Westminster & Partners / Expertise
Technology, Data & AI
Legal structure for technology that businesses can use, scale and invest in.
Technology decisions become contractual and governance decisions long before a product launches. Who may use the software? What may a supplier do with customer data? Who owns commissioned development? Which decisions require human review? What happens when a critical provider changes its service or the relationship ends?
We help businesses address those questions across technology transactions, data arrangements and the adoption of artificial intelligence. Our focus is the legal framework supporting the product and its operation, working with the people responsible for technical delivery, security and commercial decisions.
The price is only one issue in a technology agreement. Permitted use, renewal exposure, data access, ownership and the ability to change supplier also need attention.
01 / Westminster & Partners
Where we advise
SaaS, software licensing and technology procurement
We prepare and negotiate subscription agreements, enterprise SaaS terms, software licences, platform terms and related implementation and support arrangements. For providers, the work connects the product's permitted uses and commercial model with customer commitments. For buyers, it examines the rights, dependencies and restrictions that can affect deployment and future change.
Key points include authorised users and group-company access, licence metrics, usage limits, overage charges, renewal pricing, audit rights, acceptable use and suspension. We address service availability, material functionality changes, data export and the practical consequences of switching supplier. General pricing, liability and delivery provisions are coordinated with our Commercial Contracts practice.
Development, implementation and ownership
We advise on software development, integration, implementation and technical consultancy agreements. Clear specifications, milestone acceptance, change control and customer dependencies help distinguish an unfinished deliverable from a new requirement.
We examine the chain of rights in code, documentation and other deliverables, including employee or contractor contributions, pre-existing tools and third-party components. Contracts should distinguish ownership from a licence and explain what the client can use, modify or transfer. Maintenance obligations, access to source materials and any proposed escrow arrangement require their own commercial and technical assessment.
Data-processing and data-sharing arrangements
We help identify which organisation determines a processing activity and which acts on another's instructions, rather than assuming the contract's chosen label settles the question. The documentation may involve a processor agreement, controller-to-controller sharing terms or arrangements between joint controllers.
The contractual work addresses permitted purposes, instructions, access, confidentiality, security commitments, subcontractors, assistance with rights requests, incident cooperation, audits and return or deletion. We work with the business's actual data flows and controls so schedules describe the service being delivered, not a generic set of assurances that operations cannot support.
International data flows
Overseas hosting, support access and group sharing can raise different transfer questions. We map the relevant flows and assess whether restricted-transfer rules apply before selecting documentation.
Where contractual safeguards are appropriate, support may include a UK International Data Transfer Agreement or the UK Addendum to relevant EU standard clauses, together with the applicable transfer assessment and supporting measures. A signed form is not a substitute for understanding the recipients, onward transfers and protections in practice. EU or other local-law requirements are scoped separately where relevant.
AI products, procurement and commercial terms
We advise on the legal terms for buying, supplying and integrating AI-enabled services. That includes pilots, enterprise subscriptions, API arrangements and AI functionality embedded within a wider product.
We address permitted inputs and uses, access to confidential or personal information, retention, model training and improvement rights, third-party model dependencies and changes to functionality. The allocation of rights in prompts, datasets and outputs needs careful drafting; contractual permission should not be confused with a guarantee that every output attracts intellectual-property protection or is free of third-party claims.
Warranties, indemnities, evaluation criteria and human-review requirements should reflect the intended use. We also address restrictions on deployment, information needed to investigate errors, termination and the treatment of retained data or model-related assets when the service ends.
AI governance and accountable deployment
We help turn an AI initiative into a defined decision and approval process: which tools may be used, for what purpose, with which information, under whose responsibility and subject to what review.
Work can include an inventory of intended uses, a risk-triage framework, supplier questions, acceptable-use guidance, approval records and procedures for material changes or incidents. We identify when a data protection impact assessment, further regulatory analysis or specialist technical evaluation is needed. Higher-risk uses require a closer examination of the affected people, the decisions being supported and the safeguards available; one policy cannot answer every use case.
Privacy documentation and operational implementation
We support privacy notices, internal guidance, retention frameworks, rights-request procedures and contractual incident-response arrangements. Advice starts with how information is collected and used, who receives it and which obligations the business can actually implement.
A targeted review may cover a new product, an enterprise customer's requirements or a known gap in existing documentation. We prioritise the decisions and evidence needed to make progress, coordinating with internal privacy and security owners rather than treating new documents as a complete compliance programme.
Technology and data in investment and M&A
For investment in a technology business, the questions include who owns the core IP, whether key licences survive investment and whether the proposed use of data is supported.
Technology and data issues can affect the value and transferability of a business. We support legal due diligence on core licences, contractor assignments, key suppliers, data rights, AI dependencies and restrictions triggered by a change of ownership.
Findings can inform pre-completion remediation, transaction protections, disclosures and integration priorities. We distinguish the legal review from technical diligence and involve specialist advisers where code, architecture, security or model performance needs independent assessment.
02 / Westminster & Partners
Practical outputs
An engagement may produce a negotiated technology agreement, a data-processing or sharing schedule, a transfer-documentation pack, an AI use policy, a prioritised legal-risk register or a transaction due-diligence report. We agree the relevant deliverables and the decisions required from the business before work begins.
03 / Westminster & Partners
How the work progresses
- Define the decision. Establish the product, intended users, commercial objective and proposed deadline. Identify the legal entities, jurisdictions and internal decision-makers involved.
- Map the dependencies. Review the relevant contracts, information flows, third-party services and rights in the technology. Identify missing evidence and technical questions for the appropriate owners.
- Prioritise and document. Separate matters that could prevent the proposed use from points that can be negotiated or managed. Prepare the agreed contracts, assessments or governance documents.
- Resolve and implement. Work through counterparty comments and internal decisions, recording accepted risks and the controls or actions assigned to the business.
- Handover and review triggers. Set out continuing obligations and the changes that should prompt another review, such as new data uses, a replacement model provider or expansion into another market.
04 / Westminster & Partners
Questions clients ask
Can you review an AI supplier before we introduce its product?
Yes. The review can focus on contractual rights, information use, supplier dependencies and the intended deployment. Technical and security testing remain separate workstreams.
Can you certify that our AI product is compliant?
No single review can certify every use of a changing product. We can assess an agreed scope, document identified issues and support the decisions and improvements needed.
Do you build software or conduct penetration testing?
No. Our role is legal advice and documentation. Engineering, security testing, patent prosecution and litigation require separate specialist services.
Can you work alongside our product, security or in-house legal team?
Yes. We can take responsibility for a defined legal workstream or provide additional support on a specific transaction. We agree the division of work, information needed and escalation points at the outset.
05 / Westminster & Partners
Commercial focus
Technology decisions involve more than procurement price. We focus on permitted use, ownership and access to data, supplier accountability, governance and the ability to change or end an arrangement.
06 / Westminster & Partners
Published work and professional discussion
AI and financial services
Muklesur Bharuya has contributed to FT Adviser on AI in financial advice:
- AI will make managing money a whole lot easier — 13 May 2024.
- AI in advice firms: what advisers need to know — 18 July 2024.
Generative AI and legal technology
The Franco-British Lawyers Society's 2023 programme lists Muklesur as a speaker on generative AI and legal technology at City Launch Lab.
Connected to the businesses building with AI
Our involvement with AI Founders Connect provides a forum for conversations with founders, investors and technology businesses. It is a separate community initiative, distinct from the legal services we provide.
07 / Westminster & Partners
Next step
Tell us what you are building, buying or changing, the proposed use of data, and the decision you need to make.