THE ORIGIN FIELD GUIDE

Is it legal to sell company data for AI training?

Often yes, if the company holds the rights. What privacy law, contracts, copyright and the 2026 Spirit Airlines data sale mean for licensing company records.

THE SHORT ANSWER

Often yes. No US federal law bans a company from licensing its own business records for AI training. The limits come from what the records contain and what the company promised: privacy laws such as California's CCPA and Europe's GDPR when records hold personal information, customer and employee agreements, the company's own privacy policy, other people's copyright, and sector rules such as HIPAA. The usual safeguards are removing or de-identifying personal information and a written license that restricts use. This is general information, not legal advice.

  • Start with what the records contain. Personal information, customer data and third-party work each raise a different legal question.
  • Check what the company promised. Privacy policies, customer contracts and employee notices can limit a new use.
  • De-identification and a restrictive license are the usual safeguards, but neither settles every question on its own.

Can a company legally sell its data for AI training?

No single US federal law prohibits a company from licensing its own business records to an AI developer. Whether a specific deal is lawful depends on the records and the promises around them.

Four questions do most of the work. Does the material contain personal information? Did the company promise customers or employees anything about how it would be used? Does the company hold the rights to everything in it? Does a sector rule apply?

Origin Data Partners is not a law firm. This guide summarizes primary sources so you can frame questions for your own counsel. It is not legal advice.

What the 2026 Spirit Airlines data sale shows

In August 2026, Google won a bankruptcy auction for Spirit Airlines' internal business data with a $10 million bid, Axios reported. The data reportedly included about 100 million emails and 500 million Microsoft Teams chats, plus documents, spreadsheets, HR material and financial records. Passenger profiles and frequent flyer records were excluded, and the data was to be de-identified before delivery.

US bankruptcy law limits the sale of personally identifiable information when a debtor's privacy policy prohibits transferring it. The sale must then match the policy, or a court must approve it after a consumer privacy ombudsman is appointed (11 U.S.C. § 363(b)(1)). In October 2026 the ombudsman reported that Spirit and Google had taken adequate steps to protect consumer privacy, Bloomberg Law reported. As of October 8, 2026, the sale still needed court approval.

Employee data drew the objections. The Association of Flight Attendants-CWA told the court that employee data is more confidential than customer data and that de-identified records can still be linked across the data set, Fortune reported. The union did not ask to stop the sale; it asked for identifying information to be removed.

The lessons apply to a solvent company too. The sale centered on internal business records, customer databases were left out, personal information was handled before delivery, and employee data needed its own review.

Personal information is the first question.

Under the California Consumer Privacy Act, making personal information available to a third party for money or other valuable consideration is a sale (Cal. Civ. Code § 1798.140(ad)), and California residents can opt out of sales. Calling the deal a license does not change that. Since January 1, 2023, the CCPA has also covered employee and business-contact information (California Lawyers Association), which appears throughout email, chat and ticket histories.

Properly deidentified information is not personal information under the CCPA. The statute sets three conditions: reasonable measures so the data cannot be associated with a person or household, a public commitment not to reidentify it, and contracts requiring every recipient to follow the same rules (§ 1798.140(m)).

Under the GDPR, each use of personal data needs a lawful basis, and reuse for a new purpose must be compatible with the original one unless it rests on consent or a legal requirement (Article 6(4)). Anonymous information falls outside the GDPR. The European Data Protection Board's Opinion 28/2024 adds that whether an AI model trained on personal data is itself anonymous must be assessed case by case.

The HIPAA Privacy Rule does not restrict health information that has been de-identified by one of two methods, expert determination or safe harbor (HHS). Identifiable health information held by a covered entity or business associate needs a separate legal basis, such as patient authorization.

Check what the company promised.

The FTC has warned that adopting more permissive data practices, such as using data for AI training, and disclosing the change only through a surreptitious, retroactive amendment to terms or a privacy policy may be unfair or deceptive (FTC, February 13, 2024).

Customer agreements matter as much as statutes. A company that holds customer data as a service provider or processor is usually limited to processing it for that customer. Under the GDPR, a processor that decides its own purposes for the data is treated as a controller for that processing (Article 28(10)).

Read employment agreements, handbooks, works council or union agreements and confidentiality terms before including internal email, chat or HR material. In the Spirit sale, the objections came from employee representatives.

Does the company hold the rights to everything in the records?

Copyright protects expression, not facts, ideas or methods of operation (U.S. Copyright Office). Records can still contain material the company does not control: contractor work without an assignment, licensed software or content, customer files, and documents received under a confidentiality agreement.

Each of those needs its own answer before it goes into a licensed set. See what you can authorize for how to separate record categories.

Where Origin fits

Origin Data Partners helps established companies describe their records at company level and consider a permission-based introduction to a receiving program. No records are needed to start. Origin does not decide legal questions; your counsel does.

Talk to Origin about your company and potential licensing opportunities.

Common questions

Is selling company data the same as licensing it?

Not always. A license grants permission for defined uses and can leave ownership with your company. Under the CCPA, though, making personal information available for money or other valuable consideration can be a sale whatever the contract calls it.

Does removing names make records safe to license?

Not on its own. The CCPA's deidentification standard also requires a public commitment not to reidentify and contracts binding recipients. In the Spirit sale, a union argued that de-identified records could still be linked across the data set.

Can a company in bankruptcy sell its data for AI training?

It can, with limits. If its privacy policy prohibits transferring personally identifiable information, the sale must be consistent with that policy or approved by the court after a consumer privacy ombudsman is appointed.

Do we need a lawyer before talking to Origin?

No. A first conversation with Origin needs only a company-level description. Legal review belongs before any records are shared or a license is signed.

Sources and further reading

START WITH YOUR COMPANY

Explore what your
business already has.

Tell us about your business. We’ll discuss relevant records and potential licensing opportunities. No files required.