Sell Data to AI
Home Data Asset Score Pricing API documentation US labs and CROs list
For brokers
How to become an AI data broker Data broker business model Buyer programs compared Qualify a company AI training data companies
For data companies
Firmographic data providers Company data API
Seller guides
How to sell data to AI companies Is it legal? FAQ and glossary About
Check domain/company
Legal basics for companies

Is It Legal to Sell Your Company's Data to AI Companies?

Last checked: 7 October 2026 (buyer statements quoted on this page)

Often it can be, but the answer is decided record by record, not company by company. Five things decide it: who owns the records, what your client contracts say, what your staff were told, whether personal data is inside, and which sector rules apply to you.

5tests that decide whether a record can be licensed
9contract terms every seller should check before signing
60 to 90 daystypical close cited by practitioners, enough time for legal review
Start here

What "selling data to AI" actually means for a company

The legal questions make more sense once you know what is changing hands.

When an AI company or data buyer pays a business for "data", it is usually paying for a licensed copy of internal work records: documents, standard operating procedures, support tickets, chat threads, project histories, CRM notes, and code with its commit history. Buyers use these records to train and evaluate AI systems that do the same kind of work.

This is different from selling a customer list to a marketer, and the difference matters. The buyer is not after your customers' contact details. Most of the legal work in these deals goes into keeping personal and confidential details out while keeping the work itself in.

The buyers' own pages describe the arrangement as a copy, not a transfer. Mode states that it buys "an agreed copy" and that originals stay with the company. micro1 states that the company keeps ownership of its underlying data and that scope is agreed in writing (both as published, checked 7 October 2026). Whether your signed contract says the same thing is the first point your lawyer should confirm.

There is public precedent for this kind of sale. In August 2026, Google agreed to pay $10 million in Spirit Airlines' bankruptcy proceedings for the airline's internal data, including emails, Teams messages, spreadsheets and operations files, to train AI, and micro1 then made a $12.5 million rival offer (reported by ABC, TIME and others). That sale ran through a court process. A running company has no court reviewing its deal, so the review has to come from you and your lawyer.

Data licensing, in two sentences

You keep the records; the buyer receives a defined copy, for defined uses, under a contract that says what you promise about it. Legality depends on whether you had the right to make that copy and those promises.

The five tests

Five questions decide whether a record can be licensed

Run every system and folder you might include through all five. One "no" or "not sure" is enough to keep a source out of scope until your lawyer answers it.

1

Ownership: is it yours to license?

Records your company created are the natural starting point, but business files often mix in other people's material: client deliverables, vendor manuals, licensed research, contractor work and open-source code. Buyers will ask you to confirm you have the right to license everything in scope, so mixed files need sorting before export.

Ask: Which folders or systems contain material created by clients, contractors or vendors, and who owns it under those agreements?
2

Client contracts: what did you promise?

Service businesses sign NDAs, master service agreements and data processing terms with clients. These can limit what you do with client information, including any use beyond the work itself. If you hold data on a client's behalf, it may not be yours to license at all.

Ask: Do any client contracts limit secondary use, require deletion, or name the client as owner of the records?
3

Employees: what were staff told?

Chat messages and emails are written by your staff. Your handbook, IT policy and employment contracts may already say who owns work communications and how they can be used. Notice to employees is a legal question in some places and a trust question everywhere.

Ask: What have we told staff about the use of their work messages, and is new notice, consultation or consent needed?
4

Personal data: who is named inside?

Names, email addresses, phone numbers and personal details of customers, staff and contacts appear in almost every business record. California's CCPA/CPRA has its own definitions of "selling" and "sharing" personal information, other US states have similar laws, and GDPR covers personal data of people in the EU, with a UK version alongside it.

Ask: Does this dataset include personal information, and how would licensing it be treated under the privacy laws that apply to the people in it?
5

Sector rules: does your industry add a layer?

Some industries carry extra rules on top of contracts and privacy law: HIPAA for health information, GLBA for customer financial information held by financial institutions, attorney-client privilege and professional conduct rules for law firms, confidentiality duties for accountants, and export controls for some technical and research data.

Ask: Which sector laws or professional rules apply to our records, and do they permit licensing any part of them?
By data type

Where the legal questions sit, source by source

Buyers list the systems below as sources they work with. Each one raises a different first question.

Data sourceMain legal questionA sensible first step
SOPs, playbooks, wikis (Confluence, Notion)Third-party material pasted into your documents; client names in examplesSearch for client names and copied vendor content
Internal chat (Slack, Microsoft Teams)Employee notice; personal and client details in threadsPick channels in scope; leave out HR and private channels
Email (Gmail, Outlook)Messages written by outsiders; client confidentialityDecide whether external correspondence is in scope at all
Support tickets (Zendesk, ServiceNow)Customer personal dataRead your customer terms and privacy notice
CRM and sales (Salesforce, HubSpot)Personal data of contacts under CCPA/CPRA or GDPRSeparate deal reasoning from contact records
Accounting (QuickBooks, Xero, NetSuite)Client confidentiality; GLBA where it appliesReview engagement letters and client contracts
Code (GitHub, GitLab, Bitbucket)Open-source licenses, contractor IP, embedded secretsRun a license scan and a secrets scan
Patient, legal-matter or HR filesHIPAA, privilege, employment lawKeep out of scope until counsel says otherwise

Source list as published by buyer programs, checked 7 October 2026. The legal questions are generic and apply to any buyer.

Where you are

US first, with a box for EU and UK sellers

The published programs prioritize American teams, so most sellers start with US questions.

United States

For a US company the questions usually fall into three groups: your contracts (client, vendor and employee agreements), state privacy laws such as CCPA/CPRA in California, and sector laws such as HIPAA and GLBA. Questions to bring to your lawyer:

  • Which state privacy laws apply to the people named in our records?
  • Would licensing a copy for AI training count as a sale or sharing under those laws, before or after de-identification?
  • Do our privacy notices and customer terms cover this use, or do they need updating first?
  • Does HIPAA, GLBA or a professional rule apply to any source in scope?
  • Are there trade-secret or export-control concerns for technical records?

EU and UK box

GDPR, and the UK's version of it, asks for a lawful basis for each use of personal data, limits new purposes, regulates transfers outside the EU and UK, and may call for a data protection impact assessment. In some countries works councils have a say over employee data.

Published eligibility also leans American: micro1 lists the US as prioritized, then other Western markets, and Mode names US-based teams as the strongest fit (as published, checked 7 October 2026). Read the GDPR guide for sellers before you scope anything.

Who handles what

What the buyer's process covers, and what stays with you

Buyers describe privacy steps on their own pages. Those steps reduce risk after export. They do not answer whether you could share the records in the first place.

What buyers state they do

  • micro1: scope agreed in writing; sensitive and confidential information scrubbed; originals deleted after processing; no customer information exposed; the company keeps ownership of its underlying data.
  • Mode: buys "an agreed copy"; originals stay with the company; de-identifies before onward delivery.
  • micro1, in a session with former Spirit Airlines employees, said it pursues "non-sensitive, non-consumer data" with third-party de-identification.

As published on the buyers' own pages and as reported, checked 7 October 2026.

What stays with you

  • The decision to include each system, folder and date range.
  • Your obligations to clients under NDAs and service contracts.
  • What you tell, or ask, your employees.
  • The warranties you sign about ownership and consent, and any indemnity behind them.
  • Your duties as the company that collected the personal data in the first place.
For any buyer, a statement on a website is not a clause in your agreement. If a privacy step matters to you, ask for it in the contract. The clause-by-clause guide to data licensing agreements shows where each point usually sits.
Ask your lawyer

Twelve questions to bring to your lawyer

Send these to your own counsel in writing, together with your list of systems and a draft scope.

Do we own, or have the right to license, every source in scope?
Do any client contracts, NDAs or data processing terms restrict secondary use of what we hold?
Are we holding any of this data as a processor, on a client's behalf?
What have employees been told, and is new notice, consultation or consent needed?
Which privacy laws apply to the people named in these records?
Would this license count as a sale or sharing under CCPA/CPRA or a similar state law?
Do HIPAA, GLBA, privilege or professional rules apply to any of it?
Are there trade-secret or export-control concerns for technical records?
What warranties and indemnities is the buyer asking for, and are they capped?
Can we review a de-identified sample before anything is released?
What happens to the copy, and to anything built from it, when the contract ends?
Do we need board, partner or investor approval before signing?
Practical order

Leave the hardest records out, then work in order

A narrower scope is easier to defend, faster to review and simpler to de-identify.

Keep out of scope until counsel clears them

  • Patient or health records, and HR files with medical or disciplinary details.
  • Privileged legal communications and matter files (see client confidentiality).
  • Client-owned deliverables and anything under a client NDA.
  • Payment card numbers, bank details and government ID numbers.
  • Data you hold for clients as their processor.
  • Passwords, API keys and credentials anywhere in docs, chat or code.
  • Private messages, unless your notice to staff clearly covers them (see employees and company data).

Order of work

  1. 1
    Inventory

    List systems, date ranges and owners. No data leaves the building.

  2. 2
    Exclude

    Remove the categories on the left and anything regulated, such as health data.

  3. 3
    Legal review

    Client contracts, staff notices and privacy notices, with the twelve questions above.

  4. 4
    Check fit

    Run the eligibility checker against published rules.

  5. 5
    Compare terms

    Read agreements side by side; the program comparison lists what each buyer publishes.

Three situations

Three company situations, walked through

The five tests apply to everyone, but some situations add questions of their own. These are fictional, labeled examples to show where the questions come from, not advice for your case.

Fictional example

An employee-owned company

A 60-person engineering firm is owned by its staff through a share plan. The people whose messages fill its Slack workspace are also its owners, so a data deal is a governance decision as much as a legal one. Notice to staff and approval by owners become the same conversation.

  • Does the share plan or our bylaws require trustee, board or owner approval for a deal like this?
  • How will employee-owners be told, and can they ask for their own channels or mailboxes to be left out?
  • Who signs on behalf of the company, and who must be consulted first?
Fictional example

A company with client NDAs

A 35-person consulting firm signs master service agreements with confidentiality and deletion clauses. Its project folders are mostly client material; its internal SOPs, templates and training notes are mostly its own. The line between the two decides what it can even consider licensing.

  • Which records were created for a client, and which for ourselves?
  • Do our NDAs restrict any use beyond the engagement, even after de-identification?
  • Should client-facing folders be excluded entirely, leaving only internal methods in scope?
Fictional example

A company winding down

A 25-person startup will close in three months. Its archives may be one of its last assets: Forbes reported in April 2026 on shut-down startups selling Slack and email archives to AI buyers. During a wind-down, though, the authority to sell assets can shift, and creditors may have a say.

  • Who has authority to sign during the wind-down: the board, a liquidator or a court?
  • Do promises in our privacy notices and client contracts still bind us after closure?
  • Who will stand behind our warranties once the company no longer exists?
FAQ

Common questions about the legality of selling company data

Is it legal to sell company data to AI companies?

It can be. Whether it is lawful for your company depends on who owns the records, what your client and employee agreements say, whether personal data is included, and which sector laws apply to you. A buyer’s process does not answer these questions for you. This is general information, not legal advice: talk to your own lawyer before you sign.

Do we need employee consent to license our Slack or email history?

It depends on where your staff work, what your policies and contracts already say, and what the records contain. In parts of the EU, works councils may also have a say over employee data. Ask your lawyer what notice or consent applies, and decide how you will tell staff even where no rule requires it.

Can we include records that mention customers?

Customer names and details appear in most business records. Buyers state that they scrub sensitive information, but you still need to know whether your privacy notices and customer contracts allow the use, and how laws such as CCPA/CPRA or GDPR treat it. A cautious start is to leave customer-heavy sources out of scope until that is answered.

Does licensing data for AI training count as a sale under CCPA/CPRA?

That is a question for your lawyer. CCPA/CPRA has its own definitions of selling and sharing personal information, and the answer depends on whether personal information remains in the copy and on the contract terms. Do not assume that calling it a license changes the answer.

We are based in the EU. Can we still sell?

EU and UK sellers face extra questions under GDPR: lawful basis, purpose limitation, international transfers and impact assessments. Published eligibility also leans to the US: micro1 lists the US as prioritized, then other Western markets, and Mode names US-based teams as the strongest fit (as published, checked 7 October 2026).

If the buyer de-identifies the data, are we covered?

Not automatically. De-identification happens after you hand over the records, and the warranties you sign are yours. Ask who is liable if something is missed, whether liability is capped, and whether you can review a de-identified sample before release.

Can a small company sell data, or is this only for large firms?

Size matters for eligibility, not for legality. Published minimums vary: micro1 lists 30+ employees, Mode lists 20+ full-time US office employees (10+ for accounting firms and 6+ for law firms), and Grepped lists any vertical (as published, checked 7 October 2026). The legal questions on this page apply at any size.

Should we tell clients before we license data that mentions them?

Start with what your client contracts say: some may require notice or consent, others may rule the use out. Where a contract is silent, it is still a relationship decision. Ask your lawyer what is required, then decide what is wise for each client.

When the legal questions have answers

If your lawyer is comfortable with a scope, compare what each program publishes and apply where you fit. Applying is not signing.

micro1 referral page: "$100K-$2M+ for approved data packages" Mode: "$100K-$5M" Grepped: "$20K-$5M"

Independent site. Some links are referral links: if your company signs with a buyer through them, the buyer may pay us a fee. You are not charged, and we never see your data. Published ranges are the buyers' own figures, not offers, checked 7 October 2026.

Keep reading

Related legal and privacy guides