Define: Customer Information

In a contract, Customer Information refers to non-public, personally identifiable, or commercially sensitive details about a customer that one party obtains, generates, or accesses while performing services. It typically includes contact details, account records, transaction history, and preferences, and is protected by confidentiality, data protection, and permitted-use obligations set out in the agreement.

Legal accuracy standard set & glossary spot-checked by Imad Mohammed Nazar , Skadden-trained M&A lawyer, Legal Engineer at GenieAI

What Customer Information Means in a Contract

Customer Information is a defined term used to identify the specific category of data that receives heightened protection under a services or supply agreement. It typically covers any non-public detail relating to an identifiable customer, such as names, contact records, purchase or billing history, account credentials, and behavioral or preference data collected during the relationship. The term matters because it draws a line between ordinary business data and the sensitive personal or commercial details that trigger confidentiality, security, and data protection duties.

Contracts use this defined term to avoid ambiguity about what falls inside the protective regime. Rather than relying on a general reference to "confidential information," a dedicated Customer Information clause narrows the scope to data tied to end customers, which is often subject to separate legal obligations under data protection law, sector regulation, or contractual promises made to those customers. This distinction is especially important in outsourcing, cloud, and managed services arrangements where a supplier handles data on behalf of a customer-facing business.

How Customer Information Is Defined or Measured

Most agreements define Customer Information by listing categories of data rather than relying on a vague general description. Common elements include personally identifiable information, financial or payment details, usage patterns, support tickets, and any information the customer has designated as confidential. Some definitions also capture derivative data, meaning information created by analyzing or aggregating raw customer records, which can be a significant point of negotiation.

  • Personal identifiers such as name, address, email, and phone number
  • Account and transactional data, including purchase history and billing records
  • Technical or usage data collected through a product or service
  • Any information expressly marked or reasonably understood as confidential

Because the scope of the definition determines the reach of downstream obligations, well-drafted contracts also clarify what is excluded, such as information that is already public, independently developed, or lawfully obtained from a third party without restriction. These carve-outs prevent the defined term from becoming so broad that ordinary business activity is inadvertently restricted.

Where Customer Information Appears in Agreements

The term commonly appears in confidentiality clauses, data processing schedules, and service-level provisions within technology and outsourcing contracts, including a Cloud Services Agreement or a Managed Services Agreement. It also surfaces in incident response provisions, where a breach involving Customer Information triggers notification duties, and is frequently cross-referenced from an Information Security Policy that governs how such data must be stored, accessed, and transmitted.

Beyond technology contracts, the concept is relevant wherever a third party gains access to customer-facing data, such as consultancy engagements, call center outsourcing, or marketing service arrangements. A standalone Non-Disclosure Agreement may also incorporate the definition when parties exchange customer lists or account data during due diligence or partnership discussions.

Why the Exact Wording Matters

The precise scope of the Customer Information definition directly shapes the parties' obligations and liability exposure. A narrow definition might leave gaps that allow sensitive data to escape protection, while an overly broad one can create compliance burdens disproportionate to the actual risk. Ambiguous language around ownership, permitted use, and retention can also lead to disputes when a contract ends, particularly over whether a supplier must delete, return, or may retain anonymized derivatives of the data.

Wording also affects how remedies operate. If a breach clause ties notification duties, indemnities, or termination rights specifically to Customer Information, then any dispute over whether particular data falls within that definition can delay or block enforcement. Courts applying the law governing the contract will generally interpret the defined term according to its plain wording, so imprecise drafting increases the risk of an outcome the parties did not intend.

Drafting Considerations

Drafters should align the Customer Information definition with applicable data protection obligations and any promises made directly to end customers, ensuring consistency across related documents such as privacy notices and processing agreements. It is also wise to specify permitted uses, such as service delivery, analytics, or compliance reporting, and to prohibit any use beyond those purposes without consent.

Retention, return, and destruction obligations should be addressed explicitly, along with audit rights that allow verification of compliance. Parties operating in regulated sectors, such as those served by teams in Security teams, often add specific security controls or reference recognized frameworks to reduce ambiguity. Finally, definitions should be reviewed periodically, since new data types or processing activities can fall outside an older, narrower definition and leave gaps in protection.

Relevant Circumstances

  • Sale of customer databases.
  • Outsourcing customer support functions.
  • Seeking consent for data processing and data sharing.
  • Identifying and mitigating data breaches.

Looking for a quick legal answer?

Draft, review and negotiate legal documents empowered by the market-leading contracting AI.

No credit card required - 30-second signup