Trust and compliance
Start by reviewing what may be licensed.
Holding a database does not establish the right to license it. The process begins with a rights and compliance review with your counsel before buyer outreach. If the necessary rights and permissions cannot be established, the affected records are excluded or the opportunity stops.
Our role
Epistemic Labs is not a law firm and does not give legal advice.
This page provides general information. Your counsel makes the legal determinations for the proposed dataset and use. We organize the questions and evidence and handle the commercial work; a review may leave unresolved risks.
01The rights review
What the review covers.
The review considers the specific dataset and proposed uses. It may identify conditions, exclusions, or unresolved questions. It does not guarantee legal compliance or a transaction.
01
Ownership and licensing rights
Whether your company holds the rights needed to grant a license to a third party. Records created in your operations are not automatically yours to license if they were created under someone else's terms.
02
Contracts
Customer, supplier, platform, and software agreements may govern how operating data can be used. Counsel reviews the relevant terms against the proposed license, including restrictions on analytics, model training, and onward disclosure.
03
Confidentiality restrictions
NDAs and confidentiality clauses may restrict disclosure even after redaction or aggregation. Counsel checks whether consent or exclusion is needed. Sharing privileged or work-product material can risk waiver; an NDA alone does not prevent it.
04
Privacy law
Depending on their scope, the GDPR, UK GDPR, and US state privacy statutes may restrict secondary use, disclosure, and transfers. Counsel checks the applicable legal basis, purpose limits, notices, consent or opt-out requirements, and any additional rules for sensitive information.
05
Personal information
Review structured fields, free text, images, audio, and metadata for personal information. Counsel and technical reviewers determine what must be removed, transformed, or excluded. Removing names or substituting tokens does not necessarily make records anonymous or lawful to license.
06
Intellectual property
Records may include third-party copyright, trade secrets, or licensed content, such as drawings, manuals, and vendor documentation. Counsel checks which rights are needed and whether permission or exclusion is required.
07
Data provenance
Document where records came from and how they were collected, including vendor systems and partner sources. For recorded calls, counsel checks the applicable recording-consent rules, which may require every party's consent, and whether subsequent AI use or disclosure is permitted. Consent to recording does not itself authorize licensing.
08
Employee, customer, and vendor rights
People and companies that appear in your records may hold rights in them through employment terms, customer agreements, or vendor contracts. Their interests are part of the review from the start.
09
Sector-specific restrictions
HIPAA may apply to health information held by covered entities or business associates. Tax return preparers face separate use and disclosure limits under 26 U.S.C. 7216 and its regulations, including prescribed consents and exceptions; removing names alone is not enough. GLP/GMP obligations may require preservation of source records and audit trails. Counsel checks the applicable regime before disclosure.
10
Permitted model uses
Evaluation, fine-tuning, pretraining, and agent environments carry different risks. Rights may support one use and not another, so the license is scoped to what the review supports.
11
Retention and deletion obligations
Retention and deletion duties may constrain license duration and buyer use. Counsel checks how the duties apply to source records, extracts, and any trained models, including what must happen when the license ends.
12
Geographic and cross-border restrictions
Data localization, privacy transfer rules, and export controls may restrict recipients and locations. Releasing controlled technology to a foreign person can require authorization even within the same country. Counsel checks classification, recipients, destinations, and any required authorization before access is granted.
02How data is handled
Disclosure in stages, never all at once.
Each stage reveals only what the next decision requires, and nothing moves to a buyer without your approval.
01
Dataset metadata and contact details on the public site.
The assessment asks for dataset descriptions: sources, scale, structure, and rights position. Forms also collect contact and request details. There is no dataset upload field. Do not put dataset contents or confidential material in messages. The privacy notice covers attribution, analytics, and abuse prevention.
02
An NDA and disclosure review first.
Before sharing confidential schemas, samples, or contract terms, sign a mutual NDA and have counsel check what may be disclosed. An NDA does not override confidentiality duties, privacy rules, or privilege concerns.
03
Agree a controlled diligence environment.
Agree access controls, permitted recipients, and transfer methods before any dataset sample is shared. Use the separate diligence channel for approved materials. The public forms are for descriptions and requests.
04
Samples and documentation before delivery.
Organize a limited, approved sample and documentation in an agreed data room. Outreach requires seller approval, and buyer review is subject to confidentiality terms. Full delivery requires a signed license and the agreed safeguards.
Tools, where appropriate
None of these is a cure-all. Each one changes what the data is useful for, and the right choice follows from the rights review, not the other way around.
- De-identification
- Reducing identifiability, with the result assessed under the applicable legal standard. Tokenization may leave personal information. HIPAA de-identification, where applicable, requires Safe Harbor or Expert Determination; contracts and other laws still need review.
- Redaction
- Removing specific fields, passages, or image regions, such as names, account numbers, faces, and addresses.
- Aggregation
- Sharing patterns across records where individual detail is not needed. Small groups or unusual combinations may still identify people, and contractual or sector restrictions may still apply.
- Synthetic derivation
- Generating new records informed by source data. Synthetic output may reproduce sensitive details or allow inferences about people. Rights to use the source and disclose the output still need review; synthetic derivation is not a substitute for permission.
03Limits
What we will not do.
These are conditions of every engagement, not preferences, and they apply regardless of price.
- 01
Broker data you lack the rights to license.
If the review shows the rights are not there, the dataset does not go to market, in whole or in part.
- 02
License personal information without the required permissions.
Counsel reviews the legal basis, permissions, and safeguards for the specific use and disclosure. Where these cannot be established, the affected records are excluded or the opportunity stops.
- 03
Broker scraped or misappropriated data.
We do not represent datasets assembled by scraping, or data obtained without the permission of those entitled to give it.
- 04
Misrepresent provenance to buyers.
Documentation should identify sources, collection methods, processing steps, and known gaps. Unverified provenance must be identified as such.
- 05
Take ownership of your data by default.
Sellers license the rights they hold and keep ownership by default. Through our data opportunities service, we act as a broker and advisor. Any ownership transfer would require a separate negotiated agreement that the seller chooses.
Start with the rights question.
The assessment asks about origin, personal information, and confidentiality. It cannot settle the rights question, but it shows where your counsel should look first.