Skip to content

Leadership and readiness

Return-or-destroy clauses: what they mean for records you want to keep

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A return-or-destroy clause requires a party that received confidential information or customer data to give it back or destroy it when a contract ends or on request, often with written certification. For records you want to keep or license, scope is the key question: whether the clause reaches notes, derived copies and de-identified versions, and what it carves out.

Key takeaways

  • Return-or-destroy duties sit in NDAs, customer agreements, data processing agreements and consulting engagement letters.
  • A clause that covers materials derived from confidential information can reach internal notes, tickets and analyses.
  • De-identification removes personal identifiers but does not by itself remove a customer's confidential business information.
  • Records your company certified as destroyed should never appear in a licensing package, even if a copy survived.
  • Your own outbound data license needs a return-or-destroy clause that says what happens to the buyer's derived data.

What does a return-or-destroy clause require?#

A return-or-destroy clause requires the receiving party to return or destroy the disclosing party's information when the agreement ends or when the disclosing party asks. Most versions also require a written certificate confirming that destruction happened.

The details vary more than the name suggests. Some clauses let the receiving party choose between return and destruction, while others give that choice to the discloser. Many carve out copies held in routine backups, copies kept to satisfy law or regulation and copies needed for a legal hold, usually on the condition that confidentiality continues to apply to whatever is kept.

For licensing, the clause matters because it can turn records you thought you could use into records you were obliged to delete. It is often the reason a promising archive narrows during rights review, so it is worth reading early rather than at signing.

Where these clauses sit in your contract stack#

Return-or-destroy duties appear wherever your company received information it did not create. A rights review that checks only the main customer agreement will miss the ones in side letters, statements of work and old NDAs.

Older agreements deserve the same attention as current ones. The clause that governs a record is the one in force with that customer when the relationship ended, so match each record family's date range to the contract versions that applied, and note which customer relationships have already ended and triggered the duty.

Where these clauses sit in your contract stack
AgreementWhat it usually coversEffect on records you keep
Mutual or one-way NDAInformation exchanged during talks, pilots or evaluationsNotes and files from deals that never closed may be owed back
Customer master agreementCustomer data, confidential information and project inputsTickets, attachments and project files can fall in scope at termination
Data processing agreementPersonal data processed on the customer's behalfDeletion or return may be required at the end of services, with narrow retention exceptions
Consulting engagement letter or SOWClient materials provided for the engagementClient-provided files are usually out; your own work product needs a separate read
Vendor or supplier agreementPricing, specifications and technical data you receivedSupplier drawings or price files in your ERP may be restricted
Acquisition NDA or data room termsTarget information reviewed during a deal that did not closeCopies may be owed back or destroyed when talks end, and reuse is usually barred

A checklist for reading the clause#

Reading a return-or-destroy clause well means answering the same questions every time. Record the answers per agreement, so the rights review can group contracts with similar terms instead of rereading each one.

To find the clauses quickly in a contract repository or shared drive, search for phrases such as return or destroy, certify in writing, upon termination, derived from, residuals and aggregated. Each hit is a candidate clause to log against the agreement and the record families it touches.

  • Trigger: termination, expiry, a written request or the end of a specific project.
  • Scope: confidential information, customer data, personal data or all materials received.
  • Derivatives: whether notes, summaries, analyses or other materials containing or derived from the information are included.
  • Election: who chooses between return and destruction.
  • Certification: whether an officer must certify destruction in writing, and whether that has already happened.
  • Carve-outs: backups, legal and regulatory retention, legal holds and residual knowledge.
  • Aggregated or de-identified data: whether the clause expressly allows keeping it, and on what conditions.
  • Survival: whether confidentiality continues to bind any copies that are kept.

The decision rule for derived and de-identified copies#

The safest decision rule for derived and de-identified copies is this: if the clause covers derived materials, treat them as covered unless an express carve-out applies, and if the clause is silent, get counsel's view before relying on de-identification. Removing names and contact details addresses privacy, but a customer's pricing, specifications or business problems can stay confidential with every identifier stripped.

Your own work product is often a different matter. A fix your engineers wrote, a playbook your consultants built or an estimating method your team developed may belong to you even when a customer's request prompted it, although contracts that assign deliverables to the client can change that.

The decision rule for derived and de-identified copies
Copy typeUsual starting positionWhat to confirm
Original files the customer providedLikely covered; return or destroyNothing further; exclude from licensing
Tickets or emails quoting customer contentLikely covered if derivatives are in scopeWhether quoted material can be removed and the rest kept
Internal analyses built on customer dataCovered if the clause names analyses or derived materialsExpress carve-outs for aggregated or statistical outputs
De-identified recordsNot automatically outside the clauseAn express de-identification carve-out and its conditions
Aggregated metrics across many customersOften permitted when expressly carved outWhether any single customer could be singled out
Your own work product and methodsOften yours unless assigned to the clientDeliverable ownership and assignment terms

What if destruction was owed but never happened?#

Records that should have been destroyed but survived can turn up in helpdesk archives, shared drives and email, especially after staff turnover or a system migration. Exclude those records from any licensing package, and let counsel decide whether the surviving copies now need to be destroyed.

The risk is sharpest where an officer already signed a certificate of destruction. Licensing a record your company certified as gone would contradict a written statement to a customer, so search contract files and legal correspondence for certificates before scoping any record family that touches that customer.

Where the obligation was owed but no certificate was given, a former customer can sometimes be asked to consent to keeping specific material. Treat that as a negotiation with counsel involved, not as a default.

Illustrative: a consulting firm reviews its engagement archive#

Illustrative: a fictional operations consulting firm wants to license its internal knowledge, including proposal templates, project review notes, staffing plans and the playbooks its partners refined over many engagements. The records live in SharePoint engagement folders, Salesforce and a proposal library.

The rights review pulls every client engagement letter and finds return-or-destroy clauses in most, several of them covering materials derived from client information. The firm excludes all client-provided files and every engagement folder where a destruction certificate was issued. It keeps the playbooks and proposal templates, which counsel confirms are the firm's own methods, after removing client names and figures. The licensable scope shrinks, but every record left in it traces to a clear right.

Return-or-destroy terms in your own data license#

Return-or-destroy terms in your outbound data license protect your company the way your customers' clauses protect them. The license should say when the buyer must delete licensed records, how deletion is certified and how backups are treated.

Derived data needs the most attention. Trained models may be treated differently from the records themselves, so agree in advance what survives the term and what must be deleted, such as raw records, extracts and derived datasets. SourceX checks inbound return-or-destroy duties during the Rights step of the SourceX five-step transaction, before any record is scoped, and records the agreed permitted use in the SourceX Evidence Packet alongside provenance, licensing rights, the privacy record and release authorization.

Frequently asked questions

What should a certificate of destruction say?

A certificate of destruction usually identifies the agreement, describes the information destroyed, states the method and date, notes any copies kept under a carve-out such as backups or a legal hold, and is signed by an authorized officer. File it with the contract, because it later tells your rights review which records are off limits.

Do routine backups breach a return-or-destroy obligation?

Often not, if the clause carves out backups that are not readily accessible and confidentiality continues to apply to them. Restoring records from those backups for a new purpose, such as licensing, is a different act, so do not treat backup copies as a source of licensable records without counsel's view.

Does a legal hold override the clause?

A legal hold can require you to keep information a contract would otherwise require you to destroy, and many clauses expressly allow for it. The kept copies remain confidential and are held for the litigation or investigation, not for other uses such as licensing.

Can we ask a former customer for permission to keep certain records?

Yes, and some customers agree when the request is narrow, such as keeping de-identified ticket text or aggregated metrics. Put any consent in writing, describe exactly what is kept and for what purpose, and have counsel review the wording before relying on it.

Do return-or-destroy clauses reach email?

They can. Customer information sent by email sits in mailboxes and archives that a broad clause may cover, which is one reason email is often scoped narrowly or excluded in licensing reviews.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify