carved out.
The SourceX Evidence Packet then documents permitted use, the privacy record and release authorization for each package, giving counsel a source document for questionnaire answers. Data is licensed, not sold outright, and the company keeps ownership of its records.
Frequently asked questions
Should our answer name the AI developer that licenses our records?
Usually not. License agreements often treat the licensee's identity as confidential, and customers rarely need the name to assess risk. Describe the category, such as AI model developers, the record types and the safeguards. If a customer insists, check the license's confidentiality terms with counsel before disclosing anything.
Does de-identified data still count as customer data?
It depends on your contract. Some agreements define customer data to include anything derived from it, while others carve out aggregated or de-identified data. Answer using your own definitions, and say plainly whether de-identified customer content is used for anything beyond the service.
What if a customer's contract prohibits AI training on its data?
Exclude that customer's records from any training or licensing scope and keep an exclusion list that preparation teams check. Your questionnaire answer can then say that restricted customers are excluded. Review new contract riders as they arrive, since the list will change with renewals.
Can we still answer no if employee-written records are licensed?
The question asks about customer data, so licensing employee-written company records does not by itself change a truthful no. Employee records raise their own notice and privacy questions, which should be handled separately. Avoid wording that implies no data of any kind is ever licensed.
How often should the answer library be reviewed?
Review it whenever the scope of data use changes, such as a new license, a new AI feature or a new subprocessor, and on the same cycle as your other security documentation. Assign one owner, usually in legal or security, so updates are not made piecemeal by sales.
Do we need to tell existing customers before a licensing program starts?
Not always, but it is often wise. If the program uses only de-identified company records, existing contracts may not require notice, though customers may prefer to hear it from you rather than discover it in a questionnaire. If any customer data is involved, notice or consent may be required by contract or law, so counsel should decide.
Related resources
- QuestionShould companies sell or license their data?
- QuestionData licensing vs data selling: what's the difference?
- InsightDo ABL lenders restrict a distributor from licensing its data?
- InsightWho has authority to license a dissolved company's data?
- InsightAcquiring a company that already licenses its data: what to check
- SolutionData licensing: granting defined rights to use your data
See if your company qualifies
A short company assessment. No data uploads are needed.