Privacy and law

GDPR and selling data for AI training

Truly anonymous data falls outside the GDPR. Anything still personal needs a lawful basis, a purpose check, clear roles and a transfer mechanism before a lab gets it.

·5 min read

You can license data to an AI company under the GDPR, but the rules you face depend on one question: is the data still personal data when it leaves you? If it is truly anonymous, the GDPR doesn't apply to it; if anyone could still reasonably identify a person, you need a lawful basis, a purpose check, the right contract roles and, for a US buyer, a transfer mechanism.

This page is general information, not legal advice. Selling to a lab is a new use of data, so get a privacy lawyer to review your case before the first deal.

Step 1: is it still personal data?

Recital 26 of the GDPR says the regulation does not apply to anonymous information. Data counts as anonymous only if no one can identify a person by means reasonably likely to be used, by you or by anyone else, taking cost, time and technology into account.

That bar is high. Replacing names with codes is pseudonymization, and the European Data Protection Board's Guidelines 01/2025 confirm pseudonymized data is still personal data. Business records also hold personal data you might not expect. The UK ICO says the names and details of contacts at other businesses are personal data, even when those people act for their employer.

If your scrubbed dataset meets the anonymity test, most of the steps below fall away. The work of getting there, and testing it, is covered in de-identification vs anonymization and k-anonymity in plain English. If any doubt remains, plan as if the GDPR applies.

Step 2: does the new purpose fit the old one?

Data must be collected for specified purposes and not used in ways incompatible with them, the purpose limitation principle in Article 5(1)(b). Licensing records to a lab to train a model is almost never the purpose you collected them for.

Article 6(4) sets out how to judge whether a new purpose is compatible. It looks at:

  • the link between the original purpose and the new one
  • the context of collection and what people would reasonably expect
  • the nature of the data, especially special categories
  • the possible consequences for the people involved
  • safeguards such as encryption or pseudonymization

If the new purpose isn't compatible, you need a fresh lawful basis for it and updated privacy notices.

Step 3: pick a lawful basis

For most sellers the options are consent or legitimate interests under Article 6(1)(f).

Consent rarely works for historical business records, because you would need to reach every person in them. Legitimate interests is more practical but requires a documented three-part test: your interest is legitimate, the processing is necessary for it, and the interest isn't overridden by the rights of the people in the data. The ICO's guidance explains how to run that test. The EDPB applied the same three steps to AI development in Opinion 28/2024.

Safeguards strengthen the balancing step. Heavy de-identification, dropped free text, a ban on re-identification and a short license term all reduce the impact on the people in the data.

Two limits apply whatever basis you choose. People can object to processing based on legitimate interests under Article 21. Special category data, such as health information, needs an extra condition under Article 9, which is hard to meet for AI training. We leave health data out unless it is already fully anonymized under existing approvals.

Step 4: get the roles right

The GDPR assigns duties by role. A controller decides why and how data is processed. A processor acts only on a controller's instructions.

A lab that trains its own model on your data decides its own purposes, so it is a controller for that processing. Calling it a processor in the contract doesn't change that. Article 28(10) says a processor that decides the purposes and means of processing is treated as a controller for it. The IAPP has written about where that line falls for AI training.

Your own role matters too. If you hold the data as a processor for your customers, it isn't yours to license without their permission. Can I sell data I hold for my customers covers that case.

Step 5: tell people

If you rely on legitimate interests or a compatible purpose, your privacy notice has to describe the new use and the categories of recipients. Where the buyer receives personal data it didn't collect from the person, Article 14 notice duties can apply. Update notices before data moves.

Step 6: transfers outside the UK and EEA

Most AI labs are in the US. Sending personal data there needs a safeguard under Article 46, usually the European Commission's standard contractual clauses, plus a transfer risk assessment. The clauses come in modules. A lab acting as an independent controller usually signs the controller-to-controller module.

Truly anonymous data doesn't need any of this, which is one more reason to scrub hard.

Step 7: assess the risk

Large-scale or novel processing, which AI training often is, may need a data protection impact assessment. Even where it isn't strictly required, a written assessment gives you a record of the reasoning behind each of the steps above.

How our process lines up

  • Rights first. On the first call we ask about rights before anything else, and we read your customer agreements and data processing agreements during rights review.
  • Scrubbing on your machine. Our SDK scrubs data where it lives. Only scrubbed output and the scrub report are uploaded.
  • Re-identification testing. We test before every sale and keep the report.
  • Buyer terms. Licenses ban re-identification, resale and combining with other data, end on a fixed date, require deletion of raw data and bind anyone the buyer shares with.
  • Buyer approval. You approve each buyer by name.

None of that replaces your own lawful basis and notices, which only you can put in place.

Find out if your data is worth the work

The legal steps take time, so it helps to know the prize first. Our calculator gives an estimate, and recurring data revenue explains how one license can keep paying each month. If you also hold records about Californians, read the CCPA guide too, or start at sell data to AI companies.

Frequently asked questions

Does the GDPR apply to anonymized data?

No. Recital 26 says anonymous information is outside the GDPR. The catch is that data only counts as anonymous if no one could reasonably identify a person from it, and pseudonymized data does not meet that test.

Can I rely on legitimate interests to license data for AI training?

Possibly. You need a documented test showing the interest is legitimate, the processing is necessary, and the rights of the people in the data don't override it. Strong de-identification and strict buyer terms help with the balancing, and people keep the right to object.

Is an AI lab a processor or a controller?

A lab that uses your data to train its own models decides its own purposes, so it is normally a controller for that processing. Article 28(10) treats a processor that sets its own purposes as a controller.

Do I need standard contractual clauses to send data to a US lab?

If the data is personal data and leaves the UK or EEA, you need a transfer safeguard such as the standard contractual clauses and a transfer risk assessment. Truly anonymous data is outside these rules.

Find out what your records are worth.

Value my data