← Back to AI Legal Lab
Insight
Contract ReviewGenerative AI for Legal WorkLegal Outsourcing

How to Draft a Data Provision Agreement: Scope of Use, AI Training, and Treatment on Termination

Hello, I'm Noriaki Asato, Representative Attorney at LegalAgent.

A company provides its sales records to a business partner for use in demand forecasting. Another hands its equipment operation logs to an analytics firm to look for signs of failure. In transactions like these, the recipient may process the data and create analysis results or AI models. Whether those outputs may also be used for other customers, or may continue to be used after the contract ends, is sometimes not settled by the initial explanation alone.

Even if a contract states that "ownership of the data belongs to the provider," whether each particular use is permitted still needs to be confirmed. The information to be provided, the uses permitted and the treatment of outputs must be set out concretely. In this article, with a focus on transactions in which a company provides data it already holds to a counterparty, I explain the points to check when drafting the contract.

Protection of Data and the Terms of Use Set by Contract

Scope of Use Is Not Settled by the Word "Ownership" Alone

Ownership as provided in Articles 85 and 206 of the Civil Code (Japanese) is a right whose object is a tangible thing. A storage medium and the information stored on it are separate, and it is not understood that ownership of a thing automatically arises in electronic data itself.

The word "ownership" in a contract may nonetheless be recognized as meaning an agreement on terms of use. What the parties promised by that word is interpreted from the contract as a whole and the course of the transaction. However, it is unclear whether that one sentence alone amounts to agreement on copying, provision to third parties, processing and use after termination. To reduce the extent left to interpretation after a dispute arises, I think it is important to set out separately in the clauses which acts are permitted and which are prohibited.

In addition, contractual restrictions on use are basically promises between the contracting parties. A claim against a third party that obtained data leaked without authorization requires a basis other than the contract. You therefore check both the contractual management obligations and the requirements for protection under statute.

Checking Trade Secrets, Shared Data with Limited Access, and Copyright

Article 2, paragraphs 6 and 7 of the Unfair Competition Prevention Act (Japanese) define trade secrets and shared data with limited access. A trade secret must be managed as a secret, be useful for business activities and not be publicly known. Even when information is disclosed to a business partner subject to a confidentiality obligation, it is protected as a trade secret if the requirements are met. Issues include indicating to the counterparty that the information is confidential, access restrictions and control of re-disclosure.

Shared data with limited access is technical or business information, other than trade secrets, that is provided to specific persons as a business and is accumulated and managed in substantial quantity by electromagnetic means. For databases and similar resources that only certain users can access, whether they qualify is examined based on how they are actually provided and managed. Because the current provision excludes trade secrets, classification is made based on whether the data is provided outside the company as well as on the state of secrecy management and similar factors.

Both forms of protection are against wrongful acquisition, use, disclosure and similar acts as specified by statute. The requirements differ depending on the type of data, the state of management and the nature of the conduct, and a breach of contract does not necessarily also constitute unfair competition.

Furthermore, Article 12-2 of the Copyright Act (Japanese) protects as works databases that involve creativity in the selection or systematic construction of information. Rights in individual figures and facts, in the structure of the database, and in the text and images it contains each need to be checked. The mere fact that the provider manages a database does not necessarily mean it can grant free use of third-party works contained in it.

Five Items to Check in a Data Provision Agreement

1. The Data Provided and the Purpose and Scope of Use

First, identify the data covered by the contract. If the items, period covered, number of records, update frequency, file format and method of provision are set out in an appendix or similar document, both parties can confirm what the contract entitles the recipient to receive. For ongoing provision, also decide when specification changes will be notified and the procedure for discontinuing items.

Make the purpose of use concrete enough that the actual work is clear. For example, if the purpose is store-level demand forecasting, confirm the products covered, the stores covered, the departments that will use the data and the parties to whom forecast results will be provided. A statement such as "for the recipient's own business" may lead to a dispute over whether it includes use in a different business the provider did not anticipate.

In particular, inputting data into an AI system for analysis and using it for additional training of an AI model need to be treated as different uses. State expressly whether only the creation of a model dedicated to the recipient is permitted, or whether improving a model that is also provided to other customers is permitted. Where data is input into an external generative AI service, also check that service provider's conditions on storage and use for training.

2. Treatment of Processed Data, Analysis Results and AI Models

If all post-processing information is defined collectively as "deliverables," a file that merely rearranges the original data, statistical values, analysis reports and trained models all become subject to the same clause. I think it is easier for both sides to align their understanding if items of different nature are given separate definitions and their treatment is decided accordingly.

For each output, set out who holds it, whether it is delivered to the counterparty, who may use it and for what purpose, and whether it may be provided to third parties. In addition to ownership and licensing where copyright or other rights arise, contractual terms of use are also needed for statistical values and similar outputs in which rights do not necessarily arise.

For example, even where external provision of aggregated results is permitted, if the aggregation covers only a small number of subjects, the performance of the original stores or business partners may be inferable. Consider the unit of aggregation, the scope of the prohibition on reconstructing the original data, and the review procedure before publication. It is important not to conclude, on the strength of a single sentence such as "anonymized outputs may be used freely," that issues concerning personal information or business confidentiality have been resolved.

3. Provision to Third Parties, Subcontracting and Security Management

The risks borne by the provider differ between an analytics firm using a cloud provider or subcontractor and an analytics firm selling the data to another customer. Check that a clause intended to permit the former does not also permit the latter.

Where subcontracting is permitted, set out whether prior consent or notice is required, the obligations imposed on the subcontractor, supervision by the recipient and the point of contact in the event of an incident. Where data will be stored or accessed abroad, also identify the countries or regions and the services used. For security management, make access rights, authentication, encryption, log retention and the like concrete according to the confidentiality of the data and how it is operated.

You also need a deadline for the initial report in the event of a leak or similar incident, cooperation in investigation, prevention of further spread, and allocation of responsibility for external explanations. Where audit rights are established, do not limit them to on-site inspections; decide on workable methods, including presentation of reports or third-party certifications.

4. Authority to Provide, Quality and Allocation of Responsibility

On the provider's side, confirm whether the promised uses can be permitted in light of contracts with third parties, confidentiality obligations, copyright, the Act on the Protection of Personal Information (APPI) and so on. On the recipient's side, consider to what extent the provider should warrant the results of that confirmation, and who will investigate and respond if a claim concerning rights is made.

As to quality, distinguish accuracy, completeness and currency. Gaps in past logs and failure to deliver data that was promised to be updated daily call for different responses. Decide whether the data is provided after disclosing known gaps, whether it will be repaired and re-provided in the event of defects, and whether fees will be adjusted if updates stop.

Whether the provider also warrants the accuracy of analysis results is a separate issue. Separate the quality of the input data from results attributable to the analysis methods or decisions on use, and negotiate the scope and cap of damages and exceptions to limitation of liability. Even where a full disclaimer is adopted, confirm, in light of what the counterparty will use the data for, that the content is consistent with the obligations being undertaken.

5. Cessation of Use, Return and Deletion on Termination

In the termination clause, treat original data, copies, processed data, analysis results and AI models separately. If use of agreed statistical results or models is permitted even after the original data is deleted, state the conditions and the survival period expressly. Conversely, if use after termination is not permitted, set out what is subject to cessation of use and how compliance will be confirmed.

Backups and records that must be retained by law cannot necessarily all be deleted immediately. One approach is to limit the purpose of retention, prohibit use in ordinary business, and then set the retention period and the time of deletion. For certificates of deletion as well, the scope covered by the certificate and the confirmation procedure need to be aligned.

Whether information used for AI training can be individually removed from a trained model requires technical confirmation. Do not assume that deleting the original files also eliminates the effect on training; consider prohibiting or restricting, at the stage before provision, uses that would be difficult to address on termination.

Additional Checks Where Personal Data Is Included

Where the data includes personal data, confirm its treatment under the APPI separately from the name used in the contract. The Personal Information Protection Commission's General Rules Guidelines (Japanese) explain the requirements for provision to third parties, entrustment, joint use and so on.

Where handling is entrusted within the scope necessary to achieve the purpose of use, the recipient may not be regarded as a third party under Article 27, paragraph 5, item 1 of the Act. However, the explanation that it is an entrustment does not by itself permit the entrusted party to use the data for its own separate business. Q7-41 of the Commission's Q&A (Japanese) addresses cases where the entrusted party matches, person by person, entrusted personal data with personal data it obtained independently. Where use beyond the purpose or such combination is planned, the arrangement for provision needs to be considered from the outset.

For joint use, the items to be checked include the fact of joint use, the data items, the scope of joint users, the purpose of use and matters concerning the person responsible for management. Requirements such as notifying the individuals of these matters in advance or putting them in a state where the individuals can easily know them must be satisfied. For provision to a third party located in a foreign country, also check the application of Article 28 of the Act.

In addition, even where the final output is statistical information that cannot identify individuals, the lawfulness of the stages at which the original personal data is obtained, used and provided must be confirmed separately. Even where names are deleted, check whether individuals can be identified from the remaining information or by matching it with other information. For checking the related clauses, please also see Checkpoints for Personal Information Handling Clauses.

Note that the 2026 amendment to the Act on the Protection of Personal Information (Japanese) establishes special provisions for certain purposes such as preparing statistics, and on October 1 the Commission published its approach to developing the related Cabinet Order and Rules. The practical measures described in this article assume the current treatment. For a contract that relies on the new special provisions, it is necessary to confirm the processing covered, the effective date and the conditions under the finalized Rules.

The Actual Data Flow to Confirm Before Signing

In reviewing the contract, it is helpful to confirm the flow from the source of the data to the recipient, external services, subcontractors and users of the outputs in a simple diagram or list. For each stage, note the type of data, the purpose of processing, the storage location, the retention period and the person in charge.

For example, even if you believe you have requested only demand forecasting, if the analytics firm's design involves ongoing use of the data to improve a general-purpose model, agreement on that use is also required under the contract. On the other hand, uniformly prohibiting even the aggregated results you already plan to share would make it impossible to achieve the purpose of the transaction. In my view, the starting point of a data provision agreement is to confirm the actual processing with the business and technical departments and to reflect it in the license, the prohibited acts and the termination clause.

Related articles

Articles connected to this topic.

Insight / 2026.10.03 Internal Use and Copyright: What to Check When Sharing Articles, Preparing Training Materials, and Using AI Summaries Insight / 2026.08.02 Searching Internal Documents with RAG: How Copyright Risk Changes with the Type of Material Insight / 2026.07.30 Designing AI Agent Authority: What to Decide Before Entrusting Orders and Messages to AI

Services connected to this topic

Legal outsourcing Ongoing legal team support for contract review and legal operations. Generative AI legal consulting Terms, privacy, copyright, AI governance, and internal AI use rules.
View AI Legal Lab articles