For sellers3 min read
Is it legal to sell company data to AI labs?
Three questions decide whether a specific dataset can be licensed, what the "data broker" laws actually cover, and who carries the risk if something leaks.
Licensing your own company's operating data is an ordinary commercial transaction. Whether a specific dataset can go depends on three things: you own it, your customer contracts allow de-identified use, and personal information can be removed before anyone outside the company sees it. Most deals that die, die on the first one.
Question one: do you own it?
A company holds two kinds of material side by side that look the same. One is its own operating data, made in the course of its own work: internal chat, its own CRM, its own tickets, its own books. That belongs to the company. The other is material held on behalf of a client, usually under a master services agreement that assigns ownership to the client. Agency work product, a law firm's client files, a bookkeeper's client ledgers. That second kind cannot be licensed no matter what it would fetch.
Only the contracts separate the two. Sorting this out is the first check with any seller, before any buyer hears the company name.
Question two: what do your customer agreements say?
Terms of service, master agreements and data processing addenda often restrict use and disclosure further than owners remember. The clause that matters is the one about aggregated or de-identified use. Many agreements expressly permit it. That clause is the door most licensing deals walk through. Where it is missing, the data that mentions that customer may need to stay out of scope.
Question three: can personal information be removed?
Privacy law governs personal information, not business data as such. Operating data with the identifying material stripped sits in a different category from one that carries it. That is why de-identification happens before anything moves, and why no buyer with regulatory exposure will accept a dataset that still has names in it.
Removal is done by a third-party vendor, not by the seller. The vendor replaces names, emails, phone numbers and account identifiers with stable pseudonyms so that "Priya" becomes "employee 632" everywhere she appears. Relationships survive; identities do not. The vendor holds the raw export for about a week and deletes it. Buyers now use benchmarks for this work and publish their methods.
What about "data broker" laws?
California, Vermont, Texas and Oregon require data brokers to register. Those laws are aimed at businesses that collect and sell personal information about individuals they have no relationship with: people-search sites, marketing list sellers. A company licensing its own de-identified operating data is a different activity. Whether a given intermediary needs to register is a question for counsel, and we are getting that answer for our own position. It is worth asking about any broker you talk to.
Who is liable if something leaks?
Under most contracts, everyone in the chain: the seller who warranted the data, the broker who handled it, the vendor who de-identified it, the buyer who received it. That is the honest answer buyers give when asked. It is also why the process has the shape it does: a third party does the stripping, the seller reviews a sample before acceptance, raw files are deleted on a schedule, and handling terms go in the license rather than in an email. One buyer has started piloting insurance for these transactions.
Regulated industries
Healthcare is more workable than people expect, because de-identifying patient data for research and training is an established practice with established vendors. Finance, legal and anything under non-disclosure is harder, because material can be confidential without containing any personal information at all. Those data get de-identified on the seller's own premises at higher cost, or stay home.
Questions people ask
Do my employees have to consent?
Their names, emails and identifiers are removed before anyone outside the company sees the data, which is the basis most deals rest on. Whether notice is also owed depends on your jurisdiction and your own policies. Ask counsel, and tell your team anyway; it goes better.
Can I de-identify the data myself to save money?
Every buyer says no. Home-made redaction breaks the links between people and events that make the data valuable, and misses things. Use the vendor; it is a line item in the deal.
What if a customer later asks to be deleted?
Deletion requests are forwarded under the license, and the buyer honours them for stored data. Models already trained on accepted data is generally not retrained. Check how your buyer's license handles this before signing.