Key takeaway

Establish rights by record category. Owning a server or paying for software does not resolve every interest in its contents.

Build a chain of authority.

Identify the entity proposing the license, who created the material and the agreements that govern it. Operational records may combine company-authored notes, customer messages, contractor photographs and vendor documents. The rights can differ within the same ticket.

Keep source permissions and corporate approval separate. A director may approve a project without being able to override a customer confidentiality clause.

Review the agreements that created the archive.

Look at customer terms, NDAs, employment and contractor agreements, supplier licenses and platform terms. Check both historical and current versions where the archive spans several years. Flag missing agreements rather than treating them as unrestricted.

SourceStarting review
Employee-created documentCompany entity, employment terms and confidentiality
Contractor contentAssignment or license scope and allowed reuse
Customer messagePrivacy, confidentiality and permitted purposes
Vendor manual / attachmentLicense and redistribution restrictions
Mixed recordField- or attachment-level exclusions

Separate privacy from intellectual property.

Permission to use copyrighted content does not automatically establish a lawful basis to process personal information. Removing names does not clear customer confidentiality or third-party copyright. These are different questions and may need different reviewers.

Use a category-level rights register with the source, applicable agreement, allowed uses, restrictions, evidence location and responsible reviewer. No evidence should remain an open item.

Create a narrower package where needed.

If an attachment cannot be licensed, consider whether the rest of the workflow remains useful after excluding it. If a customer-specific document is restricted, ask whether a company-created generic procedure can be evaluated instead. Review the result again; a transformation can still reveal protected information.

Illustrative example: the company’s repair steps may be separable from a vendor’s copyrighted manual attached to the same work order. That separation still needs a rights and confidentiality review.

Give the approver a decision they can understand.

Present the proposed package, intended use, recipient, exclusions and unresolved questions. Ask for the necessary review before a sample, then separately before a license. A checklist produces an agenda; it does not create rights or stand in for advice on the actual transaction.

Tools for this decision

Data inventory builder →Rights & privacy review →