Last checked: 7 October 2026 (buyer statements quoted on this page)
Often it can be, but the answer is decided record by record, not company by company. Five things decide it: who owns the records, what your client contracts say, what your staff were told, whether personal data is inside, and which sector rules apply to you.
The legal questions make more sense once you know what is changing hands.
When an AI company or data buyer pays a business for "data", it is usually paying for a licensed copy of internal work records: documents, standard operating procedures, support tickets, chat threads, project histories, CRM notes, and code with its commit history. Buyers use these records to train and evaluate AI systems that do the same kind of work.
This is different from selling a customer list to a marketer, and the difference matters. The buyer is not after your customers' contact details. Most of the legal work in these deals goes into keeping personal and confidential details out while keeping the work itself in.
The buyers' own pages describe the arrangement as a copy, not a transfer. Mode states that it buys "an agreed copy" and that originals stay with the company. micro1 states that the company keeps ownership of its underlying data and that scope is agreed in writing (both as published, checked 7 October 2026). Whether your signed contract says the same thing is the first point your lawyer should confirm.
There is public precedent for this kind of sale. In August 2026, Google agreed to pay $10 million in Spirit Airlines' bankruptcy proceedings for the airline's internal data, including emails, Teams messages, spreadsheets and operations files, to train AI, and micro1 then made a $12.5 million rival offer (reported by ABC, TIME and others). That sale ran through a court process. A running company has no court reviewing its deal, so the review has to come from you and your lawyer.
You keep the records; the buyer receives a defined copy, for defined uses, under a contract that says what you promise about it. Legality depends on whether you had the right to make that copy and those promises.
Run every system and folder you might include through all five. One "no" or "not sure" is enough to keep a source out of scope until your lawyer answers it.
Records your company created are the natural starting point, but business files often mix in other people's material: client deliverables, vendor manuals, licensed research, contractor work and open-source code. Buyers will ask you to confirm you have the right to license everything in scope, so mixed files need sorting before export.
Service businesses sign NDAs, master service agreements and data processing terms with clients. These can limit what you do with client information, including any use beyond the work itself. If you hold data on a client's behalf, it may not be yours to license at all.
Chat messages and emails are written by your staff. Your handbook, IT policy and employment contracts may already say who owns work communications and how they can be used. Notice to employees is a legal question in some places and a trust question everywhere.
Names, email addresses, phone numbers and personal details of customers, staff and contacts appear in almost every business record. California's CCPA/CPRA has its own definitions of "selling" and "sharing" personal information, other US states have similar laws, and GDPR covers personal data of people in the EU, with a UK version alongside it.
Some industries carry extra rules on top of contracts and privacy law: HIPAA for health information, GLBA for customer financial information held by financial institutions, attorney-client privilege and professional conduct rules for law firms, confidentiality duties for accountants, and export controls for some technical and research data.
Buyers list the systems below as sources they work with. Each one raises a different first question.
| Data source | Main legal question | A sensible first step |
|---|---|---|
| SOPs, playbooks, wikis (Confluence, Notion) | Third-party material pasted into your documents; client names in examples | Search for client names and copied vendor content |
| Internal chat (Slack, Microsoft Teams) | Employee notice; personal and client details in threads | Pick channels in scope; leave out HR and private channels |
| Email (Gmail, Outlook) | Messages written by outsiders; client confidentiality | Decide whether external correspondence is in scope at all |
| Support tickets (Zendesk, ServiceNow) | Customer personal data | Read your customer terms and privacy notice |
| CRM and sales (Salesforce, HubSpot) | Personal data of contacts under CCPA/CPRA or GDPR | Separate deal reasoning from contact records |
| Accounting (QuickBooks, Xero, NetSuite) | Client confidentiality; GLBA where it applies | Review engagement letters and client contracts |
| Code (GitHub, GitLab, Bitbucket) | Open-source licenses, contractor IP, embedded secrets | Run a license scan and a secrets scan |
| Patient, legal-matter or HR files | HIPAA, privilege, employment law | Keep out of scope until counsel says otherwise |
Source list as published by buyer programs, checked 7 October 2026. The legal questions are generic and apply to any buyer.
The published programs prioritize American teams, so most sellers start with US questions.
For a US company the questions usually fall into three groups: your contracts (client, vendor and employee agreements), state privacy laws such as CCPA/CPRA in California, and sector laws such as HIPAA and GLBA. Questions to bring to your lawyer:
GDPR, and the UK's version of it, asks for a lawful basis for each use of personal data, limits new purposes, regulates transfers outside the EU and UK, and may call for a data protection impact assessment. In some countries works councils have a say over employee data.
Published eligibility also leans American: micro1 lists the US as prioritized, then other Western markets, and Mode names US-based teams as the strongest fit (as published, checked 7 October 2026). Read the GDPR guide for sellers before you scope anything.
Buyers describe privacy steps on their own pages. Those steps reduce risk after export. They do not answer whether you could share the records in the first place.
As published on the buyers' own pages and as reported, checked 7 October 2026.
Send these to your own counsel in writing, together with your list of systems and a draft scope.
A narrower scope is easier to defend, faster to review and simpler to de-identify.
List systems, date ranges and owners. No data leaves the building.
Remove the categories on the left and anything regulated, such as health data.
Client contracts, staff notices and privacy notices, with the twelve questions above.
Run the eligibility checker against published rules.
Read agreements side by side; the program comparison lists what each buyer publishes.
The five tests apply to everyone, but some situations add questions of their own. These are fictional, labeled examples to show where the questions come from, not advice for your case.
A 60-person engineering firm is owned by its staff through a share plan. The people whose messages fill its Slack workspace are also its owners, so a data deal is a governance decision as much as a legal one. Notice to staff and approval by owners become the same conversation.
A 35-person consulting firm signs master service agreements with confidentiality and deletion clauses. Its project folders are mostly client material; its internal SOPs, templates and training notes are mostly its own. The line between the two decides what it can even consider licensing.
A 25-person startup will close in three months. Its archives may be one of its last assets: Forbes reported in April 2026 on shut-down startups selling Slack and email archives to AI buyers. During a wind-down, though, the authority to sell assets can shift, and creditors may have a say.
It can be. Whether it is lawful for your company depends on who owns the records, what your client and employee agreements say, whether personal data is included, and which sector laws apply to you. A buyer’s process does not answer these questions for you. This is general information, not legal advice: talk to your own lawyer before you sign.
It depends on where your staff work, what your policies and contracts already say, and what the records contain. In parts of the EU, works councils may also have a say over employee data. Ask your lawyer what notice or consent applies, and decide how you will tell staff even where no rule requires it.
Customer names and details appear in most business records. Buyers state that they scrub sensitive information, but you still need to know whether your privacy notices and customer contracts allow the use, and how laws such as CCPA/CPRA or GDPR treat it. A cautious start is to leave customer-heavy sources out of scope until that is answered.
That is a question for your lawyer. CCPA/CPRA has its own definitions of selling and sharing personal information, and the answer depends on whether personal information remains in the copy and on the contract terms. Do not assume that calling it a license changes the answer.
EU and UK sellers face extra questions under GDPR: lawful basis, purpose limitation, international transfers and impact assessments. Published eligibility also leans to the US: micro1 lists the US as prioritized, then other Western markets, and Mode names US-based teams as the strongest fit (as published, checked 7 October 2026).
Not automatically. De-identification happens after you hand over the records, and the warranties you sign are yours. Ask who is liable if something is missed, whether liability is capped, and whether you can review a de-identified sample before release.
Size matters for eligibility, not for legality. Published minimums vary: micro1 lists 30+ employees, Mode lists 20+ full-time US office employees (10+ for accounting firms and 6+ for law firms), and Grepped lists any vertical (as published, checked 7 October 2026). The legal questions on this page apply at any size.
Start with what your client contracts say: some may require notice or consent, others may rule the use out. Where a contract is silent, it is still a relationship decision. Ask your lawyer what is required, then decide what is wise for each client.
If your lawyer is comfortable with a scope, compare what each program publishes and apply where you fit. Applying is not signing.
Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data. Published ranges are the buyers' own figures, not offers, checked 7 October 2026.