# Is it legal to sell company data for AI training?

> Often yes, if the company holds the rights. What privacy law, contracts, copyright and the 2026 Spirit Airlines data sale mean for licensing company records.

Canonical: https://origindatapartners.com/guides/sell-company-data-ai-training-legal
By: Origin Data Partners
Status: Published
Published: 2026-10-08
Updated: 2026-10-08
Sources checked: 2026-10-08

## Quick answer

Often yes. No US federal law bans a company from licensing its own business records for AI training. The limits come from what the records contain and what the company promised: privacy laws such as California's CCPA and Europe's GDPR when records hold personal information, customer and employee agreements, the company's own privacy policy, other people's copyright, and sector rules such as HIPAA. The usual safeguards are removing or de-identifying personal information and a written license that restricts use. This is general information, not legal advice.

## Key points

- Start with what the records contain. Personal information, customer data and third-party work each raise a different legal question.
- Check what the company promised. Privacy policies, customer contracts and employee notices can limit a new use.
- De-identification and a restrictive license are the usual safeguards, but neither settles every question on its own.

## Can a company legally sell its data for AI training?

No single US federal law prohibits a company from licensing its own business records to an AI developer. Whether a specific deal is lawful depends on the records and the promises around them.

Four questions do most of the work. Does the material contain personal information? Did the company promise customers or employees anything about how it would be used? Does the company hold the rights to everything in it? Does a sector rule apply?

Origin Data Partners is not a law firm. This guide summarizes primary sources so you can frame questions for your own counsel. It is not legal advice.


## What the 2026 Spirit Airlines data sale shows

In August 2026, Google won a bankruptcy auction for Spirit Airlines' internal business data with a $10 million bid, [Axios reported](https://www.axios.com/2026/08/17/google-spirit-airlines-bankruptcy). The data reportedly included about 100 million emails and 500 million Microsoft Teams chats, plus documents, spreadsheets, HR material and financial records. Passenger profiles and frequent flyer records were excluded, and the data was to be de-identified before delivery.

US bankruptcy law limits the sale of personally identifiable information when a debtor's privacy policy prohibits transferring it. The sale must then match the policy, or a court must approve it after a consumer privacy ombudsman is appointed ([11 U.S.C. § 363(b)(1)](https://www.law.cornell.edu/uscode/text/11/363)). In October 2026 the ombudsman reported that Spirit and Google had taken adequate steps to protect consumer privacy, [Bloomberg Law reported](https://news.bloomberglaw.com/bankruptcy-law/spirit-data-sale-to-google-passes-muster-privacy-ombudsman-says). As of October 8, 2026, the sale still needed court approval.

Employee data drew the objections. The Association of Flight Attendants-CWA told the court that employee data is more confidential than customer data and that de-identified records can still be linked across the data set, [Fortune reported](https://fortune.com/2026/08/21/flight-attendant-union-google-confidential-data-spirit-airlines/). The union did not ask to stop the sale; it asked for identifying information to be removed.

The lessons apply to a solvent company too. The sale centered on internal business records, customer databases were left out, personal information was handled before delivery, and employee data needed its own review.


## Personal information is the first question.

Under the California Consumer Privacy Act, making personal information available to a third party for money or other valuable consideration is a sale ([Cal. Civ. Code § 1798.140(ad)](https://law.justia.com/codes/california/code-civ/division-3/part-4/title-1-81-5/section-1798-140/)), and California residents can opt out of sales. Calling the deal a license does not change that. Since January 1, 2023, the CCPA has also covered employee and business-contact information ([California Lawyers Association](https://calawyers.org/privacy-law/hr-employee-data-b2b-data-to-come-within-scope-of-ccpa-on-january-1-2023/)), which appears throughout email, chat and ticket histories.

Properly deidentified information is not personal information under the CCPA. The statute sets three conditions: reasonable measures so the data cannot be associated with a person or household, a public commitment not to reidentify it, and contracts requiring every recipient to follow the same rules ([§ 1798.140(m)](https://law.justia.com/codes/california/code-civ/division-3/part-4/title-1-81-5/section-1798-140/)).

Under the GDPR, each use of personal data needs a lawful basis, and reuse for a new purpose must be compatible with the original one unless it rests on consent or a legal requirement ([Article 6(4)](https://gdpr-info.eu/art-6-gdpr/)). Anonymous information falls outside the GDPR. The European Data Protection Board's [Opinion 28/2024](https://edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf) adds that whether an AI model trained on personal data is itself anonymous must be assessed case by case.

The HIPAA Privacy Rule does not restrict health information that has been de-identified by one of two methods, expert determination or safe harbor ([HHS](https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification/index.html)). Identifiable health information held by a covered entity or business associate needs a separate legal basis, such as patient authorization.


## Check what the company promised.

The FTC has warned that adopting more permissive data practices, such as using data for AI training, and disclosing the change only through a surreptitious, retroactive amendment to terms or a privacy policy may be unfair or deceptive ([FTC, February 13, 2024](https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/02/ai-other-companies-quietly-changing-your-terms-service-could-be-unfair-or-deceptive)).

Customer agreements matter as much as statutes. A company that holds customer data as a service provider or processor is usually limited to processing it for that customer. Under the GDPR, a processor that decides its own purposes for the data is treated as a controller for that processing ([Article 28(10)](https://gdpr-info.eu/art-28-gdpr/)).

Read employment agreements, handbooks, works council or union agreements and confidentiality terms before including internal email, chat or HR material. In the Spirit sale, the objections came from employee representatives.


## Does the company hold the rights to everything in the records?

Copyright protects expression, not facts, ideas or methods of operation ([U.S. Copyright Office](https://www.copyright.gov/help/faq/faq-protect.html)). Records can still contain material the company does not control: contractor work without an assignment, licensed software or content, customer files, and documents received under a confidentiality agreement.

Each of those needs its own answer before it goes into a licensed set. See [what you can authorize](https://origindatapartners.com/guides/license-company-data#records-and-rights) for how to separate record categories.


## Legal review checklist before licensing records

Take these questions to counsel with a description of the records, not the records themselves.

- When a defined proposal arrives, use the [due diligence checklist](https://origindatapartners.com/guides/data-licensing-due-diligence) to review the recipient, scope and terms.

| Question | Why it matters | Who usually answers |
| --- | --- | --- |
| Does the set contain personal information, including employee and business contacts? | Privacy laws such as the CCPA and GDPR may treat sharing as a sale or require a lawful basis | Privacy counsel |
| Is any of it customer data we hold as a service provider or processor? | Contracts and privacy law usually limit that data to serving the customer | Contract owner with counsel |
| What do our privacy policy, terms and employee notices say about sharing? | A new use disclosed only through a quiet change may be unfair or deceptive | Legal |
| Who created each record category, and under what agreement? | Contractor, licensed and third-party material may not be ours to license | Operations with counsel |
| Does a sector rule apply, such as HIPAA? | Some data needs a specific de-identification method or authorization | Compliance |
| What will the license permit, prohibit and require after it ends? | Reidentification bans, onward-transfer limits and deletion terms protect the company | Counsel and the decision maker |


## Where Origin fits

Origin Data Partners helps established companies describe their records at company level and consider a permission-based introduction to a receiving program. No records are needed to start. Origin does not decide legal questions; your counsel does.

[Talk to Origin](https://origindatapartners.com/check-fit) about your company and potential licensing opportunities.


## Questions and answers

### Is selling company data the same as licensing it?

Not always. A license grants permission for defined uses and can leave ownership with your company. Under the CCPA, though, making personal information available for money or other valuable consideration can be a sale whatever the contract calls it.

### Does removing names make records safe to license?

Not on its own. The CCPA's deidentification standard also requires a public commitment not to reidentify and contracts binding recipients. In the Spirit sale, a union argued that de-identified records could still be linked across the data set.

### Can a company in bankruptcy sell its data for AI training?

It can, with limits. If its privacy policy prohibits transferring personally identifiable information, the sale must be consistent with that policy or approved by the court after a consumer privacy ombudsman is appointed.

### Do we need a lawyer before talking to Origin?

No. A first conversation with Origin needs only a company-level description. Legal review belongs before any records are shared or a license is signed.

## Sources

- [Axios: Google buys Spirit Airlines emails, chats, documents out of bankruptcy (August 17, 2026)](https://www.axios.com/2026/08/17/google-spirit-airlines-bankruptcy)
- [Fortune, August 21, 2026: flight attendants' union objects to the Spirit data sale](https://fortune.com/2026/08/21/flight-attendant-union-google-confidential-data-spirit-airlines/)
- [Bloomberg Law: Spirit data sale to Google passes muster, privacy ombudsman says (October 5, 2026)](https://news.bloomberglaw.com/bankruptcy-law/spirit-data-sale-to-google-passes-muster-privacy-ombudsman-says)
- [11 U.S.C. § 363, Legal Information Institute](https://www.law.cornell.edu/uscode/text/11/363)
- [Cal. Civ. Code § 1798.140, CCPA definitions](https://law.justia.com/codes/california/code-civ/division-3/part-4/title-1-81-5/section-1798-140/)
- [California Lawyers Association: HR and B2B data within CCPA scope from January 1, 2023](https://calawyers.org/privacy-law/hr-employee-data-b2b-data-to-come-within-scope-of-ccpa-on-january-1-2023/)
- [FTC: Quietly changing your terms of service could be unfair or deceptive (February 13, 2024)](https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/02/ai-other-companies-quietly-changing-your-terms-service-could-be-unfair-or-deceptive)
- [GDPR Article 6: Lawfulness of processing](https://gdpr-info.eu/art-6-gdpr/)
- [GDPR Article 28: Processor](https://gdpr-info.eu/art-28-gdpr/)
- [European Data Protection Board: Opinion 28/2024 on AI models (December 17, 2024)](https://edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf)
- [HHS: Methods for de-identification of protected health information](https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification/index.html)
- [U.S. Copyright Office: What does copyright protect?](https://www.copyright.gov/help/faq/faq-protect.html)

## Related reading

- [How to license company data for AI](https://origindatapartners.com/guides/license-company-data)
- [Company data licensing due diligence checklist](https://origindatapartners.com/guides/data-licensing-due-diligence)
- [How much is your company data worth?](https://origindatapartners.com/guides/company-data-value)
- [Who buys company data for AI training?](https://origindatapartners.com/guides/who-buys-company-data-ai-training)
