Sell Data to AI
Home Data Asset Score Pricing API documentation US labs and CROs list
For brokers
How to become an AI data broker Data broker business model Buyer programs compared Qualify a company AI training data companies
For data companies
Firmographic data providers Company data API
Seller guides
How to sell data to AI companies Is it legal? FAQ and glossary About
Check domain/company
Contracts: risk allocation

Indemnities and Warranties in AI Data Deals: Who Carries the Risk?

Last checked: 7 October 2026 (buyer statements quoted on this page)

If de-identification misses a name, a client or a health detail, someone pays for the fallout. Four parts of the contract decide who: the warranties you give, the indemnities behind them, the cap on liability, and how long all of it survives.

4contract parts that allocate risk: warranties, indemnities, caps, survival
1question to settle first: who pays if de-identification misses something
9contract risks every seller should check, whoever the buyer is
Four linked parts

How risk moves through a data contract

Each part only makes sense next to the others. A modest warranty with an unlimited indemnity can carry more risk than a broad warranty with a tight cap.

Warranties

Statements of fact you promise are true, such as that you may license the data and gave the notices required. If one is false, the buyer may have a claim.

Indemnities

A promise to cover the other side's losses from defined events, such as a claim by a third party, often including legal costs. One-way or mutual.

Liability cap

The most each side can owe, and the list of losses excluded from the contract or carved out of the cap.

Survival

How long warranties and indemnities last after delivery, or after the contract ends. Without an end date, the exposure has none either.

Read the four together, never one at a time. A narrow warranty paired with a broad, uncapped indemnity can still leave you exposed, because the indemnity may reach losses the warranty never mentioned. A broad warranty paired with a tight cap and a short survival period may be easier to live with. When you compare two drafts, write one line for each part: what you promise, what you would pay for, the most you could owe, and until when. That one-page summary is often the clearest way to compare offers that look similar on price.

The central question

Who pays if de-identification misses something?

No de-identification method is perfect. Here is how a single miss can turn into a claim, and where the contract steps in.

1

A detail slips through

A customer name in a ticket, a client identity in a chat thread, a health note in an HR message.

2

It surfaces downstream

Found by the buyer, by a later recipient of the data, or by the person it describes.

3

A complaint or claim

From a client, an employee, a customer or a regulator, under a contract or a law such as GDPR or CCPA/CPRA.

4

The contract decides

Your warranties, the buyer's process duties, the indemnities and the caps settle who bears the cost.

Buyers describe their own privacy steps. micro1 states that sensitive and confidential information is scrubbed and no customer information is exposed; Mode states that it de-identifies before onward delivery (as published, checked 7 October 2026).

For any buyer, a public description of a process is not the same as a contractual allocation of risk. The useful step is to ask how the contract reflects the process you are relying on, and what happens if it fails. The de-identification guide covers what to verify yourself.

The questions on this page are generic and apply to any buyer. They are not claims about any named company's terms.

  • Who performs the de-identification, and is that written as the buyer's obligation?
  • Do you approve the de-identified output, and does approving it move the risk to you?
  • Is your indemnity limited to breaches of your own warranties, or does it cover anything found in the data?
  • Does the buyer indemnify you if its own process misses something, or if it uses the data beyond the agreed scope?
  • Who must be told first, and how fast, if a miss is found?
What you may be asked to promise

Seven warranties sellers may be asked to give

Each is a promise about facts you need to check before signing. The consent warranties are the ones most worth preparing for.

WarrantyWhat it meansQuestion to ask first
Ownership and right to licenseYou own, or may license, everything in scopeIs client, contractor or vendor material mixed into the records?
Employee notice or consentStaff were told, or agreed, as the law and your policies requireWhat exactly were staff told, and when? (employees guide)
Customer and client consentCustomers' and clients' information may be used this wayDo our privacy notices and client contracts cover it? (client confidentiality)
No conflicting contractsLicensing breaches no NDA, client agreement or earlier data licenseHave we checked client NDAs and any prior license of the same records?
Compliance with lawCollection and licensing comply with laws such as GDPR, CCPA/CPRA, HIPAA or GLBACan this be limited to laws that apply to us, and to what we know?
No privileged or regulated contentNo privileged, patient or similarly protected records are in scopeWho checked, by what method, and is it documented?
Clean filesNo malware, credentials or secrets inside the exportHave we run a secrets scan on code, chat and documents?
Two ideas to raise with your lawyer: a knowledge qualifier, which limits a warranty to what you know after reasonable checks, and a materiality threshold, which keeps minor slips from counting as a breach. Whether either is acceptable is the buyer's decision, but asking is normal.
Indemnities

Indemnity terms to watch, and what to ask for instead

The left column describes patterns that shift more risk to the seller. The right column lists requests your lawyer can make. Neither describes any particular buyer.

Patterns that raise your risk

  • Only the seller indemnifies; the buyer promises nothing back.
  • The indemnity covers any claim connected with the data, whatever caused it.
  • Indemnity claims sit outside any liability cap.
  • The buyer controls the defense and any settlement, at your cost.
  • No time limit on when a claim can be brought.

Requests to discuss with your lawyer

  • Mutual indemnities: each side covers its own failures, including the buyer's de-identification and use beyond scope.
  • Your indemnity tied to breaches of your own warranties.
  • A cap that applies to indemnities as well, or a separate, known cap for them.
  • Prompt notice of claims and a say in how they are settled.
  • A clear period after which no new claims can be made.
Size and time

Your worst case has a size and a duration

The cap tells you how much. Survival tells you for how long. Know both before you sign.

Caps and carve-outs

A cap limits what each side can owe. Carve-outs are categories left outside the cap, sometimes privacy, confidentiality or intellectual property. If the carve-outs cover the risks most likely to arise in a data deal, the cap may protect less than it appears to.

  • Is the cap tied to fees paid, and over what period?
  • Which categories sit outside it?
  • Is the buyer's cap the same as yours?
  • Does the cap include legal costs?

Survival periods

A data copy, and models trained on it, can outlast the contract by years. Survival clauses decide which promises keep running after delivery or termination. A warranty that survives without an end date keeps your exposure open just as long.

  • How long do warranties survive after delivery?
  • Does the indemnity expire, and when?
  • Do the buyer's deletion and use limits survive as long as yours?
Before you promise anything

Check insurance, then check your own facts

Warranties are only as safe as the work behind them. These steps give you evidence for every promise you make.

Ask your insurance broker

Does your cyber or professional liability policy respond to liability you take on by contract in a data license, or does an exclusion apply? Are there notice duties you must meet? Ask the buyer what insurance it carries and whether you can see confirmation of it.

An inventory and written scope: systems, dates, teams.
An exclusion list for HR, legal, client-confidential and regulated records.
A dated record of what staff were told.
A review of client NDAs and service contracts for secondary-use limits.
A secrets scan of code, chat and documents before export.
A de-identified sample of your own data, reviewed by someone who knows your clients.
A written description of the buyer's de-identification process.
Your list of questions for the buyer, answered in writing.
Worked example

One miss, two contracts: how the same incident ends differently

The words in the risk clauses only become real when something goes wrong. This fictional example runs one incident through two different drafts.

Illustrative, fictional, not an offer and not legal analysis
The setup: a 45-person accounting firm licenses five years of internal SOP documents and ticket history. The buyer de-identifies the export. A client's name survives inside a scanned attachment that the text tool did not read, and the client complains to the firm after hearing about the deal.

Contract A

  • Only the seller indemnifies, for any claim connected with the data.
  • Indemnity claims sit outside the liability cap.
  • Warranties survive with no end date.
  • The buyer controls the defense of any claim.
Likely shape of the outcome: the firm may face its own costs and the buyer's, with no ceiling, years after it was paid, even though the miss happened in the buyer's process.

Contract B

  • Mutual indemnities; the buyer covers failures of its own de-identification.
  • A cap tied to the fees paid applies to most claims.
  • Warranties survive for 24 months after delivery.
  • Both sides are notified promptly and agree any settlement.
Likely shape of the outcome: the firm's exposure depends on whether its own warranties were true. The process failure sits with the buyer, and the firm knows its maximum exposure.

Same miss, very different result, and the difference was fixed at signing, not after the complaint. Real outcomes depend on the exact wording and the governing law, which is why your own lawyer should read these clauses before you agree to them.

Three situations

Where warranties get harder: three company situations

Fictional, labeled examples. Each one changes which promise is hardest to make, and what to ask before making it.

Fictional example

A firm holding client secrets

A 30-person law or accounting practice owes clients confidentiality, and lawyers also deal with attorney-client privilege. The "no conflicting contracts" and "no privileged content" warranties are the hardest to give honestly.

  • Which engagement letters or NDAs limit secondary use?
  • Who checks for privileged material, and how is that documented?
  • Can the warranty be limited to sources we have reviewed?
Fictional example

An employee-owned company

A 60-person firm owned by its staff gives consent warranties about people who are also its shareholders. If an owner later objects to their messages being included, that becomes a governance problem and a contract problem at once.

  • Who must approve the warranties before signing?
  • Is there a dated record of what each employee was told?
  • Can individuals opt their own channels out first?
Fictional example

A company winding down

A startup that closes next quarter cannot easily stand behind a warranty that survives for years. A buyer may want comfort that claims can still be met, and the founders will want to know whether anything follows them personally.

  • Will part of the price be held back to cover claims?
  • Is anyone asked to make personal promises?
  • Does any insurance continue after the company closes?

In each case the hardest warranty is the one about other people: clients, employee-owners or future claimants. Settle those facts inside the company before the draft arrives, and the negotiation becomes about wording rather than about what you do not yet know.

Negotiation checklist

Common mistakes, and the questions that prevent them

The left list is what sellers tend to get wrong. The right list is what to put to your own lawyer before you sign.

Five common mistakes

  • Signing consent warranties before checking what staff and clients were actually told.
  • Treating the buyer's de-identification as your protection, when the warranties are still yours.
  • Reading the cap without reading the carve-outs below it.
  • Forgetting that warranties keep running after the money is spent.
  • Assuming insurance covers contractual liability without asking the broker.

Eight questions for your lawyer

  • Which warranties can be limited by knowledge or materiality?
  • Is our indemnity limited to breaches of our own warranties?
  • Does the buyer indemnify us for its de-identification and for use beyond scope?
  • What is our maximum exposure, carve-outs included?
  • How long does each warranty and indemnity survive?
  • Who controls the defense and settlement of a claim?
  • Does approving a de-identified sample shift risk to us?
  • What notice must we give, and how fast, if we learn of a problem?
FAQ

Questions about indemnities and warranties

What is an indemnity in a data licensing agreement?

A promise by one side to cover the other side’s losses from defined events, such as a third-party claim that data was shared without the required notice or consent. It often includes legal costs. Whether it is one-way or mutual, capped or uncapped, and how long it lasts are the points to negotiate.

Who is liable if de-identification fails?

The contract decides. Liability can sit with the seller through its warranties, with the buyer through its process obligations, or be shared. Ask who performs the de-identification, whether you approve the output, and whether the buyer indemnifies you if its process misses something.

Should liability in a data deal be capped?

Ask for a cap and know its size before you sign. The usual questions are whether the cap is tied to the fees you receive and which categories, if any, sit outside it. Without a cap, your exposure is not limited by the size of the deal.

What consent warranties might we be asked to give?

Sellers may be asked to confirm that employees, customers and clients were given whatever notice or consent the law and existing contracts require for this use. Ask whether these promises can be limited to what you know after reasonable checks, and keep written records of the notices you gave.

How long do warranties and indemnities last?

As long as the survival clause says. Some last for a set period after delivery or termination; others have no stated end. Because a data copy, and models trained on it, can outlast the contract, ask for a clear expiry and check which duties survive.

Does business insurance cover a data license indemnity?

It depends on your policies. Ask your insurance broker whether your cyber or professional liability cover responds to liability you take on by contract, and which exclusions apply. Ask the buyer what insurance it carries as well.

Does approving a de-identified sample make us responsible for what it contains?

It might, depending on the wording. Some contracts could treat seller approval as acceptance of the output. Ask your lawyer whether your review is a check for your own comfort or a sign-off that shifts risk to you, and get that written into the agreement.

What happens to our warranties if the company closes?

The contract still says what it says, but a closed company cannot easily stand behind it. A buyer may ask how claims would be met after closure. Ask your lawyer how survival periods, any holdback of the price and insurance would work in a wind-down.

Read the risk terms in a real draft

Indemnities and caps only appear at the agreement stage. Check your fit, apply, and have your lawyer read the risk clauses before anything is exported.

Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data.

Keep reading

Related contract and privacy guides