Negotiating an AI procurement contract with its data clauses
The procurement of a model API to be used in a customer-experience product was set up through a negotiation focused on performance undertakings, output liability, the non-use of data in training, and the personal-data layer.
A classic software template can't carry this work
The provider's standard text was silent on hallucination, data use and the allocation of liability.
The personal-data flow could not begin without a processor agreement and transfer instruments.
Our Approach
Keeping the commercial objective at the centre, we broke the legal risks into measurable steps.
01 · Risk Map
Performance, output and data risks were matched with their corresponding clauses.
02 · Negotiation
No-use-in-training, IP and liability caps were negotiated.
03 · Data Layer
The DPA, transfer instruments and security annexes were completed.
Chronology
The main stages of the process.
A balanced contract that protected the product goal
The procurement began with a contract that struck a performance–liability balance and completed the data layer — including exit and portability clauses.
- An assurance of no use in training
- Balance of liability and performance
- A complete data layer (DPA + transfer)
- Exit and portability clauses
Related Areas of Expertise
The practice and focus areas engaged on this matter.
Sectors
The sectors in which we most frequently advise on matters of this kind.
Related Publications
Our insights and guides related to this matter.

Product compliance when selling into the EU: GPSR, accessibility, and the new packaging regime
The new preconditions for selling into the EU go beyond legal texts: a responsible person under the GPSR, an accessible store under the BFSG, packaging registration under LUCID/PPWR. A seller's-eye map of the 2024–2026 wave.
Read more →
Being a marketplace seller: 7 legal topics, from account suspension to the 1% withholding
Amazon, Etsy, Trendyol: the law of marketplace selling starts with the contract, continues with DSA verification and GPSR fields, and is tested by withholding and suspensions. 7 topics from the seller's perspective.
Read more →
E-commerce from Türkiye to the EU: VAT, OSS/IOSS and GDPR checklist
The three compliance layers of selling online to consumers in the EU: VAT registrations (OSS/IOSS), GDPR and consumer rules. A market-entry checklist for Turkish e-commerce companies.
Read more →The Team on This Matter
Our multilingual team handling the matter.
Related Matters
A selection of similar transactional and advisory matters.
Uninterrupted legal counsel for a multinational supplier
Retainer-based support across day-to-day commercial operations, contract management and compliance processes.
Designing corporate governance across group companies
Single-source management and documentation of general assembly, board and compliance processes.
Building a single compliance programme for KVKK and GDPR
Establishing the data inventory, document set, transfer mechanisms and breach plan of a group selling in two markets within a single programme.
First we clarify the commercial objective, risk appetite, timeline and the decision-maker's needs. Then we break the work down into legal analysis, document/contract structure and implementation steps, and manage the process through a single point of contact.
Owing to the legal profession's duty of confidentiality and client privilege, the files are anonymised. In a meeting, within the limits of confidentiality, we can describe our comparable experience more concretely.
In a short preliminary meeting, we take in the objective, existing documents, parties, time pressure and critical risks. Then the scope, team, timeline and fee model are clarified.
To complete a similar matter with confidence.
Let us manage your process from start to finish with our experience in similar matters.


