Data, AI + Privacy
Counsel for data, AI, and privacy transactions
Data and AI now sit at the center of how companies build products and create value. That raises new contract questions. Who owns the data and what can be done with it? Can it be used to train a model? Who is responsible when an AI output causes harm? How must personal data be protected?
Apex Legal negotiates the agreements that govern data, AI, and privacy in commercial relationships. We help companies secure the data rights they need, allocate AI-related risk, and meet their privacy and security obligations to customers and partners
What we handle
AI licensing and AI vendor agreements.
Licenses of AI models and tools, agreements with AI vendors, and allocation of risk for AI outputs.
Data licensing.
Licenses of datasets, including rights to use data for analytics and model training.
Data sharing agreements.
Data sharing and data use agreements between companies, institutions, and research partners.
Privacy terms.
Data processing agreements, privacy policies, and privacy provisions in customer and vendor contracts.
Security terms.
Security addenda, incident notification obligations, and security requirements in technology agreements.
Data and AI in transactions.
Review of data rights and AI usage in acquisitions, investments, and partnerships.
Who we work with
We represent software and AI companies, businesses adopting AI tools, life sciences and research organizations that share data, and investors evaluating data-driven companies.
Our approach
Market norms for AI and data agreements are still developing. We track how terms are evolving, focus on the rights and risks that matter most to your business, and draft agreements flexible enough to adapt as technology and expectations change.
Frequently Asked Questions
-
It depends on your contracts, your privacy commitments, and applicable law. Customer agreements and privacy policies may restrict how data can be used, and customers increasingly ask about AI training specifically. Reviewing these documents before using data for training, and updating them where appropriate, helps reduce risk.
-
Key issues include how the vendor may use your data and inputs, whether your data will be used to train the vendor’s models, ownership of outputs, confidentiality and security, accuracy disclaimers, indemnities for third-party claims, and what happens to your data when the relationship ends.
-
Ownership of AI output is still an evolving area. Contracts typically address it directly, often assigning output rights to the customer. However, the extent to which AI-generated content can be protected by copyright is unsettled. Clear contract terms remain the most reliable way to define each party’s rights.
-
A data processing agreement sets out how a service provider handles personal data on behalf of its customer, including security measures, use restrictions, and breach notification. Many privacy laws require one when a vendor processes personal data for a business, and enterprise customers often require one as a condition of doing business.
-
A data license typically grants one party rights to use another party’s data, often in exchange for payment. A data sharing agreement usually governs a mutual or research-driven exchange of data and focuses on permitted uses, protections, and responsibilities. Both should clearly define permitted uses, restrictions, and what happens to the data when the agreement ends.
-
Contracts should define what counts as a security incident, how quickly each party must provide notice, who is responsible for investigation and remediation, how costs are allocated, and how incidents interact with the limitation of liability. Clear terms help both parties respond quickly and reduce disputes.
Related industries:
Related practice areas:
Licensing data or adopting AI?
Contact us to discuss your agreements.