Skip to content

Privacy and preparation

Security questionnaire to send a data licensee (template)

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A security questionnaire for a data licensee asks the company receiving your records how it will store, access, use, delete and protect them. Send it after scope is agreed and before signing, then turn the answers into contract terms. This template has 25 questions in five groups, each paired with what a good answer includes.

Key takeaways

  • Send the questionnaire after scope is agreed and before the license is signed, so answers can shape the contract.
  • Ask dataset-specific questions; a general attestation report covers the company, not your licensed records.
  • Every copy matters: training clusters, caches, backups, evaluation sets and contractor environments.
  • Deletion answers should cover derived copies and end with a signed certificate.
  • Attach the answers to the license so they become commitments rather than descriptions.

When to send a security questionnaire to a data licensee#

A security questionnaire for a data licensee works best after the dataset scope is agreed and before the license is signed. At that point the recipient knows what it will receive, and you can still turn weak answers into contract terms or change the delivery method.

Most companies know questionnaires from the other direction, answering a customer's vendor review. Standardized sets such as the Shared Assessments SIG family are broad and cover a whole vendor relationship. This template is narrower: it asks about one licensed dataset, how it will be used for AI training or evaluation, and what happens to it when the license ends.

Expect some recipients to reply with existing attestation reports plus short written answers. That is reasonable, provided the dataset-specific questions on copies, training use and deletion get direct answers.

Storage and environment: questions 1 to 5#

Storage questions establish where your records will live and how many copies will exist. Geography deserves a direct question: the Data & Trust Alliance's Data Provenance Standards include metadata fields for allowed and excluded processing and storage geographies, a sign that dataset recipients already track it.

Storage and environment: questions 1 to 5
QuestionA good answer includes
1. Where will the licensed dataset be stored and processed?Named cloud provider or facility and regions, plus any geographies the data will never enter
2. How is it encrypted at rest and in transit, and who controls the keys?Encryption described for each layer, with key management named
3. Is the dataset kept separate from other suppliers' data and tagged with its license?Logical separation and a dataset ID linking every copy to the license terms
4. What copies will exist?An inventory covering raw storage, training shards, caches, backups and evaluation sets
5. Which subprocessors or contractors will store or process it?A named list, their locations and the agreements that bind them

Access and personnel: questions 6 to 10#

Access questions show how many people and systems can reach the raw dataset, which is usually where exposure risk concentrates. Ask about contractors explicitly, because annotation and evaluation work is often outsourced.

Access and personnel: questions 6 to 10
QuestionA good answer includes
6. Which roles can access the raw dataset?Named roles and the reason each needs access, not a general statement about staff
7. How is access granted, reviewed and revoked?An approval workflow, periodic access reviews and removal on role change
8. Are single sign-on and multi-factor authentication required?Yes for every system holding the dataset, including contractor access
9. Will contractors or annotation vendors see the data?Named firms, their agreements and the subset each one receives
10. Is access to the dataset logged, and can logs be shared?Access logs retained and available on reasonable request

Training use and permitted purpose: questions 11 to 15#

Training use questions are the part generic questionnaires leave out. They check that the recipient's plans match the permitted-use clause and that nobody intends to undo your preparation work.

Training use and permitted purpose: questions 11 to 15
QuestionA good answer includes
11. Which models or products will use the dataset?A description that matches the permitted use in the license
12. Will it be used for training, evaluation or both?A clear answer, including whether resulting models are offered to third parties
13. Will you attempt to re-identify people or link the data with other datasets?A firm no, backed by a contract clause and an internal policy
14. How do you test models for memorized passages from licensed data?A described method for detecting verbatim output of names or internal identifiers
15. Will the dataset be shared, sublicensed or resold?No, unless the license expressly allows it

Retention, deletion and return: questions 16 to 20#

Deletion questions decide what you can prove at the end of the term. Ask about derived copies, not only the original files, and settle in advance whether trained model weights are affected, which licenses usually address in a separate clause.

Retention, deletion and return: questions 16 to 20
QuestionA good answer includes
16. What happens to the dataset when the license ends?Deletion or return by a stated method, matching the license term
17. Can derived copies be deleted?Yes for shards, caches, embeddings and evaluation sets, with any exceptions named
18. Will an officer sign a deletion certificate?A written certificate listing the copies destroyed and the method used
19. How do backups containing the dataset expire?A backup rotation that ends in deletion, and no restores for new uses
20. How will you handle a request to remove specific records after delivery?A process to locate and delete the records within an agreed window

Incident response and notification: questions 21 to 25#

Incident questions set expectations before anything goes wrong. Negotiate the notification window in the contract rather than accepting whatever the recipient's standard policy says.

Read any attestation report for what it actually covers. A SOC 2 report is an attestation by a CPA firm, not a certification; the security criteria appear in every report, while availability, processing integrity, confidentiality and privacy are included only if chosen. Check that the systems named in the report are the ones that will hold your dataset.

Incident response and notification: questions 21 to 25
QuestionA good answer includes
21. Does your incident response plan cover licensed third-party datasets?Yes, with a named owner and a tested procedure
22. How quickly will you notify us of an incident involving the dataset?A specific contractual window and the details the notice will contain
23. Who is the named security contact?A person or team with direct contact details
24. Have you had an incident involving third-party data, and what changed afterward?A candid summary and the controls added
25. Which independent reports can you share, such as a SOC 2 report or ISO 27001 certificate?Current reports under NDA whose scope covers the systems holding the data; a SOC 2 Type 2 report also tests whether controls operated over a period

How to read the answers and close the gaps#

Answers become useful once each one is accepted, turned into a contract term or treated as a reason to change the delivery. Judge them against your own risk and the sensitivity of the dataset, not against a perfect standard.

Illustrative: a fictional engineering firm sends this questionnaire before licensing its internal project review records. The recipient's answers are solid on storage and access but vague on derived copies and contractor access, so the firm's general counsel adds a deletion certificate clause covering evaluation sets, requires named annotation vendors, and attaches the full answers to the license as an exhibit.

  • No inventory of copies, or an answer that copies are not tracked.
  • Training use described more broadly than the permitted-use clause.
  • No answer on re-identification, or a refusal to commit to a prohibition.
  • Deletion limited to the original files, with derived copies left out.
  • Contractor access with no named firms or agreements.

How SourceX uses questionnaire answers#

SourceX treats the recipient's security and use commitments as part of the Approval and Delivery steps of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. The supplier sees those commitments before approving release.

Permitted use and release authorization are both components of the SourceX Evidence Packet, so what a licensee commits to in its answers sits beside the record of what was prepared and approved.

Frequently asked questions

Should we send SIG Lite instead of this template?

You can send both. A standardized questionnaire covers the recipient's overall security program, while this template asks about one dataset, its training use and its deletion. Many suppliers accept a recent standardized response for the general questions and send only the dataset-specific ones.

Do the answers bind the licensee?

Only if the contract says so. Attach the answers as an exhibit, or turn key answers into representations and covenants on permitted use, deletion and notification. Without that step, answers describe intentions rather than commitments.

What if the licensee is outside the United States?

Cross-border delivery raises separate questions about transfer rules, export restrictions and where data may be stored. Some US rules restrict transfers of certain bulk data to particular countries, so assess the destination with counsel before scoping delivery.

Do we need our own SOC 2 report to send this questionnaire?

No. The questionnaire assesses the recipient. A buyer may ask about your own security posture in the other direction, but your report is not a precondition for asking how your records will be protected once they leave.

How often should the questionnaire be refreshed?

Ask for updated answers at renewal, when the recipient adds a new use or subprocessor, or after a reported incident. For longer licenses, a periodic refresh of the storage, access and contractor answers agreed in the contract keeps the record current.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for allowed and excluded processing and storage geographies, license to use and intended data use. Source
  • SOC 2 examinations use the AICPA Trust Services Criteria covering security, availability, processing integrity, confidentiality and privacy; the security common criteria apply in every report, and a Type 2 report tests whether controls operated effectively over a period. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify