Data Licensing Checklist: Provenance, Rights to Grant, Scope, Derived Data, De-Identification, and Exit
By Casey Scott McKay ·
This checklist runs a data licence from provenance tracing to exit, in the order the terms should actually be settled. It opens with the source table that determines what can lawfully be granted, and the inbound licence review that catches the redistribution prohibition before rather than after the outbound deal. It then drafts the rights-to-grant representation honestly, builds permitted use as a list covering users, contractors, purpose, territory, and combination, and settles derived data with a numeric aggregation threshold. It works model training in every direction, de-identification standards, privacy role allocation and individual rights routing, security and breach terms, and audit and suspension rights. It closes with the exit schedule drafted backwards from what the licensee holds the day after termination, and the governance gates that prevent the recurring failures.
IP and Technology > Information Technology | Checklist | Published 25 December 2025 - Updated 2 April 2026 | Casey Scott McKay - marksy.us
Summary. This checklist runs a data licence from provenance tracing to exit, in the order the terms should actually be settled. It opens with the source table that determines what can lawfully be granted, and the inbound licence review that catches the redistribution prohibition before rather than after the outbound deal. It then drafts the rights-to-grant representation honestly, builds permitted use as a list covering users, contractors, purpose, territory, and combination, and settles derived data with a numeric aggregation threshold. It works model training in every direction, de-identification standards, privacy role allocation and individual rights routing, security and breach terms, and audit and suspension rights. It closes with the exit schedule drafted backwards from what the licensee holds the day after termination, and the governance gates that prevent the recurring failures.
Keywords: data licensing checklist · provenance table · source category audit · inbound licence review · rights to grant drafting · permitted users · contractor access · purpose limitation · derived data threshold · aggregation test · model training clause · memorisation evaluation · de-identification standard · privacy role allocation · deletion request routing · security and breach terms · audit rights · exit schedule · backup copies · governance gates
How to use this checklist
| Phase | What it covers | |---|---| | 1 | The provenance table | | 2 | Inbound licence review | | 3 | Rights to grant | | 4 | Permitted users | | 5 | Purpose and scope | | 6 | Derived data | | 7 | Model training | | 8 | Personal information | | 9 | De-identification | | 10 | Privacy flow-down | | 11 | Security and breach | | 12 | Audit and suspension | | 13 | Warranties and indemnities | | 14 | Commercial terms | | 15 | Service levels | | 16 | Exit schedule | | 17 | Insolvency and change of control | | 18 | Taking a licence in | | 19 | Governance gates | | 20 | Cadence |
Boxes marked [Gate] must clear before the licence is signed, the data is delivered, or a new source is ingested.
The matter. A market dataset assembled over eight years. Thirty per cent of it came from a feed licensed under an express redistribution prohibition. Four customers had been taking it for years, and nobody read the inbound terms until the buyer asked.
Phase 1. The provenance table
- [ ] [Gate] Build a source table before drafting anything.
- Why. The rights-to-grant representation is the product, and it cannot be written honestly without it.
- [ ] One row per source: name, type, date range of records, approximate proportion of the dataset.
- [ ] Record the basis of collection: self-generated, user-supplied under terms, licensed in, purchased, scraped, research agreement, or unknown.
- [ ] Record the governing document and its reference.
- [ ] Record whether onward licensing is permitted, prohibited, or silent.
- [ ] Record whether personal information is present.
- [ ] Record any use, territory, or attribution restriction.
- [ ] [Gate] Size the unknown-provenance category.
- Trap. Most real datasets have one; its size determines how much of the representation the licensor can give, and treating it as a documentation gap rather than a finding is how bad representations get signed.
- [ ] Produce a one-page provenance summary by category with percentages, for the data room.
Phase 2. Inbound licence review
- [ ] Obtain every inbound data licence in the chain.
- [ ] Extract whether redistribution or sublicensing is permitted in any form.
- [ ] Extract purpose limitations.
- [ ] Extract whether derived outputs are addressed, and how.
- [ ] Extract change of control treatment.
- [ ] Extract term, termination, and post-termination obligations.
- [ ] Extract attribution requirements.
- [ ] [Gate] Confirm no inbound restriction prohibits the outbound grant contemplated.
- Why. Licensing out data licensed in under a redistribution prohibition is the recurring composite-dataset failure, and it surfaces during acquisition diligence at maximum cost.
- [ ] For user-supplied data, obtain the terms of use and privacy notice as they existed at collection.
- Trap. Relying on the current notice. The version in force at collection governs, and amendment is not retroactive.
- [ ] For purchased data, assess the broker's representations against its balance sheet.
- [ ] For scraped data, record what was collected, whether authentication was required, and what the site terms said. See Who Owns the Data.
- [ ] For human-subject data, obtain the consent language and confirm it covers commercial use.
- Why. Nothing downstream can expand the scope of a research participant's consent.
Phase 3. Rights to grant
- [ ] [Gate] Do not write "Licensor owns the Data."
- Why. It is usually false, and it invites the preemption argument under 17 U.S.C. § 301 that contract terms restricting use of unprotectable facts are equivalent to the rights in 17 U.S.C. § 106.
- [ ] State that the licensor holds all rights necessary to grant the rights expressly granted.
- [ ] State that the licensee acquires only the rights expressly granted.
- [ ] State that no ownership of any underlying fact is asserted by either party.
- [ ] State that the data was collected in compliance with applicable law and the terms under which it was obtained.
- [ ] Qualify honestly where the provenance table requires it.
- Trap. A knowledge qualifier on the licensor's own collection practices, which is not defensible; one on third-party sources, which is.
- [ ] Draft restrictions as permitted-use terms rather than as property assertions, which weakens the preemption argument further. See ProCD v. Zeidenberg.
- [ ] Confirm whether any European Union database directive sui generis right subsists, and grant or reserve it expressly.
Phase 4. Permitted users
- [ ] Name the licensee entity.
- [ ] Define affiliates, and state whether entities acquired later are included.
- [ ] [Gate] Include contractors, processors, and professional advisers acting on the licensee's behalf, bound by equivalent written obligations.
- Why. The analytics vendor, the offshore development team, and the hosted business intelligence tool are otherwise outside the grant from day one.
- [ ] State that the licensee remains responsible for each permitted party's compliance.
- [ ] Address the licensee's own customers, if applicable, and on what terms.
- [ ] Prohibit transfer to any party not named.
- [ ] [Gate] Circulate the permitted-user list to the team that will actually use the data before signature.
- Trap. Discovering the operational mismatch at the first audit rather than at drafting.
Phase 5. Purpose and scope
- [ ] List permitted purposes rather than writing a general statement.
- Why. Where no property right exists, anything not prohibited is permitted — the reverse of the intuition brought from patent and copyright licensing.
- [ ] Address each separately: internal analytics, product development, benchmarking, publication of aggregates, resale, model training.
- [ ] Specify volume and frequency: records, queries per period, refresh cadence, overage treatment.
- [ ] Specify retention, and how caches and backups are treated.
- [ ] Specify territory and permitted processing and storage locations.
- Why. This is a compliance term, not a commercial preference.
- [ ] Address combination with the licensee's own data and with third-party data, and state the status of the combined set.
- Trap. Silence here breaks the derived data clause, because the combined set has no defined status.
- [ ] Specify what may be published, shown to customers, or sold.
- [ ] Specify attribution, and its form.
- [ ] Prohibit expressly: re-identification, reverse engineering the collection methodology, resale in raw or substantially raw form, building a competing dataset, and training where not permitted.
- [ ] Apply the definiteness discipline of Nautilus v. Biosig Instruments by analogy: write every restriction so a reasonable reader with the agreement can say whether a use is inside it.
Phase 6. Derived data
- [ ] [Gate] Negotiate this before the fee.
- Why. It decides whether the licensee is buying a subscription or an asset, and both sides price differently once they know.
- [ ] Define Licensed Data: records as delivered, verbatim copies, subsets, filtered extracts.
- [ ] Define Transformed Data: normalised, enriched, translated, or reformatted, still traceable to source records. Treat as Licensed Data at exit.
- [ ] Define Aggregate Output: values computed across multiple records from which no source record can be reconstructed.
- [ ] Define Insights: analytical conclusions referencing but not reproducing the data.
- [ ] Define Models separately, governed by the training clause.
- [ ] [Gate] State a numeric aggregation threshold — no fewer than [N] distinct source records per output value.
- Trap. "Aggregate statistics" without a number becomes an argument about whether a count of three qualifies.
- [ ] Add a substitution test: Aggregate Output may not be supplied in a form or volume that substitutes for the data in the market.
- [ ] Prohibit reconstruction of source records from Aggregate Output, alone or in combination with other information.
- [ ] State the exit treatment of each category expressly.
- [ ] Say the quiet part in negotiation: the licensor fears substitution, the licensee fears evaporation. Both statements produce better clauses than trading redlines.
Phase 7. Model training
- [ ] [Gate] Address training expressly in every licence, in one direction or the other.
- Why. Silence is a decision, and it favours whichever party thought about it. A model survives every deletion obligation in the agreement.
- [ ] State whether training is permitted at all.
- [ ] List the activities separately: pretraining, fine-tuning, evaluation, benchmarking.
- [ ] State whether the resulting model may serve customers other than the licensee.
- [ ] State whether the model may be sold, licensed, or transferred.
- [ ] State whether the model survives termination, and on what conditions.
- [ ] State whether model outputs carry restrictions, attribution obligations, or field limits.
- [ ] Require memorisation evaluation and remediation where the licensor cares.
- Why. A model trained on a small or repetitive dataset can reproduce source records, defeating the reconstruction test the derived data clause relies on.
- [ ] Assess the licensor's own exposure where the dataset contains third-party copyrighted material.
- Why. The fair use position under 17 U.S.C. § 107, framed by Google v. Oracle America and narrowed by Andy Warhol Foundation v. Goldsmith, is genuinely uncertain, and exposure attaches to the underlying material rather than the compilation.
- [ ] Address output ownership, noting that outputs generated without human creative contribution may not be copyrightable at all. See Buying a Model.
- [ ] Price training separately from other uses.
- Trap. Bundling training into a general subscription, which is how licensors give away the asset for a year of fees.
Phase 8. Personal information
- [ ] [Gate] Determine whether the dataset contains personal information under each applicable regime.
- Trap. The definitions are broader than commercial parties assume and frequently capture device identifiers, network addresses, and inferences.
- [ ] List the categories present and the basis on which each was collected.
- [ ] Identify sectoral overlays: health, financial, education, children's data, biometric.
- [ ] Confirm the privacy notice in force at collection permits the contemplated licensing.
- Why. "To provide and improve our services" does not authorise licensing to third parties, and later amendment is not retroactive.
- [ ] Identify data originating in jurisdictions with cross-border transfer restrictions, and the mechanism relied on.
- [ ] Determine whether either party meets a data broker definition under state data broker registration requirements.
- [ ] Confirm whether individual consent, where relied on, covers commercial use and onward transfer.
Phase 9. De-identification
- [ ] Where de-identification is the basis for licensing, state the standard applied.
- [ ] For health data, identify the route: the safe harbour removing enumerated identifiers, or an expert determination that re-identification risk is very small. See Health Insurance Portability and Accountability Act de-identification.
- [ ] Record who performed and certified the de-identification, and when.
- [ ] Assess re-identification risk against the attributes retained and the auxiliary data reasonably available.
- Trap. A de-identified dataset combined with other data can become identifiable again, and risk rises with each retained attribute.
- [ ] [Gate] Prohibit re-identification expressly, extend the prohibition to combination with other datasets, and back it with audit and termination rights.
- [ ] Confirm whether aggregate outputs fall outside the applicable privacy regimes, which is the other reason the aggregation threshold matters.
- [ ] Re-assess periodically, because auxiliary data availability increases over time.
Phase 10. Privacy flow-down
- [ ] [Gate] Allocate roles: sale, sharing, or disclosure to a service provider under the California Consumer Privacy Act and state analogues.
- Why. A data licence is frequently a sale, with disclosure and opt-out consequences for the licensor.
- [ ] Where service provider treatment is intended, include the required contractual terms and confirm the conduct will match them.
- [ ] State that the licensee may process only for the listed purposes.
- [ ] [Gate] Include individual rights routing: licensor notifies, licensee acts within a period shorter than the licensor's statutory deadline, licensee confirms in writing, obligation extends downstream.
- Why. Without this clause the licensor cannot comply, and the failure is the licensor's.
- [ ] Mirror the licensor's own regulatory obligations as licensee obligations.
- [ ] Flow down every restriction imposed by inbound source contracts expressly.
- Why. Privity means nothing travels unless it is written.
- [ ] Address financial data constraints under the Gramm-Leach-Bliley Act privacy rule where applicable.
- [ ] Specify permitted processing and storage locations as a compliance term.
Phase 11. Security and breach
- [ ] Specify the security control standard by reference to a recognised framework rather than by adjective.
- [ ] Specify breach notification timing in hours, not days.
- [ ] Specify what information the notification must contain.
- [ ] Specify cooperation obligations in investigation and notification.
- [ ] Specify who bears notification and remediation costs.
- [ ] Confirm the standard matches the licensee's actual environment.
- Trap. An aspirational security schedule copied from a template, which is unmet from day one and becomes the finding after an incident. See The First Seventy-Two Hours.
- [ ] Require notice of any subprocessor change affecting the data.
- [ ] Require deletion or return of data held by any departing subprocessor.
- [ ] Address encryption in transit and at rest, and key management responsibility.
Phase 12. Audit and suspension
- [ ] [Gate] Include an audit right. Without one every restriction is aspirational.
- [ ] Specify frequency, notice period, and scope.
- [ ] Specify auditor confidentiality and, where appropriate, an independent auditor.
- [ ] Specify cost-shifting on discovery of a material discrepancy, which makes the right self-funding.
- [ ] [Gate] Include an express right to suspend access on notice for material breach, with a cure period.
- Why. Suspension is the fastest and most effective remedy, and it does not require a court.
- [ ] Confirm the technical capability to suspend actually exists.
- [ ] Include liquidated damages for defined breaches — unauthorised redistribution, re-identification, prohibited training — set as a genuine pre-estimate rather than a penalty.
- [ ] Include an acknowledgement that breach causes irreparable harm and that equitable relief is appropriate.
- [ ] Preserve trade secret claims under 18 U.S.C. § 1836 by maintaining confidentiality in fact, not only in the contract.
- [ ] Note that access statute claims under 18 U.S.C. § 1030 are narrow after Van Buren v. United States and hiQ Labs v. LinkedIn, and available mainly where authentication was circumvented.
- [ ] Where protectable material is included, register it so that 17 U.S.C. § 411 and 17 U.S.C. § 412 remedies remain available.
Phase 13. Warranties and indemnities
- [ ] Expect the licensor to warrant authority and rights to grant, and to resist accuracy, completeness, and fitness.
- [ ] Substitute a defined error-reporting and correction process for an accuracy warranty.
- Why. Data describing the world is wrong in places, and an accuracy warranty is one nobody can give; a correction process is enforceable.
- [ ] [Gate] Obtain a rights indemnity covering third-party claims that the data infringes, misappropriates, or was collected unlawfully.
- [ ] Obtain a separate privacy indemnity covering regulatory action arising from collection practices.
- [ ] Expect carve-outs: combination, modification, use outside scope, continued use after notice.
- [ ] [Gate] Negotiate a supercap for the rights and privacy indemnities above the general liability cap.
- Trap. A cap set at twelve months' fees makes the only term the licensee cares about decorative.
- [ ] Assess the indemnitor's ability to pay: balance sheet, insurance, parent guarantee.
- [ ] Confirm whether technology errors and omissions or cyber policies respond, and note that neither responds to knowingly licensing data the licensor had no right to license.
- [ ] Address unfair practices exposure under 15 U.S.C. § 45 and state analogues, which is regulator-driven.
Phase 14. Commercial terms
- [ ] Price the use, not the volume — tiered by internal analytics, redistribution, and model training.
- [ ] Set a term of one to three years, which makes exit terms decisive.
- [ ] Scrutinise exclusivity hardest of any term.
- Why. A non-rivalrous asset granted exclusively forecloses every other customer, and casual first-deal exclusivity has ended entire strategies.
- [ ] Prefer field limits, term limits, or a commitment not to license named competitors.
- [ ] Define any most-favoured-nation comparison precisely: same volume, same use rights, same term.
- [ ] Record every most-favoured-nation and exclusivity commitment in the outbound register.
- [ ] Address payment mechanics, currency, and withholding for cross-border arrangements.
- [ ] Include a change-control clause covering loss of source and regulatory withdrawal, with a fee adjustment rather than breach.
- Why. Both happen, and without the clause the licensor is simultaneously required to withdraw records and contractually obliged to supply them.
Phase 15. Service levels
- [ ] Specify availability, measured and remedied.
- [ ] Specify refresh cadence contractually rather than aspirationally.
- [ ] Specify format stability and a schema change notice period.
- Why. A schema change without notice breaks the licensee's pipeline, and it is the operational complaint that recurs above all others.
- [ ] Require the prior format to be maintained in parallel for a deprecation window.
- [ ] Specify delivery mechanism and what happens if it changes.
- [ ] Specify support obligations and response times for data quality queries.
- [ ] Specify the correction process: how errors are reported, assessed, and remedied, and in what period.
- [ ] Specify the consequence of sustained failure — fee credits, then termination.
Phase 16. Exit schedule
- [ ] [Gate] Draft this before the operative clauses, and ask what the licensee holds on the day after termination.
- [ ] Licensed Data and Transformed Data: return or destruction within a stated period, certified by an officer.
- [ ] [Gate] Address backup and archival copies expressly.
- Trap. Immutable backups cannot be purged, so a deletion certification covering them is either dishonest or ignored.
- [ ] Provide that backups remain subject to confidentiality and use restrictions until overwritten in the ordinary retention cycle, and may not be restored into production.
- [ ] Aggregate Output and Insights: retained, subject to the threshold and substitution test.
- [ ] Models: per the training clause, restated here so it is not missed.
- [ ] Outputs already delivered to the licensee's customers: continued use permitted.
- Why. Recall is impossible, and an unperformable obligation is worse than none.
- [ ] Sublicences and downstream recipients: state whether they survive and on what terms.
- [ ] Wind-down period permitting limited continued use to migrate.
- [ ] Survival: confidentiality, privacy obligations, audit rights for a period, indemnities, liability limits, dispute resolution.
- [ ] Confirm every exit obligation is one the party can actually perform.
Phase 17. Insolvency and change of control
- [ ] Assess whether the licence would be treated as an intellectual property licence in a bankruptcy, which is not obvious for data.
- [ ] Where the licensee's business depends on access, negotiate escrow with defined release conditions.
- Trap. Continuously refreshed data is far harder to escrow than a static deliverable; specify the deposit cadence and completeness.
- [ ] Address continued access on licensor insolvency by contract as well as by escrow.
- [ ] State the position on the licensee's change of control.
- [ ] State the position on the licensor's change of control, including whether the licensee may terminate.
- [ ] [Gate] Address a change of control that puts the data in the hands of a competitor of the other party.
- [ ] Confirm assignment rights on both sides and whether consent is required.
- [ ] Confirm what happens to sublicences and downstream recipients in each scenario.
Phase 18. Taking a licence in
- [ ] [Gate] Ask for the provenance summary by source category with percentages.
- Why. An inability to produce one is a material finding that should move price or produce an escrow, not a documentation gap to be waived.
- [ ] Test the rights representation rather than reading it.
- [ ] Assess whether the indemnity is worth anything: balance sheet, insurance, parent guarantee.
- [ ] Read the exit schedule as the specification of what is being bought.
- [ ] Confirm contractors and affiliates are within permitted users.
- [ ] Confirm the territory clause permits processing where processing actually happens.
- [ ] Confirm refresh cadence and schema notice are contractual.
- [ ] Confirm combination with the licensee's own data is permitted, which is usually the whole point.
- [ ] Confirm a wind-down period exists.
- [ ] Confirm the deletion-request response period is one the licensee can meet.
- [ ] Confirm the security standard matches the licensee's actual environment.
- [ ] Confirm re-identification prohibitions are stated in terms the data science team can follow.
- [ ] [Gate] Circulate the operative clauses to the engineering owner before signature.
- Why. These agreements fail more often on operational impossibility than on legal error.
Phase 19. Governance gates
- [ ] Ingestion gate. Nobody adds a data source without someone reading the terms and recording whether onward licensing is permitted.
- Why. This single control prevents the composite-dataset failure entirely.
- [ ] Outbound gate. Nobody signs a licence out without confirming provenance supports the representation.
- [ ] Record provenance metadata at ingestion: source, date, basis, terms.
- Why. Retrofitting provenance is the most expensive remediation in this field, and recording it at collection costs almost nothing.
- [ ] Maintain an inbound register with redistribution rights, change of control treatment, purpose limits, and term.
- [ ] Maintain an outbound register with scope, derived data definition, exclusivity, most-favoured-nation terms, training rights, and expiry.
- [ ] Maintain a standard form with the recurring terms pre-drafted, so negotiations reduce to price and variations.
- [ ] Maintain deletion-request routing from the privacy team to every licensee, with tracked response.
- [ ] Exercise audit rights occasionally.
- Trap. Unexercised audit rights train counterparties to treat restrictions as decorative.
- [ ] Review the privacy notice against actual practice annually.
- [ ] Agree the schema change protocol internally before promising it externally.
- [ ] Run the same analysis in both directions on any reciprocal data exchange.
- Trap. Barter deals get one short mutual agreement and none of this work, creating two problems instead of one.
Phase 20. Cadence
- [ ] Per source ingested. Terms read, provenance recorded, register updated.
- [ ] Per licence negotiated. Provenance table, derived data settled first, engineering review before signature.
- [ ] Per delivery. Confirm scope and permitted users have not drifted.
- [ ] Monthly. Deletion-request routing confirmed; schema changes notified.
- [ ] Quarterly. Outbound register review — expiries, most-favoured-nation triggers, exclusivity constraints.
- [ ] Annually. Privacy notice against practice; de-identification re-assessment; audit exercised on at least one counterparty; inbound register refreshed.
- [ ] On event. New regulation, a regulator inquiry, a source loss, a breach, a change of control on either side, or a new use case such as training.
- [ ] Before any transaction. Provenance summary, inbound and outbound registers, and outstanding exclusivity and most-favoured-nation commitments.
Phase 23. Diligence on a data asset
- [ ] Provenance by source category, with percentages.
- [ ] Inbound licence terms, specifically onward licensing and change of control.
- [ ] Terms of use and privacy notices as they existed at collection, not as they exist now.
- [ ] Consent records where consent was the collection basis.
- [ ] Outbound licences and what they committed: exclusivity, most-favoured-nation terms, derived data and training rights already granted.
- [ ] Deletion and access request handling, and evidence the obligations were met.
- [ ] Scraped proportion of the asset, and the access conditions at the time.
- [ ] Security posture and breach history.
- [ ] Regulatory correspondence touching data practices.
- [ ] [Gate] Whether the data can lawfully transfer to the acquirer at all, which in some structures requires consent or notice.
- Trap. Assuming a data asset transfers with the business. Consent-based collections and service provider arrangements frequently do not.
- [ ] Whether any granted exclusivity or most-favoured-nation term constrains the acquirer's own business.
- [ ] The recurring finding: a dataset assembled from multiple sources over years, no provenance metadata, licensed out under representations the licensor cannot support.
Phase 25. The one-page position
Data licence — [counterparty], [date], [inbound / outbound]. Dataset: [description], [N] records, refresh [cadence], formats [list]. Provenance: self-generated [%]; user-supplied under terms dated [date] [%]; licensed in [%] from [sources], redistribution [permitted / prohibited]; purchased [%]; scraped [%]; unknown [%]. Personal information: [yes/no], categories [list], collection basis [description], sectoral overlays [list], de-identification [method, certified by, date]. Rights representation: [full / qualified as to third-party sources], basis [provenance summary dated]. Indemnities: rights [yes/no], privacy [yes/no], general cap [figure], supercap [figure], indemnitor covenant strength [balance sheet / insurance / parent guarantee]. Permitted users: [entity, affiliates, contractors, processors, customers]. Purposes: [list]. Prohibited: [re-identification, redistribution, competing dataset, training if applicable, reverse engineering]. Territory and processing locations: [list]. Combination: [permitted / not], combined set status [description]. Derived data: aggregation threshold [N records]; substitution test [included]; reconstruction [prohibited]; transformed data treated as [licensed data]. Training: [permitted / prohibited]; activities covered [pretraining / fine-tuning / evaluation]; model use for other customers [yes/no]; survives termination [yes/no]; memorisation evaluation [required]. Privacy: role [sale / sharing / service provider]; individual rights routing [N-day response]; downstream flow-down [included]; transfer mechanism [description]. Security: standard [reference]; breach notice [N hours]; cost allocation [description]; subprocessor notice [included]. Audit: frequency [N per year]; cost-shifting [threshold]; suspension right [included, cure N days]; liquidated damages [defined breaches, amounts]. Commercial: term [N years]; fee structure [tiered by use]; exclusivity [none / field and term limited]; most-favoured-nation [none / defined comparison]; change control for source loss and regulatory withdrawal [included]. Service levels: availability [%]; refresh [cadence]; schema notice [N days]; deprecation window [N days]; correction process [defined]. Exit: licensed and transformed data [return / destroy, N days, certified]; backups [confidentiality continues until overwritten]; aggregates and insights [retained]; models [per training clause]; delivered outputs [continued use]; sublicences [survive / not]; wind-down [N days]; survival [list]. Insolvency: escrow [yes/no], deposit cadence [description]. Change of control: licensee [position], licensor [position], competitor scenario [addressed]. Engineering review completed [date, by]. Outstanding items: [list]. Recommendation: [sign / amend / escalate].
Phase 26. What this costs
- [ ] The provenance table takes days for a simple dataset and weeks for a composite one. It is the long pole and it should start before the first meeting.
- [ ] Inbound licence review takes an hour per agreement and prevents the failure that costs a purchase price adjustment.
- [ ] Derived data drafting takes one meeting when done first and three when done last.
- [ ] Engineering review of the operative clauses takes ten minutes and prevents most operational disputes.
- [ ] A first licence with a new counterparty runs four to eight weeks with a standard form.
- [ ] Retrofitting provenance metadata across a legacy dataset is the most expensive remediation in this field, by a wide margin.
- [ ] The asymmetry. Every control above is cheap at ingestion and expensive in diligence, which is the whole argument for the gates.
Phase 24. Metrics
- [ ] Records with complete provenance metadata, as a percentage of records held.
- [ ] Size of the unknown-provenance category, trending down.
- [ ] Inbound sources with redistribution rights extracted into the register.
- [ ] Outbound licences signed after a gate check, as a percentage.
- [ ] Licences containing a numeric aggregation threshold.
- [ ] Licences addressing model training expressly. Target one hundred per cent.
- [ ] Licences whose permitted users cover contractors and processors.
- [ ] Deletion requests routed to licensees within the contractual period.
- [ ] Audits exercised per year, and findings per audit.
- [ ] Outstanding exclusivity and most-favoured-nation commitments, and what they foreclose.
- [ ] The one that matters. Whether any licence granted in the period rests on a representation the provenance table does not support. Target zero; any other result is a gate failure rather than a drafting error.
Phase 21. Negotiation sequence
- [ ] Meeting one. Provenance and derived data only. Both parties leave knowing whether the deal is possible.
- [ ] Meeting two. Permitted use as a list, with the business and engineering teams present.
- [ ] Meeting three. Privacy allocation, flow-down, and security, with privacy counsel on both sides.
- [ ] Meeting four. Exit schedule, before the operative clauses are finalised.
- [ ] Meeting five. Commercial terms, which are now straightforward.
- [ ] [Gate] Do not negotiate price first.
- Why. Commercial terms are unpriceable until scope and residual are settled, and anchoring on price commits both parties to a deal shape neither has analysed.
- [ ] Attendees for any licence of consequence: counsel, business owner, data engineering, privacy.
- [ ] Budget four to eight weeks with a standard form, twice that without one, with provenance work starting before the first meeting.
Phase 22. If you can only do four things
- [ ] Build the provenance table. It is the representation, and everything else depends on it.
- [ ] Put a number in the aggregation threshold. It converts the most contested definition into a testable one.
- [ ] Include contractors in permitted users. Two lines, and it decides who is actually in the room.
- [ ] Say something about training. In either direction — silence gives the asset away.
Outcome. The provenance table took four days and reframed the transaction. Thirty per cent of the dataset came from a feed prohibiting redistribution in any form, which meant the licence as marketed could not be granted at all. Three routes were modelled: renegotiate the feed licence, carve the feed data out, or license only aggregates computed across the whole. The feed licensor agreed to permit redistribution of derived aggregates at a defined threshold in exchange for a revenue share, which preserved most of the value. The four existing customer licences were amended, with the licensor bearing the cost of the amendment it should have avoided. Going forward, an ingestion gate was added — nobody adds a source without recording whether onward licensing is permitted — and an outbound gate confirming provenance supports the representation. The unknown-provenance category, initially ten per cent, was reduced to two through record review, and the residual was carved out of the licensed set. The rights representation was rewritten to state what rights were held rather than asserting ownership of facts, with a supercapped indemnity behind it. At acquisition eighteen months later, the provenance summary went into the data room on day one and the data asset was not a diligence issue.
Key Authorities at a Glance
| Authority | Proposition | |---|---| | 17 U.S.C. § 102 | No protection for facts or ideas | | 17 U.S.C. § 103 | Compilations | | 17 U.S.C. § 106 | Exclusive rights | | 17 U.S.C. § 107 | Fair use | | 17 U.S.C. § 301 | Preemption | | 17 U.S.C. § 411 | Registration before suit | | 17 U.S.C. § 412 | Statutory damages and fees | | 18 U.S.C. § 1836 | Trade secret civil action | | 18 U.S.C. § 1030 | Computer Fraud and Abuse Act | | 15 U.S.C. § 45 | Unfair or deceptive practices | | Feist Publications v. Rural Telephone Service | Facts unprotectable | | Van Buren v. United States | Exceeding authorised access narrowed | | hiQ Labs v. LinkedIn | Public data and the access statute | | ProCD v. Zeidenberg | Contract terms on unprotectable data | | Google v. Oracle America | Fair use in functional works | | Andy Warhol Foundation v. Goldsmith | Transformative purpose narrowed | | Nautilus v. Biosig Instruments | Definiteness, applied to scope drafting | | California Consumer Privacy Act | Sale, sharing, service provider terms | | Health Insurance Portability and Accountability Act de-identification | Safe harbour and expert determination | | Gramm-Leach-Bliley Act privacy rule | Financial data constraints | | European Union database directive | Sui generis database right | | State data broker registration requirements | Registration and disclosure duties |
The five things people get wrong
One. They say the licensor owns the data. In most cases there is no property right at all — Feist Publications v. Rural Telephone Service makes facts free, and the more complete and rationally organised a dataset is, the less copyright it carries. Write what rights are held and what is granted.
Two. They leave derived data to the end. By then it is a deal term disguised as a definition and neither side will move. It decides whether the licensee is buying a subscription or an asset, and it should be settled before the fee.
Three. They define aggregates without a number. "Aggregate statistics" is not a boundary anyone can apply. State a minimum record count and add a substitution test.
Four. They omit contractors from permitted users. The analytics vendor, the offshore team, and the hosted tool are all outside a clause naming only the licensee entity, and the breach runs from day one until an audit finds it.
Five. They say nothing about model training. The model is the one form of derived data that survives every deletion obligation, and silence hands the asset to whichever party thought about it.
Related Documents
Articles
Guides
Checklists
Toolkits
Templates & Forms
This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Data rights and privacy obligations turn on provenance, jurisdiction, and the specific contracts in the chain. Marksy is not a law firm.