Usually not without their written permission. If you hold data on your customers' behalf, as their processor or under a service contract, the data is theirs to license, and a clause saying it is used "only to provide the service" blocks a sale even after the data is scrubbed.
That still leaves plenty you can sell. The trick is sorting your data by whose it is before anyone talks price. This page is general information, not legal advice, and a lawyer should read the contracts that decide your case.
Two kinds of data in every company
Most businesses hold both:
- Data about your own operations. Your invoices, your pipeline, your support tickets, your project plans, your lab results. You generated it running your business.
- Data you hold for customers. Their files on your platform, the books you keep for them, the documents you store, the records you process as part of a service they pay for.
The first kind is usually yours to license, subject to privacy law and any confidentiality you promised. The second kind usually isn't, because someone else controls it.
The line isn't always clean. An accounting firm's own records of how it closed a client's month sit next to the client's ledger. A support team's ticket history describes customers' problems. Sorting starts with the contracts.
Controller or processor?
Under the GDPR, the party that decides why and how data is processed is the controller. A processor acts on the controller's instructions. Most software vendors, outsourcers and service firms are processors for their customers' data, and the contract between them is a data processing agreement.
A processor that starts using customer data for its own purposes, such as licensing it to an AI lab, steps outside its instructions. Article 28(10) of the GDPR says a processor that decides the purposes and means of processing is treated as a controller for that processing, with all of a controller's duties and none of the legal basis the real controller had. The IAPP has written about how narrow the room is for a processor to train AI on customer data and stay a processor.
The safe reading: if you are a processor for a dataset, you need the controller's written permission to license it.
What owning the platform doesn't give you
SaaS terms often make the customer's ownership explicit. HubSpot's customer terms say the customer "owns and retains all rights" to its Customer Data and give HubSpot permission to use it as necessary to provide the service. Many B2B contracts read the same way. If yours do, data your customers put into your product is theirs, and your license to use it ends at running the service.
Professional confidentiality
Some professions add duties on top of contracts:
- Accountants. The AICPA's confidential client information rule bars members in public practice from disclosing client information without the client's specific consent. US tax return preparers also face IRC section 7216, which makes unauthorized disclosure or use of tax return information a crime. See selling accounting data.
- Lawyers. Model Rule 1.6 bars revealing information relating to a representation without the client's informed consent. See selling legal documents.
These rules apply even when the data has been scrubbed, because the duty attaches to the client's information, and consent is the normal way through.
Clauses to look for
When we run a rights review, these are the clauses that decide the answer:
| Clause | What it usually means |
|---|---|
| "Used only to provide the services" | Licensing to a third party is outside the permitted use |
| Customer owns all Customer Data | The data is the customer's to license |
| Confidentiality covering customer information | Disclosure needs consent, even scrubbed |
| Permission to use "aggregated" or "de-identified" data | Possibly room to license, depending on the exact wording and purpose |
| Data processing agreement naming you as processor | You act only on instructions; a sale needs permission |
| Silence | No express permission; get advice before relying on it |
A clause allowing use of de-identified or aggregated data to "improve the services" is common. It may not stretch to selling that data to someone else for their own model. The exact words matter, which is why a lawyer should read them. The law firm Frankfurt Kurnit has a useful overview of these questions.
How to get permission
If the most valuable data belongs to your customers, asking them can work.
- Start with the customers who matter most to the dataset, or those whose contracts are up for renewal.
- Explain the deal plainly. What will be shared, how it is scrubbed, who the buyer types are, what the license forbids, and what they get.
- Offer them a share. A customer whose records earn money has a reason to say yes.
- Get it in writing. An amendment or a signed consent that names the use.
- Leave out anyone who declines. Their records stay out of every batch.
Some customers will want to sell their own data directly. That's fine too, and they can apply to us themselves.
Where the line usually falls
The dataset that clears rights review can be a narrower slice than a seller first expects. Splits like these are typical:
- A software company licenses its own planning, tickets and release history, and leaves customer content out.
- An accounting firm licenses its own procedures and close checklists, and licenses client ledgers only where clients signed consent.
- A support team licenses the conversations it has on its own behalf where callers were told the call may be recorded, and leaves out calls handled for outsourcing clients.
If we can't get a clear answer on a dataset, we leave it out. Unclear rights also lower the estimate our calculator shows: "not sure" cuts it, and "customer contracts restrict it" cuts it further. We would rather find that out before a buyer does.
Start with what is clearly yours
Your own operational records are often enough to start, and permissions for customer data can come later as a second dataset. Get an estimate from the calculator, read how licenses keep paying in recurring data revenue, or apply at sell data to AI companies. The first call is 30 minutes, and rights are the first thing we ask about.
Frequently asked questions
Can I sell my customers' data if I remove their names first?
Usually not. If your contracts limit use to providing the service, or you act as their processor, scrubbing doesn't create a right to sell. You need their written permission.
What if my contract lets me use de-identified data?
Read the purpose. Permission to use de-identified data to improve your own service may not cover licensing it to an AI lab for its own model. A lawyer should check the exact wording before you rely on it.
How do I know if I'm a controller or a processor?
Ask who decides why the data is processed. If your customer decides and you follow their instructions under a data processing agreement, you are their processor for that data.
What data can I usually sell?
Records your company generated running its own business, such as your own invoices, plans, tickets and procedures, subject to privacy law and confidentiality promises. These are often the core of a first license.