Not legal advice. This page explains the general issues so you can have a faster, cheaper conversation with your lawyer. Laws vary by state, industry and the people whose data is involved.
Licensing company data is a legitimate and growing business, but “legal” depends on what is in your record. Three questions do most of the work.
Question 1: Do you own the data?
You can only license what you have the right to license.
- Usually yours: internal communications, your own documentation, your sales and operations records
- Usually not yours to license: data you process on behalf of clients (for example, an agency holding a client’s analytics or a law firm’s client files)
- Check: software vendor terms, and anything inherited through acquisitions or partnerships
Polyshares states its license does not cover what you hold on behalf of your own clients.
Question 2: What do your contracts say?
Review:
- Customer agreements and DPAs that limit how customer data may be used
- NDAs with partners, vendors and prospects
- Employment agreements and policies covering company systems and monitoring
- Investor or lender covenants restricting asset transfers
- Confidentiality clauses in any contract that appears in your email or chat
Not sure if your data qualifies? The intake takes a few minutes.
Question 3: Does it contain personal information?
Most operational data contains people’s names, emails and other details. US privacy laws, including California’s CCPA/CPRA and a growing list of state laws, regulate the sale and sharing of personal information. Sector laws such as HIPAA (health) and GLBA (financial) add stricter rules. If you hold data on people in the EU, GDPR may apply.
This is why reputable buyers anonymize data before it moves. Read how anonymization works.
The employee question
Internal chat and email include employees’ words. When Gizmodo covered startups licensing Slack data in April 2026, Marc Rotenberg of the Center for AI and Digital Policy said, “I think the privacy issues here are quite substantial.” Even when policies allow it, consider telling staff, removing identifying details, and excluding personal channels.
Categories to exclude or clear first
- Privileged attorney-client communications
- Health, medical, or insurance information
- Financial account and payment details
- Children’s data
- HR, disciplinary and medical-leave records
- Anything under a regulator’s or court’s hold
Your pre-signing checklist
- Map every system you plan to include and who the data is about.
- Flag client-held data and exclude it.
- Pull customer, vendor and partner contracts with data-use clauses.
- Confirm the buyer’s anonymization standard in writing.
- Agree retention, deletion and audit rights.
- Review indemnities and warranties with counsel.
Then use our contract checklist for the deal terms themselves.
Frequently asked questions
Do I need employee consent to license Slack or email data?
It depends on your policies, employment agreements and the laws that apply to you. Many companies have policies stating work systems belong to the company, but privacy experts have raised concerns about employees’ messages. Ask counsel, and remove identifying details regardless.
Does CCPA apply to licensing company data?
If the data includes personal information of California residents and your business is covered by the CCPA/CPRA, sharing it for value may be regulated. Properly de-identified data is treated differently. Your lawyer should confirm how this applies to you.
Can I license data about my clients?
Generally not data you hold on behalf of clients. Polyshares states its license does not cover what you hold for your own clients. Check every client contract and NDA.
Who is liable if something goes wrong?
That depends on the contract. Look at the indemnity, warranties, and anonymization obligations in the license agreement with your lawyer.