Data Monetisation 101 / Section 4 / Chapter 15

Section 04 · Understand the deal · Chapter 15

Your Company Has the Data. But Does It Have the Right to License It?

Control over an enterprise database does not necessarily confer the right to license its contents for AI development. This chapter examines the overlapping rights, contractual obligations and permissions that determine whether operational data can become a commercially transferable asset.

18 min read9 referencesSite last updated 9 October 2026

Executive perspective

Executive perspective

Enterprise data can be technically valuable yet commercially unusable because the organisation cannot establish sufficient rights to license it. Ownership of a database, copyright in individual documents, customer confidentiality, personal-data obligations and third-party licences must be assessed separately.

Four principles matter. Possession is not permission; rights depend on the proposed use; limitations may be resolved by narrowing the dataset; and documented provenance makes commercial commitments more defensible.

A prospective buyer needs confidence not simply that the provider controls the records, but that the contemplated copying, processing, training, retention and onward use can be authorised.

The task is therefore to establish a defensible chain of rights, identify which records can be included, and determine whether the resulting package justifies the legal and technical preparation required.

1. The ownership problem: what does the company actually control?

A company may operate an extensive database containing customer interactions, employee decisions, supplier documents, technical reports, system-generated measurements and operational histories.

These records may be stored on its infrastructure, administered by its employees and used extensively in its ordinary business.

None of those facts, individually, establishes unrestricted licensing authority.

The first distinction concerns physical or technical control versus legal rights. A company may control access to a CRM system without owning copyright in customer-uploaded photographs or supplier manuals. It may own copyright in a technical report while remaining prohibited from disclosing its contents under a confidentiality agreement.

The position becomes more complex when information has been collected over many years under different contracts.

UK law distinguishes copyright protection for original selection or arrangement of database material from sui generis database rights that can protect qualifying investment in obtaining, verifying or presenting database contents. These rights can coexist, but neither automatically establishes rights to every third-party work contained in the database 1.

There is also a territorial dimension. Following Brexit, qualification and reciprocal recognition rules for newly created UK and EEA databases changed. A company contemplating cross-border exploitation cannot assume identical database-right protection in every market.

Importantly, facts and measurements are not automatically protected by copyright merely because they are recorded electronically. Copyright may protect original expression or an original arrangement, while contractual, confidentiality, database-right or data-protection restrictions may still govern access and use.

The consequence is that a rights review must examine more than a single asset called “the database”.

Rights operate in layers

Consider a software company whose support platform contains:

  • System-generated records of application faults.
  • Customer-authored messages describing those faults.
  • Employee-written diagnostic notes.
  • Reports prepared by external contractors.
  • Extracts from proprietary third-party manuals.

The company may possess a strong basis to use certain internally generated operational facts, but its rights in the other material may differ considerably.

The company should distinguish the rights needed to extract and prepare records from those required to disclose them, permit model training, authorise derivative datasets or grant onward access.

The transaction concerns a defined bundle of permissions, not an abstract claim to own the data.

Exhibit 1: The enterprise data rights stack

Rights or restrictionPrincipal questionTypical evidencePotential limitation
Database rightsWho holds relevant rights in the database structure or contents?Database history, investment and ownership recordsTerritorial and qualification limits
CopyrightWho created the protected expression?Employment records, assignments, source licencesThird-party or contractor ownership
Contractual rightsWhat uses do applicable agreements permit?Customer, supplier and platform contractsRestrictions on disclosure or reuse
ConfidentialityIs the information subject to secrecy obligations?NDAs, service contracts, internal classificationsCommercial or customer confidentiality
Personal-data obligationsCan the proposed processing and sharing lawfully occur?Purpose records, lawful-basis assessment, privacy documentationIncompatible or otherwise impermissible use
Trade secretsWould the proposed disclosure undermine protected know-how?Access controls, secrecy policies, confidentiality termsLoss of secrecy or competitive advantage

These layers should be investigated independently. Establishing one does not resolve the others.

For example, the company may own copyright in an employee-produced technical note but remain restricted from disclosing customer information quoted within it.

An effective diligence process therefore evaluates the actual composition of the material and the proposed transaction, rather than relying on a broad assurance that all information belongs to the company.

2. Establishing the chain of rights across different contributors

The most useful starting point is to classify data according to its origin.

Four categories frequently require different treatment: company-authored material, customer-provided content, employee and contractor contributions, and third-party licensed information.

Customer-provided material

Customers may submit emails, images, attachments, documents, technical drawings or confidential operating information while receiving a company's services.

These contributions can be valuable because they contain real problems, contextual detail and the outcomes of business interactions.

But the company's rights may be confined to delivering the contracted service.

Historical customer agreements may authorise processing, storage and internal analysis without permitting disclosure to an independent AI developer for unrelated model training.

A clause allowing the use of information to improve services is not necessarily equivalent to permission for unrestricted external licensing. The answer depends on the wording, contractual context, proposed use and applicable law.

Rights can also vary between customer cohorts.

A company may have introduced broader data-use provisions in 2023 while retaining older contracts for customers onboarded in previous years. Applying the latest terms retrospectively without examination could create substantial contractual risk.

This makes contract versioning commercially important.

Employee-created material

In the UK, an employer is generally the first copyright owner of qualifying works created by an employee in the course of employment, subject to contrary agreement. Work produced outside that scope may require a different analysis 2.

Employment-related copyright ownership does not resolve confidentiality, personal-data or other legal requirements.

For example, a company may own copyright in an employee's operational report while the report includes identifiable employee information or confidential statements from customers.

Ownership also needs careful examination where intellectual contributions were made during an individual's employment with another organisation.

Contractors and commissioned work

Contractor arrangements are a frequent source of uncertainty.

UK Intellectual Property Office guidance explains that a freelancer or contractor will generally retain copyright in commissioned work unless the contractual arrangements provide otherwise. A commissioner may have a limited implied licence for the original purpose, but that does not necessarily confer wider licensing or ownership rights 2.

A company that paid for thousands of contractor-generated technical reports should therefore inspect its agreements before including those reports in an AI licensing package.

Where rights are unclear, possible remedies include obtaining an assignment, negotiating an additional licence or excluding affected records.

The appropriate remedy depends on whether the missing permission can be obtained economically and without imposing unacceptable restrictions.

Third-party licensed content

Operational systems routinely contain supplier manuals, reference publications, software documentation, screenshots, templates and other third-party material.

An organisation may be permitted to use this information internally without being entitled to relicense it.

Software and platform licences can also restrict extraction or onward use of particular content. The presence of information within a vendor-operated system does not establish either that the vendor owns all customer content or that the customer may commercially license everything the system contains.

The diligence process should identify material third-party contributions and determine whether they are essential to the proposed AI task.

Where they are not essential, exclusion may be more efficient than seeking broad permissions.

Intellectual-property ownership and personal-data compliance are distinct questions.

Even if a company holds all relevant copyright and database rights, sharing records that identify individuals may still require a lawful basis, appropriate purpose assessment, transparency measures, security controls and other safeguards.

Under UK data-protection rules, organisations must identify a lawful basis for relevant personal-data sharing before it begins. The ICO also distinguishes between sharing with another independent controller and engaging a processor acting on the controller's documented instructions 3.

These relationships carry different responsibilities.

A proposed AI buyer might use supplied information for its own development purposes rather than merely process it on the supplier's behalf. The parties should determine their actual roles based on what each does, not simply assign convenient labels in an agreement.

Why anonymisation requires evidence

A common proposal is to replace names and account numbers with random identifiers.

This can reduce exposure, but it does not automatically make the dataset anonymous.

Individual identity may remain inferable from unusual events, combinations of attributes, exact dates or the content of free-text descriptions.

Pseudonymisation is a risk-reduction technique, not a substitute for identifying lawful processing conditions.

A company should evaluate the likelihood of re-identification, the information available to the recipient and the utility retained after transformation.

Some records may support the AI task after removal of personal information. Others may lose the context required to interpret the underlying decision.

The correct approach is to define the task and assess which fields are necessary, rather than assuming that every record can be made suitable through generic masking.

Confidentiality and trade secrets

Confidentiality may protect information that is not personal data or copyright-protected expression.

Customer pricing, internal operating methods, supplier terms and commercially sensitive technical processes may all create disclosure restrictions.

Moreover, a company should examine its own strategic interest in preserving confidentiality.

An archive of unusual troubleshooting cases might reveal operational know-how that competitors would find difficult to reproduce.

Licensing such information externally could create revenue while weakening a competitive advantage.

Restrictions on onward use, disclosure, model derivatives and competing applications may therefore have commercial importance beyond legal compliance.

International transfers

Where UK GDPR applies, allowing a separate organisation outside the UK to access personal information can constitute an international restricted transfer, even if the data remains physically stored on UK servers.

The ICO's 2026 guidance explains the relevant three-step assessment and the potential need for adequacy regulations, appropriate safeguards or an applicable exception 4.

An overseas AI partner's remote access should therefore be considered alongside physical data transfers.

Security and contractual controls do not remove the need for an appropriate legal transfer mechanism where one is required.

The practical lesson is that privacy, confidentiality, intellectual-property and international-transfer requirements must each be evaluated on their own terms.

A favourable conclusion in one area does not establish permission in another.

4. Does AI training require different permissions from ordinary data use?

An important question is whether rights granted for conventional analytics extend to generative-AI development.

There is no universal answer. The analysis depends on jurisdiction, relevant protected material, contractual permissions and the actions undertaken.

A licence allowing data to be viewed, analysed internally or used to provide customer support does not necessarily authorise copying it into an external training corpus.

AI workflows can involve several distinct uses:

Retrieval: Documents remain in an external knowledge repository and are accessed when relevant to a task.

Training or fine-tuning: Material is used to influence a model's parameters or behaviour.

Evaluation: A controlled dataset is used to assess model performance against agreed criteria.

Dataset redistribution: Information or derived material is made available to additional parties.

Each may require different copying, access, retention and confidentiality permissions.

Selected jurisdictional considerations

In the UK, the statutory copyright exception for text and data analysis under section 29A is confined to qualifying non-commercial research and carries conditions. It is not a general permission for commercial AI training or onward data licensing 5.

The European Union has a different framework. Article 3 of Directive (EU) 2019/790 concerns text and data mining for scientific research by qualifying research organisations and cultural heritage institutions with lawful access. Article 4 provides a separate, broader text-and-data-mining exception for lawfully accessible material, subject to rights not having been expressly reserved in an appropriate manner; for content made publicly available online, the Directive refers in particular to machine-readable reservations. Implementation and application must be checked under the relevant Member State's law. Neither exception supplies a general contractual right to relicense an enterprise archive 6.

These exceptions address particular intellectual-property acts. They do not displace contractual questions outside their scope, confidentiality obligations or data-protection requirements.

In the United States, questions concerning generative-AI training, copyright infringement and fair use are context-dependent. The US Copyright Office's 2025 pre-publication report examines these issues and the development of licensing markets, but should not be treated as settling all pending litigation or establishing one rule for every dataset 7.

JurisdictionRelevant issueCommercial implication
United KingdomNarrow statutory exception for qualifying non-commercial research text and data analysisCommercial training should not be assumed to fall within that exception
European UnionText and data mining exceptions, including conditions on lawful access and rights reservationRights reservations, specific uses and national implementation require examination
United StatesFact-specific copyright and fair-use analysisNo universal conclusion should be assumed for commercial AI training
Cross-border arrangementsPotentially overlapping laws, contracts and privacy requirementsBoth supplier and recipient jurisdictions may need specialist review

This table is a high-level analytical comparison, not a legal determination for any particular transaction.

The AI Act and documentation

The EU AI Act introduces additional relevant obligations for providers of covered general-purpose AI models.

Article 53 includes requirements concerning technical documentation, copyright-compliance policies and public summaries of training content 8.

These are scoped obligations for covered model providers, not an automatic licensing checklist imposed on every company supplying an operational dataset.

Nevertheless, they may influence the information an AI developer requests from counterparties.

A prospective buyer may seek evidence of provenance, permitted uses, rights reservations and how material was obtained.

A supplier with strong records can respond more confidently than one relying on vague assertions of ownership.

The contractual question remains specific: what is the buyer proposing to do, and can the supplier lawfully authorise those actions?

The EU Data Act (Regulation (EU) 2023/2854), broadly applicable since 12 September 2025, establishes specified data-access, use and sharing arrangements, especially around connected products and related services. It does not give every business a universal right to license all operational records, override data-protection requirements or displace third-party intellectual-property rights 9.

5. Worked example: converting a mixed-rights archive into an eligible dataset

Consider a hypothetical technology-services company with 100,000 historical operational records.

The archive contains internally prepared case notes, customer-authored descriptions, reports produced by external contractors and third-party technical documentation.

Management initially assumes that the entire archive could be licensed to an AI developer.

A rights-chain audit produces a more restricted picture.

Exhibit 3: Illustrative rights-clearance waterfall

Record categoryInitial recordsHypothetical provisionally eligible sharePreliminary candidates
Company-authored operating notes50,00080%40,000
Customer-provided content25,00030%7,500
Contractor-produced reports15,00050%7,500
Third-party licensed material10,0000%0
Total100,00055,000

All counts and percentages are illustrative assumptions. The initial categories are treated as mutually exclusive for the example. Eligibility means preliminary inclusion after a hypothetical contractual and source-rights assessment; it does not establish full privacy or legal clearance.

The first review reduces the apparent dataset from 100,000 records to 55,000 preliminary candidates.

This does not mean the other 45,000 records are permanently unusable. Some might become eligible after contract amendment, new permission or a different permitted use.

It also does not mean the remaining 55,000 are ready for transfer.

The company must still assess personal information, confidentiality, data quality, technical relevance and the proposed buyer's use.

Suppose additional screening identifies unresolved personal-data and confidentiality concerns affecting 20% of the provisional candidate population.

For illustration, 44,000 records remain after excluding those cases.

That figure is not a final licensable dataset. It represents a narrower population warranting further validation.

Economic consequences

The organisation also incurs costs investigating and documenting the rights position.

Assume the following illustrative costs:

ActivityHypothetical cost
Source and contract inventory£3,400
Legal rights-chain review£9,000
Contractor permission review£4,500
Privacy and confidentiality assessment£7,200
Engineering and exclusion controls£8,000
Restricted evaluation environment£2,500
Direct costs£34,600
Contingency, 20%£6,920
Total preparation requirement£41,520

Figures are hypothetical, exclude ongoing delivery obligations and do not represent typical legal fees or market rates.

If a restricted first-year arrangement also requires £6,000 of support and compliance expenditure, the illustrative cost requirement becomes £47,520.

A hypothetical £45,000 fee would produce a negative contribution of £2,520 before tax, financing costs and other unpriced liabilities.

A hypothetical £65,000 fee would generate £17,480 of contribution on the same assumptions.

These figures are not estimates of buyer demand or licensing value. They demonstrate how rights remediation can affect commercial viability.

The company could potentially narrow the transaction to 40,000 well-documented, company-authored cases, reducing the need to obtain certain third-party permissions.

However, that narrower dataset might contain less relevant evidence for the buyer's intended task.

The economic decision must therefore consider both the cost saved through narrower scope and any technical value lost.

A smaller, clearly licensed dataset can be more commercially useful than a larger archive with unresolved rights, but only if it still satisfies the buyer's task.

6. Building a defensible licence and deciding when to stop

A rights-chain review should produce a documented position that can be translated into a contract.

It should not end with a generic statement that the company believes it owns the relevant information.

The provider should identify which categories of material it can authorise, the purpose for which each category may be used and any restrictions that must be passed through to the recipient.

The contract should distinguish rights to access and evaluate material from rights to use it for training, retain copies, create derivatives or disclose it to additional parties.

These distinctions matter because AI transactions may involve activities not contemplated by an ordinary software or information-service agreement.

Exhibit 4: Rights-specific contractual diligence

Contractual termPrincipal questionRisk if omitted
Permitted useIs training, retrieval, evaluation or another use authorised?Use exceeds intended permission
Source scopeWhich specific materials and categories are included?Restricted material enters the package
DerivativesWhat may be retained or created from licensed material?Unanticipated continuing use
Onward transferMay affiliates, subcontractors or other buyers obtain access?Uncontrolled disclosure
Duration and terminationWhen do rights expire and what obligations survive?Continuing use beyond agreed term
ConfidentialityWhat information must remain protected?Exposure of sensitive business information
Privacy responsibilitiesWhich party handles lawful processing and individual rights?Unallocated compliance obligations
Warranties and liabilityWhat can the seller actually warrant about rights and provenance?Disproportionate contractual exposure
ExclusivityWhich future uses or licences would be restricted?Loss of commercial optionality

No single model agreement resolves every transaction.

A restricted evaluation involving a small, non-personal, company-authored dataset may require relatively straightforward permissions and controls.

An exclusive licence permitting broad model development and onward use of historical customer communications could involve a substantially more complex risk assessment.

A commercially sensible supplier should avoid giving warranties broader than the evidence supporting them. For example, an absolute assurance that an archive contains no third-party rights or personal information may be inappropriate where the source records contain historical free text and attachments.

Representations, exclusions, remediation obligations and liability allocation should reflect the actual diligence performed.

Provenance as commercial infrastructure

The strongest rights position is one that can be demonstrated.

A practical rights register should identify each material category, source system, contributor, applicable agreement or rule, permitted use, restrictions, supporting evidence and accountable reviewer.

The register should also record unresolved questions and changes over time.

This matters because rights are not static. Customer contracts change, licences expire, suppliers are replaced and companies acquire new businesses.

A data licence intended to support recurring updates needs an approach for screening new records rather than assuming future material automatically carries the same permissions.

When the correct answer is no

A company should defer or decline a proposed licence if it cannot establish a defensible basis for the intended use, cannot satisfy relevant confidentiality and privacy requirements, or would surrender commercially important know-how for inadequate consideration.

It may also decline when remediation costs are disproportionate or when a buyer seeks rights broader than the technical benefit demonstrated.

A negative conclusion does not mean the underlying records lack economic significance.

They may support internal AI systems, operational analytics or process improvement without requiring the same external disclosure.

Alternatively, the company may be able to design a narrower product based on genuinely authorised materials, with controlled evaluation rather than broad training rights.

The correct decision is not necessarily to repair every possible permission gap. It is to identify the least burdensome lawful structure that still supports a worthwhile application.

Practical implications

Before approaching an AI data buyer with a material dataset, management should be able to answer six questions:

  1. Who created or supplied each significant category of information?
  2. Which contracts, intellectual-property rights and other legal restrictions apply?
  3. Does the proposed use involve retrieval, evaluation, model training, derivatives or onward disclosure?
  4. Are personal-data, confidentiality and international-transfer requirements addressed separately?
  5. Can restricted categories be excluded or permissions repaired without destroying the dataset's usefulness?
  6. Do the expected commercial benefits justify rights-clearance costs, strategic risks and continuing obligations?

The rights-chain review should progressively narrow uncertainty.

The central management question is not “Do we own the database?” It is “Can we demonstrate that we are entitled to authorise this specific use of these specific records on these specific terms?”

That distinction determines whether an operational archive is simply information the company possesses or a defensible asset it can license responsibly.


Sources and further reading

  1. UK Intellectual Property Office (2020). Sui Generis Database Rights. Explains UK and EEA database rights, copyright distinctions and post-Brexit territorial treatment. https://www.gov.uk/guidance/sui-generis-database-rights
  2. UK Intellectual Property Office (2014). Ownership of Copyright Works. Covers employee-created works, contractor arrangements, commissioned material and ownership. https://www.gov.uk/guidance/ownership-of-copyright-works
  3. UK Information Commissioner's Office. Lawful Basis for Sharing Personal Data and Data Sharing Covered by the Code. Guidance is under review following the Data (Use and Access) Act. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/lawful-basis-for-sharing-personal-data/ ; related guidance: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/data-sharing-covered-by-the-code/
  4. UK Information Commissioner's Office (2026). A Guide to International Transfers. Updated guidance on restricted transfers, recipient location and relevant responsibilities. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-guide-to-international-transfers/are-we-making-a-restricted-transfer/ ; permitted mechanisms: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-guide-to-international-transfers/how-do-we-comply-with-the-transfer-rules-if-were-initiating-the-restricted-transfer/
  5. UK Intellectual Property Office. Exceptions to Copyright, including text and data mining for non-commercial research. https://www.gov.uk/guidance/exceptions-to-copyright
  6. European Union (2019). Directive (EU) 2019/790 on Copyright and Related Rights in the Digital Single Market, particularly Articles 3 and 4 concerning text and data mining. https://eur-lex.europa.eu/eli/dir/2019/790/oj/eng
  7. US Copyright Office (2025). Copyright and Artificial Intelligence, Part 3: Generative AI Training, pre-publication report. Scope: US copyright and training analysis, not a universal legal determination. https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-3-Generative-AI-Training-Report-Pre-Publication-Version.pdf
  8. European Union. Artificial Intelligence Act, Article 53, obligations for providers of general-purpose AI models. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53
  9. European Commission. Data Act explained. Scope, data-access arrangements and application dates of Regulation (EU) 2023/2854. https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained