Executive perspective
Executive perspective
Enterprise data can be technically valuable yet commercially unusable because the organisation cannot establish sufficient rights to license it. Ownership of a database, copyright in individual documents, customer confidentiality, personal-data obligations and third-party licences must be assessed separately.
Four principles matter. Possession is not permission; rights depend on the proposed use; limitations may be resolved by narrowing the dataset; and documented provenance makes commercial commitments more defensible.
A prospective buyer needs confidence not simply that the provider controls the records, but that the contemplated copying, processing, training, retention and onward use can be authorised.
The task is therefore to establish a defensible chain of rights, identify which records can be included, and determine whether the resulting package justifies the legal and technical preparation required.
1. The ownership problem: what does the company actually control?
A company may operate an extensive database containing customer interactions, employee decisions, supplier documents, technical reports, system-generated measurements and operational histories.
These records may be stored on its infrastructure, administered by its employees and used extensively in its ordinary business.
None of those facts, individually, establishes unrestricted licensing authority.
The first distinction concerns physical or technical control versus legal rights. A company may control access to a CRM system without owning copyright in customer-uploaded photographs or supplier manuals. It may own copyright in a technical report while remaining prohibited from disclosing its contents under a confidentiality agreement.
The position becomes more complex when information has been collected over many years under different contracts.
Copyright and database rights
UK law distinguishes copyright protection for original selection or arrangement of database material from sui generis database rights that can protect qualifying investment in obtaining, verifying or presenting database contents. These rights can coexist, but neither automatically establishes rights to every third-party work contained in the database 1.
There is also a territorial dimension. Following Brexit, qualification and reciprocal recognition rules for newly created UK and EEA databases changed. A company contemplating cross-border exploitation cannot assume identical database-right protection in every market.
Importantly, facts and measurements are not automatically protected by copyright merely because they are recorded electronically. Copyright may protect original expression or an original arrangement, while contractual, confidentiality, database-right or data-protection restrictions may still govern access and use.
The consequence is that a rights review must examine more than a single asset called “the database”.
Rights operate in layers
Consider a software company whose support platform contains:
- System-generated records of application faults.
- Customer-authored messages describing those faults.
- Employee-written diagnostic notes.
- Reports prepared by external contractors.
- Extracts from proprietary third-party manuals.
The company may possess a strong basis to use certain internally generated operational facts, but its rights in the other material may differ considerably.
The company should distinguish the rights needed to extract and prepare records from those required to disclose them, permit model training, authorise derivative datasets or grant onward access.
The transaction concerns a defined bundle of permissions, not an abstract claim to own the data.
Exhibit 1: The enterprise data rights stack
| Rights or restriction | Principal question | Typical evidence | Potential limitation |
|---|---|---|---|
| Database rights | Who holds relevant rights in the database structure or contents? | Database history, investment and ownership records | Territorial and qualification limits |
| Copyright | Who created the protected expression? | Employment records, assignments, source licences | Third-party or contractor ownership |
| Contractual rights | What uses do applicable agreements permit? | Customer, supplier and platform contracts | Restrictions on disclosure or reuse |
| Confidentiality | Is the information subject to secrecy obligations? | NDAs, service contracts, internal classifications | Commercial or customer confidentiality |
| Personal-data obligations | Can the proposed processing and sharing lawfully occur? | Purpose records, lawful-basis assessment, privacy documentation | Incompatible or otherwise impermissible use |
| Trade secrets | Would the proposed disclosure undermine protected know-how? | Access controls, secrecy policies, confidentiality terms | Loss of secrecy or competitive advantage |
These layers should be investigated independently. Establishing one does not resolve the others.
For example, the company may own copyright in an employee-produced technical note but remain restricted from disclosing customer information quoted within it.
An effective diligence process therefore evaluates the actual composition of the material and the proposed transaction, rather than relying on a broad assurance that all information belongs to the company.
2. Establishing the chain of rights across different contributors
The most useful starting point is to classify data according to its origin.
Four categories frequently require different treatment: company-authored material, customer-provided content, employee and contractor contributions, and third-party licensed information.
Customer-provided material
Customers may submit emails, images, attachments, documents, technical drawings or confidential operating information while receiving a company's services.
These contributions can be valuable because they contain real problems, contextual detail and the outcomes of business interactions.
But the company's rights may be confined to delivering the contracted service.
Historical customer agreements may authorise processing, storage and internal analysis without permitting disclosure to an independent AI developer for unrelated model training.
A clause allowing the use of information to improve services is not necessarily equivalent to permission for unrestricted external licensing. The answer depends on the wording, contractual context, proposed use and applicable law.
Rights can also vary between customer cohorts.
A company may have introduced broader data-use provisions in 2023 while retaining older contracts for customers onboarded in previous years. Applying the latest terms retrospectively without examination could create substantial contractual risk.
This makes contract versioning commercially important.
Employee-created material
In the UK, an employer is generally the first copyright owner of qualifying works created by an employee in the course of employment, subject to contrary agreement. Work produced outside that scope may require a different analysis 2.
Employment-related copyright ownership does not resolve confidentiality, personal-data or other legal requirements.
For example, a company may own copyright in an employee's operational report while the report includes identifiable employee information or confidential statements from customers.
Ownership also needs careful examination where intellectual contributions were made during an individual's employment with another organisation.
Contractors and commissioned work
Contractor arrangements are a frequent source of uncertainty.
UK Intellectual Property Office guidance explains that a freelancer or contractor will generally retain copyright in commissioned work unless the contractual arrangements provide otherwise. A commissioner may have a limited implied licence for the original purpose, but that does not necessarily confer wider licensing or ownership rights 2.
A company that paid for thousands of contractor-generated technical reports should therefore inspect its agreements before including those reports in an AI licensing package.
Where rights are unclear, possible remedies include obtaining an assignment, negotiating an additional licence or excluding affected records.
The appropriate remedy depends on whether the missing permission can be obtained economically and without imposing unacceptable restrictions.
Third-party licensed content
Operational systems routinely contain supplier manuals, reference publications, software documentation, screenshots, templates and other third-party material.
An organisation may be permitted to use this information internally without being entitled to relicense it.
Software and platform licences can also restrict extraction or onward use of particular content. The presence of information within a vendor-operated system does not establish either that the vendor owns all customer content or that the customer may commercially license everything the system contains.
The diligence process should identify material third-party contributions and determine whether they are essential to the proposed AI task.
Where they are not essential, exclusion may be more efficient than seeking broad permissions.
3. Privacy, confidentiality and international use: separate legal tests
Intellectual-property ownership and personal-data compliance are distinct questions.
Even if a company holds all relevant copyright and database rights, sharing records that identify individuals may still require a lawful basis, appropriate purpose assessment, transparency measures, security controls and other safeguards.
Under UK data-protection rules, organisations must identify a lawful basis for relevant personal-data sharing before it begins. The ICO also distinguishes between sharing with another independent controller and engaging a processor acting on the controller's documented instructions 3.
These relationships carry different responsibilities.
A proposed AI buyer might use supplied information for its own development purposes rather than merely process it on the supplier's behalf. The parties should determine their actual roles based on what each does, not simply assign convenient labels in an agreement.
Why anonymisation requires evidence
A common proposal is to replace names and account numbers with random identifiers.
This can reduce exposure, but it does not automatically make the dataset anonymous.
Individual identity may remain inferable from unusual events, combinations of attributes, exact dates or the content of free-text descriptions.
Pseudonymisation is a risk-reduction technique, not a substitute for identifying lawful processing conditions.
A company should evaluate the likelihood of re-identification, the information available to the recipient and the utility retained after transformation.
Some records may support the AI task after removal of personal information. Others may lose the context required to interpret the underlying decision.
The correct approach is to define the task and assess which fields are necessary, rather than assuming that every record can be made suitable through generic masking.
Confidentiality and trade secrets
Confidentiality may protect information that is not personal data or copyright-protected expression.
Customer pricing, internal operating methods, supplier terms and commercially sensitive technical processes may all create disclosure restrictions.
Moreover, a company should examine its own strategic interest in preserving confidentiality.
An archive of unusual troubleshooting cases might reveal operational know-how that competitors would find difficult to reproduce.
Licensing such information externally could create revenue while weakening a competitive advantage.
Restrictions on onward use, disclosure, model derivatives and competing applications may therefore have commercial importance beyond legal compliance.
International transfers
Where UK GDPR applies, allowing a separate organisation outside the UK to access personal information can constitute an international restricted transfer, even if the data remains physically stored on UK servers.
The ICO's 2026 guidance explains the relevant three-step assessment and the potential need for adequacy regulations, appropriate safeguards or an applicable exception 4.
An overseas AI partner's remote access should therefore be considered alongside physical data transfers.
Security and contractual controls do not remove the need for an appropriate legal transfer mechanism where one is required.
The practical lesson is that privacy, confidentiality, intellectual-property and international-transfer requirements must each be evaluated on their own terms.
A favourable conclusion in one area does not establish permission in another.
4. Does AI training require different permissions from ordinary data use?
An important question is whether rights granted for conventional analytics extend to generative-AI development.
There is no universal answer. The analysis depends on jurisdiction, relevant protected material, contractual permissions and the actions undertaken.
A licence allowing data to be viewed, analysed internally or used to provide customer support does not necessarily authorise copying it into an external training corpus.
AI workflows can involve several distinct uses:
Retrieval: Documents remain in an external knowledge repository and are accessed when relevant to a task.
Training or fine-tuning: Material is used to influence a model's parameters or behaviour.
Evaluation: A controlled dataset is used to assess model performance against agreed criteria.
Dataset redistribution: Information or derived material is made available to additional parties.
Each may require different copying, access, retention and confidentiality permissions.
Selected jurisdictional considerations
In the UK, the statutory copyright exception for text and data analysis under section 29A is confined to qualifying non-commercial research and carries conditions. It is not a general permission for commercial AI training or onward data licensing 5.
The European Union has a different framework. Article 3 of Directive (EU) 2019/790 concerns text and data mining for scientific research by qualifying research organisations and cultural heritage institutions with lawful access. Article 4 provides a separate, broader text-and-data-mining exception for lawfully accessible material, subject to rights not having been expressly reserved in an appropriate manner; for content made publicly available online, the Directive refers in particular to machine-readable reservations. Implementation and application must be checked under the relevant Member State's law. Neither exception supplies a general contractual right to relicense an enterprise archive 6.
These exceptions address particular intellectual-property acts. They do not displace contractual questions outside their scope, confidentiality obligations or data-protection requirements.
In the United States, questions concerning generative-AI training, copyright infringement and fair use are context-dependent. The US Copyright Office's 2025 pre-publication report examines these issues and the development of licensing markets, but should not be treated as settling all pending litigation or establishing one rule for every dataset 7.
Exhibit 2: Selected copyright and AI-use considerations
| Jurisdiction | Relevant issue | Commercial implication |
|---|---|---|
| United Kingdom | Narrow statutory exception for qualifying non-commercial research text and data analysis | Commercial training should not be assumed to fall within that exception |
| European Union | Text and data mining exceptions, including conditions on lawful access and rights reservation | Rights reservations, specific uses and national implementation require examination |
| United States | Fact-specific copyright and fair-use analysis | No universal conclusion should be assumed for commercial AI training |
| Cross-border arrangements | Potentially overlapping laws, contracts and privacy requirements | Both supplier and recipient jurisdictions may need specialist review |
This table is a high-level analytical comparison, not a legal determination for any particular transaction.
The AI Act and documentation
The EU AI Act introduces additional relevant obligations for providers of covered general-purpose AI models.
Article 53 includes requirements concerning technical documentation, copyright-compliance policies and public summaries of training content 8.
These are scoped obligations for covered model providers, not an automatic licensing checklist imposed on every company supplying an operational dataset.
Nevertheless, they may influence the information an AI developer requests from counterparties.
A prospective buyer may seek evidence of provenance, permitted uses, rights reservations and how material was obtained.
A supplier with strong records can respond more confidently than one relying on vague assertions of ownership.
The contractual question remains specific: what is the buyer proposing to do, and can the supplier lawfully authorise those actions?
The EU Data Act (Regulation (EU) 2023/2854), broadly applicable since 12 September 2025, establishes specified data-access, use and sharing arrangements, especially around connected products and related services. It does not give every business a universal right to license all operational records, override data-protection requirements or displace third-party intellectual-property rights 9.
5. Worked example: converting a mixed-rights archive into an eligible dataset
Consider a hypothetical technology-services company with 100,000 historical operational records.
The archive contains internally prepared case notes, customer-authored descriptions, reports produced by external contractors and third-party technical documentation.
Management initially assumes that the entire archive could be licensed to an AI developer.
A rights-chain audit produces a more restricted picture.
Exhibit 3: Illustrative rights-clearance waterfall
| Record category | Initial records | Hypothetical provisionally eligible share | Preliminary candidates |
|---|---|---|---|
| Company-authored operating notes | 50,000 | 80% | 40,000 |
| Customer-provided content | 25,000 | 30% | 7,500 |
| Contractor-produced reports | 15,000 | 50% | 7,500 |
| Third-party licensed material | 10,000 | 0% | 0 |
| Total | 100,000 | 55,000 |
All counts and percentages are illustrative assumptions. The initial categories are treated as mutually exclusive for the example. Eligibility means preliminary inclusion after a hypothetical contractual and source-rights assessment; it does not establish full privacy or legal clearance.
The first review reduces the apparent dataset from 100,000 records to 55,000 preliminary candidates.
This does not mean the other 45,000 records are permanently unusable. Some might become eligible after contract amendment, new permission or a different permitted use.
It also does not mean the remaining 55,000 are ready for transfer.
The company must still assess personal information, confidentiality, data quality, technical relevance and the proposed buyer's use.
Suppose additional screening identifies unresolved personal-data and confidentiality concerns affecting 20% of the provisional candidate population.
For illustration, 44,000 records remain after excluding those cases.
That figure is not a final licensable dataset. It represents a narrower population warranting further validation.
Economic consequences
The organisation also incurs costs investigating and documenting the rights position.
Assume the following illustrative costs:
| Activity | Hypothetical cost |
|---|---|
| Source and contract inventory | £3,400 |
| Legal rights-chain review | £9,000 |
| Contractor permission review | £4,500 |
| Privacy and confidentiality assessment | £7,200 |
| Engineering and exclusion controls | £8,000 |
| Restricted evaluation environment | £2,500 |
| Direct costs | £34,600 |
| Contingency, 20% | £6,920 |
| Total preparation requirement | £41,520 |
Figures are hypothetical, exclude ongoing delivery obligations and do not represent typical legal fees or market rates.
If a restricted first-year arrangement also requires £6,000 of support and compliance expenditure, the illustrative cost requirement becomes £47,520.
A hypothetical £45,000 fee would produce a negative contribution of £2,520 before tax, financing costs and other unpriced liabilities.
A hypothetical £65,000 fee would generate £17,480 of contribution on the same assumptions.
These figures are not estimates of buyer demand or licensing value. They demonstrate how rights remediation can affect commercial viability.
The company could potentially narrow the transaction to 40,000 well-documented, company-authored cases, reducing the need to obtain certain third-party permissions.
However, that narrower dataset might contain less relevant evidence for the buyer's intended task.
The economic decision must therefore consider both the cost saved through narrower scope and any technical value lost.
A smaller, clearly licensed dataset can be more commercially useful than a larger archive with unresolved rights, but only if it still satisfies the buyer's task.
6. Building a defensible licence and deciding when to stop
A rights-chain review should produce a documented position that can be translated into a contract.
It should not end with a generic statement that the company believes it owns the relevant information.
The provider should identify which categories of material it can authorise, the purpose for which each category may be used and any restrictions that must be passed through to the recipient.
The contract should distinguish rights to access and evaluate material from rights to use it for training, retain copies, create derivatives or disclose it to additional parties.
These distinctions matter because AI transactions may involve activities not contemplated by an ordinary software or information-service agreement.
Exhibit 4: Rights-specific contractual diligence
| Contractual term | Principal question | Risk if omitted |
|---|---|---|
| Permitted use | Is training, retrieval, evaluation or another use authorised? | Use exceeds intended permission |
| Source scope | Which specific materials and categories are included? | Restricted material enters the package |
| Derivatives | What may be retained or created from licensed material? | Unanticipated continuing use |
| Onward transfer | May affiliates, subcontractors or other buyers obtain access? | Uncontrolled disclosure |
| Duration and termination | When do rights expire and what obligations survive? | Continuing use beyond agreed term |
| Confidentiality | What information must remain protected? | Exposure of sensitive business information |
| Privacy responsibilities | Which party handles lawful processing and individual rights? | Unallocated compliance obligations |
| Warranties and liability | What can the seller actually warrant about rights and provenance? | Disproportionate contractual exposure |
| Exclusivity | Which future uses or licences would be restricted? | Loss of commercial optionality |
No single model agreement resolves every transaction.
A restricted evaluation involving a small, non-personal, company-authored dataset may require relatively straightforward permissions and controls.
An exclusive licence permitting broad model development and onward use of historical customer communications could involve a substantially more complex risk assessment.
A commercially sensible supplier should avoid giving warranties broader than the evidence supporting them. For example, an absolute assurance that an archive contains no third-party rights or personal information may be inappropriate where the source records contain historical free text and attachments.
Representations, exclusions, remediation obligations and liability allocation should reflect the actual diligence performed.
Provenance as commercial infrastructure
The strongest rights position is one that can be demonstrated.
A practical rights register should identify each material category, source system, contributor, applicable agreement or rule, permitted use, restrictions, supporting evidence and accountable reviewer.
The register should also record unresolved questions and changes over time.
This matters because rights are not static. Customer contracts change, licences expire, suppliers are replaced and companies acquire new businesses.
A data licence intended to support recurring updates needs an approach for screening new records rather than assuming future material automatically carries the same permissions.
When the correct answer is no
A company should defer or decline a proposed licence if it cannot establish a defensible basis for the intended use, cannot satisfy relevant confidentiality and privacy requirements, or would surrender commercially important know-how for inadequate consideration.
It may also decline when remediation costs are disproportionate or when a buyer seeks rights broader than the technical benefit demonstrated.
A negative conclusion does not mean the underlying records lack economic significance.
They may support internal AI systems, operational analytics or process improvement without requiring the same external disclosure.
Alternatively, the company may be able to design a narrower product based on genuinely authorised materials, with controlled evaluation rather than broad training rights.
The correct decision is not necessarily to repair every possible permission gap. It is to identify the least burdensome lawful structure that still supports a worthwhile application.
Practical implications
Before approaching an AI data buyer with a material dataset, management should be able to answer six questions:
- Who created or supplied each significant category of information?
- Which contracts, intellectual-property rights and other legal restrictions apply?
- Does the proposed use involve retrieval, evaluation, model training, derivatives or onward disclosure?
- Are personal-data, confidentiality and international-transfer requirements addressed separately?
- Can restricted categories be excluded or permissions repaired without destroying the dataset's usefulness?
- Do the expected commercial benefits justify rights-clearance costs, strategic risks and continuing obligations?
The rights-chain review should progressively narrow uncertainty.
The central management question is not “Do we own the database?” It is “Can we demonstrate that we are entitled to authorise this specific use of these specific records on these specific terms?”
That distinction determines whether an operational archive is simply information the company possesses or a defensible asset it can license responsibly.
Sources and further reading
- UK Intellectual Property Office (2020). Sui Generis Database Rights. Explains UK and EEA database rights, copyright distinctions and post-Brexit territorial treatment. https://www.gov.uk/guidance/sui-generis-database-rights
- UK Intellectual Property Office (2014). Ownership of Copyright Works. Covers employee-created works, contractor arrangements, commissioned material and ownership. https://www.gov.uk/guidance/ownership-of-copyright-works
- UK Information Commissioner's Office. Lawful Basis for Sharing Personal Data and Data Sharing Covered by the Code. Guidance is under review following the Data (Use and Access) Act. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/lawful-basis-for-sharing-personal-data/ ; related guidance: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-sharing/data-sharing-a-code-of-practice/data-sharing-covered-by-the-code/
- UK Information Commissioner's Office (2026). A Guide to International Transfers. Updated guidance on restricted transfers, recipient location and relevant responsibilities. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-guide-to-international-transfers/are-we-making-a-restricted-transfer/ ; permitted mechanisms: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/a-guide-to-international-transfers/how-do-we-comply-with-the-transfer-rules-if-were-initiating-the-restricted-transfer/
- UK Intellectual Property Office. Exceptions to Copyright, including text and data mining for non-commercial research. https://www.gov.uk/guidance/exceptions-to-copyright
- European Union (2019). Directive (EU) 2019/790 on Copyright and Related Rights in the Digital Single Market, particularly Articles 3 and 4 concerning text and data mining. https://eur-lex.europa.eu/eli/dir/2019/790/oj/eng
- US Copyright Office (2025). Copyright and Artificial Intelligence, Part 3: Generative AI Training, pre-publication report. Scope: US copyright and training analysis, not a universal legal determination. https://www.copyright.gov/ai/Copyright-and-Artificial-Intelligence-Part-3-Generative-AI-Training-Report-Pre-Publication-Version.pdf
- European Union. Artificial Intelligence Act, Article 53, obligations for providers of general-purpose AI models. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53
- European Commission. Data Act explained. Scope, data-access arrangements and application dates of Regulation (EU) 2023/2854. https://digital-strategy.ec.europa.eu/en/factpages/data-act-explained