Skip to content

Definitions and comparisons

What is a data rights review, and what does it check?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A data rights review is a structured check of whether your company may license a defined set of records for a defined use, and what must be carved out first. It covers six areas: ownership, customer contracts, vendor terms, employee and contractor records, third-party content and prior licenses, and it produces a scope rather than a yes or no.

Key takeaways

  • A data rights review asks whether you may license specific records for a specific use, not whether you own your data in general.
  • Customer contracts and vendor terms are where most carve-outs come from.
  • The output is a scope: what is in, what is in only after redaction, what is out and which approvals are needed.
  • Rights reviews are repeated whenever new record families or new permitted uses are added to a license.

What is a data rights review?#

A data rights review is a legal and factual check of whether a company may license a defined set of records, such as Zendesk tickets from a set date range or a group of GitHub repositories, to a buyer for a defined use. It looks at who owns or controls the records, what contracts and notices say about them, and whether anyone else's rights are embedded in them.

The review is narrower than a general privacy or IP audit and more specific than asking whether the company owns its data. The same ticket archive can be licensable for model evaluation but restricted for training, or licensable except for one customer's accounts.

This is general information, not legal advice. Rights questions turn on specific contracts and the laws that may apply, so counsel should lead or check the review.

The six-item rights checklist#

The six-item rights checklist covers ownership, customer contracts, vendor terms, employee and contractor records, third-party content and prior licenses. Each item has its own source documents and its own typical result, and most reviews find something to carve out under at least one of them.

Treat the six items as a minimum. Industry-specific questions, such as franchise agreements for home services brands or client-owned designs at engineering firms, are added under the relevant item rather than handled as a separate exercise.

Two examples show why the reviewer reads the actual documents. For contractors, AIA A201-2017 Section 1.5.2 lets the contractor and its subcontractors use the architect's Instruments of Service only for performing the Work, and bars other uses without written consent from the owner, architect and the architect's consultants, so drawings and specifications received on a project usually fall under third-party content. For vendor terms, Section 8.4 of GitLab's Subscription Agreement (version GLSA_01.12.26 v8) says the customer retains all right, title and interest in Customer Content, subject to a limited license to GitLab that extends to developing and improving its software; older versions may read differently, so confirm which one your company signed.

The six-item rights checklist
ItemWhat the reviewer readsTypical result
OwnershipEntity records, acquisition agreements, asset transfer documentsConfirms which entity holds the records and can sign
Customer contractsMSAs, terms of service, DPAs, negotiated confidentiality clausesCarve-outs for customers whose contracts restrict use
Vendor termsTerms for the help desk, CRM, ERP and code hosting toolsNotes on export limits and any vendor AI training rights
Employee and contractor recordsPrivacy notices, handbooks, contractor IP assignmentsHR content excluded; IP in contractor work confirmed
Third-party contentOpen-source licenses, embedded documents, partner materialsMaterial the company does not control is removed
Prior licensesEarlier data deals, exclusivity grants, NDAsConfirms a new license does not conflict with an old one

Which documents should you gather first?#

The documents to gather first are the ones that govern the largest share of the records. A company with standard customer terms and few negotiated contracts can move quickly; one with many bespoke enterprise agreements needs a contract inventory before anything else.

Contract managers and account leads often know which customers negotiated unusual data terms, so ask them before searching every signed agreement.

  • Corporate chart, plus acquisition or merger agreements for any entity whose records are in scope.
  • Current and past versions of customer terms of service and the master service agreement template.
  • A list of customers with negotiated confidentiality, data use or data location clauses.
  • Vendor agreements and online terms for each system that holds in-scope records.
  • Employee privacy notices, handbook sections on monitoring, and contractor agreements.
  • Any prior data license, data sharing agreement or exclusivity commitment.
  • Credit agreements or investor documents with covenants on IP licenses or asset transfers.

How does a rights review change the license scope?#

A rights review changes the license scope by sorting records into categories, each with its own treatment. The review rarely says yes or no to an entire archive; it draws boundaries inside it, and those boundaries become the record list in the license.

Keep the reason next to each finding. When a buyer's diligence team asks why one customer's tickets are missing or why a repository was excluded, a short note tied to the contract clause answers the question without reopening the review.

How does a rights review change the license scope?
FindingEffect on scope
Company-owned internal records, no restrictions foundIncluded, subject to privacy preparation
Records mention customers but contracts are silent on useIncluded after customer identifiers are removed, if counsel agrees
A customer contract restricts sharing or useExcluded for that customer, or included only with consent
Customer-owned code or deliverablesExcluded
Vendor terms limit export or grant the vendor training rightsExport planned around the limit; vendor rights disclosed to the buyer
A prior exclusive license covers the same recordsExcluded until the exclusivity ends or is waived

When does the review happen, and who runs it?#

The rights review happens after a metadata fit check shows the records are worth pursuing and before any privacy preparation or sample leaves the company. Running it earlier spends legal time on records no buyer wants; running it later risks preparing records that cannot be licensed.

The general counsel or outside counsel usually leads, with the COO or CTO supplying facts about systems and record families. When an acquired company's records are in scope, involve someone who knows that company's history, because its old customer terms and vendor contracts are the documents most likely to be missing.

The review is also repeated over time. Adding a record family, extending the date range or changing the permitted use from evaluation to training each reopens part of the checklist, so keep the working file and not only the final memo.

Illustrative: a mechanical contractor reviews its job records#

Illustrative: a fictional mechanical and plumbing contractor wants to license service and project history from ServiceTitan and Procore. The general counsel runs the six-item checklist before any export is made.

Ownership is clear except for records from a smaller company acquired earlier, whose purchase agreement transferred its customer files but whose old service software terms are still being located. Several general contractors' subcontracts treat project documents as confidential, so Procore records for those projects are excluded. Technician notes include homeowner names and addresses, so they are included only after removal. No prior data licenses exist.

The resulting scope is ServiceTitan job, estimate and warranty history with personal details removed, plus Procore records from projects without confidentiality restrictions. The acquired company's records wait until its vendor terms are found.

How SourceX runs the Rights step#

Rights is the second step of the SourceX five-step transaction, after Supply and before Preparation. SourceX works through the checklist with the company and its counsel, and the findings become the licensing rights and permitted use sections of the SourceX Evidence Packet.

The company decides the final scope and approves it before preparation begins, so nothing is prepared for delivery that the company has not agreed to license.

Frequently asked questions

How long does a data rights review take?

It depends on the number and variety of contracts involved. A company with standard customer terms and a few systems can finish quickly; one with many negotiated enterprise agreements, acquired entities or unusual vendor terms needs longer. Building a contract inventory before the review starts is the most reliable way to shorten it.

What if a customer contract is silent on data use?

Silence is not permission, but it is not a prohibition either. Counsel typically looks at confidentiality clauses, definitions of customer data and privacy commitments. Many companies include such records only after customer identifiers are removed, and some ask the customer directly when the relationship allows it.

Does a rights review cover privacy law?

Partly. It checks notices and contract commitments about personal information, but the detailed privacy analysis, such as which laws may apply and what role the buyer plays, usually runs as a separate workstream alongside it and shapes how records are prepared.

Can we start before every contract is found?

Yes, by scoping in stages. Records whose rights are clear can proceed, while records tied to missing contracts wait. Staged scoping is common after acquisitions, where older agreements can be hard to locate. Record which records are pending and why, so the next stage picks up where the first one stopped.

Do we need outside counsel for a rights review?

Not always. In-house counsel familiar with the company's contracts can lead it. Outside counsel helps with unusual issues, such as acquired entities, cross-border records or prior exclusive licenses, and with drafting the license itself. Either way, the reviewer needs the actual signed documents, not summaries of them.

What does a buyer see from the rights review?

Usually not the internal memo, which may be privileged. Buyers typically see the outcome: a description of the licensed records, the permitted use, the exclusions and confirmation that the licensor has the right to grant the license, often backed by representations in the contract itself.

Sources

  • AIA A201-2017 Section 1.5.2 authorizes the Contractor and its subcontractors and suppliers to use and reproduce the Instruments of Service only for performing the Work, and bars other uses without the specific written consent of the Owner, Architect and the Architect's consultants. Source
  • Section 8.4 of the GitLab Subscription Agreement (version GLSA_01.12.26 v8) states the customer retains all right, title and interest in Customer Content, subject to a limited license to GitLab necessary for providing the Software and its development and improvement. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify