Sell Data to AI
Home Data Asset Score Pricing API documentation US labs and CROs list
For brokers
How to become an AI data broker Data broker business model Buyer programs compared Qualify a company AI training data companies
For data companies
Firmographic data providers Company data API
Seller guides
How to sell data to AI companies Is it legal? FAQ and glossary About
Check domain/company
EU and UK sellers

GDPR and Selling Company Data for AI Training

If your company is in the EU or the UK, most records an AI buyer wants contain personal data: names in email threads, colleagues in chat, customers in tickets. The GDPR has no single rule for this deal; several articles apply at once. This guide names them and the questions to settle before you sign.

Last checked: October 7, 2026. Buyer statements quoted as published on that date.

US firstmicro1: “US prioritized,” then other Western markets
20+Mode: full-time US office employees
60 to 90 daysTypical close, as practitioners cite it
Agreed copyWhat Mode says it buys; originals stay
The basic picture

What a data sale looks like through GDPR eyes

Buyer programs describe the deal in business terms: an export of documents, messages and project histories, de-identified, licensed for AI training. Data protection law sees something else. Your company collected personal data to run the business. Giving a copy to another company to train models is a new use and a disclosure to a third party. Both are “processing” under the GDPR, and each needs a justification.

So the work starts with an inventory of who appears in your records, not with a price. For the wider legal picture beyond data protection, read is it legal to sell company data.

Definition: personal data (GDPR Article 4(1))

Any information relating to an identified or identifiable natural person. In a company archive: names, email addresses, signatures, phone numbers, and often message content that describes a person, such as a sick day or a complaint.

UK companies work under the UK GDPR, read together with the Data Protection Act 2018. The structure is close to the EU text, but the two can diverge. A UK seller should get UK advice, and a group with staff in both should expect two sets of answers.

Location rules

Why most programs say “US first”

What each program publishes about where a seller should be, as published on October 7, 2026.

ProgramWhat its page says about location and languageLast checked
micro1“Primarily English”; “US prioritized,” then “other Western markets.” Also lists 30+ employees and documented processes.Oct 7, 2026
Mode“20+ full-time US office employees” (accounting firms 10+, law firms 6+); “US-based teams strongest fit.”Oct 7, 2026
GreppedLists any vertical. Read its current page for country rules.Oct 7, 2026

Sources: each program's own page. Full side-by-side terms are on buyer programs compared.

None of these pages gives a reason for the preference, and we will not guess. What we can describe is the extra work an EU or UK seller should plan for: a documented lawful basis per data source, updated notices, a transfer mechanism if data leaves the EU or UK, possibly an impact assessment, and in some countries a conversation with employee representatives. All of it adds time to the 60 to 90 days practitioners cite for a deal to close.

Before you spend money on any of it, run the eligibility checker to see which programs you fit on paper.

The articles that apply

Six GDPR questions every EU or UK seller faces

Each card names the rule and the question to take to your lawyer.

Article 6

1 Lawful basis

Article 6 lists six lawful bases. For archived records, discussion tends to center on consent and legitimate interests. The latter needs a balancing test against the rights and expectations of the people in the data. Ask: which basis fits each source, and is the test documented?

Art. 5(1)(b), 6(4)

2 Purpose limitation

Data collected for one purpose should not be further processed in an incompatible way. Article 6(4) lists factors: the link between purposes, context, nature of the data, consequences and safeguards. Ask: is AI training compatible with why these records were created?

Articles 13 and 14

3 Transparency

People must be told how their data is used. Article 14 covers data obtained from someone other than the person, which is what the buyer receives. Ask: who gives notice, to whom (staff, former staff, customers), and when?

Article 9

4 Special categories

Health, trade union membership, religious beliefs, biometric data and other listed categories may not be processed unless an exception applies. Archives hold them by accident: sick-leave emails, HR threads. Ask: how will these be found and removed before export?

Article 21

5 Right to object

Where processing rests on legitimate interests, people can object, and other rights such as erasure may apply. Ask: how do we handle a request after the copy has left, and what must the buyer do?

Article 28

6 Who is controller

Is the buyer your processor, acting on your instructions, or an independent controller with its own purposes? A processor needs an Article 28 agreement; a controller-to-controller disclosure is a different document. Ask: which fits this deal?

Recital 26

De-identified is not the same as anonymous

Buyers talk about de-identification. The GDPR draws a sharper line, and it decides whether the law still applies.

Pseudonymized

  • Names and identifiers replaced with consistent tokens, so “Person 14” stays the same person across threads.
  • Recital 26: data that could be attributed to a person using additional information should be considered information on an identifiable person.
  • So the GDPR still applies to whoever holds it.

Anonymous

  • Recital 26: the GDPR does not apply to information that does not relate to an identified or identifiable person.
  • The test considers all means reasonably likely to be used to identify someone.
  • Hard to reach for rich work records, because content itself can point to a person.

Buyers publish statements about process. micro1's page, as published on October 7, 2026, says the scope is agreed in writing, sensitive and confidential information is scrubbed, originals are deleted after processing, no customer information is exposed, and the company keeps ownership of its underlying data. Mode's page says it buys “an agreed copy,” the originals stay with the company, and it de-identifies before onward delivery.

Whether the output counts as anonymous or pseudonymous under the GDPR is a legal question about your data. Timing matters too: if scrubbing happens after the copy reaches the buyer, the transfer carries identifiable data. Ask the buyer which method it uses and where, and ask your lawyer which label applies. More in de-identification before selling data.

Chapter V

International transfers: where the copy goes next

If the buyer or its downstream recipients are outside the EU or UK, transfer rules apply on top of everything above.

Art. 6Six lawful bases
Art. 21Right to object
Art. 35Impact assessment
Chapter VTransfers abroad

Chapter V of the GDPR governs transfers of personal data outside the EU. The main routes are an adequacy decision, appropriate safeguards such as standard contractual clauses, and narrow derogations. For the United States, the EU-US Data Privacy Framework exists for companies that certify under it. UK sellers work under the UK's own transfer rules. Which route fits depends on who receives the data, whether it is still personal data on arrival, and where it goes next.

Onward delivery adds a second hop, which may be less clear than the first. Ask the buyer for recipient categories, and ask your lawyer what each hop needs.

Adequacy decisions Standard contractual clauses EU-US Data Privacy Framework Downstream recipients
Inside the company

DPIAs, employees and works councils

Data protection impact assessment

Article 35 requires a DPIA where processing is likely to result in a high risk to people's rights and freedoms. Ask your lawyer or data protection officer whether your deal meets that threshold. Even if not required, a DPIA-style write-up forces the inventory buyers ask for: sources, people, exclusions, safeguards.

Employees and their representatives

Chat and email archives are mostly employee data. Article 88 lets member states set more specific rules for employment data. In some countries employee representatives have consultation or co-determination rights; works councils under Germany's Works Constitution Act are one example. Whether a data sale triggers such rights is a question for local employment counsel. See employees and selling company data.

Client data is a separate gate. Professional firms also owe confidentiality to clients under contracts and professional rules, separate from the GDPR. See client confidentiality and data sales.
Two lists of questions

What to ask your lawyer, and what to ask the buyer

Take the middle column to your adviser and the right column to every program you talk to.

TopicAsk your lawyerAsk the buyer
Lawful basisWhich Article 6 basis fits each source? Is the balancing test written down?What basis do you rely on for your own use of the data?
CompatibilityDoes the Article 6(4) test support this further use?Is the use training only, or also evaluation and onward delivery?
NoticeWho must we inform: staff, former staff, customers, suppliers?Will you provide a contact point for requests from people in the data?
Special categoriesHow do we find and exclude Article 9 data?What does your scrubbing remove? Can we review sample output?
RolesIs the buyer our processor or an independent controller?Which contract form do you propose for data protection terms?
TransfersWhich Chapter V route applies, for each hop?Where is the data stored, and who receives it downstream?
DPIAIs one required under Article 35?Will you describe your de-identification method for our assessment?
Worked example

How a fictional Dutch software firm might work through it

A made-up company, used to show the order of questions. Nothing here is a real case, a legal conclusion or a price.

Illustrative, not an offer

Fictional profile: “Firm A”

Team
45 people, all in the Netherlands, no US office
Working language
English internally, Dutch with some clients
Records
Six years of GitHub history, Jira tickets, Slack, Google Workspace email, Zendesk support tickets
Customers
EU businesses; tickets name their staff
  1. Fit on paper. Firm A runs the checker. 45 people clears micro1's published 30+, and the Netherlands is a Western market, though micro1 says the US is prioritized. Mode's published minimum counts full-time US office employees, and Firm A has none. Grepped lists any vertical.
  2. Scope first. The founders choose a narrow first scope: code history and Jira. Email and support tickets, the sources richest in customer personal data, stay out of the first conversation.
  3. Lawyer and DPO. They ask which Article 6 basis fits Slack threads that sit alongside Jira, whether Article 14 notices go to former staff, and whether Article 35 calls for a DPIA.
  4. Representatives. They ask local counsel whether the Dutch Works Councils Act (Wet op de ondernemingsraden) or any other employee representation rule applies at their size.
  5. Transfer route. They ask each buyer where data is stored and who receives it next, so counsel can map a Chapter V route for each hop.
  6. Records. They write down every decision and every exclusion, because the file is what they would show a regulator or an auditor.
Contract checks

Questions to ask before you sign

These apply to any data licensing agreement, with any buyer. The AI data licensing agreement guide walks through each clause.

Consent and rights warranties

You may be asked to warrant that you may share the data. That covers your lawful basis and notices. Can you give it honestly?

Indemnities

Who pays if de-identification misses something? Is liability capped, and does it expire?

Scope of use

Training only, or evaluation too? Which downstream buyers? Narrow scope is easier to square with purpose limitation.

Exclusivity and resale

None, time-limited or perpetual? Resale widens the recipients your notices must cover.

Audit rights

Can you verify the de-identification, or see a sample before acceptance?

Deletion and exit

When are originals and copies deleted? What survives termination? How are later erasure requests honored?

Avoid these

Common mistakes EU and UK sellers make

Each one is easy to make early, and costly to fix after the copy has left.

“De-identified” read as “outside GDPR”

Pseudonymized data is still personal data under Recital 26. Plan as if the law applies until your lawyer says otherwise.

Relying on the buyer's process

Article 5(2) makes the controller responsible for compliance and able to demonstrate it. A buyer's statements do not replace your own records.

Samples before review

A sample of real messages is already a disclosure. Share a manifest first: systems, years, volumes, exclusions.

Forgetting former staff

Archives reach back years. People who left, and your customers' employees, are in the data and may be owed notice.

Missing Article 9 data

HR channels, sick-leave emails and benefits threads hold special-category data. Exclude these channels by default.

No written decisions

Lawful basis, balancing test, DPIA decision, exclusions: if it is not written down, you cannot show it later.

Step by step

The EU and UK seller's path

Cheap checks first. Legal spend once you know a program could fit.

1

Check fit on published rules

Headcount, location, language and systems against each program's page. The eligibility checker does this in your browser.

2

Inventory and exclusions

List systems, years and the people in each: staff, former staff, customers, suppliers. Mark HR channels, client-confidential folders and likely Article 9 data as excluded.

3

First legal review

Lawful basis per source, the Article 6(4) compatibility test, controller or processor roles, whether a DPIA is needed, whether employee representatives must be involved.

4

NDA and manifest, not data

Describe the data to buyers. Ask the right-hand column of the table above. Compare more than one answer.

5

Notices, transfer route, terms

Settle Article 13 and 14 notices, the Chapter V route for each hop and the data protection terms before anyone signs.

6

Export, de-identification, acceptance

Only the agreed scope leaves. Review sample output, keep a record of what was excluded and when copies are deleted.

FAQ

GDPR and AI data sales: common questions

Does the GDPR forbid selling company data for AI training?

The GDPR has no article written for this exact deal. It sets rules every disclosure of personal data must meet: a lawful basis, compatibility with the original purpose, transparency, safeguards for special-category data and, for transfers abroad, Chapter V. Whether a specific sale meets them depends on your data and the contract. Only a lawyer can answer that for your company.

If the buyer de-identifies the data, does the GDPR still apply?

It depends on the result and the timing. Recital 26 treats pseudonymized data that could be linked back to a person as personal data. Only information that no longer relates to an identifiable person falls outside the GDPR. If scrubbing happens after export, the transfer itself carries identifiable data.

Can a company in the EU or UK apply to buyer programs at all?

Published rules vary. micro1’s page lists “primarily English” and “US prioritized, then other Western markets.” Mode’s page lists 20+ full-time US office employees and calls US-based teams the strongest fit. Grepped lists any vertical. Read each program’s current page for its country rules, and use the eligibility checker to compare your answers with the published rules.

Do we need consent from every employee?

Consent is one of six lawful bases in Article 6, not the only one. In employment, regulators have questioned whether consent can be freely given, given the imbalance between employer and employee. Ask your lawyer which basis fits, and whether employee representatives must be informed or consulted.

Is a DPIA mandatory before a data sale?

Article 35 requires a data protection impact assessment where processing is likely to result in a high risk to people’s rights and freedoms. Large volumes of staff and customer communications reused by another company are a case where the question should be asked. Your lawyer or data protection officer should decide and record the decision.

Do UK sellers follow different rules from EU sellers?

UK sellers work under the UK GDPR and the Data Protection Act 2018, with their own regulator, the Information Commissioner’s Office, and their own transfer rules. The texts are close to the EU GDPR but separate, and they can diverge. A group with staff in both the UK and the EU should get advice on each regime.

Can we send a buyer sample records before signing?

A sample of real records is still personal data, and sending it is already a disclosure. A safer order is a manifest first: systems, years, volumes, categories and exclusions. If a buyer needs samples to evaluate the data, ask your lawyer whether they should be scrubbed first and covered by an NDA.

Who is responsible if personal data slips through de-identification?

Article 5(2) makes the controller responsible for compliance and able to demonstrate it, and each party’s exposure depends on its role in the deal. Between you and the buyer, the contract allocates cost through warranties and indemnities. Ask who pays, whether liability is capped, and how long it lasts after the deal ends.

Check your fit before you pay for legal work

If a program fits on its published rules, the questions above are worth a lawyer's time. If none fits, you saved the expense. The checker runs in your browser.

Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data.

Related reading

Keep going