Legal & privacy
AI training data licensing agreement checklist
A clause-by-clause checklist for reviewing an AI training data license, from scope and permitted use to exclusivity, security, deletion, liability and payment.

The price gets the attention, but the agreement determines what you're actually giving up and what risk you're taking on. This checklist walks through the clauses that matter most in an AI training data license, with questions to ask about each.
This is general information, not legal advice. Every deal is different. Have qualified counsel review any agreement before you sign.
1. Definition of the dataset
- Is the licensed dataset precisely defined (systems, date ranges, volumes, formats)?
- Are exclusions listed explicitly (channels, folders, record types, customers)?
- Does the definition reference the de-identification method and a documented specification?
- Is there a process for handling data delivered by mistake (outside scope)?
A vague dataset definition creates arguments later about what was promised and what was delivered.
2. Grant of rights
- Is it a license or an assignment? For operational data, a license is typical. See licensing vs. selling.
- Exclusive or non-exclusive? If exclusive, for how long and in what field of use?
- Permitted uses: training, fine-tuning, evaluation, benchmarking, internal research? Each should be listed.
- Prohibited uses: redistribution, resale, re-identification, use to build competing products, use in advertising or profiling.
- Sublicensing: can the buyer let affiliates, contractors or cloud providers access the data? Under what conditions?
- Territory and duration: worldwide? Perpetual for trained models? Time-limited for raw data?
3. Ownership and retained rights
- Do you clearly retain ownership of the underlying data?
- Are you free to keep using the data in your business?
- Under a non-exclusive license, are you free to license to others?
- Who owns the models trained on the data? (Almost always the buyer, but confirm there's no claim on your other assets.)
4. De-identification and re-identification
- Is the de-identification standard described, and who is responsible for performing it?
- Does the buyer agree not to attempt re-identification, and not to combine the data with other sources to identify individuals?
- What happens if the buyer discovers residual identifiers? (Ideally: notify you, quarantine and delete the affected records.)
5. Security and access
- What security controls must the buyer maintain (encryption, access controls, logging)?
- Where may the data be stored and processed?
- Who at the buyer can access the raw data?
- What are the breach notification obligations and timelines?
6. Retention and deletion
- How long can the buyer retain raw copies of the dataset?
- Is deletion required after training, at the end of the term, or on request?
- How is deletion certified?
- Is it acknowledged that trained model weights can't be "un-trained," and are obligations written accordingly (for example, applying deletion to stored data rather than to models)?
7. Representations and warranties
Buyers often ask sellers to warrant things like:
- You have the right to license the data.
- Licensing it doesn't violate your contracts, policies or applicable law.
- The data has been de-identified to the agreed standard.
Ask: are these warranties ones you can actually give? Are they qualified "to your knowledge"? Are they limited to the agreed specification? Overly broad warranties shift a lot of risk onto you. See is it legal to sell company data? for the underlying questions.
8. Indemnities and liability
- Who indemnifies whom, and for what?
- Is there a cap on your liability, ideally tied to the amount paid?
- Are indirect and consequential damages excluded?
- Is the buyer responsible for misuse of the data after delivery?
9. Payment terms
- What is the price, and is it fixed or variable (for example, per unit delivered)?
- When is payment due: on signing, on delivery, on acceptance, in tranches?
- What exactly constitutes "delivery" and "acceptance"? Is there an acceptance window, and what happens if the buyer neither accepts nor rejects?
- Are there holdbacks or clawbacks, and under what conditions?
10. Future deliveries and options
- Does the buyer have an option to receive future data (for example, the next year of history)?
- How would future deliveries be priced?
- Are you obligated to provide them, or only invited to?
11. Confidentiality and publicity
- Are the deal terms confidential?
- Can the buyer name you as a data partner? Can you name them?
- Do confidentiality obligations survive termination?
12. Termination
- Under what circumstances can either party terminate?
- What happens to the data and to payments on termination?
- Which obligations survive (security, deletion, re-identification bans, confidentiality)?
13. Governing law and disputes
- Which jurisdiction's law applies?
- Are disputes resolved in court or through arbitration?
A one-page summary for decision-makers
Before signing, write a short summary answering: what exactly are we licensing, to whom, for what uses, for how long, exclusively or not, for how much and when, and what we're promising. If you can't answer clearly, the agreement probably needs work.
DataOffer brings you competing offers and helps you compare not just prices but terms, so you can see what you're trading for a higher number. Nothing is shared until you approve the buyer, price and terms, and we always recommend independent legal review.
Ready to see what your data is worth?
Share rough estimates (systems, approximate volume, years of history, headcount) and we'll come back with competing offers from AI labs. No upfront cost, no commitment, and nothing is shared until you approve.
This guide is general information, not legal, tax or financial advice. Figures and ranges are illustrative; talk to qualified advisors about your situation.

