Is it legal to license company data for AI training?

By , founder of grokkedPublished Updated 8 min read

Yes, licensing your company’s data for AI training can be legal in the EU, if you handle three things. Personal data must be anonymized before it reaches a buyer, and the work to get there needs a valid legal basis under the GDPR. Your staff, and where the law requires it your works council, must be informed. And anything covered by professional secrecy or a confidentiality clause stays out.

Truly anonymous data falls outside the GDPR altogether (GDPR, recital 26). The EU AI Act puts its documentation duties on the AI labs that train models, not on you, but labs need clean provenance from you to meet them. This guide links every rule to its primary text.

Key takeaways

  • Anonymous data isn’t personal data, but the bar is high: no one may be identifiable by any means “reasonably likely to be used”.
  • Anonymizing is itself processing. As the controller, you need a legal basis, usually legitimate interests, and a documented compatibility check before you start.
  • The broker that de-identifies your data acts as your processor, under a signed data processing agreement.
  • Inform your staff in advance. Works councils have information or consent rights in Belgium, the Netherlands, France and Luxembourg.
  • Client files of lawyers, accountants and healthcare providers stay out: anonymization doesn’t lift professional secrecy.

Anonymous data is outside the GDPR

The GDPR protects information about identified or identifiable people. Recital 26 says its principles “should therefore not apply to anonymous information”, and sets the test: take into account “all the means reasonably likely to be used, such as singling out, either by the controller or by another person” to identify someone (GDPR).

Kind of dataWhat it meansDoes the GDPR apply?
Personal dataRelates to an identified or identifiable personYes
Pseudonymized dataIdentifiers replaced, but re-linkable with extra information kept separately (art. 4(5))Yes, for anyone who can re-link it
Anonymous dataNo one can identify a person with means reasonably likely to be used (recital 26)No

The test is strict. The Article 29 Working Party’s opinion on anonymization says an effective solution prevents anyone from singling out an individual, linking two records about the same person, or inferring information about them. It also warns that “pseudonymisation is not a method of anonymisation” (WP29). Replacing a name with PERSON_1 isn’t enough if the rest of the message still points to one person, which is why client, product and project names, prices and file numbers have to go too.

In September 2025 the EU Court of Justice confirmed, in EDPS v SRB, that pseudonymized data must not be regarded as personal data “in all cases and for every person”: it depends on whether the recipient can re-identify people (CJEU). Two consequences follow. A properly de-identified dataset can be anonymous for an AI lab while your originals stay personal data in your hands. And the European Data Protection Board’s draft anonymization guidelines of July 2026 ask controllers not to call data “anonymous”, “de-identified” or “de-personalised” if people are still identifiable (EDPB).

Your legal basis and the compatibility check

Licensing data to AI labs is a new purpose, different from the one you collected it for. The GDPR forbids processing “in a manner that is incompatible with those purposes” (art. 5(1)(b)), and anonymizing is itself processing: the EDPB says “anonymisation must have a legal basis under Article 6 GDPR” (GDPR, EDPB).

Most companies rely on legitimate interests (art. 6(1)(f)). The EDPB’s guidelines set three cumulative conditions, assessed and documented before processing starts (EDPB):

  1. A legitimate interest, such as earning revenue from your own know-how.
  2. Necessity. You process no more personal data than you need, which is what de-identification is for.
  3. A balancing test. Your interest must not be overridden by the rights of your employees and contacts. The employer–employee relationship weighs in that balance.

Because the purpose is new, you also run the compatibility test of article 6(4): the link between the old and new purposes, the context of collection, the nature of the data, the possible consequences for people, and safeguards such as “encryption or pseudonymisation” (GDPR). France’s regulator, the CNIL, considers legitimate interests a possible legal basis for developing AI systems, provided strong safeguards are in place (CNIL).

Consent is a poor fit at work. The EDPB considers it “problematic for employers to process personal data of current or future employees on the basis of consent as it is unlikely to be freely given” (EDPB). Special categories such as health data need an additional exemption under article 9 (EDPB), so the simplest route is to keep them out of scope.

Check too whether you need a data protection impact assessment (art. 35), which applies before processing likely to result in a high risk to people (GDPR). grokked gives you a filled-in template for the legitimate-interest and compatibility assessment, and helps with your impact assessment.

The broker’s role

When a broker such as grokked de-identifies your raw data, it acts as your processor. It may only act “on documented instructions from the controller” (art. 28(3)(a)), under a signed data processing agreement (GDPR). The decision to license, and what’s in scope, stays yours. A processor that starts deciding purposes and means is treated as a controller itself (art. 28(10)).

Look for these in the agreement: processing only on your instructions, encryption, access limited to named staff under confidentiality, deletion of raw data after packaging, a list of sub-processors, and help with staff information and your impact assessment. Read our DPA summary.

Telling your staff and works council

Employees must be told before their data is reused for a new purpose. Articles 13(3) and 14(4) require information about that purpose “prior to that further processing” (GDPR). Labor law adds collective rules. Most were written for workplace monitoring, and whether they cover data licensing is a matter of interpretation, so the safe route is to involve employee representatives early.

CountryRuleWhat it requires
BelgiumCollective agreement (CBA) no. 81 of 2002Before monitoring electronic communication data, the employer informs the works council or, failing one, the CPPT/CPBW or the union delegation, and informs each worker (CNT)
NetherlandsWOR art. 27(1)(k)The works council’s consent is needed for rules on processing employees’ personal data; a works council is mandatory from 50 people (WOR)
FranceCode du travail L2312-38 and L2312-8Companies with 50+ employees inform the CSE before introducing automated HR processing, and inform and consult it on means to monitor staff and on new technologies (L2312-38, L2312-8)
LuxembourgCode du travail L.261-1 and L.414-9Prior information to the joint committee or staff delegation before processing to monitor employees; joint decision in companies with 150+ employees (Legilux)

Two traps. In the Netherlands, a decision taken without the required consent is void if the works council invokes that within a month (art. 27(5) WOR). In Luxembourg, data collected under a monitoring notice comes with the employer’s formal commitment not to use it for any other purpose, so leave that data out.

grokked writes the briefing for your staff or works council in your language and can present it.

Clients, NDAs and professional secrecy

Confidentiality duties survive anonymization. GDPR recital 50 says further processing should be prohibited if it “is not compatible with a legal, professional or other binding obligation of secrecy” (GDPR), and criminal law protects professional secrets:

  • Belgium: article 352 of the new Criminal Code, in force since September 1, 2026, which replaces the old article 458 (eJustice, FPS Justice).
  • France: article 226-13 of the Code pénal, punishable by one year in prison and a €15,000 fine (Légifrance).
  • Netherlands: article 272 of the Criminal Code, article 11a of the Advocatenwet for lawyers, and the VGBA conduct rules for accountants (Wetboek van Strafrecht, Advocatenwet, VGBA).

That’s why grokked excludes client files for accountants, lawyers and healthcare providers. Only the firm’s own templates and procedures qualify, exported by the firm itself (details). Other businesses should check client contracts and NDAs, and leave out any client whose contract forbids sharing.

What the EU AI Act asks

The AI Act regulates AI providers, not the companies whose data they license, and it doesn’t change the GDPR. Since August 2, 2025, providers of general-purpose AI models must keep a copyright policy and publish “a sufficiently detailed summary about the content used for training” (art. 53(1)(c)–(d), art. 113) (AI Act).

The Commission’s template for that summary asks providers to disclose data licensed from rightsholders and other private datasets, including data obtained through “data intermediaries” (European Commission). So labs ask brokers for provenance: who supplied the data, under what agreement, and how it was anonymized. For high-risk AI systems, article 10 adds data-governance duties covering “the origin of data” (AI Act).

grokked supplies that provenance documentation with every dataset, so buyers can meet their obligations without ever learning your company’s name.

Checklist before you license

  1. Choose the scope: sources, channels, folders and date ranges. Leave out DMs, HR folders and anything under a confidentiality duty.
  2. Document your legitimate-interest assessment and compatibility test (art. 6(1)(f) and 6(4)).
  3. Check whether you need an impact assessment (art. 35).
  4. Sign a data processing agreement with the broker (art. 28).
  5. Inform your staff, and inform or consult your works council where required.
  6. Review the de-identified sample before anything is listed.
  7. Set buyer rules: block competitors or regions, and bar re-identification and resale.

This guide is general information about EU and national rules as of October 2026, not legal advice. For a decision about your company, ask your lawyer or data protection officer.

See what your data is worth.

Get an estimate in 60 seconds. Listing your data costs nothing.

Get paid in 7 days

Questions

Is anonymized data covered by the GDPR?

Not if it is truly anonymous: recital 26 excludes information that doesn’t relate to an identifiable person. The test counts every means reasonably likely to be used to identify someone, by you or anyone else, so pseudonymized data usually remains personal data (GDPR).

Do I need my employees’ consent to license company data?

Usually not, and consent is a weak basis at work because it is rarely freely given (EDPB). Companies typically rely on legitimate interests with a documented balancing test, inform staff in advance, and involve the works council where the law requires it.

Does the EU AI Act apply to my company if I license data?

Its data duties fall on the AI providers that train models: since August 2, 2025, general-purpose model providers need a copyright policy and a public summary of their training content (AI Act). Your part is supplying clean provenance, which your broker should document.

Can accountants, lawyers or doctors license their data?

Only internal know-how, such as templates and procedures. Client files stay out, because professional secrecy applies regardless of anonymization (details).

Is this guide legal advice?

No. It is general information about EU and national rules as of October 2026. For a decision about your company, ask your lawyer or data protection officer.

See what your data is worth.

Get an estimate in 60 seconds. Listing your data costs nothing.

Get paid in 7 days

Sources

  1. EUR-Lex, April 27, 2016. Regulation (EU) 2016/679 (General Data Protection Regulation)
  2. Article 29 Working Party, April 10, 2014. Opinion 05/2014 on Anonymisation Techniques (WP216)
  3. Court of Justice of the European Union, September 4, 2025. Press release No 107/25, Case C-413/23 P, EDPS v SRB
  4. European Data Protection Board, July 7, 2026. Guidelines 02/2026 on Anonymisation, version 1.0 (for public consultation)
  5. European Data Protection Board, October 8, 2024. Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR
  6. CNIL, June 19, 2025. Développement des systèmes d’IA : la CNIL publie ses recommandations sur l’intérêt légitime
  7. European Data Protection Board, May 4, 2020. Guidelines 05/2020 on consent under Regulation 2016/679
  8. Conseil National du Travail, April 26, 2002. Convention collective de travail n° 81 du 26 avril 2002
  9. wetten.overheid.nl. Wet op de ondernemingsraden
  10. Légifrance. Code du travail, article L2312-38
  11. Légifrance. Code du travail, article L2312-8
  12. Legilux. Code du travail (consolidated version)
  13. Belgian Official Gazette (eJustice). Code pénal of 29 February 2024, article 352
  14. FPS Justice, September 1, 2026. 1er septembre historique : entrée en vigueur du nouveau Code pénal
  15. Légifrance. Code pénal, article 226-13
  16. wetten.overheid.nl. Wetboek van Strafrecht
  17. wetten.overheid.nl. Advocatenwet
  18. NBA. Verordening gedrags- en beroepsregels accountants (VGBA)
  19. EUR-Lex, June 13, 2024. Regulation (EU) 2024/1689 (Artificial Intelligence Act)
  20. European Commission, July 24, 2025. Explanatory notice and template for the public summary of training content for general-purpose AI models

About the author

Nico Vergauwen

Nico Vergauwen is the founder of grokked, a data broker that licenses companies’ de-identified internal data to AI labs. Owners never pay anything and are paid within 7 days of each sale.

More guides