Does a company need customer consent to license its operational data?
Sometimes. Whether a company needs customer consent to license data turns on what its contracts and privacy notices promised, whose information the records hold and which privacy laws apply. Company-created B2B records can often be licensed once customer details are removed and contracts allow it; client-owned records, consumer personal data and health data usually need consent or another legal basis.
The short answer: three documents and one data question
A company does not need blanket customer consent to license every operational record, but it may need consent for some of them. The answer comes from three sets of documents and one question about the data itself, and counsel should review all four before anything is offered.
- Customer contracts. Master services agreements, order forms and data processing addenda define confidential information and customer data, and many limit their use to providing the service.
- Privacy notices and terms. What the company told people when it collected their information shapes what it can do with that information later.
- Employee and vendor notices. Internal email, chat and call records involve staff and suppliers as well as customers.
- Whose data it is. Records the company created about its own work differ sharply from records it holds for a client, consumer personal information, health information or financial customer information.
For a portfolio CFO, the practical point is that consent is rarely all or nothing. It is usually a scoping exercise: which systems, which years and which fields can go into a dataset without new permissions.
What the rules actually say
US law has no single consent rule for licensing business records. Promises the company made, sector privacy laws and state privacy statutes each cover part of the ground.
- Promises are enforceable. FTC staff have warned that it may be unfair or deceptive for a company to adopt more permissive data practices, such as sharing data with third parties or using it for AI training, and tell consumers only through a surreptitious, retroactive change to its terms or privacy policy (February 2024 staff post, not a rule).
- California. The CCPA statute requires notice at collection of the categories of personal information, the purposes and whether it is sold or shared, and limits use to what is reasonably necessary and proportionate. The Attorney General's CCPA overview explains which businesses the law covers and that consumers can opt out of the sale or sharing of their personal information.
- Health information. Under HHS guidance on HIPAA de-identification, health information de-identified through Expert Determination or the Safe Harbor method (removing 18 specified identifiers) is no longer protected health information under the Privacy Rule.
- Financial customer information. Financial institutions under the FTC's jurisdiction follow the Gramm-Leach-Bliley Act Privacy Rule, which calls for notices and opt-out rights before customer information is shared with certain nonaffiliated third parties.
- People in the EU. The GDPR can apply to organizations outside the EU that offer goods or services to, or monitor the behavior of, people in the EU, so a US company's records about EU individuals raise their own questions.
B2B confidentiality is mostly a matter of contract rather than statute. Look for clauses that restrict customer data to providing the service, define what counts as confidential information, and carve out aggregated or de-identified data.
How it applies in common situations
| Situation | What to check | Typical outcome to confirm with counsel |
|---|---|---|
| Internal records the company created: SOPs, engineering tickets on its own product, internal email | Employee notices; third-party names mentioned in passing | Often licensable once personal and third-party details are redacted |
| Support tickets from business customers | Confidentiality and data-use clauses in the MSA; whether tickets contain customers' confidential information | Often licensable with customer identifiers removed if contracts permit; some contracts require consent |
| Implementation or project files for clients | Who owns deliverables under each statement of work | Company-owned working files may qualify; client-owned deliverables need client consent |
| Work an outsourcer, agency or BPO performs for its clients | Whether the client owns the records and the data | Excluded unless each client consents |
| Consumer personal information | What the privacy notice said at collection; CCPA sale and sharing rules | Generally not a fit without a clear licensing basis |
| Health information held by an administrative business | Whether it is protected health information | De-identify under an HHS method or obtain authorization; mainly-PHI datasets are excluded |
| Customer information at a lender or insurer back office | GLBA notice and opt-out obligations | Usually removed from scope or handled under the notice |
| Records about people in the EU | GDPR applicability and lawful basis | Often removed from scope |
Project files are a common grey area. The page on customer implementation project records walks through which parts of a project archive a company typically owns.
Why client-owned records are excluded
Some companies hold large archives that are not really theirs. A contact center handles tickets for its clients' customers, an agency produces work for its clients, and an outsourced accounting firm keeps its clients' books. The company stores the records, but the client typically owns them, and licensing them without the client's consent is a red flag that SourceX screens out.
That exclusion can shrink a dataset sharply. The guide to which companies cannot license their data covers the pattern, and how much data a company needs helps judge whether what remains is still worth an inventory.
Disclosure and consent good practice
- Map first. List each system, the years it covers and whose information it holds before deciding whether anyone needs to be asked.
- Read the documents in force at collection. A privacy notice updated last year does not automatically reach records collected under an older version.
- Do not rely on a quiet policy change. Where new permission is needed, ask for it plainly instead of amending terms retroactively.
- Ask specific customers in writing when a contract requires consent, describing the use, the de-identification applied and the term.
- Agree redaction and de-identification rules with SourceX before any work begins. Nothing is delivered without an executed agreement and the company's authorization.
- Record board approval where your governance requires it; see board approval for a data license.
Questions to ask your counsel
- Which customer contracts restrict the use of customer data or confidential information, and do any carve out de-identified or aggregated data?
- What did our privacy notices say in each period covered by the records?
- Do any systems contain protected health information, financial customer information, children's data or information about people in the EU?
- Are we a covered business under the CCPA, and would a license count as selling or sharing personal information?
- Do any statements of work give clients ownership of the records we created for them?
- Who must approve a license under our governance documents and financing agreements?
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting, and remember that state privacy laws vary by state.
Next step
If a company in your network has years of its own operating records and a CFO who can work through these questions, check the baseline on who qualifies and register as a partner to make the introduction. The company can also apply directly at sourcex.si/apply.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Can a company change its privacy policy so it can license data it already holds?
A new policy can govern information collected after it takes effect, but relying on a quiet, retroactive change for data already collected is risky. FTC staff have warned that this kind of change may be unfair or deceptive. Records collected under older notices are usually handled under the terms in force at the time, or with fresh consent. Counsel should decide.
Is removing customer names enough to make B2B records licensable?
Not always. Contracts may protect a customer's confidential information whether or not its name appears, and free-text notes can identify a customer indirectly through project details, locations or product names. Removing identifiers is necessary but not sufficient. Redaction rules are agreed before work starts, and counsel should confirm the contract position for each major customer group.
Do employees have to consent before internal email and chat are licensed?
It depends on the company's employee notices and policies and on state law. Many acceptable use policies address ownership of messages on company systems, but those messages still contain personal information that should be removed or de-identified. Call recordings raise separate consent rules in some states. Ask counsel to review employee-facing documents alongside customer contracts.
Who should run the consent review inside the company?
An authorized sponsor such as the CFO or CEO leads it, general counsel or outside counsel reads the contracts and notices, a privacy or security lead identifies personal information, and IT maps which systems and years are involved. The partner who made the introduction plays no part in reviewing records. SourceX works with the sponsor on scope and redaction rules.
What if only some customer contracts allow licensing?
Then the dataset is scoped. Records tied to restrictive contracts can be excluded, held back until consent is obtained, or limited to fields the contracts permit. The data inventory records which systems, years and customer groups are in scope. A smaller, clean dataset is generally a better starting point than a large one with unresolved rights.
Related pages
- Customer implementation project records: what they are and why AI buyers value them
- Which portfolio companies are not a fit for data licensing?
- How much data does a company need?
- Does a data license need board approval at a PE-backed company?
- Which US businesses are a fit for a SourceX data licensing introduction
Free resources
- Time value of money calculator — Future and present value with optional regular payments.
- Business DSCR calculator — Debt service coverage from cash flow and loan terms.
- MCP ROI calculator — Estimate hours saved, implied savings and first-year ROI from MCP.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment