Data ownership and portability clauses in SaaS terms
Data ownership, use and portability clauses for a SaaS product's customer terms, drafted for a fixed fee of £995 in five working days.
Data ownership and portability clauses in SaaS terms
Data ownership, use and portability clauses for SaaS terms, drafted for how a product uses its customers' data, covering ownership of customer data, the licence the supplier needs, aggregated and derived data, use of data for improvement and model training, export formats and portability, retention and deletion at the end, and the processor terms the clauses sit with. £995, delivered in five working days.
Buy now, £995Customers ask who owns the data in a SaaS product, and the honest answer is that ownership is the wrong frame: data is not property in English law, and what matters is who may do what with it, for how long, and what the customer can take away when it leaves. The clauses have to say that customer data is the customer's, grant the supplier the licence it needs to run the service and no more, deal with aggregated and derived data and with training, give the customer a usable export, and set the retention and deletion that end the relationship. I draft those clauses, within a set of SaaS terms or as a replacement for the ones in yours, for a fixed fee of £995, delivered in five working days.
Who this is for
SaaS businesses in England and Wales whose customers, particularly enterprise and public sector customers, ask what happens to their data, and who need clauses that answer the question in a way procurement teams accept and the product can honour.
What matters in data ownership and portability clauses
Customer data is the customer's, and what that means
The clauses should define customer data as the data the customer and its users upload or generate through their use of the service, state that as between the parties the customer owns all rights in it, including any database right under the Copyright and Rights in Databases Regulations 1997, and that the supplier acquires no rights except the licence the terms grant. Personal data within it is governed by the UK GDPR regardless, and the ownership statement does not change who is controller and who is processor.
The licence the supplier needs
The supplier should take a licence to host, copy, process, transmit and display customer data solely to provide the service, support the customer, and comply with law, for the term and the deletion period, with the customer warranting that it has the rights to grant it and that the data is lawful. A licence 'for the supplier's business purposes' is the clause enterprise customers strike out, and the clauses should not contain it.
Aggregated data, derived data and improvement
The supplier usually wants to use usage data and aggregated, de-identified data to operate and improve the service, and the clauses should say so plainly, define what is aggregated (not identifying the customer or any person, not reversible), and say that the supplier owns the aggregated data and the improvements. Where personal data is involved, using it for the supplier's own purposes takes the supplier outside its role as processor under Article 28 of the UK GDPR unless the terms and the privacy notice establish the basis, and anonymisation has to be real.
Training models on customer data
A clause that lets the supplier train machine learning models on customer data is a commercial decision the clauses should make expressly, in one direction or the other: no training on customer data without the customer's written consent, or training on aggregated and de-identified data only, or training with an opt-out. Silence is read against the supplier. Where content is involved, the customer's copyright under the Copyright, Designs and Patents Act 1988 and any third-party rights in what the customer uploaded are the limits.
Export, portability and the format
The customer should be able to export its data at any time during the term through the product or on request, in a stated, commonly used format, and for a stated period after termination, with the supplier's assistance available at its rates. Individuals also have a right to receive their own data in a portable format from the controller under Article 20 of the UK GDPR, which the customer as controller may need the supplier's help to meet, and the processor terms should provide it.
Retention, deletion and the end of the relationship
The clauses should say how long data is retained after termination, that it is deleted or returned at the customer's election within that period and deleted thereafter, that backups are overwritten in the ordinary cycle, that deletion is certified on request, and that the supplier may retain what the law requires. Confidentiality survives deletion. Where the customer becomes insolvent, the supplier's continuing obligations to provide the service and hold the data are affected by section 233B of the Insolvency Act 1986, and the clauses should not assume the supplier can simply stop.
What it costs
SaaS terms of service, £995. Your standard customer-facing terms. Five working days.
Buying online forms the engagement on payment. The scope is what the saas and technology contracts page describes, you accept the Terms of Service at checkout, and I email you within four working hours to get started. If you would rather ask something first, email me.
What you get
- A bespoke contract drafted for how your product is sold, delivered and supported
- Service levels you can meet, with remedies that are proportionate rather than aspirational
- A liability position that is defensible and will survive enterprise procurement
- IP and data provisions that fit together rather than contradicting each other
- A commercial note on where you will get pushback and what is worth conceding
- One round of amendments
What is not included
- Negotiating individual enterprise deals, which I quote separately
- Advice on the law of jurisdictions outside England and Wales
- Technical security certification or audit
- Regulatory advice for regulated sectors such as financial services or health
Questions I am often asked
A customer wants us to confirm we will never use their data for anything. Can we agree?
You can agree not to use it for anything other than providing the service, which is what the licence says. Usage and aggregated data for improvement is a separate, defined category, and most customers accept it once it is defined.
Can we train our AI features on customer data?
Only if the terms say so, and enterprise customers will read the clause. The choice is no training, aggregated data only, or opt-out; the clauses draft the one you choose and the privacy notice matches.
How long do we have to keep a former customer's data?
As long as the terms say, and no longer. A stated export period after termination followed by deletion is what procurement expects; the clauses set the period and the certification.
Related guidance and services
- SaaS and technology contracts, £995, the service this page describes
- Data protection agreements and privacy terms, £795
- Contract review, £495
- Reviewing a data licence agreement
- SaaS terms of service for a B2B product
This page is general guidance for businesses in England and Wales, not advice on your own circumstances. Last reviewed: September 2026. Email geoffrey@caesar.co.uk.