Data Usage Monitoring
You Know What You Sent. You Have No Idea What They Do With It.
7 min read · 24 July 2026 · Privacy
A pharmaceutical company engaged a data analytics vendor under a DPA that specifically limited data use to competitive intelligence analytics for the contracted scope. Two years into the relationship, an ex-employee of the analytics vendor disclosed in an exit interview that customer datasets , including the pharmaceutical company's , were routinely being used as inputs to the vendor's internal model training pipeline, which produced predictive analytics products sold to other clients. The ex-employee had found the pipeline configuration accidentally and mentioned it in passing. The DPA prohibited this use. The vendor's internal data usage monitoring was insufficient to detect or prevent the scope violation. The pharmaceutical company had no mechanism to monitor how their data was being used in the vendor's environment , the DPA specified the authorized use, but no technical or operational monitoring confirmed whether that use was the actual use. When the disclosure surfaced, the pharmaceutical company could not determine how long the unauthorized use had been occurring, what models had been trained on their data, or what products incorporating their data had been sold. The DPA was clear. The monitoring was absent. The violation ran undetected for an indeterminate period.
What is the Data Usage Monitoring Problem, Really?
Data usage monitoring is the capability to observe how data is actually being processed in a vendor's environment , what queries are run against it, what pipelines consume it, what products reference it, and whether its actual use is consistent with the contractual use specification. It is the difference between specifying permitted use in a DPA and having visibility into whether permitted use is what is occurring. Without usage monitoring, a DPA is a governance instrument that documents authorized use and has no mechanism to detect unauthorized use.
The trust-vs-verify gap is the structural problem. Most DPA relationships are governed through trust , the vendor agrees to use data only for authorized purposes, and the customer trusts that the vendor is honoring that agreement. Trust is not inherently unreasonable in established vendor relationships. It is insufficient governance when the consequences of trust violations include regulatory breach, competitive intelligence disclosure, and unauthorized model training that cannot be remediated after the fact. Data usage monitoring converts the governance model from trust to verified , providing technical evidence of what is actually happening rather than relying on vendor self-certification of compliance.
The unauthorized use discovery problem is where trust-based governance consistently fails. Unauthorized uses of customer data , model training, competitive benchmarking, product feature development , are not the result of vendors announcing their intentions. They emerge through normal product development decisions that, from inside the vendor's organization, may not be recognized as DPA violations. A data engineer who adds a customer dataset to a training pipeline as the most readily available data source for a model development task may not know or consider whether that dataset's DPA permits model training use. The violation is real. It is not necessarily deliberate. And without monitoring, it runs until something external , an employee disclosure, a regulatory audit, a DSAR response , makes it visible.
- No query-level monitoring , absence of technical visibility into what queries are run against customer data
- No pipeline usage monitoring , inability to detect whether customer data is consumed by analytics or model training pipelines beyond authorized scope
- No product attribution monitoring , absence of mechanism to detect whether customer data contributes to vendor commercial products
- DPA compliance not technically enforced , authorized use specified contractually without technical controls enforcing scope restriction
- No customer visibility mechanism , customer has no access to usage logs or usage reports confirming authorized use
Why this matters
Data usage monitoring matters for TPRM because it is the mechanism that converts a DPA from a statement of authorized use into an enforceable governance instrument. A DPA without usage monitoring specifies the authorized use and creates legal recourse if the specification is violated. A DPA with usage monitoring provides the detection capability that makes violations discoverable before they become long-running undiscovered scope expansions.
The AI and ML dimension makes this increasingly urgent. As vendors integrate AI capabilities into their products, the temptation to use rich customer datasets as training inputs is commercially significant , customer data produces better models, better models produce better products, better products produce more revenue. The incentive to use customer data beyond the contracted scope exists at scale across the analytics, AI, and SaaS vendor landscape. Monitoring is the mechanism that distinguishes vendors who honor their DPA commitments from those who find their way to convenient data regardless.
For TPRM practitioners, data usage monitoring represents a significant governance gap in most current TPRM programs , usage monitoring is rarely assessed because it is rarely present, and its absence is normalized as the standard for DPA-governed data sharing. Asking for it raises the governance bar and creates a market signal that monitoring matters.
Where most teams get this wrong
The most consistent failure is treating the DPA as the complete governance instrument for data use. The DPA specifies the authorized use. Monitoring confirms whether the authorized use is the actual use. Neither substitutes for the other. A DPA without monitoring is governance documentation without governance verification. The pharmaceutical company's DPA was clear. The clarity did not detect the training pipeline.
- Treating DPA as complete governance without monitoring
- No usage monitoring requirement in DPA , authorized use specified without monitoring obligations
- No customer visibility into usage logs , vendor holds usage data with no customer access
- ML training use not specifically prohibited or monitored , a growing default secondary use
- Trust-based rather than verify-based DPA governance
What good looks like
Mature data usage governance programs provide customer visibility into how their data is being used , usage logs, query reports, pipeline attribution, and regular confirmation that actual use matches authorized use. At minimum, the vendor has internal monitoring that detects scope violations. Optimally, the customer has access to usage reports that provide independent verification.
- Internal usage monitoring , query logs, pipeline attribution, and product use monitoring that would detect scope violations
- Customer usage reports , periodic reports confirming actual data use against authorized scope
- ML training data monitoring , specific detection for whether customer data enters model training pipelines
- DPA compliance monitoring , automated detection of use patterns inconsistent with authorized scope
- Usage anomaly alerting , automated alerts on usage patterns that deviate from contracted use specification
Tooling
Data Access Governance , Imperva, Varonis, IBM Guardium
Database activity monitoring and data access governance platforms capture query-level usage data that can be analyzed for consistency with authorized use specifications. For TPRM practitioners, asking whether the vendor's DAM platform can generate customer-specific usage reports that confirm data queries were within authorized scope provides a specific monitoring-to-customer-visibility capability question.
ML Pipeline Governance , MLflow, Weights & Biases, Neptune.ai
ML experiment tracking platforms record training data provenance , documenting what datasets were used in model training runs. For TPRM practitioners, asking whether the vendor's ML infrastructure records data lineage that would detect unauthorized customer dataset use in model training provides a specific AI/ML scope monitoring question.
Governance challenges
The governance challenge with data usage monitoring is the operational sophistication required. Monitoring what queries are run against a dataset at the production scale requires DAM infrastructure. Monitoring what pipelines consume a dataset requires data lineage tooling. Monitoring what products reference a dataset requires product attribution infrastructure. This is a non-trivial technical investment that most analytics vendors have not made specifically for customer data scope compliance purposes.
- Add usage monitoring requirement to DPA , vendor obligation to maintain and provide usage logs
- Require customer usage reports , periodic confirmation of actual use against authorized scope
- Add ML training data prohibition monitoring , specific obligation to detect and prevent unauthorized training data use
- Ask about internal scope violation detection , would the vendor's monitoring detect the training pipeline scenario
- Include usage monitoring in vendor reassessments , confirming monitoring capability exists and is operational
If you are a small team
Add one requirement to your highest-risk DPAs at next renewal: the vendor must maintain logs of all queries run against customer data and must provide a quarterly usage report confirming that all logged queries were within the authorized use scope specified in the DPA. That single requirement transforms the DPA from trust-based to verify-based governance. The vendor who cannot fulfill it cannot demonstrate compliance with the DPA they signed.
- Add quarterly usage reporting to highest-risk DPA renewals
- Ask whether the vendor has internal monitoring that would detect the model training pipeline scenario
- Ask whether ML training use of customer data is specifically logged and monitored
- Ask for a sample usage report demonstrating what the monitoring captures
What to require
Ask directly:
"Do you maintain logs of all queries and pipeline processes run against our data , and can you provide us with periodic usage reports confirming that all usage was within the authorized scope specified in our DPA?"
"If our data were added to a model training pipeline without authorization, what technical monitoring would detect that and generate an alert , and has that monitoring ever triggered for any customer's data?"
"What is your process for confirming that customer data use is continuously within DPA scope , do you rely on trust and contractual obligations, or do you have technical monitoring that verifies scope compliance?"
Expect as evidence
- Internal usage monitoring confirmation , query logs and pipeline attribution
- Customer usage report sample
- ML training data monitoring description
- Scope violation detection capability description
A vendor who responds to the monitoring question with 'our staff understand the DPA restrictions' has described trust-based governance. Ask specifically what technical monitoring would detect if their data engineering team added customer data to a training pipeline without authorization. The answer describes whether monitoring exists or whether the DPA relies on everyone knowing and following the rules.
How to evidence it
- DPA usage monitoring requirement documentation
- Customer usage report records
- Scope violation monitoring capability confirmation
- ML training data monitoring evidence
Key Takeaway
The DPA specifies authorized use. Monitoring confirms whether authorized use is actual use. Without monitoring, the governance instrument that defines the boundary has no mechanism to detect when the boundary is crossed. The pharmaceutical company's data ran through a model training pipeline for an indeterminate period while the DPA said that was not permitted. The DPA was accurate about what was authorized. The training pipeline was real about what was happening. Between the authorization and the reality was two years of undetected scope violation discovered through an exit interview. Monitoring closes that gap. It converts the DPA from a statement of intent into a governed relationship with verification. The DPA is the boundary. Monitoring is the fence.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association