Home › Guides › Data licensing readiness
Guide · Readiness
Licensing data means granting a buyer the right to use a defined dataset, for a defined purpose, for a defined period, while your company keeps ownership. Whether that is possible is usually decided long before price comes up: by what you promised the people and customers the data came from, and by whether you can describe the dataset precisely enough for a buyer to evaluate it.
Start with the documents, not the database. Customer master agreements, data processing agreements, order forms and your public terms of service and privacy policy decide what you may do with data your platform processes. Some expressly allow use of aggregated or de-identified data; some prohibit any use beyond providing the service; many say nothing, which is not the same as permission.
U.S. regulators treat those commitments as binding. The Federal Trade Commission has said that companies which fail to abide by privacy commitments to their users and customers — including promises not to use customer data for secret purposes such as training models — may be liable under the laws it enforces, and that it has required businesses that unlawfully obtained data to delete models and algorithms built from it (FTC Technology Blog, “AI Companies: Uphold Your Privacy and Confidentiality Commitments” (Jan. 2024)). It has also warned that quietly or retroactively changing terms of service or a privacy policy to permit new uses of data already collected could be unfair or deceptive (FTC Technology Blog, “AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive” (Feb. 2024)).
The provenance lesson. In 2021 the SEC settled securities-fraud charges against App Annie, an alternative-data provider, and its co-founder for more than $10 million — the SEC’s first enforcement action against an alternative-data provider. According to the SEC’s order, the company told the companies sharing data with it that their data would be aggregated and anonymized, then used non-aggregated, non-anonymized data to make estimates more valuable to trading-firm customers, and misrepresented that to those customers (SEC press release 2021-176, “SEC Charges App Annie and its Founder with Securities Fraud” (Sept. 14, 2021)). What you tell a buyer about how a dataset was produced has to match what you told the people it came from.
A buyer cannot evaluate “our platform data.” It can evaluate a described dataset: which tables, what date range, how often it updates, roughly how many records, and how complete each field is. Write a one-page data profile and a data dictionary that defines every field you would deliver. For procurement and spend data we have a separate guide on how buyers qualify those datasets.
Business data still contains personal data: contact names, approvers, expense submitters, sole-trader suppliers. Decide early whether you would license transaction-level records with identifiers removed, or aggregates such as category-level price and volume series. Aggregates are usually easier to defend.
Legal definitions are specific. Under the California Consumer Privacy Act, information counts as “deidentified” only if it cannot reasonably be linked to a consumer and the business takes reasonable measures to prevent association, publicly commits not to re-identify it, and contractually obligates recipients to comply (California Civil Code § 1798.140 (CCPA definitions, incl. “deidentified”)). Under the GDPR, pseudonymised data that could be re-attributed with additional information is still personal data; only truly anonymous information falls outside it (GDPR Recital 26, “Not applicable to anonymous data”). NIST’s guidance on de-identification is a practical, technical reference for choosing methods (NIST SP 800-188, De-Identifying Government Datasets). Our privacy and rights guide goes further.
Buyers and their counsel ask how data is protected in your systems and how it would be delivered. A current SOC 2 report is the evidence many U.S. software buyers expect to see (AICPA & CIMA — SOC 2 overview); the NIST Privacy Framework is a useful structure for describing how privacy risk is managed (NIST Privacy Framework). Be ready to explain access controls, logging, retention and how a delivery would be secured.
Serious buyers generally want to test data before committing, for example by checking whether it would have explained past outcomes. Plan a small, representative, de-identified sample, delivered under an NDA or a short evaluation licence that limits use to evaluation and requires deletion afterward.
Have your own counsel review any agreement. Nothing in this guide is legal advice.
Tick what is true today. Nothing is stored or sent; this runs only in your browser.
Who is writing this. MyDataWorth is an independent introduction desk. We are not a data buyer, a marketplace, a law firm or an agent of any buyer, and we never receive, hold or resell a company’s data. We review whether a company looks ready for a data-licensing conversation and, only with its written go-ahead, introduce it to programs that license business data. When an introduction leads to an engagement we may be paid a referral fee by that program; we tell you who, and on what basis, before your name goes anywhere.
Request a free readiness review →
Primary sources, each read on 22 September 2026. Laws and guidance change; check the current version before relying on any of it.