We check that you have the right to license data before we touch any of it. The review happens after the NDA is signed and before the readiness report. None of what follows is legal advice, and for regulated data we ask your own counsel to sign off.
Ownership and contracts
You must own the data, or hold a license to it that allows a sale. We read your customer agreements, data processing agreements and confidentiality clauses. A clause such as "used only to provide the service" blocks a sale even after scrubbing.
Controller or processor
If you hold the data on behalf of your customers, as their processor, you usually cannot license it without their written permission. See Data you hold for customers.
Lawful basis under GDPR
Licensing data to an AI lab is a new purpose for it. Under UK and EU GDPR, that purpose needs a documented legal basis, privacy notices that cover it, and consent where consent is the basis.
California
Under California law, transferring data for money counts as a sale. De-identified data is exempt only if re-identification is banned in contract and prevented in practice. Our licenses ban it, and the scrubber and its report address the practical side.
Data leaving the UK or EEA
Sending data from the UK or EEA to a lab in the United States needs standard contractual clauses and a transfer risk assessment.
Sector rules
Health, finance, government and export-controlled data need their own review or are excluded. Semiconductor data needs an export control check.
What is excluded by default
Raw source code, security logs, credentials, and free text containing personal details stay out unless they pass a dedicated review.
Before every sale
We run the re-identification test before every sale and keep the report.