New: who buys company data, October 2026 list
Data Licensing Report

Situations

We acquired a company. Can we license its records?

We may earn a referral fee when a business we introduce completes a deal. Telegraph Lab is a commercially affiliated provider.

Data Licensing Report may earn a referral fee when a business that applies through this site completes a deal with a participating provider. Telegraph Lab is a commercially affiliated provider: the owner of Data Licensing Report is paid commission on some Telegraph Lab deals, and does not own Telegraph Lab. Providers are listed alphabetically and described from their own public materials using the same fields.

How we make money
On this page
  1. Did we buy the company, or its assets?
  2. What did the purchase agreement actually transfer?
  3. Do the acquired company’s privacy promises still apply?
  4. What about data it held for its own customers?
  5. What about its employees’ email and chat?
  6. Do any buyers ask for an acquired company’s records?
  7. What should we check?
  8. Where do we start?
Why trust us

Possibly. It turns on what the purchase agreement transferred, what the acquired company promised people when collecting their information (promises FTC staff have said survive an acquisition), and the contracts under which it held customers’ data.

Did we buy the company, or its assets?

Check the deal structure first, because it decides who holds the records now and what came with them:

How the deal was done Who holds the records What came with them
Stock purchase or reverse triangular merger The acquired company, now owned by you. Montague Law’s August 2026 article: “The same entity that signed it still holds it; only the entity’s owners changed.” Everything it had: its privacy policies, customer contracts, platform terms and any data licenses it signed
Asset purchase Your company, but only for what the agreement lists. A Wilkinson Law article (August 2025): “If the agreement doesn’t mention the customer list explicitly, it likely won’t transfer.” Contracts only if assigned: the seller conveys each one by assignment, “so the clause fires and consent is required” where a contract bars assignment

For any other structure, ask the lawyer who did the deal which entity holds what. Merging the acquired company into yours, or moving its mail into your Microsoft 365 or Google account, changes where the records sit. It does not change the terms under which they were collected.

What did the purchase agreement actually transfer?

Read four parts of it, ideally with the M&A lawyer who negotiated it:

  • Purchased and excluded assets. In an asset deal, look for books and records, intellectual property, customer lists and data by name, and for anything the seller kept, including copies.
  • The seller’s representations. Skadden’s January 2026 guidance lists “Rights to data used for training” first among the AI-related representations buyers may seek to treat as fundamental, with longer survival and higher indemnity caps. If your agreement has no such clause, note what the seller promised about privacy compliance and its rights in the data.
  • The disclosure schedules. They “allow sellers to list exceptions to the promises made in the purchase agreement” (PSBP Law, August 2025); look there for privacy policies, complaints, incidents and contracts that restrict data.
  • Any data license the acquired company had already signed. After a stock deal it stays with the company you now own; after an asset deal, it depends on the license and the agreement. If we license our data now, does it affect selling the company later? covers those terms from the seller’s side.

Whether the agreement’s indemnities reach a license you grant now, years after closing, is a question for that same lawyer.

Do the acquired company’s privacy promises still apply?

FTC staff said yes in 2014. After Facebook agreed to acquire WhatsApp, the director of the FTC’s Bureau of Consumer Protection wrote to both companies on April 10, 2014 that “WhatsApp must continue to honor these promises to consumers,” and that using its data “in a manner that is materially inconsistent with the promises WhatsApp made at the time of collection” requires consumers’ affirmative consent first. The FTC’s business blog summed it up the same day: consumers “have a right to rely on those promises remaining in full effect.”

Some state privacy laws take the acquisition itself out of what counts as a sale. Two examples:

So the question for each data set is which promise was in force when it was collected. Collect every version of the acquired company’s privacy policy, customer terms and employee handbook with the dates each applied, from the data room, the seller’s files or archived copies of its website. The FTC letter measures use against the promises made “at the time of collection,” so on its reading, records gathered under a stricter older policy are held to that policy.

What about data it held for its own customers?

Usually leave it out. If the acquired company was a service business, such as an IT firm, an agency or an accounting practice, much of what it held belonged to its clients under their contracts. Under California’s definition, a service provider works under a written contract that prohibits “Selling or sharing the personal information” and using it for any purpose other than the business purposes the contract specifies (§1798.140). Providers that address client data say much the same, as of October 2026. Polyshares’ intake says “Data you hold for your own clients is out of scope”; Miro Advisory says client information “should not be included simply because it can be anonymized”; Troveo’s guide says “anything a customer contract restricts” comes out before delivery; and Telegraph Lab (affiliated with this site) says third-party information “requires additional review and may need to be excluded”.

The deal structure matters here too. In an asset purchase, each client contract moved only by assignment, and only with consent where the contract required it. If a client never consented, you may hold its files without holding its contract. The IT managed services and accounting pages cover what client agreements in those trades usually restrict.

What about its employees’ email and chat?

The acquired company’s staff wrote its email and chat under its handbook rather than yours, and many may have left at or after closing. Their mailboxes follow the rules in Can we include former employees’ mailboxes?

Check, too, whether the acquired company’s own systems still exist. A Microsoft 365 subscription canceled after a migration leaves data that Microsoft deletes within 180 days of cancellation, and Google deletes a canceled Workspace account’s user data for good, so export before anyone cancels. If only recent mail was migrated, the older years may survive only in .pst files or old backups; Does my company’s data qualify? explains how to trace a migration gap.

Do any buyers ask for an acquired company’s records?

Of the providers in the buyers directory, only Scrimdata’s own pages name records that came with an acquisition, as of October 2026. Its partner page offers to “License legacy systems and archives from an acquisition or pivot” (profile). Whoever you approach, the limits above travel with the records.

What should we check?

Document What to look for
Purchase agreement and schedules Stock or asset deal; purchased and excluded assets; the seller’s promises about data and privacy; indemnity and how long it lasts
Disclosure schedules Privacy policies, complaints, incidents, existing data licenses
The acquired company’s privacy policies, every version What it said about sharing, selling or AI use, and the dates each applied
Its employee handbook and IT policies What staff were told about company email and personal use
Its client contracts and data processing terms Confidentiality, permitted use, deletion on termination, and whether they were assigned to you
Its software subscriptions Platform terms, and whether its accounts still exist

Where do we start?

  1. Inventory the acquired records on their own: systems, years, and whether each set was collected before or after closing.
  2. Match each set to the promise in force when it was collected, and mark anything collected under a promise not to share.
  3. Take out client-held data, unless your lawyer confirms the client’s contract allows the use.
  4. Bring the documents to counsel: the M&A lawyer who worked on the deal for the agreement, and a privacy lawyer for the policies.
  5. Describe the acquired records as their own line in an application or data inventory, with the years they cover, so a buyer can price them separately from your own.

Providers named on this page

Get offers

Find the next step for your company’s data.

  • No records or exports needed to apply
  • Free for businesses
  • Your company profile comes to our team for review

Already have an offer? Compare it

Start your application

Do you keep at least 3 years of email or business-software history?

We may earn a referral fee if a deal closes. How we make money