Rights and contracts
Sublicensing and onward transfer in data licenses: affiliates, vendors, clouds
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
A sublicensing clause in a data license decides who besides the licensee may use or handle the licensed records. Sort everyone into three groups: affiliates that may use the records for their own purposes, service providers that handle them only on the licensee's behalf, and third parties that get nothing. Require written flow-down terms for the first two.
Key takeaways
- A sublicense gives another party its own right to use the records; service-provider access does not.
- Affiliates, annotation vendors, cloud hosts and evaluation contractors each need a named position in the license.
- Every party allowed to touch the records should be bound by flow-down terms at least as protective as the license.
- The licensee should stay fully liable for what its affiliates and vendors do with the records.
- Onward transfer of the records themselves, as distinct from model outputs, is usually prohibited outright.
What does a sublicensing clause control in a data deal?#
A sublicensing clause controls whether the licensee may pass its rights in the records to someone else, and on what conditions. In software licenses the clause is often a single line; in data licenses it carries more weight, because a copy of a dataset cannot be recalled once it leaves the licensee's environment.
Two ideas are easy to blur. A sublicense gives another party its own right to use the records for its own purposes. Service-provider access lets a vendor handle the records only to perform work for the licensee, such as hosting, labeling or security review. Most supplier-friendly agreements prohibit sublicensing by default and allow service-provider access under conditions.
Onward transfer is the broader concern: any movement of the records, or a copy, to a person outside the licensee. A clean agreement says which transfers are permitted, to whom, under what terms, and how the supplier will know.
Who may touch the data: a checklist by party#
Each party that might touch the records needs a stated position in the agreement. The checklist below covers the parties that come up most often in AI data deals; the right answer for each depends on the records, the buyer and the supplier's appetite for risk.
| Party | Common supplier position | Flow-down terms to require |
|---|---|---|
| Licensee affiliates | Allowed only for named affiliates or those under common control, or not at all | Same permitted use, licensee liable for affiliate breach, rights end if control ends |
| Cloud hosting provider | Allowed as a service provider inside the licensee's own tenancy | No provider use for its own purposes, encryption, location limits if any |
| Annotation and labeling vendors | Allowed under a written services agreement after privacy preparation | Confidentiality, no retained copies, no training of vendor models, worker access controls |
| Evaluation and red-team contractors | Allowed for testing the licensed models only | Use limited to the engagement, deletion at completion |
| Licensee's customers | No access to the records; model access only | Not applicable, because records do not move |
| Acquirer of the licensee | Only through the assignment clause, often with consent | Assignee assumes every obligation in writing |
| Research collaborators or public benchmarks | Prohibited unless the supplier approves in writing | Case-by-case terms if ever allowed |
Which flow-down terms should travel with the records?#
Flow-down terms are the obligations the licensee must impose on anyone it lets handle the records. The test is simple: a vendor or affiliate should never be in a looser position than the licensee itself.
Where records still contain personal information after preparation, state privacy laws may also require specific contract terms with service providers and contractors. Counsel should check whether the flow-down set needs to carry those terms, which is one more reason to finish privacy preparation before any vendor sees the records.
- Use limited to the licensee's permitted purpose and nothing else.
- Confidentiality at least as protective as the license.
- Security controls, access logging and named roles for people who view the records.
- No further sublicensing or onward transfer.
- No attempt to re-identify people or companies removed during preparation.
- Return or deletion when the work ends, with written confirmation.
- Prompt notice to the licensee of any incident, passed on to the supplier.
- Licensee liability for the acts of every party it brings in.
How should cloud storage and processing be treated?#
Cloud storage is usually treated as service-provider access when the records sit in the licensee's own cloud account under its control. The question to ask is not which hyperscaler is used but whose account holds the records, who holds the encryption keys and whether the provider's terms allow it any use of customer content beyond running the service.
Delivery design matters as much as contract text. Large deliveries often stay in the supplier's own storage or ship on encrypted drives, so the agreement should say where the licensee may copy the records, whether copies may move between regions and when working copies must be destroyed.
Managed AI services add a wrinkle. If the licensee trains through a hosted service run by a cloud provider, check that the service terms keep customer training data out of the provider's own models and that logs or caches holding record excerpts follow the same deletion rule.
Annotation vendors and human reviewers need extra care#
Annotation vendors and human reviewers see records in readable form, which makes them the most sensitive point in the chain. Privacy preparation should be finished before any labeler sees a record, so that names, contact details and confidential customer facts are already removed.
Ask how the vendor's workforce is organized: employees or a crowd platform, which countries, which tools, and whether reviewers can download or screenshot content. Require that the vendor not use the records to train or improve its own labeling models, a term that is easy to miss in standard vendor paper.
Drafting gaps that quietly widen access#
Drafting gaps that widen access usually sit in definitions rather than in the sublicensing clause itself. A tight prohibition on sublicensing can be undone by a broad definition of 'Licensee' or 'Representatives' elsewhere in the agreement.
Read the agreement end to end with one question in mind: through which words could a person outside the licensee lawfully end up holding a copy? The gaps below are the ones general counsel find most often.
- 'Licensee' defined to include all present and future affiliates worldwide.
- 'Representatives' covering advisors, financing sources and potential investors with access to confidential information.
- A confidentiality clause that allows disclosure to anyone with a need to know, without use limits.
- Assignment permitted without consent in any merger or sale of assets.
- No rule on copies held in backups after deletion is required.
- Vendor terms incorporated by reference that override the license.
Illustrative: a 3PL limits who sees its exception records#
Illustrative: a fictional third-party logistics provider licenses years of warehouse exception records, including WMS exception notes, carrier claim emails and resolution codes. The buyer's draft lets it share the records with 'affiliates, contractors and service providers' with no further conditions.
The 3PL's general counsel replaces that sentence with a short schedule. One named affiliate may use the records for the same permitted purpose. One annotation vendor may label resolution notes under flow-down terms and a no-retention rule. The buyer's cloud tenancy is the only storage location. Everything else, including research release and benchmark publication, needs written approval.
The buyer agrees, adds a duty to notify the 3PL before changing annotation vendors, and signs a yearly attestation of who held copies. The 3PL can now answer a customer's question about where its exception history went.
How SourceX records onward-transfer permissions#
SourceX settles onward-transfer permissions during the Rights step of the SourceX five-step transaction, Supply, Rights, Preparation, Approval and Delivery, before any records are prepared or delivered. The supplier decides which affiliates, vendors and storage locations may handle the records.
The approved list of parties and conditions becomes part of the permitted-use entry in the SourceX Evidence Packet. When a customer or auditor later asks where the records went, the supplier can point to that entry and to the delivery record rather than to a buyer's general assurance.
Frequently asked questions
Is a sublicense the same as an assignment?
No. An assignment transfers the whole agreement, rights and obligations, to a new party, such as an acquirer of the licensee. A sublicense leaves the original licensee in place and grants a narrower right to someone else. Supplier-friendly agreements usually restrict both, with assignment allowed only with consent or in defined change-of-control cases.
Can the buyer share model outputs with its customers?
Usually yes, because outputs are what the buyer sells or uses, and agreements commonly treat them separately from the records. The supplier's concern is outputs that reproduce records verbatim. Some suppliers ask for reasonable measures against regurgitation of identifiable content.
What happens to vendors and affiliates when the main license ends?
Their permission should end at the same moment. The agreement can require the licensee to make sure affiliates and vendors stop using the records, return or delete their copies and confirm it in writing, so no permission outlives the license that created it.
Should a supplier ask for the name of every vendor?
That depends on the sensitivity of the records. Some suppliers want a named list with notice and a right to object to changes; others accept categories of vendors with a commitment to apply flow-down terms. Highly sensitive records justify the stricter approach.
Can the buyer publish samples in a research paper?
Not unless the agreement allows it. Most supplier-friendly licenses prohibit publishing records or excerpts, including in papers, demos and benchmarks, without written approval, because published samples can expose confidential details and cannot be withdrawn.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.