How confidentiality clause use restrictions decide what a company can license

A confidentiality clause use restriction limits what the receiving party may do with the other side's information, usually to performing the contract. If client-provided material falls inside the definition, licensing it for AI training generally needs the client's consent or a clear contractual exception, often even after the contract ends, depending on the survival term.

The short answer: read four clauses together

Whether client-provided material can go into a licensed dataset usually turns on four parts of the confidentiality clause: how confidential information is defined, what the use restriction permits, which exclusions apply and how long the obligations survive. If the material sits inside the definition and the permitted purpose is limited to performing the contract, licensing it for AI training generally needs the client's written consent or a clear contractual exception.

The outcome depends on the exact wording, the governing law named in the contract and how courts in that state read similar language. This page explains the mechanics so owners know what to ask; the company's counsel makes the call.

What does a use restriction actually prohibit?

A use restriction limits what the receiving party may do with the information, not only whom it may tell. Most confidentiality clauses contain two separate promises: non-disclosure (do not share it) and non-use (do not use it except for a defined purpose). Owners tend to remember the first and forget the second.

Licensing engages both. Preparing a dataset is a use of the information, and delivering it to an AI developer is a disclosure. Wording like the illustrative clause below blocks both unless the client agrees:

The word "solely" and the defined purpose do most of the work. Supplying training data for someone else's model is not performing the services.

Regulators read data-use promises closely too. FTC staff have stated that commitments not to use customer data for undisclosed purposes, such as training or updating models, are enforceable whether they appear in privacy policies, terms of service, promotional materials or marketplaces. That post is staff guidance aimed at AI companies, not a rule, but it shows how such commitments are viewed.

How does the definition decide what is covered?

The definition sets the perimeter, and everything inside it carries the use restriction.

Definition styleWhat it usually sweeps inLicensing implication
Broad: all information disclosed by either party, in any formClient emails, files, system access, conversationsMost records about that client fall under the restriction
Marking-based: only information marked or confirmed in writing as confidentialLabeled documents and identified disclosuresUnmarked operational records may sit outside, but read the whole clause and the parties' conduct
Category list: pricing, customer lists, technical data, business plansThe named categories, plus anything described as similarCheck each record type against the list
Covers notes, analyses and derivativesThe company's own tickets, reports and work papers that contain client informationInternal work product can be covered even though the company wrote it
Covers personal information processed for the clientData about the client's customers or staffPrivacy terms and statutes apply on top of the contract

The last row is where contract and statute overlap. Under the CCPA, a business that discloses personal information to a service provider or contractor must have a written agreement limiting its use to specified purposes, so a service company's purpose limit on client personal data may be a statutory requirement as well as a negotiated term. Whether a license could also count as a sale is covered in is licensing company records a sale under the CCPA.

Which exclusions can take material out of scope?

Standard exclusions remove information that was public, already known to the recipient, independently developed or received from someone else without a duty of confidence. They rarely help with licensing, because client records were almost always received from the client in confidence.

Three other provisions matter more:

  • Aggregated or de-identified data clauses. Some customer agreements, especially in SaaS, let the provider use aggregated or de-identified data for listed purposes. Read the purposes closely: improving the provider's own services is not the same as licensing to a third party. The guide to aggregated and de-identified data clauses covers typical wording.
  • Residuals clauses. These let staff use general know-how retained in unaided memory. They protect skills and ideas, not copied records, so they do not reach a dataset.
  • Ownership and IP terms. Copyright vests initially in the author and can be transferred in whole or in part, so an agreement that assigns deliverables to the client can leave the company without rights to license them even after confidentiality has lapsed.

How long do the obligations last?

Look for three things: the survival period, what starts the clock, and any return-or-destroy duty. Many clauses survive for a fixed number of years after termination, with trade secrets protected for as long as they stay secret. Some survive with no end date.

A return-or-destroy clause can create a second problem. If the contract required the company to delete client data when the engagement ended and the data is still in the archive, offering it for licensing brings that gap to light. Resolve it with counsel before the material appears in any inventory.

How does this apply in common situations?

SituationWhat to checkTypical outcome to confirm with counsel
MSP tickets and remote-session notes about client networksDefinition, derivatives language, purpose limit in the MSAOften restricted; exclude client-identifying content or obtain consent
Agency or consultancy deliverables and draftsIP assignment, confidentiality, portfolio-use rightsThe client may own the deliverables outright
SaaS provider's support tickets and product usage dataData-use clause, aggregated data clause, privacy termsSometimes usable in de-identified form within the stated purposes
Internal Slack or Teams discussion about running the companyWhether client information appears, plus employee privacyLargely the company's own; screen for client details and see exporting Slack and Teams DMs
Supplier price lists and partner materials received under inbound NDAsInbound NDA purpose and termUsually excluded
Records of a former client whose contract has endedSurvival period and return-or-destroy dutyObligations may still apply

What does good disclosure and consent practice look like?

When client material is valuable enough to include, ask openly and in writing. A short consent letter that names the data categories, the de-identification applied, the purpose (licensing for AI training) and the client's right to decline is easier to defend than a creative reading of old contract language.

Do not try to solve the problem by quietly editing standard terms. FTC staff have warned that adopting more permissive data practices, such as using data for AI training, and telling people only through a surreptitious, retroactive change to terms or a privacy policy may be unfair or deceptive.

In a SourceX process the company sets scope through its data inventory, and nothing is delivered until the agreement is executed and the company authorizes delivery, so contested client material can simply stay out. How it works shows where that review sits.

Questions to ask your counsel

  1. Which client agreements define confidential information broadly enough to cover our internal records about that client?
  2. Does any purpose clause, aggregated data clause or privacy term allow use beyond performing the services?
  3. Which agreements require return or destruction at termination, and did we comply?
  4. Which state's law governs each agreement, and how strictly do its courts read "solely for the purpose" language?
  5. For which clients should we seek consent, and what should the request say?
  6. Do any agreements assign ownership of deliverables or data to the client?

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

What does this mean for referral partners?

Partners never read, request or summarize a company's client contracts. What a partner can notice is the shape of the business: companies whose valuable records describe their own operations screen better than companies that mostly hold their clients' information, such as outsourcers and agencies. Records that belong to someone else, without that party's consent, are a red flag.

The company also needs to meet the baseline: a US business with 50+ full-time employees at peak (contractors excluded), several years of documented operations, the right to license what it offers, and an authorized sponsor such as the owner, CEO or CFO. The company fit checker runs a preliminary, non-binding screen, and what data licensing for AI is explains the model in plain terms: the company keeps ownership and grants a license.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. Rewards are payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed.

Next step

If you know an owner whose records are mostly their own operational history, register as a partner and introduce the company. The owner can also submit an application at sourcex.si/apply.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Does a confidentiality obligation end when the contract expires?

Not always. Many clauses say the obligations survive termination for a fixed period, and trade secret protection can last as long as the information stays secret. Some agreements set no end date at all. Check the survival clause and any return-or-destroy duty before assuming records from a former client are free to use, and ask counsel how the governing law treats open-ended terms.

Is de-identifying client material enough to satisfy a use restriction?

It depends on the wording. A use restriction usually limits the purposes for which information may be used, and removing names does not change the purpose. Some agreements expressly allow de-identified or aggregated use, often for narrow purposes such as improving the service. Where the contract is silent, de-identification lowers privacy risk but may not settle the contract question, so get counsel's view or the client's consent.

Do employee confidentiality agreements stop a company from licensing its own records?

Generally no. Employee confidentiality and invention agreements protect the company's information from misuse by staff; they do not limit what the company itself does with records it owns. Employee privacy is a separate question, shaped by notices, policies and state law, and it should be reviewed alongside the contract analysis whenever internal email or chat is part of the proposed scope.

Can a company license material it wrote about a client if the client never sent it?

Possibly not. Many definitions cover notes, analyses and other materials that contain or are derived from the client's confidential information, even when the company authored them. Ticket histories, project reports and account notes about a client can fall inside that language. Read the definition for derivative materials before treating internal work product as the company's own to license.

Does a mutual NDA signed during sales talks restrict anything?

It can. Prospects often share pricing, technical details or process documents during an evaluation under a mutual NDA limited to assessing a possible deal. Those materials carry the NDA's use restriction even if no contract followed. Sales files, proposal folders and shared evaluation documents should be checked against the NDA's purpose and term before they enter a licensing inventory.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment