Data processing agreement checklist: do your customer contracts restrict licensing records?

A data processing agreement (DPA) limits what a company may do with customer data it handles, so owners should review purpose, confidentiality, sub-processing, deletion and audit clauses with counsel before any records containing customer data are put in scope for a SourceX data license. Company-created records usually face fewer limits.

Do your customer contracts and DPAs allow licensing records?

Maybe, and the answer sits in the contracts, not in the data. A data processing agreement (DPA) is the contract in which a business that handles personal data on a customer's behalf agrees to use it only for the customer's instructions. If a record set contains customer data covered by a DPA or a purpose-limited customer contract, the owner should have counsel read those documents before that data goes anywhere near a licensing scope.

This page is a review checklist for business owners, general counsel and the CFOs who usually hold the contract folder. It does not interpret any specific contract. Partners who introduce companies never review, collect or describe customer records; the review below is the company's own job, done with its own counsel.

This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.

What is a DPA and why does it matter to a licensing decision?

A DPA, also called a data processing addendum, is usually an attachment to a master services agreement. It names who decides why personal data is processed, who only processes it on instruction, what the processor may do with it, and what happens when the relationship ends.

It matters here because a licensing scope can sweep in tickets, emails, call logs or CRM notes that contain a customer's data. If the company holds that data as a processor, it generally has no freedom to reuse it for its own purposes. The official text of the General Data Protection Regulation shows where the controller and processor roles are defined, and it can reach organizations outside the EU that serve or monitor people in the EU. A US company with European customers should assume the question is live.

Two related points from US regulators are worth knowing. FTC staff have written that a company's promises not to use customer data for undisclosed purposes, including model training, are enforceable whether they appear in privacy policies, terms or promotional materials. That is staff guidance, not a rule, but it tells owners that contract language about data use is taken at face value.

Which clauses should you read first?

Start with the clauses that restrict what the company may do with data it did not create. The table lists the usual places a restriction hides.

ClauseWhat to look forWhy it can block a license
Purpose limitation"Solely to provide the services" or "only on documented instructions"Licensing to a third party is not providing the services
ConfidentialityDefinition of confidential information, carve-outs, survival periodCustomer-supplied material may be covered for years after termination
Sub-processingApproval rights, flow-down termsA licensee or its vendors may count as a sub-processor or third party
Deletion and returnDeadline after termination, certification dutyOld archives may already be owed for deletion
Audit and notice rightsCustomer right to be told of new usesLicensing may require advance notice or consent
Ownership of outputsWho owns work product, derived data and analyticsDerived data may belong to the customer
Aggregated or de-identified dataAny right to use it for "improvement" or "analytics"The clause may or may not stretch to AI training

Do not assume a de-identified carve-out settles the question. Whether a clause that permits aggregated use reaches licensing to an AI developer is a point for counsel to read in context.

How should you triage the contract folder?

Use the three-bucket sort. It keeps the review proportional, because most of a company's records are usually its own.

  1. Bucket A, company-created records. Internal documents, finance, engineering, operations and process records the company wrote for itself. Contract restrictions rarely bite here, though employee data and third-party names still need attention.
  2. Bucket B, mixed records. Support tickets, project files and email threads that mix company work with customer content. These need a contract check per top customer and a plan for redaction.
  3. Bucket C, customer-owned records. Data the company holds only to deliver a service, such as hosted customer databases or an outsourcer's client files. Treat as out of scope unless the customer agrees in writing.

Then work through these steps:

  • List the 10 largest customers by revenue and pull each signed MSA, DPA and order form.
  • Mark each as controller, processor or neither for the data in question.
  • Flag every purpose-limit, confidentiality and deletion clause that mentions data use.
  • Note which customers are in the EU or the UK, or serve people there.
  • Record any consent, notice or approval step the contract would require.
  • Ask counsel which buckets can enter a data inventory and which need redaction first.

What does this mean in common situations?

SituationWhat to checkTypical outcome to confirm with counsel
Company writes its own SOPs, runbooks and engineering notesEmployee names, customer names inside the textOften in scope after redaction rules are agreed
Support desk holds tickets from enterprise customersCustomer MSA confidentiality and DPA purpose limitsPer-customer decision, or redact customer content
Agency or outsourcer works on client accountsWho owns campaign files and client dataFrequently out of scope without client consent
SaaS company hosts customer tenantsProcessor role, deletion dutiesTenant data is usually not the company's to license
Company has a customer in the EUGDPR role and any transfer termsCounsel decides whether and how data may be included

What to say to the owner

Keep the conversation short and practical.

The data license term sheet checklist shows what a license itself should cover, which is the other half of this review. If the company wants a plain-language record of what it has, the quality inspection records checklist is an example of a record-type walk-through. Advisors writing to their clients can adapt the CFO fit-screen email, and the subject-line guide keeps outreach plain.

How the process handles this

SourceX qualifies the company, the company completes a data inventory, and rights review happens before price and terms are agreed. Nothing is binding until the company agrees price and terms and signs, de-identification and redaction requirements are agreed before any work begins, and data is delivered only after an executed agreement and the company's authorization. Companies keep ownership; data is licensed, not sold. A company whose records mainly belong to its clients, without their consent, is a red flag rather than a candidate.

When to stop

Pause the introduction if the company cannot identify which contracts govern its main record sets, if the key customers have already objected, or if the data is mainly customer-owned. A company can come back later once the review is done. You can check basic fit without sharing contact details using the company fit checker, and read who qualifies for the baseline of 50+ full-time employees at peak (contractors excluded).

Next step

If a company you know has done this review and wants to proceed, register as a partner and make the introduction, or point the owner to the introduction email builder to draft a note.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Can a company be a processor for some data and a controller for other data?

Yes. A business can act as a controller for its own employee and sales data and as a processor for data it handles on a customer's behalf. That is why the three-bucket sort starts with classifying each record set instead of the company as a whole. Counsel should confirm the role for each set before it enters any licensing scope.

Does a signed DPA always forbid licensing?

No. Some customer contracts allow aggregated or de-identified use and others are silent. A DPA mainly limits processing of the customer's personal data to the customer's instructions. Whether a given clause reaches licensing to an AI developer is a reading for counsel, and the safest path is to keep restricted records out of scope or get written consent.

Who at the company should own the contract review?

Usually general counsel or outside counsel with the CFO or contracts manager pulling the documents. The owner or sponsor decides whether to proceed, and the technical lead explains where records live. The referring partner takes no part in reviewing contracts or records and only makes the introduction.

What if customers need to be notified?

If a contract requires notice or consent for a new use, the company has to complete that step before the affected records are included. Many companies simply exclude those customers' content. The agreed scope in the license, not the introduction, defines what is covered, so there is time to sort this out.

Do these questions apply to a company with only US customers?

The GDPR question may fall away, but contract limits still apply, as do state privacy laws and industry rules. Customer agreements are enforceable on their own terms. Counsel should still review confidentiality, purpose and deletion clauses before any customer-linked records are put in scope.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment