Annual legal checkup for businesses: the checklist, plus a data rights review

An annual legal checkup for businesses is a yearly review, usually led by outside general counsel, of entity records, key contracts, employment, intellectual property, privacy, insurance and disputes. Adding a short data rights section, covering customer contract restrictions, employee notices, archive control and who can sign, flags risk and shows whether the client could license its records.

What an annual legal checkup covers, and where data rights fit

An annual legal checkup is a yearly review in which outside general counsel walks the owner, CEO or CFO through entity records, key contracts, people issues, intellectual property, privacy, insurance and open disputes, so small problems get fixed before a financing, sale or lawsuit exposes them. A short data rights section now belongs in it.

The reason is that a company's records carry obligations and, increasingly, value. Email, CRM history, support tickets, project files and engineering systems can be licensed to AI developers for training and evaluation, but only where the company holds the rights and someone can authorize the deal. Four questions settle most of it: what customer contracts allow, what employees and customers were told, who controls the archives, and who can sign. The answers double as an early screen for a SourceX introduction.

The checklist

Send the document request ahead of the meeting, then work through each group in one sitting. Mark every line closed, open or not applicable.

Entity and governance

  • Good-standing certificates pulled for the state of formation and each state where the company is registered
  • Annual reports, franchise tax filings and registered agent details current
  • Bylaws or operating agreement match how decisions are really made
  • Minutes or written consents on file for the year's major decisions
  • Cap table, equity grants and transfer restrictions reconciled

Commercial contracts

  • Top customer and vendor agreements logged with renewal, termination and notice dates
  • Assignment and change-of-control clauses flagged before any financing or sale
  • Liability caps and indemnities compared with current insurance limits
  • Agreements that expired, or were never signed, but are still being performed

People

  • Contractor and part-time roles tested against the classification rules in each state where people work
  • Handbook updated for new state and local requirements
  • Confidentiality and invention-assignment agreements signed by every employee and contractor
  • Non-compete and non-solicit terms checked against current state law

Intellectual property, privacy and insurance

  • Trademark renewal dates calendared; domains registered to the company rather than an individual
  • Software and SaaS licenses matched to actual seats and use
  • Privacy policy compared with what the company actually collects and shares
  • Insurance schedule reviewed with the broker, including limits and retentions
  • Demand letters, open disputes and litigation holds logged

Data rights review

  • Customer contract restrictions. For the top customer agreements, note what the confidentiality, data-use and return-or-delete clauses let the company do with records it holds about or for each customer, and whether any clause mentions machine learning or model training.
  • Privacy promises. Collect every dated version of the privacy policy and terms of service. FTC staff have written that promises not to use customer data for undisclosed purposes such as model training are enforceable, and that adopting more permissive practices only through a surreptitious, retroactive change to terms may be unfair or deceptive.
  • Employee notices and work ownership. Confirm the handbook and IT policy say business systems and communications belong to the company. The Copyright Office's Circular 30 on works made for hire explains that work employees prepare within the scope of employment belongs to the employer, while commissioned work qualifies only in listed categories with a signed agreement, so contractor output usually needs a written assignment.
  • Recorded calls. Check notice practice for recorded sales and support calls; California's Penal Code 632 requires all parties' consent to record a confidential communication.
  • Archive control. Identify who administers legacy email tenants, retired CRMs and old file shares, whether complete exports exist, what the retention schedule deletes and when, and whether a migration or vendor shutdown is planned this year.
  • Authorized signatory. Confirm who can sign a data license under the governing documents, whether board, member or lender consent is needed, and whether an investor rights agreement gives anyone a say. Because 17 U.S.C. 201 lets an owner transfer rights in whole or in part, a company can license a defined use, such as AI training, while keeping everything else.

This is general information, not legal, tax or financial advice. Requirements differ by state, so apply the rules of every jurisdiction where the client operates and employs people.

When to schedule it

MomentWhy it worksData rights angle
Fiscal year-end planningOwners are already reviewing budgets and prioritiesRetention schedules and archive costs come up naturally
Ahead of insurance renewalLimits and contract indemnities get compared anywayCyber and privacy questionnaires surface how data is held
Before a financing or saleDiligence will ask the same questions laterA clean rights file shortens later diligence
After an acquisitionTwo sets of contracts, notices and archives need reconcilingThe acquired company's records may carry different promises
Before a system migrationOld platforms are about to be retiredPreserve exports before anything is switched off

How to run the session

  1. Send the document request a few weeks out: governing documents, contract list, handbook, every privacy policy version, the insurance schedule and a list of business systems with the year each went live.
  2. Pre-fill the checklist from what your file already holds so the meeting covers only open items.
  3. Take the data rights block right after commercial contracts, since the same agreements answer both.
  4. Bring in the person who administers systems for the archive-control questions; the CFO rarely knows which old tenants still exist.
  5. Close with a one-page memo listing closed items, open items with an owner and date, and anything to revisit next year.

How to use the results

ResultWhat it meansNext action
Rights clear, 50+ full-time employees at peak (contractors excluded), several years of recordsThe client may fit a data licensing introductionMention the option and suggest the company fit checker for a preliminary, non-binding read
Customer contracts restrict some recordsThose records are effectively the customer'sCarve them out, or seek consent before any licensing review
Older notices thin or missingEarly-year material may be harder to licenseUpdate notices now and record the gap
Archives deleted or nobody can exportThe history may be gonePreserve exports before the next migration
Signing authority unclearNobody can bind the companyFix it with a resolution or written consent
Under 50 full-time employees at peakBelow SourceX's baselineTreat the section as housekeeping

The company fit checker needs no contact details, and the who qualifies page sets out the full baseline. Once a client says yes, the data opportunity handoff checklist for annual client reviews covers what to pass along.

Red flags that end the licensing conversation

  • The records mainly belong to the client's own customers, as at agencies and outsourcers, and those customers have not consented.
  • The data is chiefly consumer personal information with no licensing basis, or protected health information without HIPAA authorization or de-identification.
  • The archives were deleted, or nobody can produce an export.
  • A receiver, trustee or assignee controls the assets and has not been involved.
  • The same data is already licensed for AI training.
  • Records were generated with AI in order to sell them.
  • The owner will not consider an exclusive license for an agreed term.

Raising SourceX with a client, and your own rules

If the client clears the review and fits the baseline, the introduction is short. The client can apply directly at sourcex.si/apply using your referral link, or you submit the company through the referral form. Either way you share only basic fit facts, never the checkup memo, which is confidential and may be privileged.

Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, up to $100,000 per referred company, paid only after the buyer pays and SourceX receives its fee; no reward is guaranteed and nothing comes out of the client's proceeds. Referral compensation for lawyers is governed by each state's rules of professional conduct, so read the ethics checklist for lawyers recommending a vendor and your own jurisdiction's rules before accepting anything.

Where the client has an outside board, the signatory question often reaches its agenda; the page on referral opportunities for independent board directors covers that seat. If a sale is planned, quality of earnings providers will be reading many of the same contracts.

Next step

Add the data rights block to your next annual checkup template. When a client clears it and wants to explore licensing, register as a partner so your introduction is credited, then let the client apply directly or submit it through the referral form.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

How long should an annual legal checkup take?

For a company of 50 to a few hundred employees, plan on one focused working session plus preparation, with the length driven by how many contracts and states are involved. The data rights block adds only a short segment because it reuses the contract review already on the table. Sending the document request early and pre-filling what you already hold keeps the meeting itself to open items.

Who from the client should attend the checkup?

The owner or CEO for decisions, the CFO or controller for contracts and insurance, and whoever leads HR for the people section. For the data rights block, add the person who actually administers business systems, since only they know which old email tenants, CRMs and file shares still exist and whether exports were kept. A short separate call with that person often works better than a full-room session.

Should the data rights section be priced separately?

That is a practice decision. Some counsel fold it into a fixed-fee checkup because it draws on documents already under review; others scope it as an add-on when the client has many customer contracts or acquisitions to reconcile. Either way, set expectations in the engagement letter so the client understands the section is a review of rights and notices, not a full privacy audit.

Does a clean data rights review mean the client can license its records?

No. It means the obvious obstacles were not found. SourceX still qualifies each company on size, history, data breadth and rights, the company completes a data inventory, and nothing is binding until the company agrees price and terms and signs. Buyers review the opportunity after that. The checkup simply tells you whether raising the option is worth the client's time.

Can I share checkup findings with SourceX when I make the introduction?

Do not. The memo is confidential client work and may be privileged, and partners share only basic fit facts such as size band and years of operation, with the client's consent. If the client decides to proceed, it works with SourceX directly on the inventory and rights questions and chooses what to disclose under its own agreement.

What if the client has already licensed data to an AI developer?

Log the agreement in the contract register and read its scope, term and exclusivity. Data already licensed for AI training is a red flag for a new license of the same records, though records outside that grant may still be worth discussing. Keep the agreement on the checkup list each year so renewal, expiry and any restrictions stay visible.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment