Our privacy policy says we do not sell data. Can we still license records?
Often yes, for records the promise does not cover. A 'we do not sell your data' statement binds the personal information the policy describes, and FTC staff treat such promises as enforceable. Licensing de-identified operational records outside that scope is analyzed differently, while customer personal data covered by the promise generally stays out of a licensing scope.
The honest short answer
The promise matters, but only for what it covers. A privacy policy describes how a company handles personal information it collects from the people the policy addresses: website visitors, customers, app users. Most of what AI labs and data buyers want from an operating company, such as process documents, engineering tickets, resolved support cases with identifiers removed and records of operational decisions, is not what that promise was about.
So the answer splits in two. Customer personal information that the policy says will not be sold generally stays out of a licensing scope, whatever the deal is called. Operational records that are not consumer personal information, or that have been properly de-identified, are assessed on ownership, contracts and confidentiality instead. The policy blocks a scope only when its wording reaches those records too.
Is a privacy policy promise legally binding?
Yes, in the sense that regulators enforce it. A January 2024 FTC technology blog post states that a company's promises not to use customer data for undisclosed purposes, such as training or updating models, are enforceable whether they appear in a privacy policy, terms of service, promotional materials or a marketplace. Both FTC posts cited on this page are staff guidance written under the prior FTC leadership, not rules, but they show how the agency reads these promises under its authority over unfair or deceptive practices.
The working assumption for any owner should be simple: whatever the policy promised about personal information, the company keeps.
Why calling it a license is not a loophole
California's Consumer Privacy Act statute defines 'sell' broadly, covering making a consumer's personal information available to a third party for money or other valuable consideration. A paid license of a dataset that still contains personal information can meet that definition even if the contract never uses the word 'sale'. The same statute requires a notice at collection telling consumers whether their personal information is sold or shared, and a written agreement limiting use whenever a business sells or shares it.
The consequence is practical. If the archive still contains customer personal information, labelling the deal a license does not change how the promise or the statute applies. What changes the analysis is what is actually in the dataset.
Why de-identified operational records are analyzed differently
The same California definitions take deidentified information out of personal information, but the bar is higher than deleting names. The information must not reasonably be linkable to a particular person, and the business must take reasonable measures to keep it that way, publicly commit to maintain and use it in deidentified form without trying to reidentify it, and contractually require recipients to do the same.
That is why redaction rules are fixed with the company before any export, and why the difference between licensing and selling data is more than vocabulary. A license of de-identified operational records leaves ownership with the company, limits use to agreed purposes and puts no customer's identity on the table.
| Record type | Covered by a consumer 'we do not sell' promise? | What it means for a scope |
|---|---|---|
| Customer accounts, order history, app usage | Usually yes | Leave out unless counsel confirms a lawful route |
| Support tickets and chat transcripts | The personal details in them usually are | Consider only with identifiers removed to the deidentified standard |
| SOPs, playbooks, internal wikis | Usually no | Assess on ownership and confidentiality |
| Engineering tickets, pull requests, design documents | Usually no | Check client contracts and third-party code |
| Employee email and chat | Mainly governed by employee notices and state law | Review separately from the customer policy |
| Business contacts in the CRM | Depends on the policy wording | Read whether the policy covers B2B contacts |
| Records the company holds for its clients | Governed by client contracts | Usually out of scope without client consent |
Employee records follow a different logic from customer records; the page on whether employers can use employee emails to train AI covers ownership and notice for those.
Can a company change its privacy policy to allow AI training?
Quietly rewriting the policy to reach data already collected is the risky route. In a February 2024 post, FTC staff warned that adopting more permissive data practices, such as sharing consumers' data with third parties or using it for AI training, and telling people only through a surreptitious, retroactive amendment to the terms or privacy policy may be unfair or deceptive.
The sensible planning assumption for a licensing project: data collected under the old promise stays governed by the old promise, unless counsel identifies a lawful route such as fresh, clearly presented consent. Building the scope from records the promise never covered is usually faster than trying to widen the promise.
How to answer an owner who raises it
Owners who raise this are usually right to. Acknowledge the promise, then separate the records.
If the owner or their counsel wants the full document list, the privacy due diligence checklist sets out what to pull: every version of the policy, terms of service, customer contracts and data processing agreements.
When the policy genuinely blocks a scope
Sometimes the concern is valid. Treat the affected records as out of scope, or pause, if any of these is true:
- The policy promises never to share or disclose any data derived from customers' use of the product, not only personal information.
- The business is mainly consumer-facing and the valuable records are consumer personal data with no licensing basis.
- The records cannot reach the deidentified standard without losing what makes them useful.
- The company told customers, in contracts or marketing, that their data would never be used for AI training.
- The data belongs to clients under contracts that forbid secondary use.
When one applies, narrow the scope to records the promise does not reach, such as internal operational and engineering history, or stop. The same promises follow customer data into insolvency, where the consumer privacy ombudsman process puts them at the center of any sale.
This is general information, not legal, tax or financial advice. Confirm with your own counsel before acting.
Next step
Owners can test general fit first with the company fit checker, and the how it works page shows where the rights review happens before any buyer sees an opportunity. If you advise companies and hear this objection often, register as a partner: you make the introduction, and the company works through scope and privacy questions directly with SourceX.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Does the CCPA apply to every company that has a privacy policy?
No. California's law applies to for-profit businesses doing business in California that meet at least one of its thresholds, which cover revenue, the volume of California consumers' personal information handled, and revenue from selling or sharing it. Companies outside those thresholds may still face other states' privacy laws, and the FTC's view that privacy promises are enforceable does not depend on CCPA coverage.
Does removing names make support tickets deidentified?
Rarely on its own. Ticket text often contains email addresses, phone numbers, order numbers, street addresses and details that identify a person in context. California's deidentified standard also expects reasonable technical measures, a public commitment not to reidentify and contract terms binding recipients. Redaction rules for free text, attachments and metadata need to be agreed before any export, not improvised afterwards.
What if our privacy policy changed several times over the years?
Collect every version with its effective dates. Counsel will usually start from the promise in force when each set of records was collected, so a dataset spanning many years may need different treatment by period. Archived copies of the website, legal team files and customer contract templates help rebuild the history if nobody kept a change log.
Can we ask customers for consent to use their data for AI training?
It is possible, but it has to be real consent, clearly presented, rather than a quiet policy edit, which FTC staff have warned may be unfair or deceptive. Consent campaigns take time and usually reach only part of the customer base, so most licensing scopes are built from operational records that never depended on customer consent in the first place.
Does a B2B company's privacy policy usually cover its internal records?
Usually not directly. Most B2B privacy policies describe website visitors, marketing contacts and sometimes users of the product. Internal SOPs, engineering history and project records are governed by ownership, client contracts and confidentiality duties instead. Read the policy's scope section carefully, because some B2B policies also cover business contact data held in the CRM.
Related pages
- Licensing vs selling data: what is the difference?
- Can employers use employee emails to train AI or license them?
- Privacy due diligence checklist for M&A, with a data licensing lens
- Consumer privacy ombudsman: selling personal data in bankruptcy, and the alternative
- Check Company Fit for Data Licensing
- How SourceX US company data referrals work
Free resources
- Time value of money calculator — Future and present value with optional regular payments.
- Business DSCR calculator — Debt service coverage from cash flow and loan terms.
- MCP ROI calculator — Estimate hours saved, implied savings and first-year ROI from MCP.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment