Can you sell a customer list? What the rules say and what to license instead
Sometimes, but it depends on what the business promised customers, which privacy laws cover the data and what its contracts say. Transferring a list as part of selling the whole business is common; selling consumer data on its own to a third party is often restricted. SourceX steers owners away from customer lists and toward operational records.
The short answer: it depends on promises, laws and contracts
A business can often transfer its customer list when it sells the whole company, because the list moves with the goodwill it supports. Selling or licensing that list on its own, to an unrelated third party, is a different act. It can collide with the privacy policy in force when the data was collected, with state privacy statutes, with sector rules for financial or health data, and with confidentiality clauses in customer contracts.
Three questions decide most cases:
- Promises: what did the business tell customers about selling, sharing or reusing their information when it collected it?
- Laws: which privacy rules reach this data, given where the customers live and what industry the business is in?
- Contracts: do customer agreements, NDAs or data-vendor licenses treat customer identities or transaction details as confidential?
A B2B list and a consumer list are not treated the same way, and neither are a list that moves inside a company sale and a list rented to a marketer. The rest of this page walks through the rules and the common situations.
What do the rules actually say?
No single US law governs customer lists. Several regimes overlap, and the strictest one that applies usually sets the limit.
- Privacy promises are enforceable. In a January 2024 staff post, the Federal Trade Commission said that promises a company makes about how it uses customer data, including not using it to train or update models, can be enforced whether they appear in a privacy policy, terms of service or marketing (FTC staff post on privacy commitments). A month later, FTC staff added that adopting more permissive practices, such as sharing data or using it for AI training, and disclosing them only through a quiet retroactive change to the terms could be unfair or deceptive (FTC staff post on changing terms). Both are staff guidance, not rules.
- California regulates selling and sharing. For businesses covered by the California Consumer Privacy Act, the notice at collection must say whether personal information is sold or shared, and a business that sells or shares personal information must have a written agreement limiting the recipient's use to specified purposes (California Civil Code 1798.100 et seq.). The definitions in section 1798.140 decide whether a given transfer counts, so read them before assuming a license falls outside them. Other states have their own consumer privacy laws, and the definitions vary by state.
- Financial customer data has its own rule. Financial institutions under the FTC's jurisdiction must give customers privacy notices and, before sharing their information with certain nonaffiliated third parties, opt-out rights under the Gramm-Leach-Bliley Act (FTC guidance on the Gramm-Leach-Bliley Act).
- Promises survive bankruptcy. If a debtor's privacy policy prohibited transferring personally identifiable information to unaffiliated persons and was in effect when the case began, the trustee may sell that information only consistently with the policy, or after a consumer privacy ombudsman is appointed, notice and a hearing are held and the court approves (11 U.S.C. 363).
- A confidential list may be a protected business asset. Whether a particular list qualifies as a trade secret depends on state and federal law and on how carefully the business guarded it. That question belongs with counsel, and it cuts both ways: a list worth protecting is also a list a seller should not hand to strangers.
How the rules apply in common situations
Use this table to frame the conversation with counsel. The right-hand column is a typical starting point, not a conclusion.
| Situation | What to check | Typical outcome to confirm with counsel |
|---|---|---|
| Whole business is sold and the list goes with it | Privacy policy wording on business transfers; assignment clauses in customer contracts | Often workable when the policy anticipates a sale and the buyer keeps the same use |
| B2B prospect list sold to another vendor | How contacts were gathered; terms of any purchased data; state laws that reach business contacts | Depends on the source; purchased data often comes with a no-resale clause |
| Consumer list licensed to a third party for marketing | Notice at collection, opt-out handling, any statement that the business does not sell data | Frequently restricted; may need new notice or consent |
| Financial services firm shares customer data | Privacy notices and opt-out records | Limited to what the notices and the rule's exceptions allow |
| Debtor in bankruptcy sells customer data | Privacy policy in force at filing; ombudsman's report | Court approval needed where the policy barred transfer |
| Customer data licensed for AI training | What the policy and terms said about use; client confidentiality clauses | Promises made at collection usually control; retroactive changes are risky |
The companion page on what happens to customer data when a business is sold covers the transaction side in more depth.
Why SourceX does not license customer lists
SourceX connects companies with AI labs and data buyers who license business records for training and evaluation. A customer list is mostly personal data about other people, gathered for a different purpose, and the company rarely holds a basis for licensing it. Mainly consumer personal data with no licensing basis is one of the red flags that stops a referral before qualification starts.
There is also a commercial reason: buyers are not shopping for contact data. Developers building AI agents need records of how work gets done, with steps, decisions and outcomes. A spreadsheet of names and emails shows none of that.
The same logic covers records that belong to a company's clients rather than to the company. Agencies, outsourcers and processors often hold data they have no right to license; the guide on distinguishing company data from data owned by its customers sets out the test, and the page on selling a marketing agency shows how it plays out in one industry.
What can an owner license instead?
Most established companies hold operational records that are their own work product. Any personal details inside them are handled under de-identification and redaction rules the company signs off on before work starts.
| Instead of | Consider | Why it is a different proposition |
|---|---|---|
| Consumer names, emails and purchase histories | Support ticket threads with resolutions | Shows how problems were diagnosed and solved; identities can be redacted |
| Prospect contact lists | CRM deal records with stages, notes and win or loss outcomes | Captures decisions and results; contact fields are masked |
| Loyalty or subscriber files | SOPs, playbooks and internal wikis | Company-authored and rarely about individuals |
| Marketing segments | Finance and procurement workflows with approvals | Records judgment calls with known outcomes |
| Mailing lists | Engineering tickets, code reviews and design documents | Multi-step work by the company's own staff |
To be a fit, the company also needs to clear the baseline: a US business with 50+ full-time employees at peak (contractors excluded), several years of documented operations, rights to the records and an executive who can authorize a license. The who qualifies page sets out the full criteria.
Disclosure and consent good practice
- Pull every version of the privacy policy and terms that applied while the data was collected, not just the current one.
- Map each customer segment to its source: web sign-ups, trade show scans, purchased lists, partner referrals.
- Search customer contracts and NDAs for clauses that make customer identity or transaction data confidential.
- Treat any plan to reuse customer data for a new purpose as a change that may need fresh notice or consent, decided with counsel.
- Keep the list out of emails, data rooms and introductions unless counsel has cleared the recipient and the purpose.
Questions to ask your counsel
- Which privacy policy version governed each part of the list when it was collected?
- Does a state privacy law cover this data, and would this transfer count as a sale or a share under it?
- Are any customers covered by financial or health privacy rules?
- Do customer contracts, NDAs or data-vendor terms restrict disclosure?
- Is the list protected as confidential business information, and would a sale or license weaken that protection?
- If the business is being sold, how does the purchase agreement describe the list and any limits on its use?
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
Next step
If the real question is whether a company's data has value, look past the customer list. Run the business through the company fit checker, a preliminary, non-binding screen, or have the owner apply at sourcex.si/apply. Advisors who know eligible US companies can register as a partner and make the introduction while the records stay with the company.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is a customer list an asset when a business is sold?
Usually yes. Buyers pay for customer relationships, and the list and related records are commonly scheduled among the purchased assets or simply stay with the company in a stock sale. Whether the buyer may use the data the same way depends on the privacy policy in force when it was collected and on any limits in customer contracts. Counsel on both sides normally reviews this in diligence.
Our privacy policy says we never sell data. Can we still license customer records?
Treat that statement as a binding promise. FTC staff have said such commitments are enforceable, and that quietly changing them after the fact can be unfair or deceptive. Ask counsel whether the planned use fits what customers were told. For data licensing through SourceX, the usual answer is to leave customer personal data out and focus on operational records, with personal details redacted under agreed rules.
Does B2B contact data carry fewer restrictions than consumer data?
Often fewer, but not none. Business contact details can still count as personal information under some state privacy laws, purchased B2B data usually comes with license terms that bar resale, and customer contracts may make the identity of clients confidential. Check the source of each contact, the vendor terms and the laws where the contacts live before assuming a B2B list can be sold.
Will SourceX license our customer database for AI training?
Not as a customer list. SourceX focuses on operational records a company created itself, such as tickets, deal histories, SOPs and engineering work, with personal details handled under de-identification rules agreed before any work starts. Mainly consumer personal data with no licensing basis is a red flag that stops a referral, but a company can still qualify on its other records.
Can a referral partner send SourceX a client's customer list to evaluate?
No. Partners make introductions and give basic fit information only, such as approximate headcount, years in operation and the kinds of systems the company runs. They do not export, upload or describe a client's records, and a customer list is no exception. The company works directly with SourceX on any inventory, and nothing is shared without its authorization and a signed agreement.
Related pages
- What happens to customer data when a business is sold?
- How to distinguish company data from data owned by its customers
- How to sell a marketing agency: client data limits and records that may qualify
- Which US businesses are a fit for a SourceX data licensing introduction
- Check Company Fit for Data Licensing
Free resources
- Working capital calculator — Net working capital, current ratio and quick ratio.
- Due diligence checklist generator — A tailored document request list by deal type.
- Cash flow calculator — A 12-month cash forecast with shortfalls highlighted.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment