Skip to main content
Category: Contracting & Acquisition

Data Rights

Also known as: Rights in Data, Government Data Rights
Simply put

Data Rights is a shorthand term for the license rights the U.S. Government holds in intellectual property, generally covering technical data and computer software delivered under a government contract. These rights determine how the Government may use, disclose, reproduce, and distribute the material a contractor provides. The specific scope of rights varies by contract and by the applicable contract clause, so parties should confirm the exact terms in each agreement.

Formal definition

In the context of U.S. Government contracting, Data Rights refers to the Government's license rights in two principal categories of intellectual property, generally technical data and computer software delivered under a contract. Under the standard FAR data rights clause (FAR 52.227-14, Rights in Data, General), 'data' is defined as recorded information regardless of form or media, and the clause establishes categories such as 'unlimited rights,' described as the Government's rights to use, disclose, reproduce, prepare derivative works, distribute copies to the public, and perform publicly. The scope of Government rights is typically established and preserved through data rights markings applied to the delivered data or software. This entry does not address the distinct DFARS data rights framework applicable to Department of Defense acquisitions, agency-specific tailoring, or the detailed rules governing limited rights, restricted rights, or specifically negotiated license rights; readers should verify the applicable clause and its current text against the governing regulation for their specific contract.

Why it matters

Data Rights determine who controls the intellectual property that changes hands under a government contract. For the Government, securing appropriate rights in technical data and computer software affects its ability to maintain, upgrade, re-compete, or sustain a system over its lifecycle without being locked into a single vendor. For contractors, the rights they grant, or fail to properly restrict, can affect the commercial value of proprietary technology, since data delivered with unlimited rights may generally be used, disclosed, reproduced, and even distributed to the public by the Government. Misunderstanding the scope of rights conveyed can therefore have lasting business and competitive consequences.

Because the specific rights depend on the applicable contract clause and how delivered data and software are marked, errors in this area are easy to make and difficult to reverse. Under the standard FAR clause (FAR 52.227-14, Rights in Data, General), data delivered without proper protective markings may default to broader Government rights than a contractor intended. Data rights markings are the mechanism by which parties assert and preserve the intended scope of rights, so inconsistent, missing, or defective markings can undermine a contractor's position after delivery.

Readers should also note that the FAR framework described here is distinct from the separate DFARS data rights framework that applies to Department of Defense acquisitions, and that agencies may tailor terms. Confirming the exact clause, its current text, and the negotiated terms of each specific contract is essential, because this term is a shorthand for a body of rules that vary considerably in practice.

Who it's relevant to

Government Contractors
Contractors delivering technical data or computer software under a federal contract need to understand what rights the Government will hold in that material and how to preserve any intended restrictions. Because data delivered under the standard FAR clause may carry broad Government rights, and because markings are the mechanism for asserting the intended scope, contractors should confirm the applicable clause and marking requirements for each contract rather than assuming a default outcome.
Contracting Officers and Acquisition Personnel
Those structuring and administering contracts must select and apply the appropriate data rights clause and understand the categories of rights it establishes, including unlimited rights under FAR 52.227-14. They should also be aware that the FAR framework is distinct from the separate DFARS framework used in DoD acquisitions and that agency-specific tailoring may apply.
Intellectual Property and Government Contracts Counsel
Attorneys advising on federal contracts assess how delivered data and software should be marked to preserve a client's rights and evaluate the consequences of the applicable clause. This entry does not address the detailed rules for limited rights, restricted rights, or negotiated license rights, so counsel should verify the governing regulation and current clause text for the specific agreement.
Program and Sustainment Managers
Personnel responsible for maintaining, upgrading, or re-competing a system over its lifecycle rely on the Government holding sufficient rights in the underlying data and software. Understanding whether the Government has unlimited rights or more restricted rights informs long-term sustainment and competition planning.

Inside Data Rights

License Rights Categories
Data rights in the defense context generally refer to the government's license rights in technical data and computer software delivered under a contract, rather than ownership of the data itself. Standard categories addressed in the DFARS include unlimited rights, government purpose rights, and restricted or limited rights, with the applicable category depending on the source of funding used to develop the item, component, or process. Readers should verify the current DFARS text for precise definitions and conditions.
Technical Data vs. Computer Software
Data rights provisions typically distinguish between technical data (recorded information of a scientific or technical nature) and computer software, which are addressed under separate DFARS clauses. The distinction matters because the governing clause, marking requirements, and default license rights can differ between the two. Practitioners should confirm which clause applies to a given deliverable.
Governing Regulatory Authority
For defense acquisitions, data rights are principally governed by the Defense Federal Acquisition Regulation Supplement (DFARS), which supplements the Federal Acquisition Regulation (FAR). This is a distinct regulatory framework from cybersecurity compliance authorities such as DFARS clause 252.204-7012, NIST SP 800-171, or CMMC, and should not be conflated with them even though several appear within the same regulatory supplement.
Funding Source Determination
The scope of the government's license rights generally hinges on whether development was funded exclusively at private expense, exclusively with government funds, or with mixed funding. This funding basis typically drives which rights category attaches to the delivered data or software. The specific rules and any exceptions should be verified against the current governing text.
Marking and Assertion Requirements
Contractors generally must assert claimed restrictions and apply appropriate restrictive legends or markings to technical data and software to preserve limited or restricted rights. Improper, missing, or nonconforming markings can affect the enforceability of asserted restrictions. Precise marking formats and assertion procedures should be confirmed in the applicable clauses.
Relationship to Cybersecurity Safeguarding
Data rights concern the license and use scope of delivered data, whereas safeguarding obligations for Controlled Unclassified Information (CUI) address protection of information systems and data confidentiality. These are related but separate obligations; a deliverable can be subject to both a data rights category and CUI safeguarding requirements simultaneously.

Common questions

Answers to the questions practitioners most commonly ask about Data Rights.

Does having a security Authority to Operate (ATO) mean the government has data rights in the information on that system?
No. An ATO is a time-bound authorization decision about the security posture of an information system and its acceptable risk; it is subject to continuous monitoring and does not by itself convey or define data rights. Data rights are a separate matter generally governed by contractual terms rather than by a security authorization. Do not conflate an authorization to operate with an allocation of rights in data, and verify the specific rights against the applicable contract clauses and current authoritative sources.
If a contractor delivers data under a contract, does the government automatically own it or have unlimited rights to it?
Not necessarily. Delivery of data and the scope of rights the government receives in that data are distinct concepts. The government generally acquires a defined category of rights (which can range from limited or restricted rights to unlimited rights, depending on the applicable terms), rather than ownership by default. The specific rights depend on the contract, the funding basis for developing the data, and the applicable regulatory clauses, which the reader should confirm against the current authoritative text and the contract itself.
Where should I look to determine the data rights that apply to a specific deliverable?
Data rights are generally established in the contract, including the clauses incorporated by reference and any negotiated terms, rather than in a security or compliance framework. Review the contract's data rights provisions, any associated deliverables lists, and any markings or assertions related to the data. Because interpretations can be agency-specific and terms evolve, confirm the applicable rights against the current authoritative regulatory text and, where questions remain, appropriate contracting or legal counsel. This entry does not cover the contractual or legal specifics you must verify.
How do markings on data relate to the data rights that attach to it?
Markings are generally intended to signal asserted restrictions or the category of rights associated with data, but the markings themselves do not substitute for the governing contractual terms. Proper, consistent marking in accordance with the applicable requirements is typically important to preserving asserted restrictions, and improper or omitted markings can affect how rights are treated. Because the precise marking requirements and their effects are established in regulation and the contract, verify them against the current authoritative sources rather than relying on general practice.
Are data rights the same thing as protecting Controlled Unclassified Information (CUI)?
No. Data rights concern the rights parties hold in data, while CUI safeguarding concerns the handling and protection obligations for a defined category of information. A given deliverable can be subject to both, but they arise from different authorities and address different questions. Do not assume that satisfying safeguarding or compliance obligations resolves the allocation of data rights, or vice versa; confirm each against its own governing terms and current authoritative sources.
Can data rights differ across federal civilian, defense, and other environments?
Yes. The framework and terminology governing data rights can differ depending on the acquisition context, and interpretations may be agency-specific. Requirements applicable to defense contracts may differ from those in federal civilian contracts, and state, local, tribal, and territorial obligations may differ as well. Because these terms and their applicability evolve across revisions, verify the specific rights that apply against the current authoritative text for the relevant context rather than assuming a single uniform rule.

Common misconceptions

Data rights mean the government owns the technical data or software it receives.
In most defense contract implementations, data rights refer to a license the government holds to use, disclose, or reproduce delivered data or software, not to ownership or transfer of intellectual property. The contractor may retain ownership while the government holds rights defined by the applicable DFARS category. Confirm the specific license terms in the governing clauses.
Data rights and cybersecurity compliance requirements such as DFARS 252.204-7012, NIST SP 800-171, or CMMC are the same set of obligations.
Data rights govern the scope of the government's license in delivered technical data and software, while the cybersecurity clauses and control frameworks address safeguarding of covered information and information systems. They are distinct requirements, may appear in different clauses, and one does not satisfy the other. A deliverable can be subject to both.
Once an appropriate rights category is assigned, no further contractor action is needed to protect it.
Preserving limited or restricted rights generally depends on properly asserting claimed restrictions and applying conforming restrictive markings. Missing or defective markings can undermine the intended protection. The applicable assertion and marking procedures should be verified against the current governing text.

Best practices

Identify the applicable DFARS data rights clause for each deliverable and confirm whether it is technical data or computer software, since the governing clause and default rights can differ.
Document the funding basis (private expense, government funds, or mixed funding) for developed items, components, and processes, as this generally determines the applicable rights category.
Prepare and maintain accurate assertions of claimed restrictions and apply conforming restrictive markings to preserve limited or restricted rights, verifying formats against the current governing text.
Treat data rights and cybersecurity safeguarding obligations as separate compliance tracks, confirming both when a deliverable is also subject to CUI protection requirements.
Engage contracts and legal counsel early to resolve rights category questions and any agency-specific interpretations before delivery, rather than after markings are challenged.
Verify all clause numbers, category definitions, and marking requirements against the current authoritative DFARS and FAR text, since regulatory provisions are revised over time.