Skip to content

Rights and contracts

Red flags in a data license draft: a counsel's checklist

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

The most serious red flags in a data license draft are phrases that quietly widen the buyer's rights: derived and aggregate data carve-outs, residuals clauses, unqualified supplier warranties, one-way indemnities and retention exceptions that swallow deletion. The working rule: every right should be named, limited in use and time, and matched by deletion and audit mechanics.

Key takeaways

  • Read the definitions before the grant, because terms such as Licensed Data and Derived Data decide what the grant actually covers.
  • A carve-out that lets the buyer use aggregated or de-identified data without restriction can move most of the value outside the license.
  • Supplier warranties should cover the records as delivered and the permitted uses, not every use the buyer might make.
  • Deletion clauses fail most often through exceptions for backups, embeddings, evaluation sets and internal policy.
  • Silences and survival lists are red flags too: a missing re-identification ban, or a grant listed among surviving sections, can matter as much as bad wording.

How should counsel read a buyer's first draft?#

Counsel should read a buyer's first draft of a data license from the definitions outward. Grants, restrictions and deletion duties all borrow their meaning from a handful of defined terms, and a narrow-looking grant can become a broad one through a single definition.

A consistent reading order also makes the markup faster to explain to the CEO or the board. Each red flag can be tied to the clause that creates it and the business consequence, rather than presented as a list of drafting preferences.

  • Definitions: Licensed Data, Derived Data, Aggregate Data, Model, Output, Affiliates.
  • Grant and restrictions: permitted uses, sublicensing, onward transfer.
  • Ownership: who owns derived data, synthetic data, embeddings and models.
  • Warranties, indemnities and liability caps, read side by side for symmetry.
  • Term, termination, deletion and certification.
  • Security, audit, assignment, publicity and any terms incorporated by reference.

Red-flag phrases in definitions and the grant#

The phrases below rarely look aggressive on a first read, which is why they survive into signed agreements. Grant adjectives such as perpetual and irrevocable deserve their own review, so this table focuses on the quieter wording around them, including the clauses that make a grant permanent without saying so.

Red-flag phrases in definitions and the grant
Phrase in the draftWhy it mattersFix to propose
Derived Data means any data created from the Licensed Data and is owned by LicenseeCopies, summaries and reformatted records can all be called derived, which takes them outside your deletion rightsExclude anything from which a record can be reconstructed; keep derived data under the license terms
Sections 2 (License Grant), 6 and 11 survive any expiration or terminationListing the grant in the survival clause turns a term license into a perpetual one without using the wordLet only confidentiality, deletion, output limits, accrued fees and expressly named model rights survive
Licensee may use Aggregated or De-identified Data for any purposeA buyer-side de-identification step can release the whole dataset from the licenseAggregated or de-identified versions stay subject to the same permitted uses and onward-transfer limits
Licensee and its AffiliatesUndefined affiliates can include future acquirers and sister companies building other productsDefine affiliates as entities controlled now, bound in writing, with the licensee liable for them
including, without limitation, training, evaluation and commercializationThe list is illustrative, so any unlisted use is arguably allowedTurn the list into an exhaustive set of permitted uses and reserve all other rights
Synthetic data generated by Licensee is not Licensed DataSynthetic records can closely mirror the originals and be shared freelySynthetic data stays restricted unless it passes an agreed similarity review
Residuals: information retained in the unaided memory of Licensee personnelA software-industry clause that makes confidentiality hard to enforce for dataDelete it, or limit it to general skills and know-how, never record content
subject to Licensee's Data Supplier Policy, as updated from time to timeThe buyer can change your terms by editing a web pageAttach the policy as signed; changes need written agreement
This Agreement renews automatically for successive terms unless either party gives noticeMissed notice windows extend use with no fresh review of scope or priceRenewal only by written agreement, or a reminder duty and a short notice window

Red flags in warranties, indemnities and liability#

Warranty and indemnity clauses are where risk quietly moves to the supplier. Buyers often ask the supplier to stand behind every use of the data, including uses the supplier cannot see or control, while capping their own exposure at the fees paid.

Read the two sides of the risk allocation together. A clause that looks standard on its own can be lopsided once you compare which party carries uncapped liability and for what.

Red flags in warranties, indemnities and liability
Phrase in the draftWhy it mattersFix to propose
Licensor has obtained all consents necessary for any use by LicenseeTies your warranty to uses you never agreed toLimit to the records as delivered, the permitted uses and, where fair, your knowledge
Licensor shall indemnify Licensee for all claims arising from the Licensed DataCovers claims caused by the buyer's own model outputsLimit to third-party claims caused by your breach of named warranties
Licensor's liability is uncapped for breach of the data warrantiesOne-sided if the buyer's liability is capped at feesMutual caps with symmetrical carve-outs, including the buyer's misuse and security breaches
Licensee has no responsibility for OutputsLeaves you with no remedy if a model reproduces your recordsBuyer is responsible for outputs, including reproduction of licensed records
Licensor releases all claims relating to use of the Licensed DataCan waive claims for misuse, including past and future misuseRelease only claims for uses the license expressly permits

Red flags in deletion, retention and audit#

Deletion clauses usually fail through their exceptions rather than their main promise. Counsel should list every exception, ask what copies it actually covers, and decide whether the retained copies stay under the license terms until they are gone.

Audit language matters because deletion and use limits are otherwise impossible to verify. A right to request a certificate with no deadline, no named signer and no audit fallback gives the supplier very little to rely on.

  • Retained in backups, archives or as required by internal policy: limit to backups that roll off on the normal cycle, stay confidential and are never restored for training.
  • Deletion does not apply to models, embeddings, indexes or caches: address embeddings and retrieval indexes expressly, since they can hold recoverable text.
  • Licensee may retain data for evaluation and safety: name the evaluation sets, cap their scope and keep them under the use limits.
  • Licensee will certify deletion on request: set a deadline, an officer signature and coverage of contractors and affiliates.
  • No audit right, or audit limited to the buyer's own self-assessment: add a reasonable independent audit or attestation right on reasonable notice.

Silences that count as red flags#

Some of the most important protections are absent from buyer drafts rather than badly worded. Counsel should check for a ban on re-identification and on linking the records with other data, an output restriction against reproducing licensed records, and a named security standard with breach notice to the supplier.

Other common gaps are limits on onward transfer to other model developers, named storage and processing locations, control over whether the buyer may name the supplier publicly, and a clear rule on what happens to the records if the buyer is acquired. A short schedule of supplier protections, agreed at term sheet stage, closes most of these gaps before drafting starts.

Illustrative: counsel marks up a buyer draft for a WMS vendor#

Illustrative: a fictional warehouse management software vendor plans to license de-identified support tickets linked to its Jira issues and the code fixes that resolved them. Its general counsel receives the buyer's paper and reads the definitions first.

She flags three items. Derived Data is owned by the buyer and expressly excluded from deletion, a residuals clause covers anything the buyer's staff remember, and the deletion clause exempts any copy retained under internal policy. The warranty section also asks the vendor to confirm consents for any use.

The buyer accepts that derived data stays under the license, drops the residuals clause and narrows retention to rolling backups. The warranty is limited to the records as delivered and the permitted uses, and the CEO approves the license with a one-page summary of each change.

How SourceX approaches draft review#

SourceX does not give legal advice, and the supplier's counsel takes every position. What SourceX changes is timing: permitted uses, deletion expectations and output limits are set by the supplier during Rights, before buyer paper arrives, so the first draft starts closer to terms the supplier can sign.

Once signed, the negotiated positions travel with the package. The SourceX Evidence Packet holds them as licensing rights and permitted use entries, beside the provenance, privacy record and release authorization, which gives the board and the buyer one shared account of what was approved.

Frequently asked questions

Is a residuals clause ever acceptable in a data license?

Rarely in its usual form. Residuals clauses come from software and services deals, where they protect general know-how. Applied to a dataset, they can excuse use of specific record content. If a buyer insists, limit the clause to general skills and experience and exclude any record content, customer information or confidential business details.

Should a supplier accept an as-is disclaimer on data quality?

Usually yes, and it is often the supplier who wants it. A supplier can reasonably describe the records, the collection method and the preparation applied without promising accuracy or fitness for a model. Rights and privacy warranties are a separate matter and are usually where negotiation focuses.

Who should produce the first draft?

Whoever drafts first sets the structure and defaults. Suppliers that cannot produce paper can still shape the draft by agreeing a detailed term sheet first, covering permitted uses, term, deletion, output limits and liability, so the buyer's draft starts from agreed positions.

What if the buyer says its terms are non-negotiable?

Standard terms are often negotiable on definitions, deletion mechanics and warranty scope even when headline commercial terms are fixed. Ask for a supplier rider or schedule that sits on top of the standard terms, and confirm in the order of precedence clause that the rider wins in a conflict.

Which red flags should go to the CEO rather than be settled by counsel?

Business-level choices belong with the CEO: perpetual or irrevocable grants, exclusivity, onward transfer to other model developers, whether the buyer may name the company publicly, and any uncapped supplier liability. Drafting fixes such as definitions, certificate deadlines and order of precedence can usually be settled by counsel within positions the business has already approved.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify