Due diligence checklist for vetting an AI data buyer before you share records
Vet an AI data buyer on five fronts: who the contracting entity is, what it may do with the records, how it secures and deletes them, whether it can pass them on, and how and when you are paid. Put every answer in the signed agreement, not in a sales call.
Why a data buyer deserves the same diligence as a vendor
A data license sends your records to a counterparty for a purpose and a term, so you should check that counterparty before you sign. Many published AI checklists are written from the customer side, for companies buying AI tools. This one runs the other direction: the company is the supplier, and the buyer, or the intermediary acting for it, is the party being vetted.
Use it with your counsel. It works for a direct buyer, a marketplace or an intermediary such as SourceX, and the questions are the same: who are you, what will you do with the records, how will you protect them, and when do they go away.
Group 1: identity and authority
- Legal name, state of formation and registered address of the contracting entity, matched to a public record.
- Named signatory with written authority to bind the buyer.
- Ownership and any parent or affiliate that will actually use the records.
- Who the intermediary acts for, and whether it signs as principal or agent.
- If the buyer's name stays confidential until terms are agreed, a written process for disclosing it before signature, and confirmation that the final agreement names the party.
Group 2: intended use and field of use
- The permitted purpose in plain words, for example training or evaluating models, and what is excluded.
- Whether the buyer may resell, sublicense or make the records available to third parties.
- Whether outputs may reproduce or reveal the records, and how the buyer tests for that.
- Exclusivity: what the exclusive field is, how long the term runs and what happens at expiry.
- Any use outside the agreed field treated as a breach with a stated remedy.
Group 3: security and deletion
- How the records are transferred, stored and access-controlled, and who can reach them.
- Written security commitments and the right to ask for evidence of them.
- Breach notification: timing, content and who pays for response. See what happens if a buyer suffers a breach.
- Return or deletion on expiry or termination, with written confirmation.
- Treatment of backups, derived datasets and copies held by subcontractors.
The FTC has said that a company's promises about not using customer data for undisclosed purposes can be enforced, whether made in privacy policies, terms or other statements, in its staff post on AI companies and privacy and confidentiality commitments. Put your commitments in the contract rather than relying on a buyer's marketing.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Group 4: onward transfer and personal data
- A list of approved subprocessors, with notice before changes.
- No re-identification attempts, with a contractual ban.
- Redaction or de-identification rules agreed before delivery, not after.
- Treatment of employee and customer personal information, and any notices your own policies require.
- Whether the buyer needs access to your systems. A licensing deal is typically built around an agreed dataset delivered after signing instead; see does a data buyer need access to our systems.
Group 5: money and exit
- One all-in price, in writing, with no separate charges to the company.
- Invoice date, due date and who pays whom. SourceX deals typically pay the company within about 60 days of invoicing once the buyer selects the data.
- What happens if the buyer does not select the data or does not pay.
- Termination rights, governing law and dispute forum.
- Insurance or financial standing evidence if the term is long.
How to read the answers
| Result | What it means | Next action |
|---|---|---|
| Clear written answer, matches the contract | Low diligence risk on that item | Tick it and move on |
| Verbal answer only | Unverified | Ask for it in the agreement or a schedule |
| Vague or deflected | Possible gap | Escalate to counsel before any inventory work |
| Refusal to put it in writing | Red flag | Pause the process |
| Pressure to sign or deliver quickly | Red flag | Slow down; nothing is binding until you sign |
Red flags worth stopping on
- The buyer will not name the contracting entity at signature.
- Requests for direct login access to your systems before a signed agreement.
- Any demand for an upfront fee from the company. A SourceX license has one all-in price, with SourceX's fee included.
- Wide, unspecified rights to resell or reuse the records.
- No deletion or return clause.
- A rush to "send a sample" of confidential files before terms exist.
For the broader risk picture, read common concerns about licensing company data and what AI buyers actually do with licensed records.
Which checks sit where
The company owns the decision and the diligence on terms; its counsel should read the agreement. SourceX manages the licensing process from sourcing and rights review to delivery and payment, and de-identification and redaction rules are agreed with the company before work begins. Ask SourceX directly which of the items above it will confirm in writing before you sign, and put the answers in the agreement. Nothing is binding until you agree price and terms and sign.
Using this as a partner
If you advise owners, the checklist is a useful way to show you take their risk seriously. Hand it over, let their counsel mark it up, and keep your role to the introduction. Partners earn 25% of the eligible platform fees SourceX actually collects, capped at $100,000 per referred company, and only after the buyer pays and SourceX receives its fee. Read the FAQ and the referral earnings calculator for how the formula works.
Next step
Print the groups above and mark the unanswered items for the first call. To introduce a company that wants to go through this process, register as a partner, or send the sponsor to sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Who should run due diligence on a data buyer?
The company's authorized sponsor owns the decision, and its counsel should review the agreement. Security, IT and privacy leads can answer the technical items. A partner or advisor can supply the checklist, but should not review the company's confidential records or negotiate terms on its behalf.
What if the buyer's name stays confidential until terms are agreed?
Confidential buyer names can occur before terms are final, but you should still require a written process: the name is disclosed before signature, the agreement names the contracting party, and the same use, security and deletion terms bind that party. If the name is never revealed, do not sign.
Is a security questionnaire enough?
No. Answers on a questionnaire are only as strong as the contract that repeats them. Put the controls, breach notice, subprocessor limits and deletion duty into the agreement, and ask for evidence such as audit reports where the data is sensitive.
Does a buyer need access to our systems?
Typically not. Licensed data is delivered as an agreed dataset after redaction rules are settled and an agreement is signed. Live access to production systems raises security and rights questions, so treat a request for it as a reason to ask why and to involve counsel.
What should the license say about reuse of our data?
It should state the permitted purpose, the exclusive field and term, a ban on resale or sublicensing unless you approve it, a ban on re-identification, and what happens to copies at expiry. Vague language such as any lawful purpose is worth negotiating before signature.
Related pages
- What if an AI data buyer suffers a breach after delivery?
- Does an AI buyer need access to our systems to license our data?
- Common concerns about licensing company data, answered
- What does an AI buyer actually do with licensed company records?
- SourceX referral program frequently asked questions
- Referral Earnings Calculator
Free resources
- Profit margin calculator — Profit and margin across three scenarios.
- Client opportunity brief generator — An editable intro email, summary and checklist.
- Days sales outstanding calculator — How many days customers take to pay.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment