Skip to content

Getting started

What documents prove you have the right to license your data?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Proof of data rights is a set of documents showing where records came from, that your company may license them, what use is permitted, how personal details were handled and who authorized release. Gather the evidence under those five headings before a buyer asks. A missing document is a reason to narrow the scope, not to rely on a warranty.

Key takeaways

  • Buyers ask for evidence because a contract warranty allocates risk but does not prove anything.
  • Group the evidence under provenance, licensing rights, permitted use, privacy record and release authorization.
  • Customer contracts, privacy notices, IP assignments and vendor terms are the documents most likely to limit scope.
  • Acquired and wound-down companies need extra provenance: purchase agreements and proof of who may sign.
  • Where evidence is missing, exclude the affected records or close the gap before licensing them.

Why buyers ask for proof instead of a promise#

Buyers ask for proof of data rights because a warranty in the license only says who pays if something goes wrong. AI developers are increasingly asked by their own investors, customers and, in some jurisdictions, regulators to show where training data came from, so they ask suppliers for documents, not just signatures.

Industry standards point the same way. The Data & Trust Alliance's Data Provenance Standards, published as a version 1.0.0 specification, organize dataset metadata into three groups, Source, Provenance and Use, and state that this metadata is needed to enable proper dataset selection for AI model training. The Use group includes items such as confidentiality classification, where consent documentation is kept, license to use and intended data use.

Gathering the evidence also protects you. Counsel can see which records are clean, which need work and which should be excluded, before anyone negotiates. Which laws and contract terms may apply is assessed deal by deal.

Provenance: where the records came from#

Provenance evidence shows which system produced the records, who exported them, when and how, and how the company came to hold them. It answers the first question any buyer asks: are these really your records?

Provenance is easiest to document at the moment of export and hardest to reconstruct afterward. If records were exported years ago by someone who has since left, re-run the export from the source system where it still exists, or record what is known about the old export and flag the gap.

  • System of record and account ownership: the vendor contract or hosting agreement in the company's name.
  • Export log: date, system, query or export method, and the person who ran it.
  • Data dictionary: fields, formats, date range and known gaps.
  • Chain of title for acquired businesses: the purchase agreement and the schedules listing records and systems transferred.
  • For closed or wound-down companies: the document that gives the signer authority, such as a board resolution, trustee appointment or assignment for the benefit of creditors.

Licensing rights: why the company may license the records#

Licensing rights evidence shows that no contract, notice or third-party interest prevents the company from licensing the records. Most scope reductions come from this heading, so review it one record family at a time.

Licensing rights: why the company may license the records
Record familyDocuments to checkWhat to look for
Support conversationsCustomer agreements, terms of service, privacy noticeConfidentiality, limits on reuse, clauses on de-identified data
CRM historiesPrivacy notice, list purchase terms, partner agreementsLimits on using purchased or partner contact data
Employee email and chatHandbook, IT use policy, confidentiality agreementsNotice that company systems and their contents belong to the company
Code and engineering workEmployee and contractor IP assignments, open-source licensesGaps in assignments, third-party or customer code
Project and client workClient agreements and statements of workClient ownership of deliverables and confidential material
Vendor-hosted recordsSaaS terms and data processing agreementsRestrictions on export or onward use

Permitted use: what the license allows#

Permitted use evidence defines what the buyer may do with the records and shows that the company decided it deliberately. It turns a general intention into a written scope that matches the rights you found.

The core document is the term sheet or license schedule describing allowed uses, such as training or evaluation, any field-of-use limits, excluded uses and the term. Add the internal exclusion list: customers with restrictive contracts, client projects, record types removed for sensitivity, and any buyers you have ruled out. A reader of the scope should be able to see why each exclusion exists.

Privacy record: how personal and confidential details were handled#

The privacy record documents what personal and confidential information the records contained, which rules may apply to it and what was done about it. Laws such as CCPA and other state privacy laws, and in some cases GDPR, may apply depending on whose data is involved and where those people live; counsel assesses that for each deal.

  • A data map of personal data categories in each record family.
  • The privacy notices in force across the whole period the records cover, not just today's version.
  • The preparation method: what was excluded, redacted or pseudonymized, and with which tools.
  • Quality review results: how samples were checked and what was corrected.
  • Records excluded because notice or consent could not be confirmed.

Release authorization: who approved the release#

Release authorization evidence shows that someone with authority approved this specific release of these specific records. Without it, even complete rights evidence leaves the buyer unsure the license binds the company.

Collect the board resolution or written officer approval, the delegation of authority if a manager signs, and any investor or lender consents the company's documents require. Then tie the approval to a versioned dataset manifest, so the authorization covers exactly what was delivered rather than an earlier draft.

Each later delivery under the same license, such as a refresh with newer records, needs its own authorization tied to its own manifest. A single approval for an open-ended stream of records is harder to defend.

When a document is missing#

A missing document usually means narrowing the scope, not abandoning the license. The table shows common gaps and the usual responses, which counsel tailors to each case.

Decide on each gap before preparation starts. Records that will be excluded should never enter the preparation pipeline, because removing them later means re-running redaction, review and the dataset manifest.

When a document is missing
Missing evidenceUsual response
No IP assignment from early contractorsExclude their work or obtain confirmatory assignments
Customer contract silent on reuseCounsel assessment, de-identification, or exclusion of that customer
Older privacy notice did not cover the useRemove personal data from that period entirely
Acquired company contracts never assignedExclude those records until assignment is confirmed
No export logRe-run the export with logging before release

Illustrative: a 3PL narrows its package to what it can prove#

Illustrative: a fictional third-party logistics provider wants to license warehouse exception records from its WMS: damaged receipts, short shipments, mis-picks and the notes that resolved them. Its general counsel works through the five headings one at a time.

Licensing rights is where the scope changes. Several client contracts treat all data about the client's goods as client property, so those clients are excluded. A warehouse acquired a few years earlier came with records but no assignment of its customer contracts, so its history is parked until assignment is confirmed.

The rest falls into place. Provenance comes from fresh export logs, the privacy record shows driver and receiver names removed, and the CEO signs the release after the lender confirms no consent is needed. The package is narrower than first planned, and every record in it is backed by a document.

How SourceX organizes the evidence#

SourceX assembles this evidence into the SourceX Evidence Packet, using the same five headings: provenance, licensing rights, permitted use, privacy record and release authorization. The packet is put together during the SourceX five-step transaction, before anything is delivered.

The supplier approves every step, and the packet gives supplier and buyer the same written record of what was licensed and why. The initial assessment uses metadata only, so counsel can start assembling evidence before any record leaves the company.

Frequently asked questions

Does paying for a software subscription mean we own the data in it?

Vendor terms often say the customer owns its data, but ownership is not the whole question. The records may contain customer communications, third-party content or personal data that other agreements and laws govern. Check the vendor terms for export or onward-use restrictions as well.

Can a warranty in the license replace the documents?

No. A warranty allocates liability between the parties if the rights turn out to be wrong; it does not establish them. Buyers want both, and a supplier that gives a warranty without evidence is accepting a risk it cannot measure.

How far back does the evidence need to go?

As far back as the records you license. If the dataset covers many years, you need the privacy notices, customer terms and policies that applied in each of those years, not only the current versions. Older periods with missing documents are often the first to be excluded.

Do we have to show our customer contracts to the buyer?

Usually not in full. Suppliers commonly provide a summary of the contract review and give representations about it, while keeping individual contracts confidential. Agree with counsel what the buyer may see and under which confidentiality terms.

Who should assemble proof of data rights?

General counsel or outside counsel should own it, working with IT on provenance and export logs, record owners on exclusions, and the CFO or corporate secretary on approvals and consents. A single owner keeps the evidence consistent across all five headings.

Sources

  • The Data & Trust Alliance's Data Provenance Standards (version 1.0.0 specification) define dataset metadata in three groups: Source, Provenance and Use. The specification says this metadata is needed "to enable proper dataset selection for AI Model Training." Source
  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify