Skip to content

Rights and contracts

Labels, annotations and derived data: who owns what the buyer adds?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

In most data licenses the supplier keeps ownership of its raw records and the buyer owns what it independently creates, such as labels, embeddings and models, unless the derived data clause says otherwise. The real risk is derived data that can still reveal the source records. Define derived data precisely, then limit how revealing derivatives may be shared.

Key takeaways

  • Raw records stay with the supplier; a data license grants rights to use them, not ownership.
  • Buyers usually own their own labels, annotations and models unless the contract narrows that default.
  • The most useful test is whether a derivative can reproduce or reveal the supplier's records.
  • Embeddings, synthetic data and fine-grained aggregates can carry more of the source than they appear to.
  • Deletion and survival clauses decide what happens to each kind of derived data when the license ends.

What counts as derived data in a data license?#

Derived data in a data license is anything the buyer creates from the licensed records, and the contract's definition decides which of those creations the derived data clause governs. Without a definition, the parties are left arguing over whether a label, a statistic or a vector counts as a copy of the records or as something new.

A workable definition lists the categories and then says what is excluded. One common shape reads: Derived Data means labels, annotations, enrichments, statistics, embeddings, synthetic records and other data created by or for Licensee from the Licensed Data, excluding trained model weights. Models are then handled in their own clause, because they raise different questions.

  • Labels and annotations: tags, classifications, ratings and corrections added by the buyer's staff or contractors.
  • Enrichments: licensed records joined with the buyer's other data.
  • Aggregates and statistics: counts, averages, distributions and benchmarks.
  • Embeddings: numeric vector representations of records or passages.
  • Synthetic data: new records generated to resemble the licensed ones.
  • Model weights and evaluation results: what training and testing produce.

Ownership matrix: default and negotiated positions#

The ownership matrix below shows where derived data usually lands when a contract is silent or loosely drafted, and how each side tends to negotiate. Positions vary by deal, buyer and price, so read it as a map of the bargaining range, not a rule.

Two rows cause most of the negotiation. Labeled records matter because they are where buyer ownership and supplier restrictions collide, and embeddings matter because engineers often treat them as disposable technical artifacts while lawyers treat them as copies. Settle both explicitly rather than leaving them to the general ownership clause.

Ownership matrix: default and negotiated positions
ItemCommon defaultSupplier-friendly positionBuyer-friendly position
Raw recordsSupplier ownsSupplier owns, narrow use rightsSupplier owns, broad use rights
Buyer labels and annotationsBuyer ownsBuyer owns, but treated as licensed data while attached to recordsBuyer owns outright
Labeled recordsUnclearRemain licensed data, subject to all restrictionsBuyer may keep and reuse internally
Aggregates and statisticsBuyer ownsBuyer owns only above a minimum group sizeBuyer owns and may publish
EmbeddingsUnclearTreated as licensed data and deleted at term endBuyer owns as a technical artifact
Synthetic dataUnclearLicensed data unless tested for memorizationBuyer owns
Model weightsBuyer ownsBuyer owns, with limits on reproducing recordsBuyer owns, survives termination
Evaluation resultsBuyer ownsNo publication naming the supplierBuyer may publish freely

Why the reveal-the-source test matters more than ownership#

The reveal-the-source test matters more than ownership because a buyer can own a derivative that still carries the supplier's records. A label attached to a support ticket is useless without the ticket, so a labeled dataset is in practice a copy of the licensed data with something added. Treating labeled records as licensed data for as long as they stay attached keeps the supplier's restrictions in force.

Less obvious derivatives can leak too. Research has shown that some embeddings can be partly reversed to recover the source text, synthetic records can repeat rare real ones, and aggregates over small groups can point to a single customer or employee. A supplier does not need to own any of these, but it should control how far they travel outside the buyer.

Clauses that protect a supplier#

The clauses that protect a supplier work together: one defines derived data, one allocates ownership, and the rest limit distribution, re-identification and retention. A single broad ownership clause in the buyer's favor can undo all of them, so read the ownership clause last, against the others.

Provenance standards point the same way. The Use group of the Data & Trust Alliance's Data Provenance Standards includes elements for license to use and intended data use, which reflects how buyers increasingly track permitted use as metadata that travels with a dataset and its derivatives.

  • Definition of derived data that names labels, embeddings, aggregates and synthetic records.
  • Treatment of labeled or enriched records as licensed data while they contain source content.
  • No redistribution, sublicensing or publication of derivatives that can reproduce or reveal records.
  • No attempt to re-identify people or customers, with the obligation passed to any contractor.
  • Minimum group sizes or similar safeguards before aggregates leave the buyer.
  • Deletion or return at term end, with clear exceptions such as trained model weights.
  • Survival of confidentiality and re-identification limits after termination.

When a supplier should ask for the labels back#

A supplier should ask for the buyer's labels back when expert annotations on its own records would be useful to the business, for example root-cause tags on quality records or resolution categories on support tickets. A grant-back gives the supplier a license to use those labels internally, which can feed its own analytics or future AI work.

Buyers sometimes resist because labels reflect their methods and spend. A narrower grant-back, limited to labels on the supplier's own records and to internal use, is easier to agree. Keep the supplier's existing tags, such as ticket categories and dispositions, clearly inside the licensed data so they are not mistaken for buyer creations.

Illustrative example: a distributor licenses order exceptions#

Illustrative: a fictional industrial distributor licenses order exception records from Epicor, with the related customer service emails, to a model developer. The developer's annotators tag each exception with a root cause and a resolution type. The distributor's general counsel negotiates the derived data clause before anything is delivered.

The final license gives the developer ownership of its labels and models, treats labeled records as licensed data that may not leave the developer, allows aggregates only above an agreed minimum group size and requires deletion of records, labeled records and embeddings at term end. The distributor receives a grant-back of root-cause labels for internal use, which its operations team later uses to review recurring exception patterns.

How SourceX handles derived data terms#

SourceX sets derived data terms during the Approval step of the SourceX five-step transaction, after Preparation has reduced what any derivative could reveal. The supplier approves the permitted use, including how labels, aggregates and models may be handled.

The agreed position is recorded under permitted use in the SourceX Evidence Packet, alongside provenance, licensing rights, the privacy record and release authorization, so both sides can check later what the buyer was allowed to create and keep.

Frequently asked questions

Who owns a model trained on our licensed data?

In most licenses the buyer owns the model, and the supplier's protection comes from use limits rather than ownership. Suppliers commonly negotiate restrictions on models reproducing records verbatim, on extracting records through prompts and on what happens to models trained during a license that ends early for breach.

Can the buyer resell a labeled version of our records?

Only if the license allows it. Supplier-friendly licenses treat labeled records as licensed data, which carries the same restrictions on sublicensing and resale. Check that the derived data definition and the redistribution clause both cover labeled and enriched records, and that the buyer must pass the same limits to its contractors and affiliates.

Do derived data rights survive the end of the license?

It depends on the survival clause. Buyers usually keep models and their own labels; suppliers usually require deletion of records and anything that can reproduce them, followed by a written certificate. Write down each category's fate rather than relying on a general survival sentence that leaves embeddings and labeled records in doubt.

Are evaluation results derived data?

They can be, and they matter when a buyer wants to publish benchmark results. A supplier may allow publication of aggregate scores while prohibiting examples drawn from its records or any statement that names it as the source.

Do broader derived data rights justify a higher fee?

Often they do. Under the SourceX Enterprise Data Value Framework, exclusivity increases price, and broad rights to keep and reuse derivatives move a license closer to exclusive or perpetual use. Treat derived data scope as a commercial term, not only a legal one.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify