If your company is in the EU or the UK, most records an AI buyer wants contain personal data: names in email threads, colleagues in chat, customers in tickets. The GDPR has no single rule for this deal; several articles apply at once. This guide names them and the questions to settle before you sign.
Last checked: October 7, 2026. Buyer statements quoted as published on that date.
Buyer programs describe the deal in business terms: an export of documents, messages and project histories, de-identified, licensed for AI training. Data protection law sees something else. Your company collected personal data to run the business. Giving a copy to another company to train models is a new use and a disclosure to a third party. Both are “processing” under the GDPR, and each needs a justification.
So the work starts with an inventory of who appears in your records, not with a price. For the wider legal picture beyond data protection, read is it legal to sell company data.
Any information relating to an identified or identifiable natural person. In a company archive: names, email addresses, signatures, phone numbers, and often message content that describes a person, such as a sick day or a complaint.
UK companies work under the UK GDPR, read together with the Data Protection Act 2018. The structure is close to the EU text, but the two can diverge. A UK seller should get UK advice, and a group with staff in both should expect two sets of answers.
What each program publishes about where a seller should be, as published on October 7, 2026.
| Program | What its page says about location and language | Last checked |
|---|---|---|
| micro1 | “Primarily English”; “US prioritized,” then “other Western markets.” Also lists 30+ employees and documented processes. | Oct 7, 2026 |
| Mode | “20+ full-time US office employees” (accounting firms 10+, law firms 6+); “US-based teams strongest fit.” | Oct 7, 2026 |
| Grepped | Lists any vertical. Read its current page for country rules. | Oct 7, 2026 |
Sources: each program's own page. Full side-by-side terms are on buyer programs compared.
None of these pages gives a reason for the preference, and we will not guess. What we can describe is the extra work an EU or UK seller should plan for: a documented lawful basis per data source, updated notices, a transfer mechanism if data leaves the EU or UK, possibly an impact assessment, and in some countries a conversation with employee representatives. All of it adds time to the 60 to 90 days practitioners cite for a deal to close.
Before you spend money on any of it, run the eligibility checker to see which programs you fit on paper.
Each card names the rule and the question to take to your lawyer.
Article 6 lists six lawful bases. For archived records, discussion tends to center on consent and legitimate interests. The latter needs a balancing test against the rights and expectations of the people in the data. Ask: which basis fits each source, and is the test documented?
Data collected for one purpose should not be further processed in an incompatible way. Article 6(4) lists factors: the link between purposes, context, nature of the data, consequences and safeguards. Ask: is AI training compatible with why these records were created?
People must be told how their data is used. Article 14 covers data obtained from someone other than the person, which is what the buyer receives. Ask: who gives notice, to whom (staff, former staff, customers), and when?
Health, trade union membership, religious beliefs, biometric data and other listed categories may not be processed unless an exception applies. Archives hold them by accident: sick-leave emails, HR threads. Ask: how will these be found and removed before export?
Where processing rests on legitimate interests, people can object, and other rights such as erasure may apply. Ask: how do we handle a request after the copy has left, and what must the buyer do?
Is the buyer your processor, acting on your instructions, or an independent controller with its own purposes? A processor needs an Article 28 agreement; a controller-to-controller disclosure is a different document. Ask: which fits this deal?
Buyers talk about de-identification. The GDPR draws a sharper line, and it decides whether the law still applies.
Buyers publish statements about process. micro1's page, as published on October 7, 2026, says the scope is agreed in writing, sensitive and confidential information is scrubbed, originals are deleted after processing, no customer information is exposed, and the company keeps ownership of its underlying data. Mode's page says it buys “an agreed copy,” the originals stay with the company, and it de-identifies before onward delivery.
Whether the output counts as anonymous or pseudonymous under the GDPR is a legal question about your data. Timing matters too: if scrubbing happens after the copy reaches the buyer, the transfer carries identifiable data. Ask the buyer which method it uses and where, and ask your lawyer which label applies. More in de-identification before selling data.
If the buyer or its downstream recipients are outside the EU or UK, transfer rules apply on top of everything above.
Chapter V of the GDPR governs transfers of personal data outside the EU. The main routes are an adequacy decision, appropriate safeguards such as standard contractual clauses, and narrow derogations. For the United States, the EU-US Data Privacy Framework exists for companies that certify under it. UK sellers work under the UK's own transfer rules. Which route fits depends on who receives the data, whether it is still personal data on arrival, and where it goes next.
Onward delivery adds a second hop, which may be less clear than the first. Ask the buyer for recipient categories, and ask your lawyer what each hop needs.
Article 35 requires a DPIA where processing is likely to result in a high risk to people's rights and freedoms. Ask your lawyer or data protection officer whether your deal meets that threshold. Even if not required, a DPIA-style write-up forces the inventory buyers ask for: sources, people, exclusions, safeguards.
Chat and email archives are mostly employee data. Article 88 lets member states set more specific rules for employment data. In some countries employee representatives have consultation or co-determination rights; works councils under Germany's Works Constitution Act are one example. Whether a data sale triggers such rights is a question for local employment counsel. See employees and selling company data.
Take the middle column to your adviser and the right column to every program you talk to.
| Topic | Ask your lawyer | Ask the buyer |
|---|---|---|
| Lawful basis | Which Article 6 basis fits each source? Is the balancing test written down? | What basis do you rely on for your own use of the data? |
| Compatibility | Does the Article 6(4) test support this further use? | Is the use training only, or also evaluation and onward delivery? |
| Notice | Who must we inform: staff, former staff, customers, suppliers? | Will you provide a contact point for requests from people in the data? |
| Special categories | How do we find and exclude Article 9 data? | What does your scrubbing remove? Can we review sample output? |
| Roles | Is the buyer our processor or an independent controller? | Which contract form do you propose for data protection terms? |
| Transfers | Which Chapter V route applies, for each hop? | Where is the data stored, and who receives it downstream? |
| DPIA | Is one required under Article 35? | Will you describe your de-identification method for our assessment? |
A made-up company, used to show the order of questions. Nothing here is a real case, a legal conclusion or a price.
These apply to any data licensing agreement, with any buyer. The AI data licensing agreement guide walks through each clause.
You may be asked to warrant that you may share the data. That covers your lawful basis and notices. Can you give it honestly?
Who pays if de-identification misses something? Is liability capped, and does it expire?
Training only, or evaluation too? Which downstream buyers? Narrow scope is easier to square with purpose limitation.
None, time-limited or perpetual? Resale widens the recipients your notices must cover.
Can you verify the de-identification, or see a sample before acceptance?
When are originals and copies deleted? What survives termination? How are later erasure requests honored?
Each one is easy to make early, and costly to fix after the copy has left.
Pseudonymized data is still personal data under Recital 26. Plan as if the law applies until your lawyer says otherwise.
Article 5(2) makes the controller responsible for compliance and able to demonstrate it. A buyer's statements do not replace your own records.
A sample of real messages is already a disclosure. Share a manifest first: systems, years, volumes, exclusions.
Archives reach back years. People who left, and your customers' employees, are in the data and may be owed notice.
HR channels, sick-leave emails and benefits threads hold special-category data. Exclude these channels by default.
Lawful basis, balancing test, DPIA decision, exclusions: if it is not written down, you cannot show it later.
Cheap checks first. Legal spend once you know a program could fit.
Headcount, location, language and systems against each program's page. The eligibility checker does this in your browser.
List systems, years and the people in each: staff, former staff, customers, suppliers. Mark HR channels, client-confidential folders and likely Article 9 data as excluded.
Lawful basis per source, the Article 6(4) compatibility test, controller or processor roles, whether a DPIA is needed, whether employee representatives must be involved.
Describe the data to buyers. Ask the right-hand column of the table above. Compare more than one answer.
Settle Article 13 and 14 notices, the Chapter V route for each hop and the data protection terms before anyone signs.
Only the agreed scope leaves. Review sample output, keep a record of what was excluded and when copies are deleted.
The GDPR has no article written for this exact deal. It sets rules every disclosure of personal data must meet: a lawful basis, compatibility with the original purpose, transparency, safeguards for special-category data and, for transfers abroad, Chapter V. Whether a specific sale meets them depends on your data and the contract. Only a lawyer can answer that for your company.
It depends on the result and the timing. Recital 26 treats pseudonymized data that could be linked back to a person as personal data. Only information that no longer relates to an identifiable person falls outside the GDPR. If scrubbing happens after export, the transfer itself carries identifiable data.
Published rules vary. micro1’s page lists “primarily English” and “US prioritized, then other Western markets.” Mode’s page lists 20+ full-time US office employees and calls US-based teams the strongest fit. Grepped lists any vertical. Read each program’s current page for its country rules, and use the eligibility checker to compare your answers with the published rules.
Consent is one of six lawful bases in Article 6, not the only one. In employment, regulators have questioned whether consent can be freely given, given the imbalance between employer and employee. Ask your lawyer which basis fits, and whether employee representatives must be informed or consulted.
Article 35 requires a data protection impact assessment where processing is likely to result in a high risk to people’s rights and freedoms. Large volumes of staff and customer communications reused by another company are a case where the question should be asked. Your lawyer or data protection officer should decide and record the decision.
UK sellers work under the UK GDPR and the Data Protection Act 2018, with their own regulator, the Information Commissioner’s Office, and their own transfer rules. The texts are close to the EU GDPR but separate, and they can diverge. A group with staff in both the UK and the EU should get advice on each regime.
A sample of real records is still personal data, and sending it is already a disclosure. A safer order is a manifest first: systems, years, volumes, categories and exclusions. If a buyer needs samples to evaluate the data, ask your lawyer whether they should be scrubbed first and covered by an NDA.
Article 5(2) makes the controller responsible for compliance and able to demonstrate it, and each party’s exposure depends on its role in the deal. Between you and the buyer, the contract allocates cost through warranties and indemnities. Ask who pays, whether liability is capped, and how long it lasts after the deal ends.
If a program fits on its published rules, the questions above are worth a lawyer's time. If none fits, you saved the expense. The checker runs in your browser.
Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data.