
Data Commercialisation and Licensing
IP, data protection and confidentiality for data assets
Data commercialisation involves three overlapping legal frameworks: intellectual property (copyright in content and database rights), data protection (where the dataset contains personal data), and confidentiality (protecting proprietary information and trade secrets). Telecoms operators, payment processors and technology businesses hold datasets with commercial value. A well-drafted data licence addresses all three layers. IP licensing establishes what the licensee can do with the content and the database as a whole. Data protection compliance under UK GDPR governs how personal data within the dataset is processed. Confidentiality provisions protect proprietary methodologies, algorithms and commercially sensitive information that the licence makes accessible. The licence has to carry all three, and a gap in any one of them is a gap in the whole arrangement.
Why data commercialisation matters now
Three regulatory shifts. First, the ICO has been active on data commercialisation, and its enforcement has been tested. The Commissioner issued an enforcement notice against Experian over the transparency of its marketing data processing. The First-tier Tribunal allowed Experian’s appeal in part and substituted a materially narrower notice (Experian Ltd v Information Commissioner [2023] UKFTT 132 (GRC)), and the Upper Tribunal dismissed the Commissioner’s appeal (Information Commissioner v Experian Ltd [2024] UKUT 105 (AAC)). The practical point is unchanged: a data licence is a processing arrangement, and both parties should be able to evidence lawful basis and transparency from the outset.
Second, payment transaction data is already constrained by the Payment Services Regulations 2017. Regulation 97 prohibits a payment service provider from accessing, processing or retaining personal data for the provision of payment services without the explicit consent of the payment service user, and regulation 70(3)(f) prevents an account information service provider from using, accessing or storing information for any purpose other than the account information service the user has explicitly requested. A long-term regulatory framework for commercial variable recurring payments has not yet been made; the FCA has said that, subject to the legislation expected to give it new powers, it would consult on a long-term regulatory framework by the end of 2026, and any further constraints would take effect only then.
Third, for telecoms operators, location data sits under PECR as well as the UK GDPR, and the PECR route is the narrower of the two. Regulation 14 permits location data other than traffic data to be processed only where the user or subscriber cannot be identified from it, or, where the processing is necessary to provide a value-added service, with that person’s consent. Consent obtained for an operator’s own value-added service does not reach a licensee’s use unless the licence agreement carries it through, and regulation 14(5) confines processing to the provider, the third party providing the value-added service and persons acting under their authority.
Common data commercialisation failures
Six recurring mistakes. First, treating data commercialisation as a single legal problem. Some clients draft a pure IP licence that ignores data protection. Others focus entirely on UK GDPR compliance and fail to address the IP rights in the dataset (copyright in the individual items, copyright in the database itself as a literary work under section 3(1)(d) of the Copyright, Designs and Patents Act 1988, which is original only where the selection or arrangement of its contents is the author’s own intellectual creation (section 3A(2)), and the sui generis database right under regulation 13 of the Copyright and Rights in Databases Regulations 1997). Both approaches leave gaps. The licence must establish the IP rights being granted, the data protection framework for any personal data, and confidentiality protections for proprietary information.
Second, conflating anonymisation with pseudonymisation. The test is the means reasonably likely to be used to enable identification, assessed against a motivated intruder and not against a purely hypothetical chance of identification (ICO anonymisation guidance, How do we ensure anonymisation is effective?). Data that does not clear that test remains personal data. We regularly see clients licence “anonymised” data that can be re-identified by cross-referencing with publicly available datasets.
Third, failing to conduct a DPIA before the licence is signed. Data commercialisation often triggers the DPIA threshold. Where Article 35 requires one, failing to carry it out is itself an infringement, and Article 83(4)(a) places it in the tier attracting fines of up to 8.7 million pounds or 2 per cent of total worldwide annual turnover, whichever is higher.
Fourth, relying on legitimate interests under Article 6(1)(f) without conducting the balancing test. A privacy notice saying “we will use your data to provide telecoms services” does not support selling the data to a third-party marketer.
Fifth, failing to address PECR for telecoms data. Regulation 14 permits location data other than traffic data to be processed only where the user or subscriber cannot be identified from it, or, where the processing is necessary to provide a value-added service, with that person’s consent given on the regulation 14(3) information. If an operator has collected location data for internal network management and wants to licence it to a mapping service, fresh consent is needed.
Sixth, audit rights over downstream use. A licensor that cannot see what the licensee and its sub-licensees do with the data cannot evidence its own compliance, so the licence carries information and audit rights over use, onward transfer and retention down the chain. Where the licensee acts as processor, Article 28(3)(h) of the UK GDPR requires the contract to oblige it to make available the information needed to demonstrate compliance with that Article and to allow for and contribute to audits conducted by the controller or an auditor the controller mandates. Where the parties jointly determine the purposes and means, Article 26 requires an arrangement setting out their respective responsibilities, and a transfer of the data outside the United Kingdom has to meet Article 44A. Two limits apply to what an auditor may see: the licensee’s confidentiality obligations to third parties, and, where licensor and licensee compete, section 2 of the Competition Act 1998, which catches the exchange of commercially sensitive information between competitors.
| Common issue | Better approach |
|---|---|
| Treating as a single legal problem | Addressing all three layers: IP, data protection and confidentiality |
| Confusing anonymisation with pseudonymisation | Honest anonymisation assessment with documented methodology |
| Skipping DPIAs for commercialisation activities | DPIA completed before any data sharing arrangement |
| Relying on legitimate interests without balancing test | Documented balancing test with evidence of data subject expectations |
| Ignoring PECR for telecoms location data | Fresh consent under PECR regulation 14, given on the regulation 14(3) information |
| No audit rights over downstream data use | Contractual audit rights with breach remedies |
The three layers a data licence must cover
On IP, a well-drafted agreement identifies the rights being licensed (copyright, database right, or both), the scope of the licence (territory, duration, exclusivity, permitted uses), and any restrictions on derivative works or onward licensing. On data protection, it establishes the lawful basis clearly, addresses anonymisation honestly, specifies controller/processor relationships with precision, addresses data subject rights, requires a DPIA where processing is high-risk, and addresses sector-specific restrictions for telecoms data (PECR), payment data (the Payment Services Regulations 2017) and technology platform data (AI training). On confidentiality, it protects proprietary methodologies, trade secrets and commercially sensitive information with appropriate restrictions, audit rights and remedies for breach.
Bratby Law helps clients structure data commercialisation deals that work across all three layers. We advise on IP rights identification and licensing structure, conduct lawful basis analysis under UK GDPR, review consent coverage, advise on DPIA requirements, and draft confidentiality provisions that protect proprietary information while enabling the commercial purpose of the licence.
How Bratby Law helps
We advise licensors and licensees on data commercialisation across telecoms, payments and technology sectors. We cover all three legal layers: IP licensing (identifying and structuring rights in content and databases, including sui generis database right), data protection (lawful basis analysis, consent review, DPIA requirements, controller/processor structuring), and confidentiality (protecting proprietary information, trade secrets and commercially sensitive methodologies). We advise on PECR restrictions for telecoms data and on the Payment Services Regulations 2017 for payment data.
Frequently asked questions
Can we licence customer data if we collected it for a different purpose?
Only if the new purpose is compatible with the purpose for which the data was collected. Since 5 February 2026 that test sits in Article 8A of the UK GDPR, inserted by section 71(5) of the Data (Use and Access) Act 2025, section 71(4) of which omitted the former Article 6(4); and Article 5(3) now states that processing is not lawful by virtue only of being compatible, so a lawful basis is needed in addition. A privacy notice saying “we collect data to provide telecoms services” is unlikely to support licensing to a marketing analytics firm. Where the data was collected on consent, Article 8A(4) narrows the routes further, and fresh consent is usually the only practical one.
Do we need a DPIA before we licence data?
A DPIA is required where a type of processing is likely to result in a high risk to the rights and freedoms of individuals, and Article 35(3) says one is required in particular for large-scale processing of special category data, for systematic and extensive automated evaluation on which decisions with legal or similarly significant effects are based, and for systematic monitoring of a publicly accessible area on a large scale. Data commercialisation often triggers the threshold. Commission a DPIA before signing a licence. If in doubt, err on the side of conducting one.
What is the difference between anonymisation and pseudonymisation?
Anonymisation means data cannot be attributed to a specific person. Pseudonymisation means identifiers have been removed but re-identification is possible with additional information. Pseudonymised data remains personal data under UK GDPR. If a data provider says the data is “anonymised”, ask for evidence of the methodology and re-identification testing.
Can we licence location data from a telecoms network?
Only with the consent of the user or subscriber for that use. Regulation 14 permits location data other than traffic data to be processed only where the user or subscriber cannot be identified from it, or, where the processing is necessary to provide a value-added service, with that person’s consent. Regulation 14(3) requires the provider, before obtaining that consent, to state the types of location data, the purposes and duration of the processing, and whether the data will be transmitted to a third party for the value-added service. Collection for internal network management does not extend to third-party licensing. Fresh consent is required.
What rights should a data licensor reserve?
The right to audit the licensee’s compliance; require deletion if the licensee breaches terms; restrict further processing or sub-licensing; and terminate if the licensee creates regulatory risk. If relying on legitimate interests, reserve the right to terminate if the balancing test changes.
What IP rights exist in a dataset?
Three potential rights. Copyright may subsist in the individual content items (text, images, code) and in the arrangement or selection of the dataset as a literary work. Database right under the Copyright and Rights in Databases Regulations 1997 protects databases where there has been substantial investment in obtaining, verifying or presenting the contents. Confidential information protection applies to proprietary methodologies, algorithms and trade secrets, enforceable through contractual confidentiality provisions. A well-drafted licence addresses all applicable rights and specifies the scope of grant for each.
How do we protect proprietary information in a data licence?
Confidentiality provisions in the licence should define what constitutes proprietary information, restrict use to the licensed purpose, impose obligations on the licensee’s employees and sub-contractors, require return or destruction on termination, and provide for injunctive relief in addition to damages. Where the dataset reveals proprietary methodologies or algorithms, consider whether the licence should restrict reverse engineering or decompilation.
Related transactions pages
See also our other transactions pages:
- Mergers and Acquisitions (M&A)
- Private equity
- SaaS and Cloud Services
- Subsea cables
- MVNOs and MVNEs
- Interconnection, peering and access agreements
- Network sharing and co-location agreements
- Digital Infrastructure Projects
- NSIA Clearances
Independent directory rankings
Our specialist expertise is recognised in major independent legal directories:
- Chambers & Partners: Rob Bratby is ranked as a Band 2 lawyer in the UK Guide 2026 in the “Telecommunications” category: Chambers
- The Legal 500: Rob Bratby is listed as a Leading Partner for Telecoms in London (TMT: IT and Telecoms). The Legal 500
- Lexology: Rob Bratby is recognised in the Lexology Index as a Global Elite Thought Leader for telecoms and media, and as a Thought Leader for data privacy and protection: Lexology



