Skip to content

Software companies

What if a customer objects after their data was licensed?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

When a customer objects after its data was licensed, two documents decide what happens: your contract with that customer and your license with the AI developer. Answer with evidence first, confirming whether the customer's records were in scope at all. Then stop future deliveries and use whatever removal terms the license already contains.

Key takeaways

  • Most objections are settled by showing exactly what was and was not delivered, so keep a record-level manifest for every delivery.
  • Future deliveries are always in your control; copies already delivered come back only if the license provides for it.
  • Sort the objection by type before replying, because a privacy complaint, a confidentiality claim and a reputational concern need different remedies.
  • Removal, suppression and deletion-certification terms have to be negotiated before the first delivery, not after a complaint.

What happens legally when a customer objects to a data license?#

A customer objection starts a review of your rights; it does not automatically mean the license was a breach. The answer turns on what the customer agreement permitted when the records were prepared, what actually reached the licensee, and what the data license lets you change after delivery.

For a SaaS company, the objection usually arrives through an account manager or a procurement contact, not through legal. The first job of the general counsel is to get it into one channel, in writing, before sales promises a deletion the company cannot deliver or concedes a breach that did not happen.

Sort the objection before you answer it#

Objection type determines the remedy, so classify each complaint before drafting a reply. Customers rarely use legal language, and the same sentence, such as "we never agreed to this", can mean a contract claim, a privacy worry or simple surprise.

The table below pairs common objections with the first record to pull and the remedy that usually fits. Keep the classification in the matter file; it shows later why the company chose one response over another.

Sort the objection before you answer it
What the customer saysWhat it usually meansFirst record to checkRemedy that usually fits
You used our data without permissionA contract or ownership claimCustomer agreement data-use and aggregated data clausesShow the permitting clause, or exclude and remove
Our employees' or clients' details are in itA privacy concernPrivacy record and de-identification method for that deliveryVerify redaction, then suppress or remove
You disclosed our confidential informationA confidentiality claimConfidentiality definition and the delivered recordsRemove affected records and certify deletion
We do not want to help train AIA preference or reputational concernNotices and FAQs the customer receivedSuppress from future deliveries, explain scope
Nobody told usA communication gapCustomer notice history and account emailsExplain what was licensed and offer an opt-out
Delete it from the model tooA request beyond the recordsLicense terms on trained modelsExplain what the license covers and what it does not

A written playbook keeps the company consistent when the second and third objections arrive. Run the same steps every time, and keep sales and support on scripted acknowledgments until legal has an answer.

Speed matters less than accuracy here. A fast reply that guesses wrong about scope is harder to walk back than a short acknowledgment followed by a precise answer.

  • Log the objection: who raised it, their authority to speak for the customer, the exact wording and the date received.
  • Acknowledge in writing that the company is reviewing the concern, without admitting breach or promising deletion.
  • Pull the delivery manifest and check, by customer and account identifiers, whether any of that customer's records were delivered.
  • Place the customer on the suppression list immediately so nothing new ships while the review runs.
  • Read the customer agreement, any order form changes, the DPA and any AI or data-use addendum that applied at preparation time.
  • Decide the remedy, and if it involves the licensee, send notice under the license using record IDs rather than the customer's name.
  • Confirm the outcome to the customer in writing, stating what was delivered, what was removed and what will not ship again.
  • Update customer notices, the internal FAQ and the scoping rules so the same gap does not recur.

Contract terms that make removal possible#

Removal is possible only where terms on both sides of the transaction anticipate it. The customer agreement decides whether the records could be licensed at all, and the data license decides whether anything can be pulled back once delivered.

General counsel should review both columns before the first delivery. A gap on either side leaves the company with goodwill requests instead of enforceable rights.

Contract terms that make removal possible
TermWhere it livesWhat it lets you do
Data-use or aggregated data clauseCustomer agreementShows the company had the right to use the records in the first place
Customer opt-out rightCustomer agreement or AI addendumGives a clear path for customers who decline, before or after delivery
Removal on noticeData licenseRequires the licensee to delete identified records it already holds
Suppression and replacementData licenseLets the supplier exclude records from refreshes and substitute others
Deletion certificationData licenseProduces written proof to show the objecting customer
No re-identification and no onward transferData licenseLimits the spread of records and supports the privacy position
Trained-model provisionsData licenseStates what happens to models and evaluation sets after removal

What a remedy can and cannot reach#

A remedy reaches records the company still controls and records the licensee agreed to give back; it rarely reaches a model that has already been trained. Explaining that boundary early prevents a customer from expecting a result no one can deliver.

Suppression handles the future: the supplier simply stops including that customer's records in any refresh or new package. Stored copies at the licensee are reachable through a removal clause and a deletion certificate. Trained model weights are a different matter: licenses typically address them by limiting future training runs and evaluation use rather than promising to undo past training, and that is the term to negotiate if your customers are likely to ask.

Whatever the remedy, describe it precisely. "Your records will not be included in any future delivery, and the licensee has certified deletion of the copies it held" is an answer a customer's counsel can accept; "we have taken care of it" is not.

Illustrative: a dispatch software vendor answers a large account#

Illustrative: a fictional maker of dispatch software for elevator service companies licensed de-identified Zendesk tickets and linked Jira issues to an AI developer. Several months later, the operations director at one of its largest customers emailed the account manager to say the customer had never agreed to its data training anyone's AI.

The general counsel logged the objection, put the customer on the suppression list and checked the delivery manifest. Tickets from the customer's admins were in the delivery, with company names and contact details removed, and the customer agreement contained a clause allowing de-identified support data to be used for product and service purposes, which did not clearly cover licensing.

Because the clause was ambiguous, the company chose not to argue it. It sent a removal notice under the license using record IDs, received a deletion certificate, and gave the customer a written summary of what had been delivered and removed. It then updated its customer FAQ and added an explicit AI-licensing opt-out to its renewal paperwork.

How SourceX handles objections and removal#

SourceX builds removal into the transaction rather than treating it as an exception. In the SourceX five-step transaction (Supply, Rights, Preparation, Approval, Delivery), the Rights step reviews customer agreements before any record is prepared, and customers whose contracts restrict use are excluded at that stage.

Each delivery is documented in a SourceX Evidence Packet covering provenance, licensing rights, permitted use, the privacy record and release authorization, so a supplier can answer "was our data included?" from a record rather than from memory. Removal and suppression terms are negotiated in the license itself, and the supplier approves every step. Industry provenance metadata points the same way: the Data & Trust Alliance's Data Provenance Standards include fields for consent documentation location and license to use.

Frequently asked questions

Do we have to tell the licensee which customer objected?

Usually not. The licensee needs enough to find and delete the records, which means delivery and record identifiers, not the customer's name. Putting the customer's name in a notice to a third party risks a fresh confidentiality problem on top of the original one. Check whether the license specifies the notice format, and keep the mapping between customer and record IDs inside your own company.

Can one customer's objection put the whole license at risk?

It can if the license contains a rights warranty and the objecting customer's contract did not permit the use, because the licensee may then have a warranty claim. That is why rights review happens before preparation. If an objection reveals a wider contract problem across many customers, review the full delivery with counsel rather than handling complaints one by one.

What if the objection comes from an individual rather than a customer company?

Treat it as a privacy request first. Laws such as the CCPA or GDPR may give individuals rights over personal information, depending on where they are and what was delivered. Route it through the company's privacy request process, check the privacy record for that delivery, and assess the response with counsel.

Does de-identification end the discussion?

No. De-identification lowers privacy risk, but a customer can still have a confidentiality or contract objection to de-identified records that describe its operations, configurations or problems. Answer the objection the customer actually raised, and do not rely on redaction to resolve a question about permission.

How can a SaaS company reduce objections before licensing?

Tell customers what is licensed and what is not, in plain language, before the first delivery. Exclude customers whose agreements forbid AI use, offer a simple opt-out, and give account managers a short script. Customers who learn about a license from their own vendor rarely react the way customers who learn about it secondhand do.

Sources

  • The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify