Private equity and portfolios
Processor vs controller: why SaaS vendors cannot license customer personal data
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A SaaS vendor acting as a processor generally cannot license customer personal data, because it may process that data only on its customer's instructions and for the customer's purposes. Licensing records to AI developers is the vendor's own purpose. The vendor's own operational records, such as code, release notes and internal tickets, usually sit outside that role.
Key takeaways
- A processor handles personal data on a controller's behalf and generally may not use it for purposes of its own.
- Licensing records to AI developers is a new purpose of the vendor's, so customer personal data in the product is normally out of scope.
- Aggregated or de-identified data clauses in a data processing agreement rarely amount to permission to license records to third parties.
- Code, code reviews, release notes and internal engineering tickets are generally the vendor's own records, but they need scanning for pasted customer data.
What makes a SaaS vendor a processor?#
A SaaS vendor is a processor when it handles personal data on behalf of its customer, which decides why and how that data is processed. GDPR uses the terms controller and processor, many US state privacy laws use similar terms, and California's law uses labels such as business, service provider and contractor for comparable roles.
For most B2B software, the customer's records inside the product, such as its own customers' names, its employees' entries and the files it uploads, are handled in this role. The data processing agreement attached to the subscription usually says so and limits the vendor to processing on the customer's instructions.
The same vendor can be a controller for other data, such as business contact details in its own CRM or its billing records. Role is assessed per data set, not per company.
What a processor may and may not do#
A processor may do what the controller instructs and what is needed to provide the contracted service, and it generally may not repurpose the data for its own ends. The exact limits come from the laws that may apply and the data processing agreement, so read both.
Licensing records to an AI developer is a disclosure for the vendor's own purpose. That puts customer personal data held as a processor outside what a vendor can offer, however useful the records look.
| A processor generally may | A processor generally may not |
|---|---|
| Store, host and back up customer data to deliver the service | Use customer data for its own products or commercial purposes |
| Process data on the customer's documented instructions | Disclose or license customer data to third parties without authorization |
| Use approved sub-processors under contract | Add sub-processors outside the agreed process |
| Return or delete data at the end of the service | Keep customer data after termination beyond what the terms allow |
| Use data as the agreement expressly permits, such as for security or support | Treat an improve-the-service clause as permission to license records |
Do aggregated or de-identified data clauses change the answer?#
Aggregated or de-identified data clauses rarely change the answer for licensing, because they are usually written for narrow internal uses such as benchmarks, security and product improvement. Many agreements let the vendor produce aggregated statistics, which is different from passing record-level material to a third party for model training.
De-identification is also harder than it looks in free text. Support conversations and notes often contain names, account numbers and personal details in unstructured form. Read the exact definition of de-identified or anonymized data in the agreement, check whether it permits disclosure to third parties at all, and have counsel assess whether the standard can be met for the records in question.
Which vendor-owned records sit outside the processor role#
Vendor-owned operational records sit outside the processor role because the vendor creates them for its own business rather than on a customer's behalf. For many software companies these are also the records AI developers find most useful: how engineers find, discuss and fix problems.
| Record | Usually processor data? | Licensing consideration |
|---|---|---|
| Customer records inside the product | Yes | Out of scope for vendor licensing |
| Source code and commit history | No | Remove secrets; check open-source and customer-owned code |
| Code reviews and pull request discussions | No | Scan for pasted customer data |
| Release notes and internal docs | No | Usually lower risk; check for customer names |
| Internal engineering tickets | No, but often contain pasted customer data | Scan, redact and review |
| Support tickets with customer admins | Often controller data for business contacts, but check the agreement | Privacy laws may apply; review notices and contracts |
| Product usage telemetry | Depends on the agreement | Read the data processing agreement and terms closely |
How to separate vendor-owned records from customer data#
Separating vendor-owned records from customer data is mostly a scoping and scanning exercise, and it is easier to do system by system than record by record.
Human review stays in the process because the tool makers say it must. Presidio, an open-source SDK for identifying and anonymizing personal data in text and images, states that because it uses automated detection there is no guarantee it will find all sensitive information, and that additional protections should be used.
- Exclude production databases, customer file stores and backups of customer content at the start.
- List the vendor's own systems, such as GitHub or GitLab, Jira or Linear, Confluence or Notion, Zendesk or Intercom, and Slack.
- Search engineering tickets and code reviews for pasted customer records, screenshots and log extracts.
- Run automated detection, then human review of the results.
- Remove or redact identified customer data and record what was done.
- Have counsel check the result against the data processing agreements and privacy notices.
Illustrative: a property management software vendor draws the line#
Illustrative: a fictional holdco owns a property management software vendor whose product stores tenant names, lease terms and payment histories for its landlord customers. The holdco's general counsel is asked whether the vendor can license records to an AI developer.
Counsel concludes that tenant and lease records in the product are processed for landlord customers and are out of scope. The candidate package is the vendor's own: GitHub repositories, code reviews, Jira issues, release notes and internal design docs. A scan finds tenant details pasted into some Jira issues during debugging; those are redacted and the redactions are checked by hand. Support tickets with landlord staff are deferred pending a separate review of the privacy notice.
The resulting scope is smaller than the first idea, but every record in it belongs to the vendor.
How SourceX scopes SaaS records#
SourceX scopes SaaS records by starting from the vendor's own systems and leaving out customer data the vendor processes on others' behalf. The Rights step of the SourceX five-step transaction checks data processing agreements, customer terms and privacy notices before any preparation begins.
The privacy record in the SourceX Evidence Packet then documents how engineering tickets, code reviews and other vendor-owned records were scanned and redacted, so the vendor has a written account to show its own customers or a future acquirer if asked.
Frequently asked questions
Can a customer authorize the vendor to license its data?
A customer acting as controller could, in principle, authorize a new use, but it would need its own legal basis and notices for the individuals involved, and the terms would have to be specific. In practice this is rare and slow, so most vendors scope licensing to their own records instead.
Would the AI developer become a sub-processor if it received customer records?
No, and that is part of the problem. A sub-processor works for the controller's purposes within the processing chain. An AI developer licensing records uses them for its own purposes, so passing customer personal data to it would fall outside the processor role rather than extend it. That is why customer data stays out of scope.
Does this apply if the product holds only B2B data?
Business contact details are still personal data under many privacy laws, and commercial records such as customer pricing or contracts are usually covered by confidentiality terms. B2B products face fewer privacy issues than consumer ones, but the processor limits on customer data still apply.
Is product telemetry personal data?
It can be. Telemetry tied to user IDs, IP addresses or device identifiers may be personal data, and the agreement may define it as customer data. Aggregated, non-identifying metrics are less sensitive, but whether they can be licensed depends on the exact contract language.
What about an acquired product with older terms?
Older terms may be looser or stricter than current ones, and records collected under them generally stay subject to them. Audit the terms in force when the records were collected, not just today's version, before scoping anything from an acquired product.
Does updating our terms now let us license existing customer data?
Usually not for data already collected under the old terms, and changes to processor terms typically need customer agreement. Updated terms may shape what is possible for future data. Counsel should advise on both the change process and its limits.
Sources
- Presidio's documentation warns that because it uses automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information, and that additional systems and protections should be employed. Source
- Presidio is an open-source, MIT-licensed SDK for PII identification and anonymization in text and images. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.