Cloud Data Ownership Disputes .

1. Meaning of Cloud Data Ownership Disputes

Cloud Data Ownership Disputes arise when two or more parties disagree about who has the legal rights, control, access, use, licensing, exploitation, retention, portability, or deletion rights over information stored or processed through cloud-computing infrastructure.

The parties may include:

  • cloud-service provider;
  • SaaS provider;
  • customer/business enterprise;
  • data controller/data fiduciary;
  • data processor;
  • employees or contractors;
  • data subjects;
  • software developers;
  • third-party vendors;
  • cloud-storage or data-centre operators.

The central question is often stated simply as:

“Who owns the data stored in the cloud?”

But legally, the question is more complicated because ownership, possession, custody, access, control, processing rights, intellectual-property rights and privacy rights are not necessarily the same thing.

UNCITRAL's guidance on cloud contracts specifically distinguishes customer data from the provider's service and recommends contractual allocation of rights concerning access, use, derived data, portability, retrieval and deletion.

2. Basic Principle of Cloud Data Ownership

In a conventional cloud arrangement, the customer generally supplies or generates the underlying business data, while the cloud provider supplies the infrastructure or software environment used to store and process it.

Therefore, a typical arrangement may look like:

Customer → owns/controls customer data

Cloud provider → owns/controls cloud platform and infrastructure

Provider → receives limited contractual rights to process customer data

This distinction is expressly illustrated in the Salesforce contractual arrangement considered by Indian tax authorities: Salesforce's master subscription agreement stated that the customer exclusively owned rights, title and interest in customer data, while Salesforce retained rights in the service itself.

Thus:

Storage of data by a cloud provider does not by itself transfer ownership of the customer's data to the cloud provider.

3. Why Cloud Data Ownership Disputes Arise

Cloud data disputes commonly arise from ambiguity concerning:

  1. raw customer data;
  2. personal data;
  3. business records;
  4. metadata;
  5. usage data;
  6. aggregated data;
  7. anonymised data;
  8. derived data;
  9. analytical outputs;
  10. AI-generated outputs;
  11. databases;
  12. customer lists;
  13. proprietary information;
  14. trade secrets;
  15. backups;
  16. data generated after termination.

The most difficult category is usually derived or aggregated data.

For example:

A retailer uploads millions of customer transactions to a cloud platform.

The provider then creates:

  • purchasing trends;
  • statistical models;
  • customer-behaviour analytics;
  • industry benchmarks.

The question becomes:

Does the customer own the resulting analytical dataset, or can the provider commercially exploit it?

This is precisely why cloud contracts should distinguish customer data from provider-generated or service-derived data. UNCITRAL recommends expressly addressing rights to cloud-service-derived data and how those rights operate during and after termination.

4. Ownership vs Custody vs Control

These concepts should not be confused.

Ownership

Means the legally recognized entitlement to the relevant property or rights.

Custody

Means physically or technically holding data for another party.

Control

Means determining how data can be accessed, processed, transferred or used.

Processing

Means performing operations on data, such as:

  • storing;
  • organizing;
  • retrieving;
  • analysing;
  • transmitting;
  • deleting.

A cloud provider may therefore possess and process data without becoming its owner.

5. Customer Data

Customer data ordinarily includes:

  • customer databases;
  • employee records;
  • financial information;
  • transaction records;
  • inventory information;
  • uploaded documents;
  • emails;
  • photographs;
  • business records;
  • customer-generated content.

A well-drafted cloud contract should clearly state:

“As between the parties, all right, title and interest in Customer Data remain with the Customer.”

The contract should additionally specify the limited licence granted to the provider for hosting, processing, securing and backing up the data.

6. Provider's Intellectual Property

The cloud provider normally retains ownership of:

  • software;
  • source code;
  • object code;
  • APIs;
  • algorithms;
  • platform architecture;
  • documentation;
  • technical processes;
  • proprietary databases;
  • trademarks;
  • service improvements.

Therefore, a customer owning its data does not mean that it owns the cloud provider's software.

The Salesforce arrangement considered by the Delhi High Court illustrates this distinction: the customer owned customer data, while Salesforce retained rights in the underlying service and related intellectual property.

7. Raw Data, Derived Data and Aggregated Data

This is one of the most important issues.

Raw data

Data directly supplied by the customer.

Example:

Customer's list of 50,000 customers.

Derived data

Information generated by processing customer data.

Example:

Customer lifetime-value calculations.

Aggregated data

Information combining data from multiple customers.

Example:

Average purchasing trends of 500 retailers.

Anonymised data

Data altered so that individuals cannot reasonably be identified, subject to the applicable legal standard.

A contract should specify who owns or may use each category.

UNCITRAL specifically notes that providers may seek rights to use customer data for analytics, statistics, predictions and other purposes and recommends that contracts clearly define such rights and impose appropriate restrictions.

8. Data Ownership under Indian Law

India does not have one comprehensive statute simply declaring:

“The person who creates digital data owns it.”

Instead, different legal regimes may apply depending upon the nature of the data.

Relevant laws include:

1. Digital Personal Data Protection Act, 2023

Deals with processing and protection of digital personal data.

2. Information Technology Act, 2000

Relevant to electronic records, computer resources and cybersecurity-related issues.

3. Indian Contract Act, 1872

Crucial where ownership and usage rights are contractually allocated.

4. Copyright Act, 1957

Potentially relevant to original databases, compilations, software and other copyrightable works.

5. Trade Marks Act, 1999

Relevant where data includes protected branding and marks.

6. Indian Evidence Act / Bharatiya Sakshya Adhiniyam framework

Relevant to evidentiary use of electronic records.

7. Competition law

May become relevant where control over data creates market-power or exclusionary concerns.

9. Contract Is Central to Cloud Data Ownership

The most important document is usually the:

Master Cloud/SaaS Agreement.

It should expressly determine:

  • who owns customer data;
  • who may access it;
  • why the provider may process it;
  • whether the provider may analyse it;
  • whether data can be sold;
  • whether data may be used for AI training;
  • whether data can be aggregated;
  • whether data can be anonymised;
  • who owns derived data;
  • how data is exported;
  • how long it is retained;
  • how it is destroyed.

UNCITRAL similarly emphasizes that cloud agreements should expressly identify the rights necessary for service provision and the provider's permitted uses of customer data.

10. Important Case Laws

Case 1 — M/s Salesforce.com Singapore Pte. Ltd. v. Deputy Director of Income Tax

This is one of the most useful Indian authorities for understanding cloud/SaaS data ownership.

Facts

Salesforce provided CRM services to Indian customers through its cloud-based platform.

Customers:

  • entered their business data;
  • stored information on Salesforce;
  • retrieved the information;
  • generated reports through the platform.

The contractual arrangement expressly stated that the customer exclusively owned all rights, title and interest in Customer Data.

Salesforce retained ownership of the underlying service and associated intellectual property.

Importance

The case demonstrates the distinction between:

customer data and cloud software/service.

The provider can supply the technological environment without acquiring ownership of the customer's underlying data.

Principle

Cloud hosting and processing do not necessarily transfer proprietary rights in customer data to the service provider.

This is one of the strongest Indian authorities to cite in an examination on cloud-data ownership.

11. Case 2 — Commissioner of Income Tax v. Salesforce.com Singapore Pte. Ltd. (Delhi High Court, 2024)

The Delhi High Court subsequently examined the Salesforce cloud-based CRM model.

Facts

The business model involved:

  1. Salesforce entering into a Master Subscription Agreement with Indian customers;
  2. customers paying subscription fees;
  3. customers uploading and storing proprietary data;
  4. Salesforce providing access to that data through its cloud platform;
  5. access continuing only during the subscription period.

The contractual arrangement distinguished the customer's proprietary data from Salesforce's service and intellectual property.

Importance

Although the principal dispute was tax-related, the judgment provides valuable factual and contractual analysis of cloud data.

Principle

A SaaS provider may provide customers with access to their own proprietary information without transferring ownership of the underlying data or transferring ownership of the provider's software.

12. Case 3 — M/S Yodlee Inc. v. Deputy Commissioner of Income Tax (2024)

This case is relevant to the legal characterization of cloud computing.

Facts

Yodlee supplied cloud-based services and software to customers.

The dispute involved whether the cloud service amounted to a transfer of rights in software/processes.

Decision/Reasoning

The tribunal relied upon earlier decisions holding that cloud-based services generally do not necessarily involve a transfer of rights in the underlying software or process.

The subscriber obtains online access to the service; it does not necessarily obtain a right to reproduce the underlying software.

Importance

The case helps establish the distinction between:

  • ownership of data;
  • ownership of software;
  • right to access software;
  • right to reproduce software.

Principle

Access to cloud software is not equivalent to ownership of the software or acquisition of copyright rights in it.

13. Case 4 — North Mississippi Medical Center, Inc. v. Quartiz Technologies

This is a particularly direct foreign case on cloud data ownership.

Facts

North Mississippi Medical Center transferred its data-management operations to Quartiz Technologies.

The agreement required Quartiz to:

  • move the hospital's database to the cloud;
  • configure the database;
  • manage the data.

The parties subsequently amended their agreement to address data ownership and hosting-account ownership.

The amended agreement expressly provided that:

the hospital's business data, records and reports were its exclusive property.

It further provided that access by Quartiz did not create an ownership interest or licence in favour of Quartiz.

Importance

This is an excellent example of how courts approach the issue:

Contractual wording can expressly determine data ownership.

Principle

Where a cloud contract expressly declares customer data to be the customer's exclusive property, the provider's possession and access do not by themselves create ownership rights.

14. Case 5 — Navigators Logistics Ltd. v. Kashif Qureshi & Ors.

This Delhi High Court litigation is important for proprietary business information and data misappropriation.

Facts

The plaintiff alleged that former employees had misappropriated proprietary information, including:

  • customer information;
  • internal business data;
  • commercially valuable information.

The dispute involved allegations concerning unauthorized transfer and use of proprietary data.

Importance

The court emphasized that allegations concerning data misappropriation and trade-secret-type information could not necessarily be dismissed at the threshold where specific factual material supported the allegations.

Principle

The case demonstrates that commercially valuable information may receive legal protection through:

  • confidentiality;
  • contract;
  • trade-secret principles;
  • injunctions;
  • evidence of unauthorized acquisition/use.

It is particularly useful where cloud data is copied from a company's cloud environment by employees or competitors.

15. Case 6 — State Bank of India v. Commissioner of Service Tax, Mumbai-II

This case is relevant to the distinction between ownership of data and providing access to data.

Legal issue

The case concerned classification of services involving data and online access.

The tribunal recognized that the question of who owns the underlying data can be important in determining the legal nature of the service.

The principle has subsequently been relied upon in cases concerning data-processing and OIDAR services.

Importance

For cloud disputes, the case supports an important analytical approach:

The provider's technological ability to access or process information does not necessarily mean that the provider owns the information.

16. Case 7 — Innodata India Pvt. Ltd. v. Commissioner, CGST Noida

This case involved data-processing services.

Facts

The service provider processed data belonging to third parties.

The issue included whether the provider was providing access to its own content or merely processing data belonging to others.

Decision

The tribunal distinguished between:

  • ownership of data/content; and
  • processing or providing services in relation to that data.

The fact that a service provider processes data does not necessarily mean that the provider owns the underlying data.

Relevance

This distinction is highly relevant to cloud environments.

For example:

Cloud provider = processor/custodian

does not necessarily mean:

Cloud provider = owner.

17. Case 8 — SS&C Technologies Holdings, Inc. v. D.E. Shaw & Co. (2026)

This recent U.S. litigation provides a modern example of contractual data-ownership disputes.

Facts

The dispute involved software/data generated through SS&C's Geneva platform.

The parties disputed contractual provisions concerning:

  • data ownership;
  • proprietary information;
  • control over data;
  • ability to transition to competing systems.

The defendant alleged that contractual data-ownership provisions effectively restricted its ability to move to competing providers.

Importance

The case demonstrates that data ownership can become connected with:

  • vendor lock-in;
  • competition law;
  • interoperability;
  • switching costs;
  • contractual restrictions.

Principle

Data ownership clauses can have commercial consequences beyond simple property rights because they can affect a customer's ability to migrate to competing platforms.

18. Case 9 — Microsoft Corporation v. United States

The famous Microsoft warrant litigation is important for the jurisdictional dimension of cloud data.

The dispute concerned data stored in Microsoft's cloud infrastructure outside the United States and the extent to which U.S. authorities could compel Microsoft to produce that information.

Although the litigation ultimately became moot after statutory changes, it demonstrated a fundamental cloud-law problem:

Where is cloud data legally located when it is distributed across multiple countries?

The U.S. Supreme Court materials identified several possible jurisdictional connections, including:

  • physical storage;
  • location of the account holder;
  • location of the service provider;
  • location from which the provider controls the data. 

Importance

This is extremely relevant to international cloud-data ownership and control disputes.

19. Important Distinction: Ownership Does Not Equal Privacy

A person or company may have contractual ownership or control over data while another person may have privacy rights in the same data.

For example:

A company owns its customer database commercially.

But the individual customers whose personal information appears in that database may have statutory rights concerning:

  • processing;
  • access;
  • correction;
  • consent/notice where applicable;
  • deletion/erasure where applicable;
  • security.

Therefore:

Commercial ownership and personal-data rights can coexist.

20. Data Ownership and the DPDP Act

The Digital Personal Data Protection Act, 2023 changes the way cloud data disputes should be analysed.

The legal question is not simply:

“Who owns the database?”

It also becomes:

“Who determines the purpose and means of processing personal data, and what contractual obligations govern the processor?”

Thus, cloud agreements should allocate responsibilities relating to:

  • personal-data processing;
  • security safeguards;
  • breach response;
  • subcontractors;
  • retention;
  • deletion;
  • compliance assistance;
  • data-subject rights.

21. Cloud Data and Copyright

Copyright law may apply where the data constitutes a protected work or database compilation.

However, not every item of data is copyrightable.

For example:

Likely factual data

  • names;
  • addresses;
  • dates;
  • numerical transactions.

Facts generally cannot simply become copyright-protected merely because they are stored in a cloud database.

But:

  • original database structure;
  • original selection;
  • arrangement;
  • software;
  • creative reports

may potentially attract intellectual-property protection.

Therefore, the phrase “ownership of data” must not automatically be equated with copyright ownership.

22. Trade Secrets and Cloud Data

Cloud-stored information may constitute confidential commercial information.

Examples include:

  • customer lists;
  • pricing models;
  • supplier information;
  • business strategies;
  • algorithms;
  • source code;
  • product-development plans.

If such information is improperly copied from a cloud system, the customer may seek remedies based upon:

  • contract;
  • confidentiality;
  • breach of confidence;
  • intellectual property;
  • employment obligations;
  • injunctions.

23. Data Portability

Ownership becomes practically meaningless if the customer cannot retrieve its data.

Therefore, cloud agreements should provide:

  • export rights;
  • machine-readable formats;
  • reasonable retrieval periods;
  • API access;
  • migration assistance;
  • backup rights;
  • metadata export;
  • reasonable transition costs.

UNCITRAL recognizes interoperability and portability as important contractual issues because, without contractual commitments, the burden of creating compatible export mechanisms may fall entirely upon the customer.

24. Data Deletion After Termination

One of the most difficult issues arises when the contract ends.

Questions include:

  • When must the provider return the data?
  • When must it delete the data?
  • What happens to backup copies?
  • What happens to metadata?
  • What happens to disaster-recovery copies?
  • Must the provider provide a deletion certificate?
  • Can the provider retain information to comply with law?

A good contract should address these matters expressly.

UNCITRAL notes that deletion may involve multiple locations, backups, subcontractors and different storage media, making contractual specifications particularly important.

25. Data Aggregation Disputes

Suppose 1,000 customers provide data to a cloud provider.

The provider combines the data and produces:

“Industry-wide market analytics.”

The customer may argue:

“The analytics are derived from my confidential information.”

The provider may respond:

“The dataset is aggregated and anonymised.”

The legal answer depends on:

  • contract;
  • confidentiality obligations;
  • applicable data-protection law;
  • whether re-identification is possible;
  • whether the resulting dataset contains protectable expression;
  • whether the provider's use was authorized.

Therefore, cloud contracts should expressly define aggregated data.

26. AI Training and Cloud Data Ownership

This is becoming one of the most important modern issues.

Suppose a company stores:

10 million customer records

in a cloud AI platform.

The provider uses that information to train an AI model.

Potential questions include:

  1. Did the contract permit AI training?
  2. Who owns the trained model?
  3. Who owns model outputs?
  4. Can the provider use the model for other customers?
  5. Can customer information be reconstructed?
  6. Can confidential information be embedded in model parameters?
  7. Does anonymisation sufficiently protect the customer?
  8. Is the provider allowed to commercialize derived analytics?

The contract should therefore distinguish:

Customer Data → Customer

Provider Platform → Provider

Customer-specific outputs → expressly allocated

General service improvements → expressly defined

AI models/trained weights → expressly allocated

27. Cloud Data Ownership and Vendor Lock-In

Vendor lock-in occurs where customers become so dependent upon a cloud provider that changing providers becomes commercially difficult.

This may result from:

  • proprietary formats;
  • high migration costs;
  • restricted APIs;
  • termination fees;
  • data-export limitations;
  • withholding of metadata;
  • contractual restrictions.

Data ownership disputes can therefore become competition-law disputes.

The recent SS&C Technologies v. D.E. Shaw litigation illustrates how contractual data ownership provisions may be alleged to restrict customers' ability to transition to competing systems.

28. Common Claims in Cloud Data Ownership Litigation

1. Declaratory relief

A party asks the court to declare who owns the data.

2. Injunction

A party seeks to prevent unauthorized use or disclosure.

3. Breach of contract

The provider allegedly violated the data-ownership clause.

4. Confidentiality claim

The provider allegedly disclosed confidential information.

5. Copyright claim

Protected database/software material was allegedly copied.

6. Trade-secret claim

Confidential business information was allegedly misappropriated.

7. Data-protection claim

Personal data was processed contrary to law.

8. Conversion/misappropriation-type claims

Depending upon the applicable jurisdiction and legal characterization.

9. Damages

Financial loss caused by unauthorized use.

10. Data-return/deletion order

The customer seeks return or destruction of information.

29. Defences Available to Cloud Providers

Providers may argue:

A. Contractual licence

The customer granted permission to use the data.

B. Necessary processing

Access was necessary to provide the contracted service.

C. Aggregation

The information was converted into properly aggregated/anonymised data.

D. No proprietary right

The information is factual and does not attract the claimed IP right.

E. Customer consent

The customer accepted the relevant terms.

F. Security/legal obligation

Disclosure was required by law.

G. Provider-generated information

The disputed material was independently created by the provider.

H. Limitation of liability

The contract limits monetary recovery.

30. Remedies Available to Customers

A customer may seek:

  • declaration of ownership;
  • injunction against unauthorized use;
  • return of data;
  • data export;
  • deletion;
  • damages;
  • account restoration;
  • specific performance;
  • confidentiality orders;
  • arbitration;
  • termination of the cloud agreement;
  • indemnification.

31. Essential Clauses in a Cloud Data Ownership Agreement

ClausePurpose
Customer Data OwnershipEstablishes ownership
Provider LicenceDefines permitted processing
ConfidentialityProtects business information
Data UsageRestricts secondary use
AI TrainingSpecifies whether data may train models
Aggregated DataDefines provider's rights
Derived DataAllocates ownership
Data PortabilityAllows migration
Data ExportSpecifies format and procedure
Data RetentionDetermines retention period
Data DeletionProvides post-termination destruction
BackupAllocates responsibility
SecurityDefines safeguards
SubprocessorsControls third-party access
AuditPermits compliance verification
Government RequestsRegulates disclosures
IP OwnershipSeparates data from software
Dispute ResolutionDetermines arbitration/litigation
Governing LawDetermines applicable law

32. Case-Law Summary

CaseMain Principle
Salesforce.com Singapore Pte. Ltd. v. Deputy Director of Income TaxCustomer can retain exclusive ownership of customer data while provider owns the cloud service
Commissioner of Income Tax v. Salesforce.com Singapore Pte. Ltd.SaaS arrangement distinguishes customer proprietary data from provider's service/IP
M/S Yodlee Inc. v. DCITCloud access does not necessarily transfer software/IP rights
North Mississippi Medical Center v. Quartiz TechnologiesExpress contractual language can make customer data exclusively the customer's property
Navigators Logistics Ltd. v. Kashif QureshiProprietary business information and data misappropriation can support litigation/injunctive claims
State Bank of India v. Commissioner of Service TaxOwnership/control of data is relevant when characterizing data-related services
Innodata India Pvt. Ltd. v. Commissioner, CGSTProcessing another party's data does not necessarily constitute ownership of that data
SS&C Technologies Holdings v. D.E. Shaw & Co.Data-ownership provisions can affect portability and competition/vendor lock-in
Microsoft Corp. v. United StatesCloud data creates difficult questions concerning location, jurisdiction and control

33. Key Legal Principles for Examinations

The following points are particularly important:

  1. Cloud storage does not automatically transfer ownership of data to the cloud provider.
  2. Ownership and access are different legal concepts.
  3. Custody and processing do not necessarily constitute ownership.
  4. The cloud provider normally owns its platform, software and infrastructure, while the customer generally retains rights in its customer data, subject to the contract.
  5. Contractual language is the first place to look for allocation of data rights.
  6. Raw, derived, aggregated and anonymised data should be separately defined.
  7. A provider's right to process data for service delivery does not automatically create a right to commercially exploit it.
  8. Data portability is an important practical component of ownership.
  9. Termination provisions should deal with return, retention and deletion.
  10. Personal-data rights are not identical to commercial ownership rights.
  11. Copyright does not automatically protect every item of data.
  12. Confidential business information may receive protection through contractual and trade-secret principles.
  13. AI training creates new disputes concerning derived data, model ownership and outputs.
  14. Cloud data may be geographically distributed, creating jurisdictional complications.
  15. Vendor lock-in can transform a data-ownership dispute into a competition or interoperability issue.

34. Conclusion

Cloud Data Ownership Disputes arise because cloud computing separates data from the physical infrastructure on which it is stored. The customer may own or control the underlying information while the cloud provider possesses the technical infrastructure necessary to access, process, back up and transmit it.

Indian law does not treat “data ownership” as one simple universal property right. The legal position depends upon a combination of:

  • contract law;
  • intellectual-property law;
  • confidentiality and trade-secret principles;
  • data-protection law;
  • information-technology law;
  • competition law;
  • arbitration law.

The Salesforce decisions are particularly useful because they demonstrate the distinction between customer ownership of data and provider ownership of the cloud service, while North Mississippi Medical Center v. Quartiz Technologies provides a clear example of an express contractual allocation of cloud-data ownership.

Ultimately, the safest legal approach is to ensure that the cloud agreement expressly answers six questions:

Who owns the raw data? Who may access it? Who may use it? Who owns derived/aggregated data? How can the customer retrieve it? What happens to it after termination?

If these questions are not answered clearly, cloud data can become the subject of substantial contractual, IP, confidentiality, privacy, competition and cross-border litigation.

LEAVE A COMMENT