Data Licensing and Rights Toolkit: Provenance, Scope, Derived Data, and Compliance

By ·

Data is the asset most often licensed and least often owned, and the gap between commercial expectation and legal reality is where data deals go wrong. This toolkit collects the whole framework - what rights actually subsist, why contract does the work property does not, and how to draft accordingly. It covers thin compilation copyright after Feist, trade secret protection and the disclosure problem, the absence of a US database right, and the preemption argument that shapes how restrictions should be written. It then works the provenance table that the rights-to-grant representation depends on, permitted use drafted as a list, the derived data definition with a numeric aggregation threshold, model training in every direction, privacy flow-down, and the exit schedule drafted backwards from what the licensee holds afterwards.

IP and Technology > Information Technology | Toolkit | Published 7 March 2024 - Updated 19 June 2026 | Casey Scott McKay - marksy.us

Summary. Data is the asset most often licensed and least often owned, and the gap between commercial expectation and legal reality is where data deals go wrong. This toolkit collects the whole framework — what rights actually subsist, why contract does the work property does not, and how to draft accordingly. It covers thin compilation copyright after Feist, trade secret protection and the disclosure problem, the absence of a US database right, and the preemption argument that shapes how restrictions should be written. It then works the provenance table that the rights-to-grant representation depends on, permitted use drafted as a list, the derived data definition with a numeric aggregation threshold, model training in every direction, privacy flow-down, and the exit schedule drafted backwards from what the licensee holds afterwards.

Keywords: data licensing toolkit · Feist originality · compilation copyright · sui generis database right · trade secret in data · contract as property substitute · provenance table · rights to grant · permitted users · derived data threshold · aggregation test · model training rights · memorisation evaluation · de-identification · privacy flow-down · deletion routing · audit and suspension · exit schedule · backup copies · governance gates


Start Here

A client says: we own the data.

The correct first response is a question. Which data, and what do you mean by own?

Because in most cases the answer is that they possess it, they control access to it, and they have contracts with the people who supplied it — and none of those is ownership in the sense the word usually carries. There is frequently no property right in a dataset at all. What exists is a bundle of contractual positions and practical controls that, arranged well, behave like property, and arranged badly behave like nothing.

That is not a defect to be lamented. It is the operating condition of the entire data economy, and understanding it changes how these deals are drafted.

Three consequences follow, and they govern everything in this toolkit.

Everything not prohibited is permitted. Where no property right exists, the licence is not describing rights — it is creating them. So permitted use is a list, not a purpose statement, and the reverse of the intuition practitioners bring from patent and copyright licensing.

Nothing binds anyone outside privity. A competitor obtaining the same data independently owes nothing. A licensee's customer or downstream recipient may be entirely outside the arrangement. So flow-down obligations carry the whole compliance structure.

Nothing is self-executing. Remedies are contractual — breach damages, not statutory damages, no fee shifting absent a clause, no injunction as of right. So the audit right and the suspension right are the enforcement mechanism, and both must be drafted and technically executable.

This toolkit answers four questions. What rights actually subsist? Where did the data come from, and what can honestly be represented? What does the licensee get to keep? And what happens on the day after termination?

Settle provenance and derived data first. Everything else is easier once both parties know what may lawfully be granted and what the licensee gets to keep.


What Rights Subsist

Copyright in the individual items, sometimes. Photographs, articles, and code within a dataset carry their own copyright. Facts, measurements, and observations do not.

Copyright in the compilation, thinly. 17 U.S.C. § 103 protects compilations, but Feist Publications v. Rural Telephone Service holds that protection extends only to original selection, coordination, or arrangement — and that facts are never original because they are discovered rather than created. 17 U.S.C. § 102 excludes facts and ideas from subject matter.

What Feist rejected. The sweat of the brow doctrine. A directory listing every subscriber alphabetically involved substantial labour, no originality, and received no protection.

The practical consequence. A comprehensive dataset organised in an obvious way has essentially no copyright. The more complete and rationally arranged it is, the less protection it carries — precisely backwards from commercial intuition.

Where compilation copyright does bite. Curated selections reflecting editorial judgment, original taxonomies, and genuinely creative arrangements.

No sui generis database right in the United States. The European Union created one; Congress has repeatedly declined. Proposals surface periodically and go nowhere. See European Union database directive.

Trade secret, where secrecy holds. 18 U.S.C. § 1836 and state law protect information deriving independent economic value from not being generally known, subject to reasonable measures. The tension is structural: protection requires secrecy and licensing requires disclosure, so a dataset licensed to a hundred customers under weak terms is not a secret.

Contract, which is what actually does the work.

Access controls and technical measures, supplying the practical enforcement legal rights do not.

Privacy law, which constrains rather than protects — limiting what the holder may do and granting rights to the individuals the data describes.

Preemption. 17 U.S.C. § 301 preempts state law rights equivalent to copyright, and defendants argue that contract terms restricting use of unprotectable facts are preempted. Most courts hold contract claims survive because a promise is an extra element, following the reasoning in ProCD v. Zeidenberg, but the argument recurs. Draft restrictions as permitted-use terms rather than property assertions and it gets weaker still.


Provenance

The representation every data licence contains is that the licensor has the right to grant the licence. The question it presupposes is where each part of the dataset came from and what was permitted at each step.

The categories, each with a different answer.

Self-generated. Sensor readings, the licensor's own transaction records, measurements it took. The cleanest position, subject to privacy law where the data describes people.

Collected from users under terms of use and a privacy notice. The scope of what those documents permitted controls, and the version in force at collection governs. "To provide and improve our services" does not authorise licensing to third parties, and later amendment is not retroactive.

Licensed in from third parties. The inbound licence controls what may be sublicensed, and most inbound data licences prohibit onward licensing outright — which means the dataset cannot be licensed out in its current form at all.

Purchased from brokers, where the broker's own provenance is frequently opaque and its representations are the only assurance, worth what its balance sheet is worth.

Scraped. Discussed below, and genuinely contested.

Received under research or collaboration agreements, carrying use restrictions and sometimes publication or reach-through obligations.

Derived from human subjects, where consent scope governs absolutely and no downstream agreement can expand it.

The composite problem. Real datasets mix these categories, and the licensor frequently cannot say which records came from where. A dataset assembled over a decade by multiple teams has no provenance record, and reconstructing one is the most expensive remediation in this field.

Which is why the rights-to-grant representation is negotiated so heavily, and why the indemnity behind it matters more than the royalty.

Write the representation honestly. That the licensor holds all rights necessary to grant the rights expressly granted; that the licensee acquires only those rights; that no ownership of any underlying fact is asserted; and that the data was collected in compliance with applicable law and the terms under which it was obtained. Qualify where the provenance table requires it — a knowledge qualifier on third-party sources is defensible, one on the licensor's own collection practices is not.

Back it with two indemnities. Third-party claims that the data infringes, misappropriates, or was unlawfully collected; and a separate privacy indemnity covering regulatory action arising from collection practices. Negotiate a supercap above the general liability cap, because data licences are small in fee terms and large in exposure terms.

For a licensee, the indemnity is the product. A cheap licence without it, from a thinly capitalised licensor, is a licence to bear the risk yourself.


Scope and Derived Data

Permitted use is a list. Users, including affiliates and — the omission that recurs — contractors, processors, and professional advisers acting on the licensee's behalf. Purposes, each stated and each permitted or not. Volume and frequency. Retention, including caches and backups. Territory and processing locations, which are compliance terms rather than preferences. Combination with the licensee's own or third-party data, with the status of the combined set stated. Output. Attribution.

Prohibited uses, stated expressly. Re-identification. Reverse engineering the collection methodology. Resale in raw or substantially raw form. Building a competing dataset. Training where not permitted.

Derived data is the term that decides the deal, and the one most often left vague. Define the spectrum explicitly.

State a numeric aggregation threshold. "No fewer than [N] distinct source records per output value, from which no individual record's values can be derived."

Why a number. Nautilus v. Biosig Instruments is a patent definiteness case, but the discipline transfers: a boundary a reasonable reader cannot apply is not a boundary. "Aggregate statistics" without a number becomes an argument about whether a count of three qualifies.

Add a substitution test — Aggregate Output may not be supplied in a form or volume that substitutes for the data in the market — and a reconstruction prohibition covering combination with other information.

Say the quiet part in negotiation. The licensor fears substitution; the licensee fears everything it builds evaporating. Both statements produce better clauses than trading redlines.

Where the line sits determines whether a licensee can build a business. A licensee that must delete everything derived has bought a subscription; one that may retain aggregates and models has bought an asset. Negotiate this before the fee, and both sides price it correctly.


Model Training

Every data licence written today should address it, in one direction or the other. Silence is a decision, and it favours whichever party thought about it.

The terms to state, in order.

Why memorisation matters. A model trained on a small or repetitive dataset can reproduce source records, defeating the reconstruction test the derived data clause relies on. Where the licensor cares, require an evaluation and a remediation obligation rather than relying on the definition alone.

Why a model is different from other derived data. It can retain most of the dataset's commercial value after the licence ends, in a form deletion obligations do not reach. A licensor permitting training without addressing the model has effectively granted a perpetual licence.

The licensor's own exposure. Where the dataset contains third-party copyrighted material, granting training rights may expose the licensor to claims it cannot indemnify. The fair use position under 17 U.S.C. § 107, framed by Google v. Oracle America and narrowed by Andy Warhol Foundation v. Goldsmith, is genuinely uncertain — and the exposure attaches to the underlying material rather than to the compilation, which is why provenance matters more here than anywhere.

Output ownership. State who owns outputs, and note separately that outputs generated without human creative contribution may not be copyrightable at all — a limitation on what either party can own rather than an allocation between them.

Price training separately. It is a different use with a different value and a different residual, and bundling it into a general subscription is how licensors give away the asset for a year of fees.


Privacy and Compliance

The constraint that overrides the contract. Where the data describes identifiable people, privacy law governs regardless of what the licence says.

Classify first. Does the dataset contain personal information as each applicable regime defines it? The definitions are broader than commercial parties assume and frequently capture device identifiers, network addresses, and inferences.

Allocate roles. Under the California Consumer Privacy Act and state analogues, classify the transfer as a sale, a sharing, or a disclosure to a service provider, and draft to the classification. A data licence is frequently a sale, with disclosure and opt-out consequences for the licensor. Where service provider treatment is intended, include the required terms and confirm the conduct will match them.

Purpose limitation. State that the licensee may process only for listed purposes, compatible with the privacy notice in force at collection.

Individual rights routing — the clause most licences omit and the licensor most needs. The licensor notifies; the licensee acts within a period shorter than the licensor's statutory deadline; the licensee confirms in writing; the obligation extends downstream. Without it the licensor cannot comply, and the failure is the licensor's.

Sectoral overlays. Health data under the Health Insurance Portability and Accountability Act de-identification standards, financial data under the Gramm-Leach-Bliley Act privacy rule, education records, and children's data each impose independent constraints.

De-identification. Where it is the basis on which data becomes licensable, state the standard applied and who certified it. Prohibit re-identification expressly, extend the prohibition to combination with other datasets, and back it with audit and termination rights. Re-assess periodically, because auxiliary data availability increases over time.

Registration. Where either party meets the definition, note obligations under state data broker registration requirements, which apply independently of the licence.

Security. Specify the control standard by reference to a framework rather than by adjective, breach notification timing in hours rather than days, cooperation obligations, and who bears notification costs.

Source-contract flow-down. Mirror inbound restrictions in the outbound licence expressly, because privity means nothing travels unless it is written.


Scraping and Access

The question. May a party collect data from a website or service without permission, and may the operator stop it?

The access statute. 18 U.S.C. § 1030 prohibits accessing a computer without authorisation or exceeding authorised access.

Van Buren v. United States narrowed "exceeds authorised access" substantially, holding it covers obtaining information from areas that are off limits, not using information one is entitled to obtain for an improper purpose. The gates-up-or-down framing means a policy violation is not a federal crime.

hiQ Labs v. LinkedIn held that scraping publicly available data — accessible without authentication — likely does not violate the statute, because there is no authorisation gate to breach.

What remains available to an operator. Technical measures: authentication, rate limiting, blocking. Contract, where formation is adequate, which is the strongest remaining tool. Trespass to chattels, requiring actual impairment. Copyright, where the scraped material is itself protectable as distinct from facts. And breach of contract by an account holder scraping through an authenticated account.

Formation matters enormously. Clickwrap generally binds; browsewrap frequently does not, and terms nobody agreed to bind nobody. See Terms That Actually Bind.

For a data licensor. A dataset built by scraping is one whose rights-to-grant representation is difficult to give, and licensees should ask directly what proportion was collected that way.

For an operator. If the data matters, put it behind authentication and terms that bind. Publishing it openly and relying on a policy nobody agreed to is not a strategy.


Exit

Draft this before the operative clauses, and ask one question: what does the licensee hold on the day after termination?

Licensed Data and Transformed Data. Return or destruction within a stated period, certified by an officer.

Backup and archival copies. Address expressly. Immutable backups cannot be purged, so a deletion certification covering them is either dishonest or ignored. The workable term: backups need not be purged, remain subject to confidentiality and use restrictions until overwritten in the ordinary retention cycle, and may not be restored into production.

Aggregate Output and Insights. Retained, subject to the threshold and the substitution test.

Models. Per the training clause, restated in the exit schedule so it is not missed.

Outputs already delivered to the licensee's customers. Continued use permitted, because recall is impossible and an unperformable obligation is worse than none.

Sublicences and downstream recipients. State whether they survive and on what terms.

Wind-down period. A defined transition window for migration, worth more to a licensee than most other terms and costing the licensor little.

Survival. Confidentiality, privacy obligations, audit rights for a period, indemnities, liability limits, and dispute resolution.

Licensor insolvency. A data licence may not be an intellectual property licence for bankruptcy purposes, which makes escrow and continued-access arrangements more valuable than in software deals — noting that continuously refreshed data is far harder to escrow than a static deliverable, so specify deposit cadence and completeness.

Change of control. State the position on both sides, and address the scenario that puts the data in a competitor's hands.


Enforcement

What the licensor actually has. Breach of contract and whatever technical control it retains. Not statutory damages, not fee shifting absent a clause, and not an injunction as of right.

Suspension of access is the most effective remedy and the fastest, because it does not require a court. Draft an express right to suspend on notice for material breach with a cure period, and confirm the technical capability exists.

Liquidated damages for defined breaches — unauthorised redistribution, re-identification, prohibited training — set as a genuine pre-estimate rather than a penalty.

Injunctive relief acknowledgement that breach causes irreparable harm, which helps without guaranteeing.

Audit-triggered cost shifting, which makes the audit right self-funding when a discrepancy is found.

Trade secret claims under 18 U.S.C. § 1836 where secrecy was actually maintained, carrying stronger remedies including fee shifting.

Copyright claims where the misappropriated material includes protectable elements rather than facts, requiring registration before suit under 17 U.S.C. § 411 and timely registration for statutory damages under 17 U.S.C. § 412.

Access statute claims under 18 U.S.C. § 1030, narrowed considerably and available mainly where authentication was circumvented.

Unfair practices under 15 U.S.C. § 45 and state analogues, which are regulator-driven in most cases.

The practical point. The suspension right and the audit right do more work than every litigation remedy combined. Exercise the audit right occasionally, because unexercised audit rights train counterparties to treat restrictions as decorative.


Governance

Provenance metadata at ingestion. Source, date, basis, and terms, recorded at the time. Retrofitting is the most expensive remediation in this field and recording costs almost nothing at collection.

An ingestion gate. Nobody adds a source without someone reading the terms and recording whether onward licensing is permitted. This single control prevents the composite-dataset failure entirely.

An outbound gate. Nobody signs a licence out without confirming provenance supports the representation.

The inbound register. Every source with redistribution rights, change of control treatment, purpose limits, and term extracted, consulted before any outbound licence.

The outbound register. Every licence granted with scope, derived data definition, exclusivity, most-favoured-nation terms, training rights, and expiry — so the next deal is negotiated with knowledge of the last.

A standard form with the recurring terms pre-drafted, so negotiations reduce to price and a handful of variations.

Deletion routing from the privacy team to every licensee, with tracked response.

Annual notice review. Compare the privacy notice against actual practice, since the notice at collection governs and drift is found by regulators rather than by the business.

Reciprocal exchanges. Run the same analysis in both directions. Barter deals get one short mutual agreement and none of this work, creating two problems instead of one.


Pricing and Structure

Why data pricing is unlike software pricing. The marginal cost of another copy is zero, the value to each licensee differs enormously, and the asset depreciates continuously as the world it describes changes.

Price the use, not the volume. Tiered pricing by use right — internal analytics, redistribution, model training — aligns price with the terms that matter and makes the restrictions commercially meaningful.

Term. One to three years is typical, because the data refreshes and both parties want to reprice. Short terms make exit terms decisive.

Exclusivity is expensive, because a non-rivalrous asset granted exclusively forecloses every other customer. Prefer field limits, term limits, or a commitment not to license named competitors.

Most-favoured-nation clauses. Define the comparison precisely — same volume, same use rights, same term — or every later deal triggers a rebate. Track granted terms in the outbound register.

Service levels. Availability, refresh cadence, format stability, and schema change notice. A schema change without notice breaks the licensee's pipeline and is the operational complaint that recurs above all others.

Data quality. Licensors resist accuracy warranties correctly, since data describing the world is wrong in places. Substitute a defined error-reporting and correction process, which gives the licensee something enforceable without warranting the world.

Change control. What happens if the licensor's own source is lost, or a regulator requires records to be withdrawn. Both happen, and both should have a stated consequence short of breach.


Diligence on a Data Asset

Ten questions.

  1. Provenance by source category, with percentages.
  2. Inbound licence terms, specifically onward licensing and change of control.
  3. Terms of use and privacy notices as they existed at collection, not as they exist now.
  4. Consent records where consent was the collection basis.
  5. Outbound licences and what they committed — exclusivity, most-favoured-nation terms, derived data and training rights already granted.
  6. Deletion and access request handling, with evidence the obligations were met.
  7. Scraped proportion of the asset, and the access conditions at the time.
  8. Security posture and breach history.
  9. Regulatory correspondence touching data practices.
  10. Whether the data can lawfully transfer to the acquirer at all, which in some structures requires consent or notice.

The recurring finding. A dataset assembled from multiple sources over years, with no provenance metadata, licensed out under representations the licensor cannot support. It is common, it is expensive to remediate, and it is why data assets are frequently valued at a discount to what the business expects.

The seller's answer. Build the provenance summary before the process opens, put it in the data room on day one, and the asset stops being a diligence issue.


Worked Situations

The composite dataset. A licensor wants to license a market dataset assembled from four sources over eight years. The provenance table shows forty per cent self-generated, twenty per cent user-supplied under terms permitting "sharing with partners," thirty per cent from a third-party feed licensed under an express redistribution prohibition, and ten per cent unknown. The deal as proposed cannot be done. The routes are: renegotiate the feed licence from a position of weakness; carve the feed data out, which may destroy the value; or license only derived aggregates computed across the whole, which the feed licence may or may not permit. Doing the provenance table in week one turns a broken deal into a scoped one; doing it during diligence turns it into a price adjustment.

The analytics vendor. A licensee takes a subscription for internal analytics. Its modelling is performed by an offshore contractor and its business intelligence tool is a hosted third-party service ingesting the data. Both are outside a permitted-user clause naming only the licensee entity, and the breach runs from day one. The fix is two lines at drafting and expensive after an audit. Circulate the permitted-user list to the engineering team before signature.

The training clause that was not there. A provider licensed a specialist corpus for "internal research and development" on a two-year subscription. The licensee trained a model, launched a product, and declined to renew. The deletion clause required return or destruction of the licensed data, which the licensee performed. The model remained, and nothing addressed it. The provider had sold its asset for two years of subscription fees.

The exclusive that foreclosed everything. A licensor granted its first customer worldwide exclusivity for a good price, with no field limit and a five-year term. Two years later every subsequent conversation ended at the same point. Exclusivity in a non-rivalrous asset should be the most scrutinised term in the agreement and is routinely the least.


Common Errors

Writing "Licensor owns the Data." Usually false, invites the preemption argument, and a better formulation costs one sentence.

Leaving derived data to the end, by which point it is a deal term disguised as a definition and neither side will move.

Defining aggregates without a number.

Omitting contractors from permitted users.

Not addressing training, so the model outlives the licence and takes the asset with it.

Requiring deletion of backups, so the certification is given dishonestly or the clause is ignored.

Missing the deletion-request routing clause, leaving the licensor unable to comply with its own obligations.

Licensing out data licensed in under a redistribution prohibition, because nobody read the inbound terms.

Relying on browsewrap terms that never bound anyone.

Granting exclusivity casually in an early deal, foreclosing the entire subsequent strategy.

Setting the indemnity cap at twelve months' fees, which makes the only term the licensee cares about decorative.

No audit right, so every restriction is aspirational.

No wind-down, stranding the licensee's customers mid-contract.

Treating a reciprocal exchange as a formality.


The View from Abroad

The European sui generis database right protects a database in which there has been substantial investment in obtaining, verifying, or presenting the contents, independently of any copyright in the arrangement.

Why it matters to a US practitioner. A dataset with no US protection may carry a genuine property right in Europe, which changes both the licensing posture and the enforcement options for the same asset.

Its limits. The investment must be in obtaining data rather than in creating it, which excludes datasets that are byproducts of another activity. The distinction has been litigated extensively and is not intuitive.

Term. Fifteen years, renewed by substantial new investment, which in practice makes a continuously updated database perpetually protected.

Drafting consequence. Where a dataset has European coverage, grant and reserve the database right expressly rather than relying on a general intellectual property clause drafted for US assets. An unrestricted grant can give away a right the licensor did not know it held, and silence can leave it unexploited.

Data localisation and transfer. Independent of any property right, a growing number of regimes constrain where data may be stored and processed. These are compliance obligations the licence must reflect in its processing-location terms rather than issues to resolve after signature.


A Closing Note

A data licence is doing something unusual: creating the rights it grants, rather than allocating rights that already exist.

That changes the drafting discipline in three ways. Everything not prohibited is permitted, so permitted use is a list. Nothing binds anyone outside privity, so flow-down obligations carry the whole compliance structure. And nothing is self-executing, so the audit right and the suspension right are the enforcement mechanism.

Settle provenance first, because the representation is the product and it cannot be written honestly without the source table. Settle derived data second, with a number in the aggregation threshold, because it decides whether the licensee is buying a subscription or an asset. Address training expressly in every direction, because a model is the one residual that quietly survives every other term.

Then draft the exit schedule and work backwards, asking what the licensee holds on the day after termination — and price the deal against that answer rather than against the volume of records delivered.


The Negotiation Sequence

Meeting one. Provenance and derived data. Nothing else. Both parties leave knowing whether the deal is possible and what shape it takes.

Meeting two. Permitted use as a list, walked through line by line with the business and engineering teams present. This is where contractor access, combination rights, and output restrictions get settled by people who know how the work is actually done.

Meeting three. Privacy allocation, flow-down, and security, with privacy counsel on both sides.

Meeting four. Exit schedule, before the operative clauses are finalised.

Meeting five. Commercial terms, which are now straightforward because everyone knows what is being sold.

Why this order. Commercial terms are unpriceable until scope and residual are settled, and negotiating price first anchors both parties to a deal shape neither has analysed.

Who attends. For any licence of consequence: counsel, the business owner, someone from data engineering, and privacy. The engineering representative prevents the most common category of error, which is a restriction the business cannot operate within.

Time budget. Four to eight weeks with a standard form, twice that without one. The provenance work is the long pole and should start before the first meeting.

A note on operational impossibility. These agreements fail more often on that than on legal error — a deletion obligation nobody can perform, a processing-location restriction contradicting the licensee's architecture, a refresh commitment the licensor's pipeline cannot meet. Ten minutes of review by someone who runs the systems prevents most of the disputes in this area.


Metrics


A note on the word "own" in a term sheet. Commercial parties write "Licensor owns the Data" and mean something sensible: that the licensor controls it and the licensee may not treat it as its own. The sentence is harmless until read against a preemption argument or a diligence question, at which point it commits the licensor to a proposition it cannot support. The better formulation costs a sentence and removes a category of argument.


A note on the second deal. Counterparties vary enormously in their standard forms, their flexibility, and their approval cycles. Keep a short internal note per counterparty after each negotiation, and the second deal costs a fraction of the first.


A Suggested Reading Path

For the framework:

  1. Selling Something You Cannot Own
  2. Licensing Data as a Commercial Asset
  3. Data Licensing Checklist

For the collection and access questions:

  1. Who Owns the Data
  2. Terms That Actually Bind
  3. Taking It Apart

For the model and output layer:

  1. Buying a Model
  2. Fair Use After Warhol

For the privacy and security layer:

  1. The Data Behind the Marketing
  2. The First Seventy-Two Hours
  3. Running a Data Breach Response

Primary Authorities

| Authority | Proposition | |---|---| | 17 U.S.C. § 102 | No protection for facts or ideas | | 17 U.S.C. § 103 | Compilations | | 17 U.S.C. § 106 | Exclusive rights | | 17 U.S.C. § 107 | Fair use | | 17 U.S.C. § 301 | Preemption | | 17 U.S.C. § 411 | Registration before suit | | 17 U.S.C. § 412 | Statutory damages and fees | | 18 U.S.C. § 1836 | Trade secret civil action | | 18 U.S.C. § 1030 | Computer Fraud and Abuse Act | | 15 U.S.C. § 45 | Unfair or deceptive practices | | Feist Publications v. Rural Telephone Service | Facts unprotectable | | Van Buren v. United States | Exceeding authorised access narrowed | | hiQ Labs v. LinkedIn | Public data and the access statute | | ProCD v. Zeidenberg | Contract terms on unprotectable data | | Google v. Oracle America | Fair use in functional works | | Andy Warhol Foundation v. Goldsmith | Transformative purpose narrowed | | Nautilus v. Biosig Instruments | Definiteness, applied to scope drafting | | California Consumer Privacy Act | Sale, sharing, service provider terms | | Health Insurance Portability and Accountability Act de-identification | Safe harbour and expert determination | | Gramm-Leach-Bliley Act privacy rule | Financial data constraints | | European Union database directive | Sui generis database right | | State data broker registration requirements | Registration and disclosure duties |


Forms and Templates

The artefact that decides a data deal is not the agreement but the provenance table, and it should exist before drafting begins. One row per source, with the source name and type, the date range of records obtained, the approximate proportion of the dataset, the basis of collection — self-generated, user-supplied under terms, licensed in, purchased, scraped, received under a research agreement, or unknown — the governing document reference, whether onward licensing is permitted or prohibited or silent, whether personal information is present, and any use, territory, or attribution restriction. The unknown row is the finding, most real datasets have one, and its size determines how much of the rights-to-grant representation the licensor can honestly give. The Portfolio Inventory Template adapts to that table and to the two registers a working programme maintains: the inbound register carrying each source with redistribution rights, change of control treatment, purpose limits, and term; and the outbound register carrying each licence granted with scope, derived data definition, exclusivity, most-favoured-nation terms, training rights, and expiry.

The License Agreement Template is the instrument, and the clauses requiring the most attention are the ones this practice invented rather than inherited: the rights representation written as what rights are held rather than as ownership of facts; permitted users including contractors and processors; the aggregation threshold stated as a number; the training clause covering pretraining, fine-tuning, evaluation, model reuse, and survival; the individual rights routing that lets the licensor comply with its own obligations; and the exit schedule addressing backups with continuing confidentiality rather than impossible deletion. The Assignment Agreement Template matters where a dataset transfers with a business, and where the question is whether it can lawfully transfer at all — which, for consent-based collections and service provider arrangements, it frequently cannot without notice or consent.


Related Toolkits and Checklists

The Data Licensing Checklist runs the deal in the order the terms should be settled, with gates before signature and before any specification is sent. The AI Procurement and Governance Toolkit covers the model layer that training rights feed into, including output ownership and vendor indemnity. The State Privacy Compliance Toolkit covers the notices, consents, and breach obligations that constrain what may be licensed regardless of the commercial deal. The IP Audit and Portfolio Governance Toolkit covers the register discipline this practice depends on. And the Software, Data, and Open Source Toolkit covers the code layer that sits alongside the data in most technology transactions.


Related Documents

Articles

Guides

Checklists

Toolkits

Templates & Forms


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Data rights and privacy obligations turn on provenance, jurisdiction, and the specific contracts in the chain. Marksy is not a law firm.

Read this article on Marksy