Global
Data Provenance
The short answer. A provenance record is worth having only if it survives to the file. "Collected from the internet" is not provenance, because it answers where the data came from without answering what was done to it, under what authority, and who agreed. A usable record carries the source, the collection date and method, the rights basis, the consent reference, the transformations applied, and the retention terms. Two provisions make this concrete rather than philosophical: the training-content summary required of general-purpose model providers, and the record of processing activities required of controllers.
The law
Regulation (EU) 2024/1689 Article 53(1)(d)
(d) draw up and make publicly available a sufficiently detailed summary about the content used for training of the general-purpose AI model, according to a template provided by the AI Office.
This sets the standard a provenance record has to feed. A summary that satisfies this provision cannot be written from a supplier's general description of a dataset, because it has to be sufficiently detailed and it follows a published template. In practice it pushes the requirement down the chain: the model provider asks the data supplier, and the data supplier has to have kept records at the level of the corpus rather than the purchase order.
GDPR Article 30(1)
Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility. That record shall contain all of the following information: (a) the name and contact details of the controller and, where applicable, the joint controller, the controller's representative and the data protection officer; (b) the purposes of the processing; (c) a description of the categories of data subjects and of the categories of personal data.
Where the corpus contains personal data, this is the provision that turns provenance into a legal obligation rather than good practice. The record has to name the purposes and describe the categories of data subjects, which for a voice dataset means the speakers and their location. A record created after the fact from memory will not match what the supplier actually did, which is why it belongs in the collection specification.
GDPR Article 5(2)
The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1 ("accountability").
Accountability is the reason a provenance record exists. The burden is to demonstrate compliance, which means the documentation has to exist before anyone asks for it. For a data buyer this is the provision that justifies asking a supplier for records rather than assurances: an assurance is not a demonstration.
Who it applies to
Provenance and lineage are not the same thing, which is why so many records are useless. Lineage describes where data came from: a URL, a publisher, a studio, a crawler. Provenance describes the whole chain, including what was done to the data and under what authority. A lineage record tells you the data is a web scrape. A provenance record tells you which reservation of rights applied at collection and who authorized the copy.
Three parties need it. The seller needs it to answer diligence questions and support a warranty. The buyer needs it to satisfy its own downstream obligations, including the training-content summary if it is building a general-purpose model. The buyer's customer needs it because an enterprise procurement review now asks for training data documentation as a matter of course.
The obligation that makes it binding depends on the data. If the corpus contains personal data, Article 30 applies to the controller and Article 5(2) requires the compliance to be demonstrable. If the buyer is training a general-purpose model, Article 53(1)(d) requires a public summary. If the corpus is purely synthetic with no personal data, there may be no legal obligation at all, and the record is still what makes the dataset sellable.
This is one area where the buyer's location matters less than usual, because the record travels with the data. A record produced for an EU project is the same document a US buyer will ask for.
- A corpus you collected yourself: you are the source of the record, and it has to be built during collection.
- A corpus you bought: you can only pass on what the supplier kept, so the record is a contractual deliverable.
- A corpus you are reselling: your customer will ask for the record, and a gap becomes their problem too.
What it costs to get wrong
There is no penalty for a poor provenance record as such. The exposure comes through the provisions the record supports. Failing to maintain the record of processing activities required by Article 30 falls under Article 83(4)(a) at up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher.
For a general-purpose model provider, failing the Article 53 duties can attract Commission fines under Article 101 of up to 3% of annual total worldwide turnover or 15 million euros, whichever is higher, where the infringement is intentional or negligent. A missing training-content summary is not a formatting problem at that point.
The consequence that decides most commercial outcomes is contractual rather than regulatory. A dataset without a provenance record cannot pass an enterprise procurement review, and it cannot be resold to a customer who has its own disclosure obligation. That is a deal-level cost that arrives whether or not a regulator is interested.
There is also an asymmetry worth naming. A supplier with a good record can answer diligence questions in days. A supplier without one has to reconstruct the answer, and reconstruction produces inconsistencies — different dates, different purposes, different counts — that a reviewer reads as evidence that nobody was tracking the data at all.
How to comply when you are buying data
A provenance record is cheap to build at collection time and expensive to reconstruct afterwards, which is the whole argument for making it a specification item rather than a documentation task.
Six fields sound like a lot until you compare them to the cost of not having them. Every field is something the supplier already knows at collection time and cannot reliably reconstruct a year later.
On projects we source, the provenance fields below are populated as the data is collected rather than compiled at delivery, and they are delivered with the dataset. We are a procurement agent and not a law firm, so this is a factual record of the chain rather than an assessment of whether the chain is sufficient for your jurisdiction.
- Require the record at file or batch level, not at dataset level. A single paragraph describing "the corpus" cannot support a disclosure obligation, and it cannot answer a question about one source among many.
- Insist on the six core fields: source and rights holder, collection date and method, rights basis or license reference, consent record reference where personal data is involved, transformations applied, and retention or deletion terms.
- Ask what happened between collection and delivery. Noise reduction, filtering, resegmentation and transcription all change the data, and a record that stops at collection is a lineage record rather than a provenance record.
- Make the record a contractual deliverable with a defined format. If it is not in the deliverables schedule, it will not arrive, and chasing it after the invoice is paid is the weakest position you can hold.
- Check that the record can survive one more hop. If your own customer has a disclosure obligation, the record you receive has to be sufficient to feed theirs, which means it cannot be summarised to the point where the source detail is lost.
Related compliance topics
-
Data Licensing Agreement
data licensing agreement
-
AI Training Data Laws
ai training data laws
-
AI Training Data Governance
ai training data governance
-
California AI Training Data Transparency Act
ai training data transparency act
-
Biometric Data under GDPR
gdpr biometric data
-
Illinois BIPA
bipa
Not legal advice
We are a sourcing company, not a law firm. Nothing on this page is legal advice, and it does not create a lawyer–client relationship. Whether a particular dataset is permissible in your jurisdiction depends on your use case, where you operate, and where the people in the recordings are located. Our role is to document the chain of consent accurately so that your counsel can assess it.
Sourcing data under Data Provenance?
Tell us the language, the hours, and what the data needs to look like. You will get a real number and a real timeline — not a range. If we cannot source it well, we will tell you that instead.
- Pilot batch before the full run, so problems surface early.
- Consent documentation delivered with the data.
- No medical or clinical data. No recorded telephone calls.