Draft for Tamir's review. Not published.
Separate the service from the data rights
Service guarantees and data rights can be negotiated separately. Ask for the data clauses in plain language: who owns what, and who may use it for what. Keep raw, derived and aggregated data yours, and license the vendor only what the service needs.
Get API access included at a documented rate, so you aren't paying to read your own data. Require a full history export in an open format at exit. Check whether the vendor uses your data for benchmarking across its other customers.
Treat free offers and exclusivity as a price
A company that builds a system for free, or runs a free pilot, is paid in data, position and dependence. Treat it as a procurement. Define what data it may access, for what purpose and for how long, and what you receive in return.
Exclusive reuse rights can outlast the funding that bought them. Ask your research, service and planning owners which future options the exclusivity would close. Check whether the partner's promised value really needs rights that broad.
Depending on your seat
If you're on the board, approve data products one by one rather than as a revenue line. For each, ask what data, at what level of aggregation, under what legal basis, to whom and for which uses. Ask what the contract does to your position at renewal.
If you're the CEO or run IT, get privacy and legal positions in writing before any data moves. Have someone on your side review the anonymization method. Make sure future work still goes through normal procurement.
What to check before you decide
- Mark every clause that assigns data rights to the other party, and ask for raw, derived and aggregated data to stay yours.
- Limit the other party's use to the service, with a defined purpose, duration and no onward use.
- Require return or deletion at exit, and a full history export in an open format.
- Get privacy and legal positions in writing on what may be shared and under which approval.
- Have someone on your side review the anonymization method before any transfer.
- Ask which future uses, suppliers or partnerships the terms would restrict, including at renewal.
- For a free offer, put a market value on the system and define what you receive for your data.
Questions people ask
Long term equipment service contract gives the maker our operating data, what should the board require?
Require that the plant owns its operating data and licenses the maker what the service needs, that the data is returned and the access ends at exit, and that the maker's remote access is controlled. Service guarantees and data rights can be separated. It depends on how much of the plant runs on this maker's equipment and on what the plant plans to do with the data.
Board approving a telehealth platform contract priced per member with the vendor holding consultation data, what should we require?
Require that the fund owns the consultation data and the vendor processes it only for the service, that pricing has caps and tiers at the fund's growth, that clinical records flow into the fund's systems, and that exit returns the data and transitions members. It depends on the fund's privacy obligations and on how the platform connects to clinical records.
Management wants to sell our mobility data to third parties, what should the board require before approving?
Require clarity on what data, at what level of aggregation, under what legal basis, to whom and for what uses, with the authority's position and a privacy assessment. Aggregated data for planning is a different matter from individual movement data. It depends on your privacy rules, the authority's contract terms on data and the buyers' intended uses.
Should we grant exclusive reuse rights over hospital-generated information?
Assess the future options being exchanged separately from the platform funding. Approval depends on permitted use, exclusivity scope, public responsibilities, and legal and ethical review by appropriate owners.
A company offers to build our public system for free in exchange for data access, what are the risks and what terms would make it acceptable?
Treat it as a procurement, because it is one: the agency pays with data, position and dependence. Acceptable only if the agency owns the system and data, the company's data use is limited and lawful, and future work goes through normal procurement. It depends on your procurement and data protection rules and on what the data could be used for.
A startup offers a free AI triage pilot in return for anonymised member data, should we sign and on what terms?
Treat the data as the payment and price it accordingly: limited scope, defined purpose, verified anonymisation, no onward use, deletion at the end, and rights for the fund to the results. A free pilot with open-ended data use is an expensive one. It depends on your privacy rules for secondary use and on whether the anonymisation is real.
Signing a renewable asset monitoring platform contract, what data ownership and API terms should I insist on?
Keep ownership of raw and derived plant data, get API access included rather than priced per call, and secure a full history export at exit. Vendors agree to these more often than their first draft suggests. It depends on how many plants you run and on which other systems need the data.
How I can help with this decision
- Ask or talk (Free)
- I give my view on which data terms in your deal usually cost you later, and which ones the other party usually accepts.
- Review (Pay if it was worth it)
- I write an independent review of the deal's data, access, pricing and exit terms against your obligations and plans. I recommend to approve, set conditions, restructure or decline.