Client-owned data vs company-owned data: a rights map for service providers

Service providers usually own their internal operating records but not the data they hold for clients. Managed service providers, 3PLs, TPAs, PEOs, agencies and call centers each have a company-owned layer and a client-owned layer, and contracts decide where the line falls.

When do you need a rights map for client data?

Use this rights map whenever you are about to introduce a company that works on its customers' data: managed service providers, 3PLs, third-party administrators, PEOs, agencies, collections shops and contact centers. The short rule: a service provider usually owns its own operating records and does not automatically own what it holds for clients. The table below shows where each type typically lands. The contract decides, so treat every row as a prompt for a question, not a conclusion.

Rights map by service-provider type

Provider typeTypically company-ownedTypically client-owned or needs consentFirst question to ask
Managed service providerInternal runbooks, ticket workflow design, finance, HR, salesClient environment data, credentials, logs from client systemsDoes the master services agreement address use of ticket content?
3PL and freight brokerageSOPs, pricing policies, internal exception notesShipment contents, shipper rates, consignee detailsWhich fields in the TMS come from the shipper?
Third-party administratorCorporate finance, HR, operations manualsMember and claims records, plan sponsor dataIs any record non-PHI and non-member?
PEO and payroll bureauOwn finance, sales, internal support processesWorksite employee records, payroll dataDo client agreements restrict secondary use?
Agency (marketing, creative, software)Proposals, internal project management, pitch outcomesClient assets, campaign data, customer listsWho owns the working files at delivery?
Collections agencyInternal compliance procedures, financeDebtor account data and creditor filesIs any record free of consumer data?
Contact center and BPOTraining content, QA scorecards, internal analytics designCall recordings, transcripts, customer interactionsDo client contracts allow reuse of recordings?
Property managerOwn accounting, leasing process, maintenance workflow designOwner financials, tenant recordsAre tenant and owner records separate?
Architecture firmInternal proposals, QA records, financeDrawings, specifications, site informationDo contracts transfer ownership at delivery?

How to use the map with the template below

A map is only useful if you capture the answers consistently. Copy the notes template into your own file, fill it in from conversation, and keep it free of record contents. You note categories and the owner's answers, never the records themselves.

>

>

>

>

>

>

Add one line per category and avoid free-text descriptions of confidential material.

A sample client email asking about consent

Use this only after the owner has said the idea is worth exploring and prefers to check client terms first.

Personalize it with the company name and the specific system under discussion. Follow up in a week if you hear nothing, and stop after two follow-ups.

What the answers mean

ResultWhat it meansNext action
Large internal layer, clearly company-authoredStrong rights positionRun the company fit checker and introduce
Mixed, contracts silentRights uncertainAsk counsel to review; introduce only if the company-owned layer stands alone
Mostly client-ownedRights weakDo not introduce; see poor-fit industries
Clients' consent obtained in writingRights improvedTell SourceX about the consent during qualification

The guide on how to distinguish company data from data owned by its customers explains the tests in more depth, and the buy-and-build sectors guide shows where service providers appear in acquirer strategies.

Where the map breaks down

Real companies rarely fit one row. A managed service provider may run its own software products, a 3PL may sell analytics, and an agency may keep a proprietary playbook built from years of client work. In each case ask what the company created independently of any single client, and whether any contract assigns that work to the customer. This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

Two further checks help. First, look at how records are labeled inside the systems: a ticketing tool with a client field on every record is easier to scope than one where client details are scattered through free text. Second, ask whether the company ever signed a data-processing or confidentiality schedule that limits secondary use. Those clauses decide more outcomes than industry labels do, and the company, not the partner, should confirm them with counsel.

What never to include in any message

  • Confidential records, screenshots or excerpts from a client system.
  • Promises of payment, reward amounts or any suggestion that a deal is certain.
  • Claims that a company qualifies or that rights are cleared. SourceX reviews rights, and the company signs.
  • Statements about specific buyers. Refer to AI labs and data buyers generally.

Partners earn 25% of the eligible platform fees SourceX actually collects, capped at $100,000 per referred company, payable only after the buyer pays and SourceX receives its fee. No reward is guaranteed.

Next step

Fill in the rights note for the next service-provider company you consider. If a clear company-owned layer exists, register as a partner and introduce it, or have the owner apply at sourcex.si/apply. The baseline is on the who qualifies page.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Who owns data a service provider creates for a client?

It depends on the contract. Often the client owns data it supplies and results delivered to it, while the provider owns its own tools, methods and internal records. Agreements vary, so a rights map is a starting question list, not a legal conclusion.

Can a managed service provider license ticket history?

Possibly, if its contracts permit and client information can be removed or consented. Ticket content often contains client details, so the provider and counsel decide the scope. SourceX reviews rights and agrees redaction rules with the company before any work.

What if clients have given consent in writing?

Written consent improves the rights position, and SourceX can look at it during qualification. The consent needs to cover the intended use, which is an exclusive AI-training license for an agreed term. Counsel should confirm the wording.

Do I need to review the contracts myself?

No, and you should not. Partners give basic fit information only. The company and its counsel review its contracts, and SourceX reviews rights during qualification. Your role is to ask which categories look clear and note the answers.

Why does a service provider with many clients look attractive but fail?

Because volume is not ownership. A provider can hold years of rich records that mostly belong to its customers. Buyers need clean rights, so the screen focuses on the company-authored layer, which is often smaller than the owner expects.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment