Global

Data Licensing Agreement

The short answer. Five clauses decide whether a data deal works: the scope of use, sublicensing and model-distribution rights, term and termination, indemnity, and what happens to models already trained when the license ends. The last one is the clause most often missing and the most expensive to be without, because a model cannot be untrained. Where the corpus contains personal data, the agreement also has to do the work of a data processing contract, because GDPR does not let a person sign away their rights the way a copyright owner can license a work.

The law

17 U.S.C. §101 (definition of "transfer of copyright ownership")

A "transfer of copyright ownership" is an assignment, mortgage, exclusive license, or any other conveyance, alienation, or hypothecation of a copyright or of any of the exclusive rights comprised in a copyright, whether or not it is limited in time or place of effect, but not including a nonexclusive license.

This definition tells you which licenses have to be in writing. An exclusive license is a transfer of ownership, so it must be documented as one. A nonexclusive license is not, which means it can arise informally.

17 U.S.C. §204(a)

A transfer of copyright ownership, other than by operation of law, is not valid unless an instrument of conveyance, or a note or memorandum of the transfer, is made in writing and signed by the owner of the rights conveyed or such owner's duly authorized agent.

The writing requirement is why a verbal grant of exclusivity is worth nothing. The signature must come from the rights owner or their authorized agent, so a supplier who sublicenses can only pass on what their own agreement permits.

GDPR Article 28(3)

Processing by a processor shall be governed by a contract or other legal act under Union or Member State law, that is binding on the processor with regard to the controller and that sets out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects and the obligations and rights of the controller.

Where the corpus contains personal data, the agreement is not only a copyright license. It also has to state the subject matter, duration, nature and purpose of the processing and the categories of data and data subjects. A voice corpus is a specific category of data, and a generic services contract does not satisfy this.

GDPR Article 28(3)(h)

(h) deletes or returns all the personal data to the controller after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data.

This is the deletion duty on the processor at the end of the arrangement, and it collides with the commercial reality of training. A supplier can delete its copies. It cannot delete the buyer's model weights, and the provision does not ask it to. That gap is what the termination clause must resolve.

Who it applies to

There are usually two agreements in a data deal and they are frequently confused. One is the license from the corpus owner, a copyright instrument. The other is the consent chain from the speakers, a data protection instrument that cannot be created by contract between buyer and seller. A license agreement silent on the second does not create it.

The distinction matters because personal data rights cannot be waived. A copyright owner can license a work broadly and permanently. A data subject cannot contract away the right to erasure or to withdraw consent, so the agreement has to build the mechanism for those rights to be exercised rather than purporting to exclude them.

Who signs what depends on the structure. Where a supplier collected the data itself, it is the controller for the collection and the buyer is typically a controller for its own training. Where the supplier is passing through data collected by someone else, the chain has to be documented, because the buyer's rights are limited by every link above it.

Territorially, a license agreement is a contract, so the parties can choose the governing law. What they cannot choose is which rights exist. A grant is only as effective as the rights the grantor held under the law where those rights arise, so a contract governed by the law of one country can still be defeated by a defect under another.

  • Direct license from the collector: the simplest structure, and the only one where the consent chain and the rights grant sit in the same organization.
  • Sublicense through a reseller: workable, but the buyer's rights are capped by the terms the reseller agreed to upstream.
  • Marketplace purchase: usually a nonexclusive license on standard terms, with the rights question disclaimed and no consent chain attached.

What it costs to get wrong

The first consequence is contractual, and it is the one that arrives most often. An indemnity claim for a rights defect in a delivered corpus is capped by the contract, and the cap is usually the contract value. If the buyer has already integrated the data and shipped a product, the cap is far below the cost of the remedy.

The second is a failure of the processing contract itself. Where Article 28 applies and the agreement does not contain the required terms, Article 83(4)(a) covers the controller and processor obligations under Articles 25 to 39 at up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher. That tier is lower than the consent tier, but it applies to a defect that is entirely within the parties' control.

The third is the un-undoable one. A model trained on data the buyer had no right to use cannot be made lawful by amending the agreement, and the practical remedy is retraining on a clean corpus. For a large model that is not a legal cost, it is a product cost, and it is the reason buyers now negotiate termination clauses more carefully than price.

There is also a downstream exposure that sits outside the contract entirely. If the buyer's customer relied on a warranty about the data and the defect surfaces later, the buyer is passing on an indemnity it did not fully receive, and the gap between the two caps is the buyer's loss.

How to comply when you are buying data

The clauses below are the ones worth spending negotiation time on. Everything else in a data agreement is largely standard.

The clause that gets the least attention and causes the most damage is the one about trained models. Every other clause governs what happens to the data. That one governs what happens to the product, and it is the only clause where the remedy cannot be completed by deleting a file.

Where a project involves personal data, we document the consent chain as a deliverable so that the agreement has something to point at, and we are explicit about what the chain does not cover. We are a procurement agent and not a law firm, so the drafting belongs with your counsel; what we can do is make sure the factual record the agreement depends on is accurate.

  • Define the scope of use by naming the acts. Training, fine-tuning, evaluation and benchmarking are different acts, and a grant that covers one does not cover the others. Say which.
  • Get sublicensing and model-distribution rights in writing, separately. The right to train and the right to ship what you trained are different grants, and the second is the one your customers depend on.
  • Resolve what happens to trained models on termination. The options are that the license survives for existing models, that the model must be retrained, or that a wind-down period applies. Pick one explicitly rather than leaving it to a dispute.
  • Make the indemnity match the risk. A cap at the contract value is standard and is also far below the cost of a recall. Negotiate the cap against the deployment, not against the invoice.
  • Attach the consent chain and the provenance record as deliverables. A license over data whose chain is undocumented is a license over an unknown quantity, and diligence will treat it that way.

How we handle consent and licensing →

Related compliance topics

Not legal advice

We are a sourcing company, not a law firm. Nothing on this page is legal advice, and it does not create a lawyer–client relationship. Whether a particular dataset is permissible in your jurisdiction depends on your use case, where you operate, and where the people in the recordings are located. Our role is to document the chain of consent accurately so that your counsel can assess it.

Sourcing data under Data Licensing Agreement?

Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.

  • Pilot batch before the full run, so problems surface early.
  • Consent documentation delivered with the data.
  • No medical or clinical data. No recorded telephone calls.

We reply within two business days. Your details are used only to answer this request. See our privacy policy.

Contact

Talk to a human

Send a specification and we will come back with a real number and timeline.

Submit a sourcing request

Or email hello@linguacorpus.com