Read
3 minute read
April 21, 2026
3 minute read
As data becomes an increasingly valuable asset, organizations must carefully structure their agreements to address the unique challenges that data presents. Some of the challenges include how to define data, addressing ownership and use rights (if any), and manage associated risks. A poorly drafted agreement can expose your organization to significant privacy and security risks, regulatory penalties, or disputes over data rights that may be difficult or costly to resolve.
Defining Data: Categories and Considerations
At its core, data can be understood as the presentation of information in a machine-readable format. However, not all data is created equal, and agreements must account for the different types of data involved. Key categories include:
- Personal Data: Information relating to identifiable individuals, which triggers specific legal obligations under privacy laws such as GDPR, CCPA, and other data protection regimes.
- Operational and Machine-Generated Data: Data produced through business operations, equipment sensors, or automated systems. This category is growing rapidly with the proliferation of IoT devices and automated processes.
- Shared vs. Sensitive Data: Organizations should differentiate between shared data (accessible by both parties for operational purposes) and sensitive data (such as intellectual property or personal data). These categories trigger different levels of consent requirements, security obligations, and usage restrictions.
- Anonymized or Pseudonymized Data: Data that has been processed to remove or obscure personal identifiers. While this may reduce certain compliance obligations, pseudonymization is not the same as anonymization and re-identification risks must be addressed.
Data Ownership and Use Rights
Questions of data ownership and use are highly context-dependent and vary based on the technology involved and the nature of the parties’ relationship, and also what they want to accomplish. Key considerations include:
- Context-Specific Allocation: In software contexts, outputs may be best owned by the customer, particularly where the customer provides the inputs. In other contexts, such as data analytics services, ownership structures may differ.
- Capturing Intended Uses: Agreements should clearly articulate what the data will be used for, as well as any impermissible use cases. While it is impossible to anticipate every future use case, drafters should address foreseeable uses based on input from the organization without attempting to future-proof every scenario.
- Tiered Use Framework: Consider implementing a tiered structure that specifies: (i) uses that are expressly permitted; (ii) uses that require prior consent (such as new use cases as they arise); and (iii) uses that are prohibited. This framework should also address data flows to third parties, if allowed, including mandatory consent procedures where required.
Technology and Terminology Considerations
Organizations should ensure that they have a clear understanding of the underlying technology involved in the agreement. This is particularly important where the technology involves generative AI, machine learning, or hybrid approaches, as each may have different implications for data use, the potential for model training, and output ownership.
Consider whether transfer of data is truly necessary to accomplish the agreement’s objectives, or whether alternative approaches (such as providing access without transfer) may be more appropriate.
In some cases, parties may be wise to characterize the arrangement as a “data sharing agreement” rather than a “license agreement,” as the former characterization may more accurately reflect the nature of the relationship and avoid unintended IP implications that could arise under the latter characterization.
Key Takeaways
- Understand the use cases: Gain a thorough understanding of what will be done with the data before drafting the agreement.
- Separate data from IP: Where appropriate, divorce data rights from intellectual property rights, as they may require different layers of protection and different contractual treatment.
- Be jurisdictionally aware: In certain jurisdictions, particularly the EU, avoid framing data in terms of “ownership.” Instead, focus on use rights, access rights, and custody of data.
- Address data-related risks: Identify and allocate risks associated with the specific types of data involved in the agreement, including security, privacy, and regulatory compliance risks.
- Educate end users: Ensure that end users understand what they can and cannot do with the data under the agreement. This includes addressing questions such as whether the data may be used for training AI models or whether outputs may be used to improve systems. Signing the agreement is not the last step for managing data under the agreement.
Data-related agreements present unique challenges that require careful attention to evolving regulatory requirements, rapidly changing technology, and complex ownership and use questions. Our team has significant experience navigating these issues across industries and jurisdictions. We encourage you to reach out early in the negotiation process so we can help you structure agreements that protect your interests, ensure compliance, and position your organization to realize the full value of its data assets.


