Who Owns the Data in a SaaS Agreement, and What the Provider Can Do With It

When a business signs up for a SaaS product, it puts its data into someone else’s system. Customer records, financial information, employee data, usage patterns, and everything else the software touches now live on the provider’s infrastructure. The SaaS agreement governs who owns that data, what the provider is allowed to do with it, and what happens to it when the relationship ends.

Most customers focus on price, functionality, and uptime, and skim the data provisions. The data section usually reads as standard boilerplate, and much of it is. But the terms that define ownership, the license the customer grants the provider, and the provider’s right to use the data for its own purposes are where real rights are allocated. A customer that does not read those terms closely may grant the provider more than it intended, in ways that matter both during the relationship and after it ends.

Reading the data provisions comes down to four questions: who owns the data, what license the customer grants the provider, what the provider can do with the data beyond running the service, and what happens to the data when the agreement ends.


Who Owns the Data

Most SaaS agreements state that the customer owns its data. That statement is important and worth confirming, but on its own it settles less than it appears to. Ownership of the data is the starting point, not the whole picture, because the customer typically grants the provider a broad license to use that data, and the scope of that license determines what the provider can actually do.

The more important distinction is often between customer data and other categories the agreement defines separately. Many agreements carve out usage data, aggregated data, anonymized data, or derived data, and treat those categories differently from the customer’s own content. Usage data about the operation of the service, such as login frequency, feature utilization, and performance metrics, is different from data, insights, or outputs derived from the substance of the customer’s information, and the agreement should not treat those categories as interchangeable.

The customer may own its content, while the provider claims broader rights over data about how the customer uses the service, or over data derived from the customer’s content. For analytics and AI-enabled services, the agreement should also be checked for how it treats outputs generated from customer data, which may be defined separately from both customer data and derived data. The definitions section is where these lines are drawn, and the lines matter more than the headline statement that the customer owns its data.

Before relying on a statement that the customer owns its data, read the definitions. What exactly is customer data, and what has been defined out of it as usage data, aggregated data, derived data, or output? The scope of the customer data definition determines how much the ownership statement actually protects.


The License the Customer Grants

For the provider to run the service, the customer has to grant it a license to use the customer’s data. This is necessary and generally uncontroversial in principle. The provider cannot host, process, display, or back up the data without permission to do so. The question is how far the license goes beyond what running the service requires.

A license limited to what is necessary to provide the service is appropriate. It lets the provider operate the software, store and process the data, and deliver the functionality the customer is paying for. A well-scoped license ties the provider’s rights to the purpose of providing the service and goes no further.

A broader license is where the customer may give away more than it realizes. Language permitting use to improve or develop the provider’s services, other products, models, or business operations can extend well beyond operating the service for the customer. Under that kind of language, the customer’s data becomes an input to the provider’s broader operations, and the customer has agreed to it by accepting the license. The breadth of the license, not the ownership statement, determines what the provider can do with the data.

The customer should test the license against two questions: whether each permitted use is necessary to provide the service, and whether any right continues after the relationship ends. The license also has to be read together with the confidentiality provisions, privacy terms, and any data processing addendum, each of which may impose separate limits on the provider’s use and disclosure of the data.


What the Provider Can Do Beyond Running the Service

Beyond the license to operate the service, many SaaS agreements grant the provider rights to use customer data for its own purposes. These provisions determine whether the provider may use the data for purposes that benefit its broader business rather than only the customer receiving the service.

Aggregation and anonymization provisions are common. The provider may reserve the right to aggregate the customer’s data with other customers’ data, anonymize or de-identify it, and use the resulting information for analytics, benchmarking, or product development. Whether this is acceptable depends on how robust the aggregation and anonymization actually are, and on what the provider is permitted to do with the result. Data that is genuinely aggregated or effectively de-identified generally raises fewer concerns than data that is nominally anonymized but could be re-identified.

One of the most significant emerging issues is the right to use customer data to train the provider’s machine learning models. A clause permitting the provider to use customer data, or data derived from it, to train, develop, or improve its models can mean the customer’s data is being used to build capabilities the provider then offers to everyone, including the customer’s competitors. For a business whose data reflects proprietary processes, customer relationships, or competitively sensitive information, this is a material concern that is easy to miss because the clause is often brief and located in a general data-use section rather than flagged as a distinct grant.

These provisions are receiving more attention and may be negotiable, particularly in enterprise arrangements or where the customer’s data is sensitive or strategically valuable. Providers sometimes offer opt-outs from model training, commitments not to use customer data for training, or different data-use terms by product or tier. A customer that raises the issue often has more room to negotiate than the standard terms suggest.

Read the provider-use provisions for what they permit beyond running the service, and pay particular attention to any right to use the data for model training. Where the data is sensitive, that right may be one of the most important provisions in the agreement, and it may be negotiable if the customer raises it.


What Happens to the Data When the Agreement Ends

When a customer stops using a SaaS product, it needs its data back, and it needs to know the provider will not keep using it. The termination provisions govern both, and they are frequently overlooked at signing because no one is thinking about the end of the relationship at the beginning of it.

Data return and retrieval terms determine whether, and how, the customer can get its data out. The agreement should provide for the customer to export or retrieve its data in a usable format, within a defined window after termination. Terms to confirm include the format the data comes back in, whether it is usable outside the provider’s system, how long the customer has to retrieve it before the provider deletes it, and whether the provider charges for retrieval or for the assistance needed to complete it. A right to get the data back that comes in an unusable format, or within an impractically short window, is worth less than it appears.

Data deletion terms determine what happens to the customer’s data on the provider’s systems after the relationship ends. The customer generally wants confirmation that the provider will delete its data within a defined period after termination, subject to any legal retention obligations and standard backup cycles. The deletion obligation should also extend to the provider’s subprocessors, with any retained backup copies remaining inaccessible and subject to the agreement’s confidentiality and use restrictions until overwritten. The customer should also confirm that any licenses granted to the provider terminate when the agreement does, so the provider cannot continue using the data after the relationship has ended. A license that survives termination, combined with the absence of a deletion obligation, may allow the provider to retain and continue using the customer’s data long after the commercial relationship has ended, subject to any other contractual or legal restrictions.

Confirm both halves of the exit: that the customer can retrieve its data in a usable form within a workable window, and that the provider will delete the data and stop using it after termination. The two together determine whether leaving the provider is clean or leaves the customer’s data behind and still in use.


The Takeaway

A statement that the customer owns its data is the beginning of the analysis. What matters just as much is how customer data is defined, what license the customer grants, what the provider is permitted to do with the data beyond running the service, and what happens to the data when the agreement ends. Those terms, taken together, determine what the customer has actually agreed to.

For most SaaS relationships, the standard data terms may be perfectly acceptable. For a business whose data is competitively sensitive, or whose use of the service generates valuable information, the data provisions deserve the same scrutiny as the commercial terms. The right to use customer data for model training, in particular, has become a provision worth reading closely and, where the data warrants it, negotiating. The ownership statement is where reading the data provisions starts, not where it ends.

This post is general information only and does not constitute legal advice. For questions about a particular agreement, contact Cruxterra Law Group.

Next
Next

What a Letter of Intent Actually Commits You To