Skip to content

Leadership and readiness

How to keep a data licensing project confidential inside your company

By SourceX Editorial · Updated

Short answer

To keep a data licensing project confidential inside your company, run it on a need-to-know basis: a small named group, a neutral code name, restricted folders and channels, and a written plan for when each wider group is told. Widen the circle at decision points rather than by rumor, and brief employees before any approved release.

Key takeaways

  • People join a confidential project when their work starts, not because they are senior.
  • A neutral code name keeps the project out of calendars, file names and email subjects.
  • Honest, high-level answers protect confidentiality better than cover stories.
  • Each widening of the circle happens at a planned decision point and comes with a short briefing.
  • Employees should hear about an approved license from leadership before they notice its effects.

Why keep a data licensing project quiet at the start?#

A data licensing project should stay quiet at the start because nothing has been decided, and early rumors fill the gap with worse stories: the company is being sold, people are being replaced by AI, customer data is for sale. Those stories travel faster than any correction.

Confidentiality also protects the work itself. Early conversations involve open questions about rights and customers, and a partial picture reaching customers or competitors can do more harm than the full one. The goal is not secrecy forever; it is controlled timing, with a plan for who hears what, when and from whom.

Who needs to know, and when#

A need-to-know plan lists each stage of the project, the people who must be involved to complete it and what they are told. People join when their work starts, not because of their title, and the plan is written down so nobody adds colleagues informally.

Who needs to know, and when
StageWho knowsWhat they are told
Exploration and fit checkCEO, the CFO or COO, one IT leadMetadata questions only; no files move
Rights reviewAdd counsel and the records owner for each systemScope, systems and the contracts under review
PreparationAdd the named staff running exports and reviewTheir task, the confidentiality expectations and the code name
ApprovalAdd the board or owners, plus lenders or investors if consents applyProposed terms, risks and the recommendation
Delivery and afterEmployees broadly, and customers where your plan or contracts call for itWhat was licensed, what was excluded and why

Choosing a code name#

A code name lets people discuss the project in calendars, file names and email subjects without describing it. Pick something neutral that does not hint at data, AI, a sale or a buyer; a place name or an unrelated word works well.

Avoid cover stories. If someone outside the circle asks what IT is doing in the old help desk archive, an honest high-level answer such as a records review is true and sufficient. An invented explanation becomes a credibility problem the moment the project is announced, and it puts the IT staff who repeated it in an unfair position.

Controls that keep the circle small#

Practical controls keep project information where the plan says it should be, and most are settings in tools the company already uses. The aim is to make the confidential path the easy one, so people do not improvise with personal folders or forwarded threads.

  • A restricted project folder with named members, not inherited department access.
  • A private chat channel and a short distribution list instead of team-wide threads.
  • The code name in calendar titles, file names and email subjects.
  • A written confidentiality reminder for everyone added to the circle, referring to existing employment obligations.
  • NDAs in place with outside parties before any project discussion.
  • Exports kept in an access-logged location, never in shared drives or personal folders.
  • No samples, screenshots or extracts sent outside the company before approval.
  • A review of the access list at each stage, removing anyone whose part is finished.

Common leak points and how to close them#

Leaks in a confidential project rarely come from someone deciding to talk; they come from routine systems that show project activity to people outside the circle. Calendars, invoices and vendor account teams are the usual suspects, and each has a simple fix.

Walk through the list below with the IT lead and the CFO at the start, since between them they control most of the systems involved.

Common leak points and how to close them
Leak pointWhat gives the project awayHow to close it
Calendar invitesDescriptive titles visible to assistants and shared calendarsCode name in titles and private events
Export activityStaff notice large exports, archive restores or new service accountsBrief each system owner and give them an honest, high-level answer
Vendor account teamsA request for bulk export prompts the vendor to contact other people at the companyRoute vendor contact through one named person
Invoices and expensesCounsel or consultant invoices describe the matter to the accounts payable teamCode name on engagement letters and invoices
Board and investor materialsDecks forwarded beyond the intended readersLimited distribution and a confidentiality label on each copy
Outside partiesCounterparty staff mention the talks to mutual contactsNDA in place before the first substantive conversation

When to widen the circle#

The circle widens at planned decision points: when preparation needs more hands, before board approval and before any release. Each widening comes with a short briefing so new members know what the project is, what it is not and what they may say if asked.

Employees should hear about an approved license from leadership before they notice its effects or hear about it elsewhere. A short employee notice and an FAQ prepared in advance answer the predictable questions about jobs, customer data and what was excluded, and they keep managers from inventing their own explanations.

If a leak happens, bring the next widening forward rather than denying the project. A brief, accurate statement that the company is exploring licensing of operational records, with nothing yet decided, is easier to stand behind than silence or denial.

Illustrative: an industrial distributor runs Project Harbor#

Illustrative: a fictional industrial distributor runs SAP Business One for orders, a TMS for deliveries and a shared customer service inbox for order problems. When an AI developer asked about its order exception history, the CEO opened Project Harbor with the CFO and the IT manager only.

Outside counsel joined for the rights review under its engagement letter. During preparation, the customer service lead was briefed and added, because only she could explain how the inbox had been tagged over the years. Warehouse staff noticed IT pulling archives and asked questions; the IT manager said the company was reviewing old records, which was true.

At the approval stage the CEO briefed the leadership team, then all staff, using a prepared FAQ that explained what was licensed, what was excluded and that no customer names left the company. Because employees heard it from the CEO first, the questions that followed were about the work rather than about a sale.

How SourceX supports a quiet start#

The SourceX fit check collects metadata, not files, so the exploration stage can be run by a few people answering questions about systems and record types. Nothing is shared during the initial assessment, and the supplier approves every later step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery.

SourceX also publishes templates for an employee notice and an employee FAQ, which a company can adapt for the moment the circle widens.

Frequently asked questions

Do employees in the circle need to sign a separate NDA?

Often not. Existing employment agreements and policies may already cover confidential company information, so check them with counsel. A short written reminder when someone joins the project, naming the code name and what is confidential, makes the expectation clear without new paperwork.

What if someone asks directly whether we are selling data?

Answer honestly at the level of detail the plan allows: the company is exploring whether operational records could be licensed, nothing has been decided, and customer and employee details would be removed. Never deny a project that exists; a false denial costs more trust than an early disclosure.

Do customers need to be told?

That depends on customer contracts, your privacy notices and the laws that may apply, which counsel should review. Even where no notice is required, prepare an answer in case a customer asks, and decide in advance who responds so account managers are not caught improvising.

What if the project is cancelled?

Close it as carefully as you ran it. Revoke project access, delete working copies of exported records, record the decision and the reason, and tell the people who knew that the project has ended. A quiet, documented close keeps a cancelled project from resurfacing later as a rumor.

Should middle managers be kept out until the end?

Not until the end, but until their teams are affected. A manager whose staff will run exports or answer questions should be briefed before that work starts, so they can protect time and handle questions. Keeping them out longer usually means they learn about it from their own team.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify