Do 'no expectation of privacy' policies cover AI training use of employee data?
Usually not on their own. A 'no expectation of privacy' clause mainly supports monitoring, investigations and employer access to company systems; few were written with licensing records to outside AI developers in mind. Treat the clause as one input, not consent: de-identify records, check what each policy version promised and have counsel review before licensing workplace data.
The honest short answer
Usually not on their own. A 'no expectation of privacy' clause in a handbook or acceptable use policy mainly supports monitoring, investigations and employer access to company systems. Few were drafted with licensing workplace records to outside AI developers in mind, so treat the clause as one input rather than as consent, and plan for de-identification and counsel review first.
Owners raise the clause in good faith. It reads broadly, employees signed it and it often says the company may access anything on its systems for any business purpose. But a clause that defeats a privacy claim about the employer reading email does not automatically answer a different question: whether the company may hand that content to a third party for a new use. Commentators have flagged exactly that secondary-use gap.
What these clauses typically do and do not settle
| The clause typically supports | It typically does not settle |
|---|---|
| Employer review of email, chat and files on company systems | Disclosure of message content to an outside party |
| Monitoring for security, compliance and investigations | New purposes added after the messages were written |
| Access during legal holds and litigation | Personal messages employees sent from work accounts |
| Rebutting an employee's claim that work systems were private | State notice duties for workforce data |
| Discipline for policy breaches | Privacy of customers, vendors and candidates in the same threads |
The last row is easy to miss. Work email is full of people who never signed the handbook.
Why regulators care about secondary use
Two FTC staff posts from 2024 show the direction of thinking, although both address consumer data rather than employees, and both are staff guidance, not rules, issued under the agency's previous leadership. In January 2024 FTC staff said that promises not to use customer data for undisclosed purposes, such as training models, are enforceable whether they appear in privacy policies, terms of service or marketing. In February 2024 staff warned that quietly changing terms of service or a privacy policy to permit AI training through a surreptitious, retroactive amendment may be unfair or deceptive.
The lesson carries over: what people were told when the records were created matters, and rewriting it afterward is risky. Employment, privacy and wiretap laws add their own rules, and the federal wiretap and stored-communications questions are explained in ECPA for employers.
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
How to respond when an owner says the handbook covers it
What to do instead
- Collect every version of the communications policy and handbook, with effective dates, and note what each said about access, monitoring and use.
- Separate business records from personal messages and from threads dominated by outside parties.
- Apply a default exclusion list; the list of data to exclude from AI training is a good starting point.
- De-identify what remains, under rules the company agrees with SourceX before work begins.
- Update the policy for the future using a clause outline such as the electronic communications policy template, and apply it only from its effective date.
If the company captures screens or keystrokes, also work through the keystroke and screen monitoring checks before scoping.
For partners hearing this objection
Do not argue the law. Acknowledge the clause, explain that the licensing process does not lean on it and suggest the owner run the company fit checker for a preliminary read. Then step back: a partner introduces the company and never handles, exports or describes its records.
Next step
When the owner is ready, register as a partner and make the introduction. Sending them how it works first shows that counsel review and de-identification come before any delivery.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does an employee's signed acknowledgment count as consent to AI training?
Rarely by itself. An acknowledgment shows the employee received the policy as it was written at the time. If that version said nothing about licensing or AI training, the signature does not add the purpose. Even where a newer policy mentions it, counsel should decide whether consent is required at all, and de-identification usually matters more than signatures.
Is a 'no expectation of privacy' clause still worth keeping?
Yes. It does real work for security monitoring, internal investigations, legal holds and access to a departed employee's files, and it sets honest expectations about company systems. The mistake is treating it as a blanket permission for every future use. Keep it, describe secondary uses such as de-identified analytics separately, and date each version so its reach is clear.
Are personal messages in work email ever licensable?
As a default, no. Even where a policy limits personal use, employees send personal messages from work accounts, and those messages are both the least connected to the business and the most sensitive. Standard practice is to filter them out before any scope is set, along with HR matters, privileged threads and messages that mainly carry clients' confidential information.
Do customers and vendors in work email change the analysis?
Yes. A handbook binds employees, not the customers, suppliers and candidates who appear in the same threads. Their information is governed by the company's external privacy notice, its contracts and applicable law, none of which an internal policy touches. That is one more reason business email is scoped through filtering and de-identification rather than on the strength of a handbook clause.
What should a partner say if the owner insists the handbook settles it?
Agree that the handbook is useful evidence of ownership and access, then explain that the licensing process does not rely on it alone. Records are de-identified under rules agreed before work begins, personal messages are excluded and the company's counsel reviews the policy history. After that, let the owner and SourceX take the conversation forward.
Related pages
- ECPA for employers: the Wiretap Act, the Stored Communications Act and consent to disclose
- What data should be excluded from AI training? A default exclusion list
- Electronic communications policy template: clauses to adopt before licensing
- Is employee keystroke and screen monitoring legal, and can captures be licensed?
- Check Company Fit for Data Licensing
- How SourceX US company data referrals work
Free resources
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment