Last checked: 7 October 2026 (buyer statements quoted on this page)
If de-identification misses a name, a client or a health detail, someone pays for the fallout. Four parts of the contract decide who: the warranties you give, the indemnities behind them, the cap on liability, and how long all of it survives.
Each part only makes sense next to the others. A modest warranty with an unlimited indemnity can carry more risk than a broad warranty with a tight cap.
Statements of fact you promise are true, such as that you may license the data and gave the notices required. If one is false, the buyer may have a claim.
A promise to cover the other side's losses from defined events, such as a claim by a third party, often including legal costs. One-way or mutual.
The most each side can owe, and the list of losses excluded from the contract or carved out of the cap.
How long warranties and indemnities last after delivery, or after the contract ends. Without an end date, the exposure has none either.
Read the four together, never one at a time. A narrow warranty paired with a broad, uncapped indemnity can still leave you exposed, because the indemnity may reach losses the warranty never mentioned. A broad warranty paired with a tight cap and a short survival period may be easier to live with. When you compare two drafts, write one line for each part: what you promise, what you would pay for, the most you could owe, and until when. That one-page summary is often the clearest way to compare offers that look similar on price.
No de-identification method is perfect. Here is how a single miss can turn into a claim, and where the contract steps in.
A customer name in a ticket, a client identity in a chat thread, a health note in an HR message.
Found by the buyer, by a later recipient of the data, or by the person it describes.
From a client, an employee, a customer or a regulator, under a contract or a law such as GDPR or CCPA/CPRA.
Your warranties, the buyer's process duties, the indemnities and the caps settle who bears the cost.
Buyers describe their own privacy steps. micro1 states that sensitive and confidential information is scrubbed and no customer information is exposed; Mode states that it de-identifies before onward delivery (as published, checked 7 October 2026).
For any buyer, a public description of a process is not the same as a contractual allocation of risk. The useful step is to ask how the contract reflects the process you are relying on, and what happens if it fails. The de-identification guide covers what to verify yourself.
The questions on this page are generic and apply to any buyer. They are not claims about any named company's terms.
Each is a promise about facts you need to check before signing. The consent warranties are the ones most worth preparing for.
| Warranty | What it means | Question to ask first |
|---|---|---|
| Ownership and right to license | You own, or may license, everything in scope | Is client, contractor or vendor material mixed into the records? |
| Employee notice or consent | Staff were told, or agreed, as the law and your policies require | What exactly were staff told, and when? (employees guide) |
| Customer and client consent | Customers' and clients' information may be used this way | Do our privacy notices and client contracts cover it? (client confidentiality) |
| No conflicting contracts | Licensing breaches no NDA, client agreement or earlier data license | Have we checked client NDAs and any prior license of the same records? |
| Compliance with law | Collection and licensing comply with laws such as GDPR, CCPA/CPRA, HIPAA or GLBA | Can this be limited to laws that apply to us, and to what we know? |
| No privileged or regulated content | No privileged, patient or similarly protected records are in scope | Who checked, by what method, and is it documented? |
| Clean files | No malware, credentials or secrets inside the export | Have we run a secrets scan on code, chat and documents? |
The left column describes patterns that shift more risk to the seller. The right column lists requests your lawyer can make. Neither describes any particular buyer.
The cap tells you how much. Survival tells you for how long. Know both before you sign.
A cap limits what each side can owe. Carve-outs are categories left outside the cap, sometimes privacy, confidentiality or intellectual property. If the carve-outs cover the risks most likely to arise in a data deal, the cap may protect less than it appears to.
A data copy, and models trained on it, can outlast the contract by years. Survival clauses decide which promises keep running after delivery or termination. A warranty that survives without an end date keeps your exposure open just as long.
Warranties are only as safe as the work behind them. These steps give you evidence for every promise you make.
Does your cyber or professional liability policy respond to liability you take on by contract in a data license, or does an exclusion apply? Are there notice duties you must meet? Ask the buyer what insurance it carries and whether you can see confirmation of it.
The words in the risk clauses only become real when something goes wrong. This fictional example runs one incident through two different drafts.
Same miss, very different result, and the difference was fixed at signing, not after the complaint. Real outcomes depend on the exact wording and the governing law, which is why your own lawyer should read these clauses before you agree to them.
Fictional, labeled examples. Each one changes which promise is hardest to make, and what to ask before making it.
A 30-person law or accounting practice owes clients confidentiality, and lawyers also deal with attorney-client privilege. The "no conflicting contracts" and "no privileged content" warranties are the hardest to give honestly.
A 60-person firm owned by its staff gives consent warranties about people who are also its shareholders. If an owner later objects to their messages being included, that becomes a governance problem and a contract problem at once.
A startup that closes next quarter cannot easily stand behind a warranty that survives for years. A buyer may want comfort that claims can still be met, and the founders will want to know whether anything follows them personally.
In each case the hardest warranty is the one about other people: clients, employee-owners or future claimants. Settle those facts inside the company before the draft arrives, and the negotiation becomes about wording rather than about what you do not yet know.
The left list is what sellers tend to get wrong. The right list is what to put to your own lawyer before you sign.
A promise by one side to cover the other side’s losses from defined events, such as a third-party claim that data was shared without the required notice or consent. It often includes legal costs. Whether it is one-way or mutual, capped or uncapped, and how long it lasts are the points to negotiate.
The contract decides. Liability can sit with the seller through its warranties, with the buyer through its process obligations, or be shared. Ask who performs the de-identification, whether you approve the output, and whether the buyer indemnifies you if its process misses something.
Ask for a cap and know its size before you sign. The usual questions are whether the cap is tied to the fees you receive and which categories, if any, sit outside it. Without a cap, your exposure is not limited by the size of the deal.
Sellers may be asked to confirm that employees, customers and clients were given whatever notice or consent the law and existing contracts require for this use. Ask whether these promises can be limited to what you know after reasonable checks, and keep written records of the notices you gave.
As long as the survival clause says. Some last for a set period after delivery or termination; others have no stated end. Because a data copy, and models trained on it, can outlast the contract, ask for a clear expiry and check which duties survive.
It depends on your policies. Ask your insurance broker whether your cyber or professional liability cover responds to liability you take on by contract, and which exclusions apply. Ask the buyer what insurance it carries as well.
It might, depending on the wording. Some contracts could treat seller approval as acceptance of the output. Ask your lawyer whether your review is a check for your own comfort or a sign-off that shifts risk to you, and get that written into the agreement.
The contract still says what it says, but a closed company cannot easily stand behind it. A buyer may ask how claims would be met after closure. Ask your lawyer how survival periods, any holdback of the price and insurance would work in a wind-down.
Indemnities and caps only appear at the agreement stage. Check your fit, apply, and have your lawyer read the risk clauses before anything is exported.
Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data.