Does a client NDA stop a company from licensing records about that client?
An NDA or master agreement can bar licensing any record that contains the counterparty's confidential information, unless the contract permits it, the counterparty consents or the information is removed. Records without it can often still be licensed. The company's own team and counsel screen the archive; partners never touch it.
What does an NDA actually restrict when records are licensed?
Often it restricts part of the archive, not the whole license. An NDA or master services agreement binds the company to protect the other party's confidential information, so any record containing that information is off the table unless the contract allows the use, the counterparty consents, or the information is removed. Records without it can usually still be licensed. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
The practical question is therefore a screening question: which parts of the archive carry other companies' confidential information, and can they be excluded or redacted? Partners never touch the archive; the company's own team and counsel do the screening.
Why do customer emails and chats create the problem?
Operational archives mix the company's own work with its counterparties' material. A support ticket quotes a customer's configuration. A Slack thread pastes a vendor's pricing. A shared-drive folder holds a client's statement of work. Each of these may fall inside a confidentiality clause. FTC staff noted in January 2024 that promises not to use customer data in undisclosed ways, including for training or updating models, are enforceable whether made in privacy policies, terms of service or other materials. That is staff guidance, not a rule, but it signals why companies read their promises before licensing anything.
How do you read an NDA or MSA clause for this purpose?
Check five things in each agreement:
| Clause | What to look for | Effect on a data license |
|---|---|---|
| Definition of confidential information | Broad ("all information disclosed") or narrow (marked or identified) | Broad definitions reach more of the archive |
| Permitted use | Limited to the stated project or purpose | Training or licensing is usually not a permitted use |
| Permitted disclosure | Employees, advisers, affiliates only | A third-party buyer is typically outside the list |
| Return or destruction | Obligation to delete on termination | May require removing records already in the archive |
| Residuals or derived data | Whether insights or aggregated data are carved out | May help, but wording varies widely |
If the clause is silent or ambiguous, treat it as restrictive until counsel says otherwise.
What is the 4-step archive screen the company runs?
The company's team, with counsel, runs this screen. The partner only knows that it exists.
- List counterparties. Pull the list of customers, vendors and partners that have signed confidentiality terms.
- Map where they appear. Identify counterparty domains in email, client channels in chat, client folders in shared drives and attachments from those parties.
- Decide per bucket. For each bucket choose one of: exclude, redact, or keep because consent or a carve-out exists.
- Document the decision. Record the rule used, so SourceX and the buyer can see what was left out and why.
De-identification and redaction requirements are agreed with the company before any work begins, and data is delivered only after an executed agreement and the company's authorization. The metadata-only data inventory builder helps the company list systems without describing contents.
What are the common situations and typical outcomes to confirm?
| Situation | What to check | Typical outcome to confirm with counsel |
|---|---|---|
| Customer emails with the client's own technical details | NDA definition and permitted use | Exclude the thread or redact identifying and confidential content |
| Internal-only Slack channels | Employee confidentiality, no counterparty content | Often usable, subject to privacy review |
| Client-specific shared folders | MSA ownership clauses | Exclude unless the client consents |
| Privileged legal threads | Attorney-client privilege | Exclude; privilege can be lost by disclosure |
| Vendor pricing in procurement email | Vendor NDA | Exclude or redact |
| Records the company created about its own operations | No third-party content | Core of most licenses |
For records where the contract is silent on AI, see whether SaaS terms restrict using exported data for AI training and the related page on AI-generated documents as training data.
Can the company ask the counterparty for consent?
Yes, and sometimes that is the cleanest route for a high-value relationship. Consent should be written, specific about AI training use, and cover the scope of records and the buyer type. Treat consent as optional upside: the safer default is to exclude. The reasoning on why consent underpins licensing is in why consent is the foundation of AI data licensing. Leakage questions are covered in whether an AI model can reveal confidential information, and what happens when the term ends is in what happens to your data when an AI training license ends.
What should a partner say?
How does this connect to the referral reward?
Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 cumulative per referred company. Rewards become payable only after the buyer pays and SourceX receives its fee, and no reward is guaranteed. A narrower scope after screening can mean a smaller deal, so set expectations accordingly. Licensed professionals should check their own rules on referral fees and disclosure.
When should you stop?
Stop if the data belongs to someone else without consent, if an outsourcer or agency would be licensing its clients' records, or if nobody can say which counterparties are covered by confidentiality terms. Also stop if the company has fewer than 50 full-time employees at peak (contractors excluded) or the owner will not consider an exclusive license.
Next step
If the company's own records are the core of its archive, register as a partner and make the introduction. The company can start directly at sourcex.si/apply, and how it works explains each stage. For commercial context, see pros and cons of licensing company data to AI developers and how to negotiate an AI data licensing deal.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can a company license data covered by an NDA if it removes names?
Not necessarily. Removing names may not remove the confidential information itself, because technical details, pricing or strategy can identify the counterparty or remain protected. Whether redaction is enough depends on the NDA definition and on counsel's reading. When in doubt, exclude the material or obtain written consent.
Does an NDA usually mention AI training?
Older agreements rarely do. Silence does not mean permission. Most permitted-use clauses limit use to a stated purpose, and licensing records to a third-party buyer is usually outside it. Counsel should read each material agreement, and the company should assume restrictive treatment until confirmed.
Who does the screening, the partner or SourceX?
Neither partner nor SourceX screens the raw archive first. The company's own team, with counsel, runs the screen. Partners make the introduction and give basic fit information only. Redaction and de-identification requirements are agreed with the company before any work begins.
What if most of the archive is client material?
Then the license may be small or may not qualify. If the data mainly belongs to clients, an outsourcer's or agency's clients especially, and consent is missing, that is a red flag. Companies with a core of their own operational records still may qualify after exclusion.
Does a signed license with a buyer override the NDA?
No. The company cannot grant rights it does not have. A license agreement does not cancel obligations owed to third parties under earlier contracts, which is why rights and confidentiality are checked in qualification, before price and terms are agreed.
Related pages
- How to negotiate an AI data licensing deal: priorities in order
- Pros and cons of selling or licensing company data to AI developers
- How SourceX US company data referrals work
- Why consent is the foundation of AI data licensing
- Can AI-generated documents be licensed as AI training data?
- Can an AI model trained on your data reveal confidential information?
Free resources
- IRR calculator — Internal rate of return on annual cash flows.
- Business valuation calculator — Enterprise and equity value from EBITDA, your multiple, cash and debt.
- Portfolio data opportunity scanner — Screen several companies in one session.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment