AI developers are looking for new sources of AI training data. One hot source is internal operational data, such as company Slack or Teams messages, documents, tickets, and source code. Startups that are shutting down have been selling their Slack archives, email, and Jira tickets to AI developers. Operating companies are now getting the same calls. We are fielding a lot of questions from clients about whether, and how, they can say yes.
The highest-profile public example is Spirit Airlines. In August, Google won a bankruptcy auction for Spirit's internal business data with a $10 million bid. The proposed sale has drawn objections from Spirit's flight attendants' union and from a software vendor that says some of the data belongs to it.
Spirit is a bankruptcy case, but the questions it raises apply to any company with valuable data. If your company is approached to sell its data, what does it take, and what are the concerns? This article addresses that question, outlines issues companies should consider, and touches on what to do if your vendors hold your data.
Is It Legal?
As all good lawyers say, “it depends.” Selling company data for AI training can be done, but most companies cannot sell everything a buyer requests, and the work required is usually more than the offer suggests.
Key Concerns
Rights to the Data. A company that holds data does not necessarily have the right to sell it. Email and chat contain other companies' confidential information, often covered by NDAs and commercial agreements. Licensed data, open source and vendor code, third-party copyrighted material in attachments and shared files, and data generated by vendor tools may come with restrictions or competing ownership claims. In Spirit, a software vendor objected that records its platform generated belong to the vendor. The extraction method can also create problems. Slack's API terms, for example, prohibit third-party application providers from using API data to train a large language model. Finally, a sale may waive privilege over legal communications and jeopardize trade secret protection for pricing logic, strategy documents, and source code.
Privacy Commitments. Companies must comply with the privacy statements in effect when the data was collected. Most privacy policies, employee notices, and handbooks do not contemplate selling workplace communications for AI training. The FTC has long treated retroactive changes to privacy promises as potentially deceptive, and has specifically warned that adopting more permissive practices, such as sharing data with third parties or using it for AI training, through a quiet amendment to a privacy policy or terms of service may be unfair or deceptive. For data already collected, companies are bound by prior commitments unless they obtain consent. For data collected going forward, such as a recurring feed, companies can update notices prospectively and, where appropriate, obtain opt-in consent.
Privacy Law. The CCPA applies to the personal information of California employees, job applicants, contractors, and business contacts. A transfer of workplace data for money or other valuable consideration is a sale of personal information unless the data meets the CCPA's definition of de-identified (Cal. Civ. Code § 1798.140(m)), which requires technical measures, a public commitment not to re-identify, and contractual obligations on recipients. Selling personal information also triggers notice, opt-out, and risk assessment obligations (see Cal. Code Regs. tit. 11, § 7150). Internal data may also contain information subject to HIPAA, GLBA, children's privacy laws, biometric laws, and call recording consent laws, as well as the GDPR and other international laws.
Limits of De-Identification. Buyers may offer to de-identify the data, but de-identification has limits. Removing identifying details from millions of emails and chat messages is much harder than removing names from structured fields. De-identification also addresses whether a record can be linked to an individual, not whether its content is confidential. A disciplinary thread or pay complaint remains sensitive without a name attached. Buyers also want records to stay linked to each other, which is what makes the data valuable and what makes it possible to draw conclusions about individuals or small groups.
Employees and Labor. Employee communications about pay, scheduling, and working conditions may be protected concerted activity under Section 7 of the National Labor Relations Act (29 U.S.C. § 157), whether or not employees are unionized. Selling those communications, particularly in a form that could be used to identify or profile employees, could draw scrutiny under the NLRA. Where employees are unionized, the collective bargaining agreement may restrict the sale, and the company may have bargaining obligations.
Competition and Permanence. You may be selling data to a company that could ultimately use it to train an AI that develops a competing product. Once data is used to train a model, it cannot practically be pulled back out. Models can also reproduce portions of their training data in outputs to other users. The short-term value may not be worth the long-term risk.
Goodwill. Selling company data can damage trust. Even in Spirit, where the airline is no longer operating, the sale drew public objections from its flight attendants' union. An operating company has current employees, customers, and business partners who may be upset to learn their communications were sold, and that reaction can turn into complaints to regulators, contract disputes, or litigation.
Public Disclosure. The sale may not stay confidential. California's AB 2013 requires generative AI developers to publicly disclose high-level information about their training data, including its sources and whether it was purchased or licensed. The EU AI Act has similar requirements.
Practical Steps
Companies approached to sell data should treat the offer like any other high-risk data transaction: know what you have, confirm you can sell it, exclude what you should not sell, and control how the buyer can use it. Below are some practical steps.
Prepare Before the Call. Companies should know what data they hold, where it came from, and what their notices and contracts allow them to do with it, before an offer arrives. That groundwork makes it possible to say yes on good terms if the company chooses to. It also matters beyond these deals. Gaps in data rights and notices can surface in M&A diligence and affect how the company and its data are valued.
Assemble the Team. Legal, privacy, security, HR, and communications should be involved. These deals should not be run by business development alone. Do not share sample data before this review, since a sample itself could be a disclosure.
Inventory the Data. Identify the systems, record types, volume, and time period requested. Consider listing each data set by system, record count, and start date, and marking each as included or excluded.
Confirm the Right to Sell. Review customer, partner, vendor, and data license agreements, identify data held as a service provider or processor, and review platform terms for the systems the data will be extracted from.
Evaluate the Economics. Weigh the price against the cost of the review, the residual risk, and the effect on employees and business partners.
Define Exclusions. Exclude high-risk data entirely rather than relying on de-identification. Consider privileged material, HR and personnel files, payroll and tax records, health and benefits information, union-related communications, customer and partner confidential information, licensed data, and data from regulated systems.
Control De-Identification. Select (or jointly select) the de-identification provider, approve the protocol, and require certification to the company's satisfaction.
Secure the Transfer. Extracting and transferring large volumes of data requires robust security. Limit who accesses raw data before de-identification, avoid giving buyer tools direct access to company systems, and use a secure transfer method.
Negotiate the Terms. The agreement should restrict how the buyer can use the data, allocate privacy risk, and address what happens if something goes wrong. Privacy and security representations in particular deserve careful attention.
Document the Decision. Document the review, exclusions, de-identification protocol, and business justification, along with any required risk assessment. If the company is later acquired, a prior data sale will come up in diligence, and buyers will expect to see this record.
If Your Vendors Hold Your Data
Your data does not need to be sold by you to end up in a training set. Vendors that hold company data get the same inquiries, and may sell that data when they are acquired, shut down, or file for bankruptcy. Companies that want to keep their data out of training sets should look closely at the vendors that hold it, starting with HR and collaboration vendors.
Review the Contract. Check whether the agreement permits the vendor to sell, license, or transfer company data, and whether de-identified or aggregated data carve-outs leave room for a sale.
Plan for a Sale or Shutdown. Confirm what happens to company data if the vendor is acquired, goes out of business, or files for bankruptcy, including whether the data must be returned or deleted.
Act Before an Offer Arrives. Contract changes are far easier to negotiate before a vendor receives an offer of its own.
If You Are the Vendor. Expect customers to ask you these same questions, and check whether your customer agreements and data processing agreements would permit a sale before you entertain an offer.
If you have received one of these inquiries, want to get ahead of one, or want to review your vendor agreements, please send me a message.

/Passle/644c41cc474c4c94b77327c8/SearchServiceImages/2026-10-01-01-21-33-675-6abdb59d9e010dd7f474bd1d.jpg)
/Passle/644c41cc474c4c94b77327c8/SearchServiceImages/2026-09-09-04-48-18-909-6aa0e512414b094d694c464a.jpg)
/Passle/644c41cc474c4c94b77327c8/MediaLibrary/Images/6373fcf4f636e919680b254a/2024-02-12-23-06-45-859-65caa4857f5a53a7bf1fc7df.jpg)
/Passle/644c41cc474c4c94b77327c8/SearchServiceImages/2026-08-06-00-31-43-267-6a73d5ef5b401acf132e82f2.jpg)