- Canadian law doesn't generally treat raw data the way it treats physical property or even intellectual property like a copyright.
- What counts as "customer data" — the records you input, the outputs the software generates, aggregated or anonymized derivatives, or all of the above?
- Most SaaS vendors, especially larger platforms, offer a standard-form agreement that isn't built for negotiation.
Most Ontario businesses now run at least part of their operations on someone else's software: a CRM, an accounting platform, a booking tool, an e-commerce backend. All of that software collects data — customer records, transaction history, usage patterns — and stores it on the vendor's servers, not yours. When the relationship ends, or a dispute arises, the question of who actually owns that data can matter a great deal.
The uncomfortable answer is that "data ownership" isn't automatically resolved by common sense or by who typed the information in. It's resolved — or left unresolved — by whatever your contract with the software vendor actually says. A well-drafted data ownership clause in a SaaS or software agreement is one of the few ways a business can lock down its rights before there's ever a disagreement.
This article explains what these clauses generally cover, why the issue is more contract-driven than people expect, and what to look for before you sign a vendor's standard terms.
Data Isn't "Owned" the Way a Building Is
Canadian law doesn't generally treat raw data the way it treats physical property or even intellectual property like a copyright. There is no single, automatic "data ownership" right that attaches to a spreadsheet of customer names the way title attaches to a house. Instead, rights over data usually come from a mix of sources: contract terms, intellectual property in how the data is organized or presented, confidentiality obligations, and — where the data is about identifiable people — privacy law.
That means when a SaaS agreement is silent on data ownership, the practical answer to "who owns this" can be genuinely unclear, and unclear terms tend to favour whichever party wrote the contract — usually the vendor.
What a Data Ownership Clause Should Actually Cover
A useful clause does more than say "customer owns its data." It should address:
- Scope. What counts as "customer data" — the records you input, the outputs the software generates, aggregated or anonymized derivatives, or all of the above?
- The vendor's licence to use it. Vendors almost always need some licence to use your data to operate the service (processing, backups, support). The question is how far that licence extends — does it let the vendor use your data to train other products, benchmark against other customers, or sell aggregated insights?
- Export rights. Can you get your data out, in what format, and at what point in the relationship (during the term, on request, only at termination)?
- Retention and deletion. What happens to your data after the contract ends — is it deleted, and on what timeline, or does the vendor retain it in backups indefinitely?
- Sub-processors. Does the vendor use other companies (cloud hosting, analytics, support tools) that will also touch your data, and under what terms?
Vendor Templates vs. What a Customer Should Push For
Most SaaS vendors, especially larger platforms, offer a standard-form agreement that isn't built for negotiation. Smaller and mid-sized vendors are often more willing to adjust key terms, especially around data.
| Issue | Typical vendor default | Worth negotiating for |
|---|---|---|
| Ownership statement | Vague or silent | Explicit statement that customer data belongs to the customer |
| Use of your data for the vendor's own purposes | Broad licence, including product improvement | Narrowed to what's needed to provide the service |
| Export on exit | "Available on request," no format guarantee | Defined export format and a window to retrieve it |
| Data after termination | Deleted "in accordance with vendor's policy" | Specific deletion commitment, in writing |
Personal Information Is a Special Case
If the data in question includes information about identifiable individuals — your customers, employees, or website visitors — the analysis doesn't stop at the contract. Under Canada's federal Personal Information Protection and Electronic Documents Act (PIPEDA), which applies to Ontario businesses' commercial activity, an organization that collects personal information generally remains responsible for it even when a third-party vendor is the one storing or processing it. Handing data to a SaaS provider doesn't hand off your privacy obligations along with it.
In practice, this means your contract with the vendor should also address how the vendor will safeguard personal information, limit its own use of it, and cooperate if you receive a request from an individual to access or correct their information.
Red Flags in a Vendor's Standard Terms
- [ ] No mention of who owns customer-entered data at all
- [ ] A broad licence letting the vendor use your data for "any business purpose"
- [ ] No committed export format or window before deletion
- [ ] Sub-processors not disclosed or not restricted
- [ ] No obligation on the vendor regarding personal information it processes on your behalf
Frequently asked questions
If we stop paying, does the vendor keep our data forever?
It depends entirely on the contract. Some agreements let the vendor retain data indefinitely in backups; others commit to deletion within a defined period after termination. If the agreement is silent, ask the vendor directly and get the answer in writing before you rely on the platform for anything important.
Can a vendor use our data to train its own product features?
Many vendor agreements include a licence broad enough to allow this, particularly for aggregated or "anonymized" data. Whether that's acceptable depends on your business and your customers' expectations — it's worth reading this section closely rather than assuming it only covers routine service delivery.
Does it matter if the data includes our customers' personal information?
Yes. Beyond the ownership question, you generally remain responsible under Canadian privacy law for personal information you've collected, even while it sits on a vendor's servers. Your vendor contract should reflect that.
Is a verbal understanding with a vendor's sales rep enforceable?
Most business contracts don't need to be in writing to be enforceable, but proving what was actually promised becomes very difficult without documentation. Get any data-related commitment written into the agreement itself, not left as a sales conversation.
This is a corporate question
Start a file online — flat, published fees, reviewed by a licensed Ontario lawyer before a dollar is owed.