Guides

Is it legal to sell your company's data to AI under the GDPR?

Often yes, if you sell only data you control, test the new purpose properly and remove personal details first. This guide explains each step in plain terms and ends with a checklist you can work through with your team.

The short answer

The GDPR does not ban selling business data. It sets conditions on personal data: information about a person who can be identified, such as a customer, an employee or a contact at a supplier. Most company records contain some of it, in email signatures, CRM notes, tickets and chat messages.

Three questions decide whether a sale can go ahead. Is the data yours to sell? Do you have a lawful basis for the new purpose? And are the personal details removed before anything leaves your company? The steps below take these one at a time.

Step 1: Check which data is yours to sell

You can only sell data you control. Under the GDPR, the controller decides why and how personal data is processed. If you process data on behalf of a client, as a processor, the data belongs to that client's purposes. Payroll you run for clients, support you provide inside a client's systems and data you host for customers usually fall into this group.

Contracts matter too. Client agreements and NDAs often limit how you may use information you received in the course of the work. Read them before you scope a sale.

Copyright is a separate question. In many EU countries the employer is treated as the author of work that employees create as part of their job. The Dutch Copyright Act (Auteurswet, article 7) is one example. The rules differ per country, so check yours. Content written by third parties, such as a supplier's manual or a report you bought, is not yours to license even when it sits in your files.

  • Data you collected for your own business purposes: usually yours to consider.
  • Data you process for clients as a processor: not yours, leave it out.
  • Material restricted by a client contract or NDA: follow the contract.
  • Third-party content inside your files: not yours to license.

Step 2: Decide what stays out completely

Some data should never be part of a sale, even after cleaning. Special categories of personal data, such as health information, religion, trade union membership or biometric data, carry strict rules. National ID numbers and similar identifiers are also excluded.

If your profession has a duty of secrecy, as lawyers, notaries, accountants and doctors do, client-identifying and privileged content stays out or is fully stripped. Workflows, templates, internal know-how and anonymised patterns can still be valuable and are usually unaffected.

Step 3: Test the new purpose

You collected customer and employee data to run your business. Licensing a de-identified copy for AI training is a new purpose. Article 6(4) of the GDPR asks you to check whether that new purpose is compatible with the original one. The test looks at the link between the two purposes, the context in which the data was collected, the type of data, the possible consequences for the people involved and the safeguards you apply, such as de-identification.

For most companies the lawful basis will be legitimate interest. That requires a written legitimate interest assessment: what your interest is, whether the processing is necessary for it, and whether it overrides the interests of the people in the data. Strong safeguards weigh heavily in that balance.

Because the processing is new and involves large volumes, a data protection impact assessment (DPIA) is usually needed. It records the risks and the measures you take against them. Your data protection officer, if you have one, should be involved from the start.

Step 4: Understand what de-identification does

Replacing names with codes is pseudonymisation. The European Data Protection Board confirmed in its Guidelines 01/2025 that pseudonymised data is still personal data for anyone who can link it back to a person.

In September 2025 the EU Court of Justice ruled in EDPS v SRB that pseudonymised data may not be personal data for a recipient who has no reasonable means to re-identify anyone. That helps the buyer. It does not remove your duties as the source: you still processed personal data to create the dataset, and you still have to be transparent about it.

In practice this means removing identifiers thoroughly, keeping no key that a buyer could use, and treating your own side of the process as processing of personal data.

Step 5: Tell people and give them a way to object

Update your privacy notice to say that de-identified copies of business records may be licensed for AI training, and on what basis. When you rely on legitimate interest, people have a right to object. Give them a simple route, such as an email address, and a way to remove their data from future packages.

Step 6: Involve your works council

If staff messages or records are part of the sale and you have a works council, involve it early. In the Netherlands, the works council (ondernemingsraad) must consent to arrangements on processing employee personal data under article 27(1)(k) of the Works Councils Act. Germany's works councils have similar co-determination rights, and many other EU countries have comparable rules.

Step 7: Keep the paperwork buyers ask for

AI labs increasingly ask where training data came from. The Dutch Data Protection Authority's guidance on generative AI and the GDPR (June 2026) treats legitimate interest as the most realistic basis for AI developers, including for datasets lawfully obtained from third parties. It also expects buyers to check that their suppliers limited what they collected.

The EU AI Act adds a second reason. Providers of general-purpose AI models must publish a summary of their training data, using a template the European Commission released in July 2025. The Commission's enforcement powers apply from 2 August 2026, with fines of up to 3% of worldwide turnover or €15M. Licensed data with clean paperwork is easier for labs to use, so good documentation also supports your price.

Checklist

Work through these points before any data leaves your company.

  • List the sources you want to sell and confirm you are the controller for each.
  • Check client contracts, NDAs and professional rules for limits on reuse.
  • Exclude processor data, third-party content and anything under secrecy or privilege.
  • Exclude special-category data and national ID numbers.
  • Run and record the compatibility test under Article 6(4).
  • Write a legitimate interest assessment.
  • Carry out a DPIA, with your data protection officer if you have one.
  • Update your privacy notice and set up a route for objections.
  • Involve your works council if staff data is included.
  • Agree in writing with the buyer what the data may be used for.
  • Keep a record of sources, removals and approvals for buyers and regulators.

How Lodex handles this

We agree the scope with you in writing before we connect, and you approve each source. We connect read-only, remove names, contact details, customer identifiers and special-category data during processing, and delete the originals once processing is done. We license only to AI labs, under contract, and nothing is published. The signed scope and terms also give you a record for your own files.

Questions

Do I need consent from every customer?

Usually not. Most companies rely on legitimate interest, supported by a compatibility test, a balancing assessment and strong de-identification. People must be informed and able to object.

Is anonymised data outside the GDPR?

Truly anonymous data is. But data where names are replaced by codes is pseudonymised, and that is still personal data for anyone who can re-identify it. Treat your own processing as GDPR processing.

Can I sell data I hold for my clients?

Not if you process it as a processor on their behalf. That data serves your client's purposes. Your own procedures, templates and internal records are a different matter.

Do I need a DPIA?

In most cases, yes. Reusing large volumes of business records for a new purpose is the kind of processing a DPIA is meant for. It also gives buyers the documentation they look for.

Does the EU AI Act apply to my company as a seller?

The AI Act's training data duties fall on the AI model provider. They affect you indirectly: labs need to know where data came from, so clear records make your data easier to sell.

This is general information, not legal advice.

Know the price before you sell.

Answer three questions about your company and get a payout range in under a minute.

Get your estimateBook a call

Answer all three to see your range and book a call.

  • You approve every source
  • Customer and personal details removed
  • Never sold to your competitors
  • Nothing is shared before you sign
Get your estimate