Manufacturing
Who owns telemetry from machines you sold?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Telemetry from machines you sold is rarely owned outright by anyone; your sale terms, embedded software license and service contracts decide who may use it. Installed base telemetry ownership turns on those documents, plus privacy laws and, for EU customers, the EU Data Act. License only fleet data your terms clearly permit, stripped of customer identity and process recipes.
Key takeaways
- Machine data rights are mostly set by contract, so the useful question is who may use the data, for what, and with whose consent.
- Sale terms, controller software licenses, portal terms and service agreements can each grant or limit telemetry rights.
- Machine health data is usually the strongest licensing candidate; customer recipes, setpoints and part programs usually stay out.
- EU customers add statutory layers, including the EU Data Act and GDPR, that counsel should map before EU fleets are scoped in.
- Fixing data clauses for new sales stops the rights gap from growing with every unit shipped.
Who controls telemetry once the machine is on the customer's floor?#
Control of telemetry from a sold machine is set mainly by contract, not by who built the sensor or who holds the hardware. The customer owns the machine, you may still own the controller software, and the agreements between you say who can access, use and share what the machine reports.
That is why asking who owns the data often produces a less useful answer than asking who may use it, for what purpose, and with whose consent. A licensing review asks the second question, document by document, for each group of customers in the installed base.
Three things usually decide the answer: the terms that governed the sale, the license for the embedded software or connectivity portal, and any service or remote monitoring agreement signed later. Privacy laws and the EU Data Act may then add obligations that sit on top of the contract.
Which documents decide telemetry rights?#
The documents that decide telemetry rights are usually spread across sales, engineering and service, and no single team holds all of them. Pull every version in use over the life of the installed base, because older units may sit under very different terms than newer ones.
Inside each document, read the definitions before the grant. Look for defined terms such as Machine Data, Usage Data, Customer Data, Aggregated Data or Feedback, then find the permitted-use clause attached to each. A right to use usage data to provide and improve the products is much narrower than a right to use, aggregate and commercialize de-identified data for any purpose, and only the second clearly reaches a third-party license.
| Document | What to look for | Common pattern |
|---|---|---|
| Terms and conditions of sale | Data, confidentiality and software clauses | Older terms are often silent on data, which leaves the question open rather than settled in your favor |
| Embedded software or controller license | Rights in machine-generated data and diagnostic output | Many reserve use of diagnostic and usage data for support and product improvement |
| Remote monitoring or portal terms | What is collected, permitted uses, sharing with third parties | Often the clearest grant, but only for customers who accepted them |
| Service and maintenance agreements | Use of data gathered during service visits and uptime programs | Some limit use to performing the service; others allow aggregated analysis |
| Customer purchase order terms | Clauses claiming ownership of all data about the customer's operations | Large buyers' terms may claim the data, and which terms formed the contract becomes a question for counsel |
| Dealer and distributor agreements | Who holds the end-customer relationship and service history | A distributor may control the customer list and the service records |
What can you license in common customer scenarios?#
What you can license depends on which scenario each customer group falls into. Sort the installed base by scenario first, then decide scope group by group rather than for the fleet as a whole.
For US customers, there is generally no statute that assigns ownership of machine data, so contracts, confidentiality duties and trade secret law carry most of the weight. State privacy laws may apply where telemetry includes personal information, and some state right-to-repair laws may require access to diagnostic tools or information for certain equipment. Counsel should confirm which, if any, reach your products.
| Scenario | What usually controls | What may be licensable | Check first |
|---|---|---|---|
| US customer, terms include a data clause | Your sale terms and software license | De-identified machine health data, fault codes and run hours | Whether the clause covers third-party licensing or only internal product improvement |
| US customer, terms silent on data | Confidentiality duties and general contract law | A narrower scope, or nothing until updated terms or consent | Whether the data reveals production volumes or processes |
| EU customer | Contract, plus the EU Data Act and GDPR where they apply | Depends on counsel's reading of user access rights and limits on data holder use | Which entity sold the machine and where data is stored |
| Customer on a service or monitoring contract | Service agreement and portal terms | Alarm histories, service work orders and repair outcomes, where wider use is permitted | Whether use is limited to delivering the service |
| Customer PO terms claim all data | Possibly the customer's terms | Usually nothing from that customer without written consent | Which terms actually governed the sale |
| Machine resold to a second owner | Original terms, which may not bind the new owner | Usually leave out until rights are clear | Whether your terms run with the equipment |
| Equipment you lease or provide as a service | Your lease or service contract, since you still own the hardware | Often a broader scope, if the contract grants data use | Carve-outs for the customer's process data; EU lessees may have their own access rights |
Telemetry, process data and personal data are not the same#
Machine telemetry describes the machine, process data describes the customer's production, and personal data describes people. The three carry different rights, and a licensing scope usually separates them before anything else is decided.
- Machine health: vibration, temperatures, pressures, alarm and fault codes, run hours and component cycle counts. Usually the strongest candidate.
- Usage patterns: utilization, shift patterns, idle time and energy draw. These can reveal customer production volumes, so treat them as confidential.
- Process data: recipes, setpoints, part programs and cycle parameters tuned for a customer's product. Usually the customer's confidential information and excluded.
- Personal data: operator logins, badge IDs, technician names and site contacts. Removed or pseudonymized during preparation.
- Service records: tickets, technician notes, parts replaced and outcomes. Often your own records, even though they describe the customer's equipment.
How do EU customers change the analysis?#
EU customers add statutory rules on top of the contract. The EU Data Act, which applies in stages, covers data generated by connected products and related services. It may give users rights to access that data and to have it shared with third parties of their choice. It may also limit a manufacturer's own use of non-personal product data, and its sharing of that data with third parties, to what a contract with the user allows.
The regulation also contains protections for trade secrets, and GDPR may apply separately wherever telemetry includes personal data, such as operator identifiers or location data tied to a person. Which obligations apply, from when and to which products is a question for counsel, assessed deal by deal and machine family by machine family.
One practical option is to scope EU fleets out of a first license and bring them in later, once counsel has mapped the data flows and customer agreements. That keeps a US package moving without guessing about a different legal regime.
Illustrative: a compressor maker sorts its installed base#
Illustrative: a fictional maker of industrial air compressors sells through its own sales team and a network of distributors. Newer units report pressure, temperature, motor current, alarm codes and run hours to a remote monitoring portal, and the field service team logs every visit, diagnosis and part replaced in a service management system.
Counsel sorts the installed base into groups. US customers who accepted the current portal terms granted use of de-identified machine data beyond support, so their alarm histories and linked service outcomes go into scope. Units sold under older terms with no data clause, customers whose purchase orders claimed all operational data, every EU unit and every distributor-serviced unit are left out for now.
The resulting package is smaller than the fleet but clean: each record traces to a customer group with documented terms. The company also rewrites its sale terms and portal terms so that future units ship with a clearer, more specific grant.
How to close the telemetry rights gap going forward#
Closing the rights gap means writing data terms for the machines you have not sold yet. None of these steps changes past sales, but together they stop the problem from growing with every new unit shipped.
- Add a specific data clause to sale terms covering machine data, aggregation and de-identified third-party licensing.
- Align the controller software license and portal terms so they say the same thing.
- Record which version of the terms each customer accepted, by serial number.
- Separate process data and recipes from machine health data in the data model.
- Tell customers plainly what is collected and how it is used.
- Review distributor agreements for ownership of service records and customer data.
How SourceX approaches installed base telemetry#
SourceX treats telemetry as a rights question first. In the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery, the rights review maps each customer group to the terms that govern it, and only groups with documented permission move forward. The fit check collects metadata, such as machine families, years of history and the terms in use, not data files.
For any package that proceeds, the SourceX Evidence Packet records provenance, licensing rights by customer group, permitted use, the privacy record and release authorization. Large telemetry archives stay in the manufacturer's own storage or ship on encrypted drives, and the manufacturer approves the prepared package before delivery.
Frequently asked questions
Does selling the machine transfer the data to the customer?
Not automatically. A sale transfers the hardware, but data rights depend on the sale terms, the software license and any later agreements. Where the documents are silent, counsel will look at confidentiality duties, course of dealing and the laws that may apply. Silence rarely gives either side a clean right to license the data to a third party.
Is de-identified telemetry free of customer restrictions?
Not always. Removing customer names helps with confidentiality and privacy, but some contracts restrict use of any data generated at the customer's site, and aggregated usage can still reveal production volumes or processes. Read the clause wording rather than relying on name removal alone.
Can we license telemetry collected through a third-party IoT platform?
Possibly, but the platform's terms add another layer. Check whether the platform provider claims rights in collected data, whether bulk exports are allowed, and whether your customer agreements mention the platform. The licensable scope is the overlap of all three sets of terms.
Do customers need to be told about a data license?
That depends on the contracts and the laws that may apply. Some terms require notice or consent for third-party use; others already permit de-identified sharing. Even where notice is not required, clear language in updated terms reduces surprises and protects relationships. Counsel should confirm the approach for each customer group.
Does the EU Data Act stop us licensing telemetry from EU customers?
Not necessarily, but it may change what you need first. The regulation may tie your use and onward sharing of non-personal product data to a contract with the user, and users may have their own rights to access and share the same data. Many manufacturers leave EU fleets out of a first package until counsel has mapped the products, contracts and data flows involved.
Are warranty claims part of the telemetry question?
Warranty claims and the failure analysis behind them are usually your own records, and paired with alarm histories they are often the most useful part of a package. Keep claim details that name customers or reveal their processes out of scope unless the governing terms allow them.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.