Skip to content

Private equity and portfolios

Processor vs controller: why SaaS vendors cannot license customer personal data

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A SaaS vendor acting as a processor generally cannot license customer personal data, because it may process that data only on its customer's instructions and for the customer's purposes. Licensing records to AI developers is the vendor's own purpose. The vendor's own operational records, such as code, release notes and internal tickets, usually sit outside that role.

Key takeaways

  • A processor handles personal data on a controller's behalf and generally may not use it for purposes of its own.
  • Licensing records to AI developers is a new purpose of the vendor's, so customer personal data in the product is normally out of scope.
  • Aggregated or de-identified data clauses in a data processing agreement rarely amount to permission to license records to third parties.
  • Code, code reviews, release notes and internal engineering tickets are generally the vendor's own records, but they need scanning for pasted customer data.

What makes a SaaS vendor a processor?#

A SaaS vendor is a processor when it handles personal data on behalf of its customer, which decides why and how that data is processed. GDPR uses the terms controller and processor, many US state privacy laws use similar terms, and California's law uses labels such as business, service provider and contractor for comparable roles.

For most B2B software, the customer's records inside the product, such as its own customers' names, its employees' entries and the files it uploads, are handled in this role. The data processing agreement attached to the subscription usually says so and limits the vendor to processing on the customer's instructions.

The same vendor can be a controller for other data, such as business contact details in its own CRM or its billing records. Role is assessed per data set, not per company.

What a processor may and may not do#

A processor may do what the controller instructs and what is needed to provide the contracted service, and it generally may not repurpose the data for its own ends. The exact limits come from the laws that may apply and the data processing agreement, so read both.

Licensing records to an AI developer is a disclosure for the vendor's own purpose. That puts customer personal data held as a processor outside what a vendor can offer, however useful the records look.

What a processor may and may not do
A processor generally mayA processor generally may not
Store, host and back up customer data to deliver the serviceUse customer data for its own products or commercial purposes
Process data on the customer's documented instructionsDisclose or license customer data to third parties without authorization
Use approved sub-processors under contractAdd sub-processors outside the agreed process
Return or delete data at the end of the serviceKeep customer data after termination beyond what the terms allow
Use data as the agreement expressly permits, such as for security or supportTreat an improve-the-service clause as permission to license records

Do aggregated or de-identified data clauses change the answer?#

Aggregated or de-identified data clauses rarely change the answer for licensing, because they are usually written for narrow internal uses such as benchmarks, security and product improvement. Many agreements let the vendor produce aggregated statistics, which is different from passing record-level material to a third party for model training.

De-identification is also harder than it looks in free text. Support conversations and notes often contain names, account numbers and personal details in unstructured form. Read the exact definition of de-identified or anonymized data in the agreement, check whether it permits disclosure to third parties at all, and have counsel assess whether the standard can be met for the records in question.

Which vendor-owned records sit outside the processor role#

Vendor-owned operational records sit outside the processor role because the vendor creates them for its own business rather than on a customer's behalf. For many software companies these are also the records AI developers find most useful: how engineers find, discuss and fix problems.

Which vendor-owned records sit outside the processor role
RecordUsually processor data?Licensing consideration
Customer records inside the productYesOut of scope for vendor licensing
Source code and commit historyNoRemove secrets; check open-source and customer-owned code
Code reviews and pull request discussionsNoScan for pasted customer data
Release notes and internal docsNoUsually lower risk; check for customer names
Internal engineering ticketsNo, but often contain pasted customer dataScan, redact and review
Support tickets with customer adminsOften controller data for business contacts, but check the agreementPrivacy laws may apply; review notices and contracts
Product usage telemetryDepends on the agreementRead the data processing agreement and terms closely

How to separate vendor-owned records from customer data#

Separating vendor-owned records from customer data is mostly a scoping and scanning exercise, and it is easier to do system by system than record by record.

Human review stays in the process because the tool makers say it must. Presidio, an open-source SDK for identifying and anonymizing personal data in text and images, states that because it uses automated detection there is no guarantee it will find all sensitive information, and that additional protections should be used.

  • Exclude production databases, customer file stores and backups of customer content at the start.
  • List the vendor's own systems, such as GitHub or GitLab, Jira or Linear, Confluence or Notion, Zendesk or Intercom, and Slack.
  • Search engineering tickets and code reviews for pasted customer records, screenshots and log extracts.
  • Run automated detection, then human review of the results.
  • Remove or redact identified customer data and record what was done.
  • Have counsel check the result against the data processing agreements and privacy notices.

Illustrative: a property management software vendor draws the line#

Illustrative: a fictional holdco owns a property management software vendor whose product stores tenant names, lease terms and payment histories for its landlord customers. The holdco's general counsel is asked whether the vendor can license records to an AI developer.

Counsel concludes that tenant and lease records in the product are processed for landlord customers and are out of scope. The candidate package is the vendor's own: GitHub repositories, code reviews, Jira issues, release notes and internal design docs. A scan finds tenant details pasted into some Jira issues during debugging; those are redacted and the redactions are checked by hand. Support tickets with landlord staff are deferred pending a separate review of the privacy notice.

The resulting scope is smaller than the first idea, but every record in it belongs to the vendor.

How SourceX scopes SaaS records#

SourceX scopes SaaS records by starting from the vendor's own systems and leaving out customer data the vendor processes on others' behalf. The Rights step of the SourceX five-step transaction checks data processing agreements, customer terms and privacy notices before any preparation begins.

The privacy record in the SourceX Evidence Packet then documents how engineering tickets, code reviews and other vendor-owned records were scanned and redacted, so the vendor has a written account to show its own customers or a future acquirer if asked.

Frequently asked questions

Can a customer authorize the vendor to license its data?

A customer acting as controller could, in principle, authorize a new use, but it would need its own legal basis and notices for the individuals involved, and the terms would have to be specific. In practice this is rare and slow, so most vendors scope licensing to their own records instead.

Would the AI developer become a sub-processor if it received customer records?

No, and that is part of the problem. A sub-processor works for the controller's purposes within the processing chain. An AI developer licensing records uses them for its own purposes, so passing customer personal data to it would fall outside the processor role rather than extend it. That is why customer data stays out of scope.

Does this apply if the product holds only B2B data?

Business contact details are still personal data under many privacy laws, and commercial records such as customer pricing or contracts are usually covered by confidentiality terms. B2B products face fewer privacy issues than consumer ones, but the processor limits on customer data still apply.

Is product telemetry personal data?

It can be. Telemetry tied to user IDs, IP addresses or device identifiers may be personal data, and the agreement may define it as customer data. Aggregated, non-identifying metrics are less sensitive, but whether they can be licensed depends on the exact contract language.

What about an acquired product with older terms?

Older terms may be looser or stricter than current ones, and records collected under them generally stay subject to them. Audit the terms in force when the records were collected, not just today's version, before scoping anything from an acquired product.

Does updating our terms now let us license existing customer data?

Usually not for data already collected under the old terms, and changes to processor terms typically need customer agreement. Updated terms may shape what is possible for future data. Counsel should advise on both the change process and its limits.

Sources

  • Presidio's documentation warns that because it uses automated detection mechanisms, there is no guarantee that Presidio will find all sensitive information, and that additional systems and protections should be employed. Source
  • Presidio is an open-source, MIT-licensed SDK for PII identification and anonymization in text and images. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify