Skip to content

Rights and contracts

Indemnification in data licenses: who covers which claims

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

The indemnification clause in a data license agreement usually makes the supplier cover claims that it lacked the right to provide the records or collected them unlawfully, and makes the buyer cover claims from its own use, including misuse, model outputs and use beyond scope. The working rule: each side indemnifies for the risks it controls.

Key takeaways

  • Each party should indemnify for risks it controls: suppliers for rights and collection, buyers for use and outputs.
  • A supplier IP indemnity should cover the right to provide the records, not every claim about what a model later produces.
  • Privacy indemnities should follow whoever prepared the data and whoever could re-identify it.
  • Caps, exclusions and defense procedures matter as much as the indemnity promise itself.
  • Check whether insurance responds to data licensing claims before agreeing to any uncapped indemnity.

Who covers which claims in a data license?#

Indemnification in a data license allocates third-party claims to the party best placed to prevent them. Suppliers typically cover claims that they had no right to license the records or that the records were collected unlawfully. Buyers typically cover claims arising from how they use the records, train models and deploy what they build.

AI training makes the allocation harder than in an ordinary software license, because the records pass through a model the supplier never sees. A supplier cannot control what a model generates, how it is deployed or which customers rely on it. Drafts that ask suppliers to stand behind model behavior shift risk to the party with the least control.

Claim by claim: who typically indemnifies#

Claim by claim, suppliers usually indemnify for rights and collection, while buyers indemnify for use, model outputs and their own security. The positions below are common starting points, not rules, and counsel adjusts them for each deal.

Some claims fall between the rows. A supplier's former customer might object to the license itself, even though records were de-identified before delivery. Whether that claim follows the supplier's notices and contracts or the buyer's handling of the records depends on its facts, so the indemnity wording should say which trigger applies.

Claim by claim: who typically indemnifies
Claim typeUsually indemnifiesWhyWhat to negotiate
Supplier lacked rights to license the recordsSupplierSupplier controls ownership and its own contractsKnowledge qualifier; scope limited to records as delivered
Records collected in breach of privacy or recording lawsSupplierSupplier controlled collection and noticesLimit to collection practices, not buyer processing
Breach of a customer contract that restricted reuseSupplierSupplier signed those contractsA disclosure schedule of known restrictions
Buyer re-identifies people in prepared recordsBuyerBuyer controls its own processingAn express ban on re-identification
Use outside the permitted scopeBuyerBuyer controls useA precise permitted use definition
Model outputs infringe or cause harmBuyerBuyer controls training, deployment and safeguardsExclude output claims from the supplier indemnity
Security breach at the buyerBuyerBuyer controls storage after deliverySecurity standards and breach notice duties

How to scope a supplier IP indemnity#

A supplier IP indemnity should promise that the supplier had the right to provide the records for the licensed use, and stop there. Broader wording, such as covering any claim that the licensed data or anything derived from it infringes, can pull model outputs, combined datasets and buyer modifications into the supplier's exposure.

Common narrowing tools include limiting the indemnity to records as delivered, excluding claims caused by buyer modifications or combination with other data, adding a knowledge qualifier for third-party content embedded in records, and carving out material the supplier flagged as third-party in its disclosures. Email and document archives need care, because they often hold attachments created by other companies.

Privacy indemnities and who prepared the data#

Privacy indemnities should follow whoever controlled collection and whoever did the preparation work. If the supplier, or a provider acting for it, removed personal and confidential details before delivery, the buyer will ask the supplier to stand behind that work. If the buyer did its own preparation on raw records, the buyer should carry that risk.

Two limits protect a supplier that prepares data carefully. The indemnity should not cover re-identification by the buyer, which the license should prohibit outright. And it should be tied to an agreed preparation standard, so the supplier promises a documented method rather than a perfection that no automated tool delivers.

Model outputs and downstream use#

Claims about model outputs belong with the buyer in most data licenses, because only the buyer controls training choices, safety filters, deployment and its own customer terms. A supplier that licenses support transcripts has no way to stop a model from producing a harmful answer months later.

Suppliers should also resist indemnities that run to the buyer's customers or affiliates without limit. If the buyer wants to pass protection downstream, that is a commercial decision for the buyer's own contracts, priced and managed there.

Caps, exclusions and procedure#

The mechanics around an indemnity, from the cap to the defense procedure, often matter more than its headline scope. A narrow indemnity with no cap can expose a supplier more than a broad one with sensible limits.

Before agreeing to any indemnity, check whether the company's insurance responds to claims arising from data licensing. Cyber, technology errors and omissions and media liability policies each carry their own exclusions, and many exclude liability a company takes on by contract, so ask the broker in writing before signing rather than after a claim arrives.

  • Cap: an overall limit, often tied to fees paid under the license, with any higher limit reserved for specific claims.
  • Exclusions from the cap: decide which claims, if any, sit outside it, and keep that list short.
  • Procedure: prompt notice, the indemnifying party's right to control the defense, and no settlement admitting fault without consent.
  • Mitigation: the indemnified party takes reasonable steps, such as stopping use of disputed records.
  • Remedy options: a right to replace, remove or re-prepare disputed records before liability attaches.
  • Survival: how long indemnities last after the license ends.

Illustrative: an architecture firm negotiates a mutual indemnity#

Illustrative: a fictional architecture firm is licensing internal design review markups kept in Bluebeam, plus RFI responses and submittal logs from its project records, to a developer building tools for project teams. The developer's draft asks the firm to indemnify any claim relating to the licensed data or any model trained on it, with no cap.

The firm's counsel proposes a mutual structure. The firm indemnifies claims that it lacked rights to the records as delivered, subject to a cap and excluding client-owned drawings, which were removed during preparation. The developer indemnifies claims from its use, model outputs and any re-identification attempt. Both sides add a replace-or-remove remedy for disputed records, and the firm's partners approve the license.

How SourceX approaches risk allocation#

SourceX works through indemnities in the Rights and Approval steps of the SourceX five-step transaction, after the rights review has shown what the supplier can actually stand behind. The SourceX Evidence Packet records provenance, licensing rights, the privacy record and release authorization, which gives both sides a factual basis for scoping each indemnity.

The supplier approves the final license, including the indemnity, cap and procedure. The aim is an allocation in which each side carries the risks it can control.

Frequently asked questions

Is a mutual indemnity always better for a supplier?

Not always. Mutual wording can look balanced while leaving the supplier's side broad and the buyer's side narrow. Compare the actual claims each party covers, the caps on each side and the exclusions, rather than relying on the label.

Should a supplier indemnify trade secret claims?

Sometimes, where records might contain another company's confidential information, such as a former partner's documents in an email archive. Preparation that removes third-party material lowers the risk, and the indemnity can be limited to material the supplier knew or should have known about.

What is the difference between a warranty and an indemnity here?

A warranty is a promise about facts, such as the supplier holding rights to the records, and breaching it gives the buyer a claim for its own losses. An indemnity, as most data licenses draft it, covers third-party claims and the cost of defending them. Data licenses usually contain both, and caps should address both.

Should privacy claims have a different cap from IP claims?

Sometimes. Parties occasionally agree a separate, higher cap for privacy and data protection claims, because regulatory exposure and notification costs can exceed the fees under a license. If that is proposed, tie the higher cap to claims the supplier actually controls, such as unlawful collection, rather than to any privacy issue.

Can indemnities be limited to the term of the license?

They often survive termination for a defined period, because claims can arise after delivery. Suppliers can negotiate a fixed survival period rather than an open-ended one, aligned with how long the buyer may keep the records and anything derived from them.

Do indemnities replace the need for a rights review?

No. An indemnity only moves money after a claim. A rights review before licensing prevents many claims in the first place and tells a supplier what it can safely promise.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify