PONOPT FIELD NOTES · Закупки и vendor management

Data-Processing Terms Every AI Vendor Contract Should Address

AI vendor contracts need clear clauses on training-data bans, retention, subprocessors, residency, incidents, audit rights, and model provenance under GDPR and the EU AI Act.

Before you sign, the contract must settle who may process customer data, for what purpose, where it is stored, how long it is kept, and whether the vendor may train models on it. Under GDPR Article 28 the data-processing agreement must state the subject matter, purpose, duration, and data categories. EU AI Act Articles 10 and 53 add expectations on dataset quality, provenance, and documentation. This clause guide walks through each term you should demand, with practical trade-offs.

Key takeaways

  • Map roles and jurisdiction first: GDPR controller/processor roles plus EU AI Act provider/deployer labels determine which clauses become mandatory.
  • Explicitly prohibit or tightly cap the vendor's use of your prompts, outputs, and customer data to train, fine-tune, or improve models unless you consent in writing.
  • Replace vague deletion promises with defined retention periods per data category and certified deletion or return within fixed days of termination.
  • Secure advance notice, approval, and objection rights over subprocessors, plus written data-location and cross-border transfer rules with lawful safeguards.
  • Demand compressed incident-notification windows (roughly 24–72 hours), forensic cooperation, genuine audit rights, and assistance with data-subject requests.
  • Verify the provenance and quality of training data and require change control over model updates, as EU AI Act Articles 10 and 53 anticipate.

Fix the roles and governing law first

Negotiating clauses before you know who plays which role produces a weak contract. On the EU side, GDPR distinguishes the controller, who decides the purposes and means of processing, from the processor, who acts on the controller's documented instructions. The EU AI Act adds a separate axis: the provider places the system on the market, while the deployer uses it under its own authority. Your jurisdiction and the legal regimes that attach to your data decide which of these labels apply and which clauses are therefore mandatory.

Article 28 GDPR requires that a processor be engaged by a contract that sets out the subject matter, duration, nature and purpose of the processing, the types of personal data, the categories of data subjects, and the controller's obligations and rights. The same clause-boundary thinking applies under other privacy laws, such as Russia's 152-FZ, which similarly expects a written processing mandate between the operator and any external processor that touches personal data.

A useful discipline is to build a data-flow map before drafting: for each stream (prompts, outputs, logs, metadata, training sets) record whose data it is, the purpose, the controller and processor, the physical location, and the applicable regime. This article is general guidance, not legal advice; requirements vary by sector and by the countries where you and your vendor operate.

NIST's AI Risk Management Framework reinforces the governance view: supply-chain risk is only enforceable if the contract is the enforcement mechanism, so treat the agreement as a governance document rather than a routine procurement formality.

  • Separate GDPR controller/processor roles from EU AI Act provider/deployer labels
  • Identify every applicable privacy and AI regime before drafting terms
  • Build a data-flow map so each clause maps to a real processing stream

Training-data restrictions and service-improvement rights

The single most consequential data clause is what the vendor may do with your information. Standard terms often grant the vendor broad rights to use customer data to improve or enhance the service, and generative-AI vendors increasingly seek express rights to train, fine-tune, and improve models on customer inputs and outputs.

If those rights are unchecked, proprietary data can be absorbed into models that serve competitors or that commingle multiple customers' data. Once absorbed, the data is practically impossible to retrieve, segregate, or remediate. The contract should therefore state plainly that the vendor may not use customer data, prompts, or outputs for training, retraining, or model improvement without the customer's explicit, informed consent.

A workable compromise distinguishes processing that is technically necessary to deliver the service from processing for other purposes. Allow the former, forbid the latter. If the vendor asks for a right to train on anonymized data, test that the anonymization is irreversible; otherwise the information remains personal data and carries the same obligations.

  • Prohibit training, fine-tuning, and model improvement on your data absent written consent
  • Permit only processing technically necessary to deliver the service
  • Treat 'anonymized' training data as personal data unless anonymization is proven irreversible

Retention, return, and deletion on exit

Vague commitments to delete data 'in due course' or 'within a reasonable period' are weak and hard to enforce. Specify retention periods for each category of customer data — prompts, outputs, inference logs, metadata, and any training sets your data helped create — and state what happens at the end of the relationship.

Article 28 GDPR sets the benchmark: on the controller's choice, the processor must delete or return all personal data after the services end and delete existing copies, unless Union or Member State law requires storage. Your contract should mirror this: at termination the vendor returns your data or certifies deletion, destroys copies within a fixed number of days, and keeps only what the law expressly requires. Ask for a written certification you can retain as evidence.

  • Define retention periods per data category, not one vague global promise
  • Give the customer the choice between return and deletion at termination
  • Require written certification of deletion within a fixed number of days

Subprocessors, data residency, and cross-border transfers

AI vendors routinely engage subprocessors for cloud hosting, model inference, and data annotation. The contract should require advance disclosure of all subprocessors, give you approval and objection rights over new appointments, and mandate that equivalent data-protection obligations flow down to each one. Under Article 28, a processor may not engage another processor without prior specific or general written authorization from the controller, and must inform the controller of any intended changes.

Data location deserves explicit text, not blog assurances. If storage and processing must stay within approved regions, say so, and address access by vendor staff. For cross-border transfers, require a lawful mechanism — standard contractual clauses or an adequacy decision under GDPR, or the relevant consent and notice steps where other laws such as Russia's 152-FZ govern transborder flows of personal data.

Also read the difference between consumer and enterprise tiers carefully. In enterprise API agreements customer data is often excluded from model training, but that guarantee lives in the contract text, not in a sales pitch or a general policy page. Verify it clause by clause.

  • Advance disclosure, approval, and objection rights over all subprocessors
  • Written residency rules for storage, processing, and vendor staff access
  • A lawful transfer mechanism for every cross-border flow of personal data

Security incidents, audit rights, and data-subject support

A breach in the vendor's environment is your breach to explain to customers and regulators. The agreement should require notification within a compressed window after discovery — roughly 24 to 72 hours as a working benchmark — along with preservation of forensic evidence, cooperation in investigation and remediation, and assistance with any regulator notification you must make.

Secure genuine audit rights: the ability to conduct or commission an independent assessment of the vendor's data-handling practices, security posture, and compliance with contractual and regulatory requirements. Where GDPR applies, the processor must make available the information needed to demonstrate compliance and allow for audits and inspections. The contract should also require the vendor to assist you in responding to data-subject requests — access, rectification, erasure, and portability — because those duties remain yours as controller.

Governance does not stop at the contract. Internal policies and employee training matter because users may paste sensitive data into public chat tools that retain and reuse it. Where AI outputs drive consequential decisions such as hiring, lending, or underwriting, add requirements for model explainability and human-in-the-loop oversight.

  • Compressed incident-notification window with forensic preservation and regulator assistance
  • Real audit rights, including independent third-party assessment
  • Vendor assistance with data-subject requests and explainability for consequential decisions

Dataset provenance, quality, and model change control

The more consequential the decisions your AI supports, the more the provenance and quality of the underlying data matter. For high-risk systems, Article 10 of the EU AI Act requires that training, validation, and testing datasets be relevant, sufficiently representative, and as free of errors and complete as possible, and that governance practices cover data collection, origin, preparation, bias examination, and gap identification.

For general-purpose AI models, Article 53 obliges providers to keep up-to-date technical documentation of the training and testing process and to make publicly available a summary of the content used for training. Translate these expectations into contract language: the vendor should warrant the lawful provenance of its training data, document sources and preparation steps, and disclose model capabilities and limitations.

Add change control. A provider should not silently swap in a new model version that alters behavior, data flows, or quality. Require advance notice of model updates and a mechanism for you to approve the change or re-evaluate the relationship. Also decide ownership of outputs and any vendor indemnity for claims that training data or outputs infringe third-party rights, and carve these critical risks out of broad liability caps where possible.

  • Vendor warranty on lawful provenance and documented sources of training data
  • Disclosure of model capabilities, limitations, and preparation steps
  • Notice and approval rights before any model update or provider change

AI Vendor Data-Processing Checklist: Twelve Clauses to Verify Before Signing

Use this checklist at signature and again at renewal. Mark an item as complete only when the exact contract text satisfies it — not when a brochure, product page, or sales call promises it.

  1. Roles and law mapped: you confirm controller/processor status (and provider/deployer roles where the EU AI Act applies), and list the governing privacy and AI regimes.
  2. Purpose and scope stated: the DPA sets out the subject matter, purpose, duration, types of data, and categories of data subjects as Article 28 GDPR requires.
  3. Training restriction in writing: an express ban or cap on using prompts, outputs, and customer data for training, fine-tuning, or improvement without written consent.
  4. Retention defined per category: separate periods for prompts, outputs, inference logs, and metadata.
  5. Return and deletion on exit: the vendor returns data or certifies deletion and destroys copies within a fixed number of days of termination.
  6. Subprocessor controls: advance disclosure, approval and objection rights, and equivalent obligations flowing down to each subprocessor.
  7. Data location locked in: approved regions for storage, processing, and staff access appear in the text.
  8. Lawful transfers: every cross-border flow rests on standard contractual clauses, an adequacy decision, or the consent and notice steps your law requires.
  9. Security and incidents: notification within roughly 24–72 hours, forensic preservation, and assistance with regulator notification.
  10. Audit and monitoring: a right to conduct or commission an independent assessment of data handling and security.
  11. Data-subject support: the vendor assists with access, rectification, erasure, and other requests you must fulfil as controller.
  12. Provenance and change control: the vendor warrants lawful training-data provenance and must notify you before model updates that change processing.

Questions people ask

Why is a standalone data-processing agreement not enough for an AI vendor?

A data-processing agreement is necessary but not sufficient because AI raises issues a standard DPA does not cover: whether the vendor may train models on your data, what happens to prompts and outputs, model provenance and quality, change control over model versions, and output ownership and indemnity. A DPA fixes the GDPR Article 28 obligations — purpose, duration, data categories, instructions, deletion — but the AI-specific risks live in the broader contract, which should therefore be treated as a governance document rather than a formality.

What does the EU AI Act require of providers regarding training data and documentation?

For high-risk systems, Article 10 requires that training, validation, and testing datasets be relevant, sufficiently representative, and as free of errors and complete as possible, and that data-governance practices address collection, origin, preparation, bias examination, and gaps. For general-purpose AI models, Article 53 requires providers to keep up-to-date technical documentation of the training and testing process and to make publicly available a summary of the content used for training. Translate these duties into your contract through warranties on provenance and documentation obligations.

How long should an AI vendor take to notify you of a data security incident?

Work toward a notification window of roughly 24 to 72 hours from discovery as a benchmark, while confirming what your own law requires of you. For example, under GDPR a controller normally notifies its supervisory authority within 72 hours of becoming aware of a breach. The contract should also require forensic preservation, cooperation in investigation and remediation, and assistance with the regulator notifications you must make. The vendor's promise to notify you in time is what lets you meet your own deadlines.

Can I prevent my vendor from using customer data to train its models?

Yes, through an explicit contractual restriction. The single most important clause is a statement that the vendor may not use your customer data, prompts, or outputs to train, retrain, or improve its models without your explicit, informed consent. If a vendor resists a total ban, you can permit only processing technically necessary to deliver the service and require prior written approval for anything else. If the vendor proposes training on anonymized data, verify the anonymization is irreversible; otherwise the data remains personal data carrying full obligations.

Which data categories should a retention clause specify for an AI service?

At minimum, separate prompts (the inputs you send), outputs (the generated responses), inference logs and telemetry, metadata about usage, and any training or fine-tuning datasets your data helped create. Specify a retention period for each rather than a single generic promise. On termination, require the vendor to return or delete the data and destroy copies within a fixed number of days, keeping only what law expressly requires storage for, and to certify the deletion in writing.

What should I do if my model is updated or replaced by the provider without notice?

The contract should contain change control: the provider must notify you in advance of any model update, version change, or provider-side modification that affects behavior, data flows, quality, or the terms of processing, and give you a window to review and approve or object. Where AI outputs drive consequential decisions such as hiring, lending, or underwriting, pair change control with model explainability and human-in-the-loop oversight so you can reassess after any update.

Sources and further reading

Sources were checked when this page was generated. Confirm changing dates, rules and prices with the original publisher.

  1. Article 10: Data and Data Governance | EU Artificial Intelligence ActFuture of Life Institute / AI Act tracker
  2. Article 53: Obligations for Providers of General-Purpose AI Models | EU Artificial Intelligence ActFuture of Life Institute / AI Act tracker
  3. Art. 28 GDPR – ProcessorGDPR-info.eu
  4. AI Risk Management Framework (AI RMF)NIST, U.S. Department of Commerce
  5. The AI Vendor Contract Is Becoming More Important Than the Privacy PolicyTucker Ellis LLP
  6. Использование ИИ и нейронных сетей в контексте 152-ФЗ: правовые риски и меры для оператораБ-152
  7. Новая правовая архитектура регулирования ИИ в Европе и её значение для РоссииАссоциация юристов России