New: who buys company data, October 2026 list
Data Licensing Report

Question

Is it legal to sell company emails and records?

On this page
  1. Our GC contracts have confidentiality clauses. Am I breaching them?
  2. Do our software providers’ terms matter?
  3. Is this legal in Texas?
  4. Insurance claims work means homeowners’ names, addresses and claim numbers. Can that go out?
  5. What counts as regulated data?
  6. We had a lawsuit in 2019. Is that correspondence privileged?
  7. Do I have to tell my employees or customers?
  8. If something leaks, who’s on the hook?
  9. My partner owns 30%. Does he have to sign off? Does my bank loan or cyber insurance say anything?
  10. Do I need a lawyer, and what kind?
Why trust us

In the US, licensing your own business records is generally a contract matter. The limits: promises to others (GC and client confidentiality, NDAs, platform terms), privacy laws on personal information, regulated health, financial or children’s data, and privilege. Frankfurt Kurnit’s October 1, 2026 commentary says it “can be done, but most companies cannot sell everything a buyer requests”.

Our GC contracts have confidentiality clauses. Am I breaching them?

That depends on the wording of each clause, and it is the first thing to check. Frankfurt Kurnit’s commentary notes that email and chat often hold other companies’ confidential information protected by NDAs and commercial agreements, and advises reviewing customer, partner, vendor and data license agreements before any sale (Frankfurt Kurnit).

Read each clause for four things:

  • What counts as confidential. Only documents marked confidential, or everything the GC shares about a project.
  • What use is allowed. Whether use is limited to performing the work.
  • What is carved out. Whether your own work product, or information with names removed, falls outside the clause.
  • How long it lasts. Whether it survives the end of the job.

If a clause covers what a GC gave you, those documents and threads are the risk, and you can leave that GC’s projects out of scope (how to leave out records). Programs expect this. Polyshares says “Data you hold for your own clients is out of scope”, and Miro Advisory says “Client information should not be included simply because it can be anonymized”. The same reading applies to NDAs you signed with suppliers or partners. Ask your own lawyer whether a particular clause permits a license.

Do our software providers’ terms matter?

They can, especially when a buyer would read your data through a software company’s API rather than from an export you make. Slack’s API terms, effective October 10, 2025, say apps distributed beyond your own organization may not “use API Data to train a large language model” or bulk export message and file data without an additional agreement. ServiceTitan’s API terms, updated April 15, 2026, forbid providing, selling or licensing data obtained through its APIs to third parties for AI training unless another written agreement with ServiceTitan allows it (ServiceTitan). The Slack and ServiceTitan pages cover each platform’s terms and exports.

Ownership claims are the other risk. In the Spirit Airlines sale, Frankfurt Kurnit reports, a software vendor objected that records generated on its platform belonged to it (Frankfurt Kurnit). If a provider proposes to connect to your chat, email or job software, ask how its access fits that platform’s terms, and read your own subscription terms for who owns what you put in.

The Texas laws that bear on it regulate the personal information inside your records, and which ones reach you depends on whose information it is and how large the company is. The main one is the Texas Data Privacy and Security Act, in effect since July 1, 2024 (Texas Attorney General):

Two other Texas rules matter here. Chapter 521 of the Business and Commerce Code requires a business to “implement and maintain reasonable procedures” to protect sensitive personal information and sets breach-notice deadlines (below). The Texas Rules of Evidence decide privilege in Texas courts (also below). Whether your company is small under the SBA table, and whether any record you would license counts as a sale of personal data, are questions for your own lawyer.

Insurance claims work means homeowners’ names, addresses and claim numbers. Can that go out?

Possibly, under conditions that do not apply to the rest of your records, so treat claim files as a separate decision. Homeowners are the people in your records that privacy law covers most directly: under the Texas act, Texas homeowners dealing with their own house are consumers, and GC staff are not.

  • If your company is not a small business under the SBA standard, giving homeowners’ personal data to a buyer for money can fit the act’s definition of a sale unless it qualifies as deidentified data, and homeowners can opt out of sales (Texas Attorney General).
  • If it is a small business, it is generally exempt, but selling sensitive data needs consent. Names and addresses are not on the act’s sensitive list; a homeowner’s health diagnosis mentioned in a file would be (§541.001).
  • Claim and policy numbers tie a record to an insurer’s file. None of the provider lists in how providers de-identify names claim numbers, so ask in writing whether they are replaced.
  • If a claim file holds copies of driver’s licenses, that matters separately: Texas counts a name combined with a driver’s license number as sensitive personal information (§521.002).
  • An insurer’s or claims administrator’s contractor program has its own agreement; read it the way you read a GC contract.

The plainest option is to leave claim files out of scope; leaving out records shows how.

What counts as regulated data?

Data a specific law governs because of what it is or who holds it. Frankfurt Kurnit’s list of what internal records can contain includes information subject to HIPAA, the Gramm-Leach-Bliley Act, children’s privacy laws, biometric laws and call-recording consent laws (Frankfurt Kurnit). The rules below apply only if their condition fits your company.

Data The rule applies if Source
Health information (HIPAA) Your company is a covered entity (a health plan, a clearinghouse, or a provider that transmits health information electronically in standard transactions) or a business associate of one HHS
Employees’ medical leave records (FMLA) You are a private employer with 50 or more employees in 20 or more workweeks; medical certifications and histories must be kept as confidential medical records in separate files Department of Labor, 29 CFR 825.500(g)
Consumer financial information (Gramm-Leach-Bliley) Your company offers consumers “financial products or services like loans, financial or investment advice, or insurance” FTC
Children’s data (COPPA) Your website or online service collects personal information from children under 13 FTC
Texas “sensitive data” Records about Texas consumers include health diagnoses, religious beliefs, immigration status, precise geolocation or data on a child under 13 §541.001

If a row applies, leave that category out or get advice before it goes into scope. Personal matters no specific law covers can still be the most sensitive thing in an archive; see what happens to personal information.

We had a lawsuit in 2019. Is that correspondence privileged?

Some of it may be, and licensing it could put that protection at risk. In Texas courts, the lawyer-client privilege covers “confidential communications made to facilitate the rendition of professional legal services to the client” (Rule 503), and the holder waives it by voluntarily disclosing “any significant part of the privileged matter” (Rule 511). Frankfurt Kurnit warns that a sale “may waive privilege over legal communications”.

  • Emails between the company and its lawyers about the case are the kind of communication the privilege rule describes. Keep them out of scope whole.
  • Letters to and from the other side, and court filings, were not communications with your own lawyer. Check the settlement agreement and any court order from the case for confidentiality terms before treating them as licensable.
  • Which files are which is a question for the lawyer who handled the case, who will also know where they were kept.

Leaving out records lists four ways to describe case material so the exclusion holds.

Do I have to tell my employees or customers?

It depends on what you told them when you collected their information, and on where they live. FTC staff warned in February 2024 that “It may be unfair or deceptive for a company to adopt more permissive data practices—for example, to start sharing consumers’ data with third parties or using that data for AI training” through quiet changes to terms or privacy policies. Frankfurt Kurnit adds: “For data already collected, companies are bound by prior commitments unless they obtain consent.” Start with three documents: your website privacy policy, your customer terms and your employee handbook.

  • Texas employees and business contacts are outside the Texas privacy act, which excludes people acting in a commercial or employment context (above).
  • Texas homeowners and other consumers are generally covered unless your company is a small business. A covered business that sells sensitive data must post this notice in the same place and manner as its privacy notice: “NOTICE: We may sell your sensitive personal data.”
  • California employees or customers matter if your company meets the California act’s thresholds, such as gross annual revenue over $26,625,000 (the statute’s $25 million, adjusted for inflation from January 1, 2025); its exemptions for employee and business-to-business information “expired on December 31, 2022”. Frankfurt Kurnit says a transfer of workplace data for money is a sale under that act unless it meets its de-identification definition.
  • Employees generally: communications about pay, scheduling and working conditions “may be protected concerted activity under Section 7 of the National Labor Relations Act”, and a union contract may restrict a sale.

Your lawyer can say whether notice or consent is legally required for your records. Whether people find out is a separate matter. The Spirit Airlines sale drew objections in court from the flight attendants’ union (Fortune) and two more unions that joined it (court filing).

If something leaks, who’s on the hook?

The law assigns notice duties by who owns or holds the data; the license agreement decides who pays. In Texas, a business that owns or licenses computerized data containing sensitive personal information must notify affected people no later than 60 days after determining a breach occurred, and the attorney general within 30 days if at least 250 Texans are affected. A business holding someone else’s data must tell the owner “immediately after discovering the breach” (§521.053).

Frankfurt Kurnit’s advice is that the agreement “should restrict how the buyer can use the data, allocate privacy risk, and address what happens if something goes wrong”, and that “Privacy and security representations in particular deserve careful attention”. In the agreement, look for:

  • how fast the buyer must tell you about a breach;
  • who notifies affected people, and who pays for it;
  • an indemnity for the buyer’s breach, and any cap on it;
  • insurance the buyer must carry;
  • when raw and delivered copies are deleted;
  • what you promise about your own rights to the data, since a broad promise is where a missed confidentiality clause comes back to you.

The simplest protection is to keep sensitive personal information out of the copy altogether.

My partner owns 30%. Does he have to sign off? Does my bank loan or cyber insurance say anything?

Each is answered by a document you already have, not by a general rule. Read them before you sign, and keep a record. Frankfurt Kurnit notes that “If the company is later acquired, a prior data sale will come up in diligence, and buyers will expect to see this record”.

Document What to look for Read it with
Company agreement (LLC), or bylaws and any shareholders’ agreement (corporation) Decisions that need every owner’s or a supermajority’s approval. For a Texas LLC, the statute’s default is that an action outside the ordinary course of business needs a majority vote of all governing persons (Texas Business Organizations Code §101.356); the company agreement can set its own rule, since that section is not among those it cannot change (§101.054) Your company lawyer
Loan and security agreements Covenants on selling, licensing or transferring assets outside the ordinary course, and whether the bank’s lien covers “general intangibles”, the Uniform Commercial Code’s term for personal property outside its other categories, including software (UCC §9-102) Your lawyer, then your banker
Cyber insurance policy Whether a breach of data you handed to someone else is covered, what you must tell the insurer about changes, and any exclusions for data you shared Your insurance broker
GC contracts, client contracts and NDAs Confidentiality and permitted use (above) Your lawyer

Whether your partner’s approval is legally required turns on these documents and your company’s form, which is a question for your lawyer. If the license is exclusive or long, it binds the company for years; selling versus licensing explains those terms.

Do I need a lawyer, and what kind?

Yes, before you sign the license agreement, and preferably before any sample leaves the company. Frankfurt Kurnit advises: “Do not share sample data before this review, since a sample itself could be a disclosure.” A sample you make and keep on your own computer is not shared. You need your own lawyer, not the provider’s, for three questions on this page: whether your contracts allow the license, which files are privileged, and whether notice or consent is required.

The kinds of lawyer that fit:

  • A technology or data-licensing transactions lawyer with privacy experience, to read the license, the de-identification terms, the permitted uses and the indemnities.
  • Your company’s regular business lawyer, for owner approvals and the loan documents.
  • The lawyer who handled the 2019 case, to identify privileged files.

Bring the offer or term sheet, the draft agreement, your data inventory, a list of contracts with confidentiality clauses, your privacy policy and employee handbook, the company agreement, the loan and security agreements, and the cyber policy. Frankfurt Kurnit warns that the work required “is usually more than the offer suggests”. What’s the catch covers the rest of the trade-offs, and the guide lays out the process from first description to payment.

Providers named on this page

Get offers

Find the next step for your company’s data.

  • No records or exports needed to apply
  • Free for businesses
  • Your company profile comes to our team for review

Already have an offer? Compare it

Start your application

Do you keep at least 3 years of email or business-software history?

We may earn a referral fee if a deal closes. How we make money