New Data Protection Terms

Image reads "This week's musings on tech contracts". New Data Protection Terms. Tech Contracts Academy.

I’ve repeatedly warned that you can’t really own data, since no form of IP offers ownership of information. (Trade secret law comes close but still doesn’t fit the bill.) In my book and our trainings, I’ve suggested that customers claim ownership of “their data” anyway, in AI, SaaS, and other cloud contracts – but recognize that they’ve achieved little or nothing.[1] To fill in the gap left by ownership terms, I’ve recommended terms on control of customer data, restricting what the vendor can do with it. That remains my recommendation, but lately I’ve worried that “copyright preemption” might interfere with those terms. So I’ve drafted a clause meant to reduce the risk:

Why you don’t own your data and why you should claim it anyway

I’ve explained this elsewhere, but in short, data is information, and you can’t patent or copyright information. Patent covers inventions, not information. And copyright covers works of authorship that you’ve written, recorded, etc., and you didn’t write your data. And copyright protects expression – words, code, images, etc. – not the underlying information. You might have a “compilation copyright” (and you might not), but even that won’t keep you vendor from mining your data, violating privacy protections, etc.

You probably do have trade secrets within your data, but most likely the majority of the dataset doesn’t qualify. It’s of little or no competitive value. So trade secrets could protect a few nuggets or a lot but probably not all customer data. (There are exceptions: full datasets that could qualify for trade secret protection.)

Still, it’s worth claiming those trade secrets and that possible compilation copyright. And your data could include documents, photos, or other content that does enjoy normal copyright protection (not to mention trademark protection). So claim the IP. We’ve got language for you in The Tech Contracts Handbook, Subchapter II.J.1, and in our site’s clause library (A(1) through A(4) at the link). Then, recognize that you haven’t achieved much vis-à-vis the non-copyrightable parts of the data – and move on to data control.

Data control

Data control terms will probably do a better job than ownership at protecting your data. The data control section says the vendor won’t mine your data, share it with third parties, or make much use of it at all other than to provide the technology: the SaaS, AI, etc. Data control terms also govern security, restrict server location, regulate e-discovery, and generally cover the privacy-focused requirements found in data protection addendums (DPAs – GDPR stuff, state privacy law terms, etc.).

We provide data control terms too, in The Tech Contracts Handbook too – Chapter II.J – and in our clause library (part II-J).

Data control terms, however, might raise a concern related to copyright law.

Copyright preemption problem?

Copyright preemption comes from U.S. federal law, though other nations have similar rules. Broadly speaking, neither state law nor a contract can create rights substantially similar to those of the copyright statute. You can’t use a contract to create a “private version of copyright,” protecting a work that otherwise doesn’t beneift from copyright. Without getting into the details, copyright preemption casts a shadow on any contract term saying a party won’t copy the other’s text, image, code, or other content, if that content lacks copyright protection. A clause like that could be unenforceable.

A recent paper by Mark Lemley and Peter Henderson suggests copyright preemption invalidates the contract terms AI vendors use to protect weights, outputs, and other assets that (probably) have no copyright protection.[2] Those terms try to block competition in the same way as copyright. (More on AI terms and copyright preemption in a future article.) The article got me thinking about control terms too. In control clauses, are we trying to create restrictions similar to those of copyright, leading to preemption?

Control terms should still work, but …

I think the answer is “no.” As that same Lemley/Henderson paper points out, copyright preemption generally does not block terms meant to protect privacy or trade secrets.[3] Those terms don’t chase copyright’s goal of ensuring no one copies your work to compete with you. Rather, privacy terms protect third party consumers’ rights, and trade secret terms focus on use of information, rather than copying of text or other expression.

Also, much data control addresses data mining, not reproduction or distribution of data or the other exclusive rights of copyright holders. So data control terms regulate data in a way copyright doesn’t.

Copyright preemption, then, should not interfere with data control terms. But let’s make sure. The sample clause following the first paragraph above essentially says the contract’s data control terms are not meant to create a private version of copyright. Rather, those control terms protect privacy: a goal not served by copyright. And the control terms protect consumers and other third parties, not just the customer’s competitive position, unlike copyright. Finally, the sample clause says the data control terms protect the customer’s trade secrets and other sensitive information. That does involve a restriction on competition, like copyright, but one focused on restricting information – secrecy – rather than reproduction of text or other expression.

A court could disregard the clause above and analyze copyright preemption without it. But maybe not. The clause could and should guide a court about the purpose of data control terms. Plus, the clause arguably does more than offer a self-serving explanation of other terms. It could be interpreted as a waiver by the customer of any competition-focused restriction on copying data – or at least the parts of data that have no copyright protection. And that should increase the odds of enforcement.

Of course, if you’re actually trying to use data control terms to create your own version of copyright, the clause might not work and could be counter-productive. But that’s not the goal for most data control terms.

Interested in learning more? Please consider our trainings, including The Tech Contracts Master Class™, Data Terms in AI and Cloud Services Contracts, and more.


THIS ARTICLE IS NOT LEGAL ADVICE. IT IS GENERAL IN NATURE AND MAY NOT BE SUFFICIENT FOR A SPECIFIC CONTRACTUAL, TECHNOLOGICAL, OR LEGAL PROBLEM OR DISPUTE, AND IT IS NOT PROVIDED WITH ANY GUARANTEE, WARRANTY, OR REPRESENTATION. LEGAL SITUATIONS VARY, SO BEFORE ACTING ON ANY SUGGESTION IN THIS ARTICLE, YOU SHOULD CONSULT A QUALIFIED ATTORNEY REGARDING YOUR SPECIFIC MATTER OR NEED.

[Updated Feb. 02, 2026]

© 2025, 2026 Tech Contracts Academy, LLC


1. See, Tollen, The Tech Contracts Handbook, Subchapter II.J.1; Tech Contracts Academy® (TCA), The Tech Contracts Master Class™, course 2; TCA, Data Terms in AI and Cloud Services Contracts, Lesson 2.

2. Lemley, Mark A. and Henderson, Peter, “The Mirage of Artificial Intelligence Terms of Use Restrictions” (December 09, 2024), Princeton University Program in Law & Public Affairs Research Paper No. 2025-04.

3. Id., pp. 1367, 1370, 1381.

Related Posts

Enter your information and connect with us to learn about training for contract managers, procurement professionals, and lawyers.