Situations
We operate in the UK or EU as well as the US. Does that change things?
On this page
- What should I check?
- Which of our records does GDPR or UK GDPR cover?
- Does removing names make the records anonymous?
- Do we need a lawful basis to license the records?
- Can the records go to a US provider?
- Which providers say they take companies outside the US?
- What do I do next?
Yes, for the personal data your UK or EU operation holds. GDPR and UK GDPR set the tests for when de-identified records count as anonymous, whether a new use is allowed and how records reach a US buyer; counsel in each country applies them.
What should I check?
| Check | The rule | Who answers it |
|---|---|---|
| Which records the law covers | GDPR Article 3; UK GDPR | Counsel in each country |
| Whether the licensed copy would be anonymous | GDPR Recital 26; ICO anonymisation guidance | Counsel, with the provider’s written method |
| Lawful basis and purpose for the new use | GDPR Articles 5, 6, 13 and 14; ICO purpose limitation guidance | Counsel |
| Sensitive categories | GDPR Article 9 | Counsel |
| Transfer to the US | GDPR Chapter V; Data Privacy Framework; contract clauses | Counsel and the provider |
| Whether a provider takes non-US companies | Its own pages | The provider |
Which of our records does GDPR or UK GDPR cover?
Those your UK or EU operation handles, and possibly more. GDPR applies to processing “in the context of the activities of an establishment of a controller or a processor in the Union, regardless of whether the processing takes place in the Union or not” (Article 3(1)), and to a company outside the EU that offers goods or services to people in the EU or monitors their behavior there (Article 3(2)). UK GDPR has a matching rule for the UK.
Personal data is “any information relating to an identified or identifiable natural person” (Article 4(1)). Unlike the Texas act described on Is it legal?, it has no carve-out for people acting at work, so information about staff, customers’ contacts and suppliers’ staff named in your records counts.
The Data (Use and Access) Act 2025 has amended UK GDPR, and the ICO said most of the Act’s remaining data protection provisions came into force on February 5, 2026. Ask counsel which of your companies is the controller for each set of records, since that company carries the duties below.
Does removing names make the records anonymous?
Not by itself. Recital 26 says GDPR does not apply to anonymous information, and that to decide whether someone is identifiable, “account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person to identify the natural person directly or indirectly”. Pseudonymized data “which could be attributed to a natural person by the use of additional information should be considered to be information on an identifiable natural person”.
The EU Court of Justice refined this on September 4, 2025, in EDPS v SRB, a case under the matching rules for EU bodies. It held that pseudonymized data “must not be regarded as constituting, in all cases and for every person, personal data”, since pseudonymization can, depending on the circumstances, stop people other than the original holder from identifying anyone. Whether that holder had to tell people about a recipient is judged at the time of collection, from the holder’s own point of view.
The UK regulator’s anonymisation guidance, which the ICO says is under review after the 2025 Act, treats identifiability as “a spectrum”, tested against a “motivated intruder”, and says the same information can be personal data for you and anonymous for a recipient without the extra information. It adds: “The end result (the anonymous information) is not subject to data protection law, but the procedure (anonymisation) is.”
Consistent labels, where one person is Person 01 throughout, are pseudonymization under these definitions (what “anonymized” means). Ask counsel whether the delivered copy would be anonymous in the buyer’s hands; preparing it is processing either way.
Do we need a lawful basis to license the records?
For the personal data in them, yes. The new use also has to meet the purpose limitation rule in Article 5(1)(b), under which data are collected “for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes”. What each rule covers:
- Lawful basis (Article 6(1)). Every use needs one, such as consent or legitimate interests, the second only where the rights of the people concerned do not override them.
- Compatibility (Article 6(4)). For a new purpose not based on consent or on a law, the test weighs the link to the original purpose, the context, the kind of data, the consequences for people, and safeguards “which may include encryption or pseudonymisation”.
- Notice (Articles 13(3) and 14(4)). People must be told about a new purpose “prior to that further processing”, whether the data came from them or, with some exceptions, from someone else.
- Sensitive data (Article 9(1)). Processing data about health, trade union membership and the other listed categories is prohibited unless an exception applies. A sick-leave thread in a manager’s inbox can contain health data.
The UK rules differ in detail. The ICO’s purpose limitation guidance, updated March 23, 2026 for the 2025 Act, sets out when a new purpose counts as compatible and says “You must have a lawful basis for all of your processing”.
Questions for counsel: which basis covers preparing and licensing the records, whether AI training fits the purposes in your privacy notices, whether those notices must change first, and which records fall under Article 9.
Can the records go to a US provider?
Only through a transfer mechanism, and onward transfers count too (Article 44). As of October 2026:
- EU-U.S. Data Privacy Framework. Since the Commission’s decision of July 10, 2023, “personal data can flow safely from the EU to US companies participating in the Framework” without extra safeguards. The EU General Court dismissed a challenge on September 3, 2025; the challenger appealed to the Court of Justice on October 31, 2025, WilmerHale reported that December.
- The UK Extension, usable from October 12, 2023. The ICO says the US recipient must be active on the DPF List, self-certified to the UK Extension and certified for the type of data, HR or non-HR (updated July 30, 2026).
- Contract clauses when the recipient is not certified: the EU’s standard contractual clauses of June 4, 2021, or the UK’s IDTA or Addendum with a transfer risk assessment.
Where de-identification happens matters here, since some providers receive raw records and others work inside your systems (who sees raw records). Ask every provider in writing which entity receives the records, where they are processed, which mechanism covers the transfer, and where the prepared copy goes next.
Which providers say they take companies outside the US?
Several, on different terms, and Nyne requires US employees. Below is every provider whose own pages set a seller-location rule or ask for the seller’s country, as of October 2026:
| Provider | What it says about location |
|---|---|
| Avelence | Profile form lists the UK, Germany, France, the Netherlands and Ireland among headquarters options (form) |
| Google content offer pilot | Says it has tested the pilot with partners “worldwide”; participants are in roughly 100 countries, VentureBeat reported on September 30, 2026 |
| Handshake AI | Payout estimator offers USA, Canada, Europe and Other (source) |
| License My Data | Enquiry form asks “Which country is the data in?” |
| micro1 | “We currently prioritize US companies, followed by other Western markets”; demand strongest in the US, UK and Canada; wants records in English; its payout estimator’s headquarters options are “United States”, “Canada or Europe” and “Other” (source) |
| Nyne | Requires “20+ full-time U.S. W-2 employees”; its estimator also lists Canada, Europe and Other |
| Polyshares | Intake asks for headcount in each country and the share of data in English (source) |
| Telegraph Lab (affiliated) | Calculator offers USA, Canada, Europe and Other (source); introductions through its partners must be US-based (source) |
The other providers in the buyers directory publish no seller-location rule on their program pages, so ask them directly. Location can also move a number; what determines the price covers Avelence’s lower model range for UK and European companies.
What do I do next?
- Map the records by entity and country: which company holds each system, whose data it holds, and where.
- Collect the privacy notices your UK and EU staff and customers were given, and any contracts that limit their data.
- Take this checklist to counsel in each country before any UK or EU sample is prepared, since preparing it is already processing.
- Ask providers the transfer questions in writing and file the answers with your data inventory.
- Consider the scope. Leaving UK or EU records out of a first license is one option to raise with counsel; leaving out records explains how exclusions are written.
Providers named on this page
Get offers
Find the next step for your company’s data.
- No records or exports needed to apply
- Free for businesses
- Your company profile comes to our team for review