Compliance · Data licensing

What is actually in a data licensing agreement

Most of the value in one of these agreements is decided by clauses nobody reads out loud in the meeting. These are the ones worth slowing down for.

WritingBy Landon LittleSeptember 28, 20267 min read

Why this post does not give you a template

A lot of people searching for this are looking for a document to fill in. It is worth saying plainly why that is the wrong tool here.

In most contracts, a template is a reasonable starting point because the variables are obvious: parties, dates, amounts. In a data licensing deal, the terms carrying the most value are the ones a template cannot guess, and getting one of them wrong does not produce an obviously bad contract. It produces a contract that looks fine and quietly gives away the asset.

So instead, here is what each clause actually decides. Read it, form a view on what you want, then have a lawyer draft or review the real thing.

The four clauses that decide the value

These are the ones to slow down on, because each of them can be worth more than the number on the front page.

The scope clauses, in the order they usually matter
ClauseWhat it decidesThe question to ask
ExclusivityWhether you can license this data to anyone else, and for how longIf this is exclusive, what am I giving up in every future deal?
Field of useWhat the buyer may use the data forIs this licensed for one purpose, or for anything they ever build?
DerivativesWho owns what comes out the other sideIf they train a model on this, what is my position in that model?
Term and survivalWhen it ends, and what outlives the endingWhat exactly happens to every copy on the last day?

The clause that is not optional

Most of this list is commercial negotiation. One item is not.

If the deal is structured around the data being de-identified under the CCPA, the statutory definition at Civil Code section 1798.140, subdivision (m) requires three things, and the third is that the business contractually obligates any recipients of the information to comply with all provisions of that subdivision. That includes the commitment not to attempt reidentification.

This is not a nice-to-have term you can trade away for a better price. If it is missing, the data does not meet the statutory definition, and the reason the transfer sat outside the personal-information rules in the first place stops being true.

The clauses that protect you afterwards

  • Representations and warranties: what you are promising about the data, and what you are not. Promising more than you can verify is the most common way a seller creates a problem for themselves.
  • Indemnity: who carries the cost if something goes wrong, and whether it is capped. An uncapped indemnity from a small business to a large buyer is an asymmetric risk worth naming out loud.
  • Security and handling obligations: how the recipient must store and transmit the data, and whether subcontractors are permitted.
  • Onward transfer: whether the buyer may pass the data to affiliates, contractors, or acquirers. A license to one company can become a license to an industry through this clause alone.
  • Audit rights: whether you can ever verify any of the above, and at whose cost.
  • Confidentiality: covering the deal terms themselves, not only the data.
  • Governing law and dispute resolution: which is the clause nobody reads until it is the only one that matters.

How payment is usually structured

Payment terms vary more than people expect. A lump sum on delivery is the simplest and the easiest to value. Structures that pay over time, or that tie payment to the buyer's use, shift risk toward the seller and are much harder to verify without audit rights.

If a broker is involved, the fee structure is its own term: whether it is a percentage, whether it is contingent on closing, and whether the broker is paid on renewals or expansions of the original license. Nova's own arrangement is a percentage paid only if you accept an offer and a deal closes, which is one model among several rather than a standard.

Before you sign

  • Read your own privacy policy and customer contracts first. They can prohibit what the agreement permits.
  • Decide your position on exclusivity and derivatives before the negotiation, not during it.
  • Make sure the recipient-obligation clause is present if the deal rests on de-identification.
  • Confirm what happens to every copy at termination, in writing.
  • Have a lawyer review the actual document. Not a template, and not this post.

This is general information about how these agreements are typically structured, plus one statutory requirement quoted from published text. It is not legal advice and it is not a substitute for a lawyer who has read your specific deal.

Sources

  • Cal. Civ. Code 1798.140(m), definition of deidentified, including the requirement at (m)(3) to contractually obligate recipients.
  • Cal. Civ. Code 1798.140(v)(3), personal information does not include deidentified or aggregate consumer information.
  • All other clause descriptions above are general commercial practice, not statutory requirements.

Questions this post answers

Is there a standard data licensing agreement template?
There are templates in circulation, and using one you cannot evaluate is how businesses sign away things they did not mean to. The terms that matter most in these deals, exclusivity, field of use, and ownership of derivatives, are exactly the ones a generic template will get wrong for your situation. The useful preparation is knowing what each clause does, then having a lawyer draft or review the actual document.
What is the most important clause?
Usually exclusivity, because it is the one that forecloses the future. An exclusive license can be worth more upfront and means you cannot license that data to anyone else, possibly ever. A non-exclusive license pays less per deal and leaves the asset intact for the next one.
Who owns a model trained on my data?
Whatever the derivatives clause says, which is why it deserves more attention than it usually gets. Data going into a training run and a model coming out of it are different assets, and an agreement that is silent on the second one has not left it unresolved in your favour. Decide it explicitly.
Is any clause actually required by law?
One is, if the deal relies on the data being de-identified under the CCPA. The statutory definition requires the business to contractually obligate any recipients of the information to comply with all the same provisions, including not attempting reidentification. Without that clause the data does not meet the definition, and the whole structure the deal rests on comes apart.
What happens to the data when the agreement ends?
Only what the agreement says happens. Deletion, certification of deletion, and whether anything already derived from the data survives termination are separate questions with separate answers. A term that expires while the copies persist is not really a term.

Wondering what your own data is worth?

We broker the deal on your behalf: you approve the buyer and the price, you keep every original, and nothing is owed unless a deal closes.

Book a 20-minute call

Pick a time that works. Twenty minutes on video, no pitch. You leave knowing whether this is worth doing.