Do you need client consent to license your company’s data to AI?
This is for UK company owners and managing directors whose process documents, tickets or playbooks might be worth licensing, but who worry about what clients, staff and suppliers have a say in. The short answer: it depends on what the material contains and what your contracts say. This is general information, not legal advice. Take advice from a solicitor on your own contracts.
Do you need your clients’ consent to license your company’s data?
Sometimes. If the material is yours, contains no client information and no personal data, you usually don’t need anyone’s consent beyond what your own contracts require. If it contains client information, or you hold it on a client’s behalf, you probably need their permission first. Check the contract.
Consent is rarely the whole question. Three things decide it: who owns or controls the information, what your contracts and confidentiality clauses allow, and whether personal data is involved. The tree below puts them in order. For what buyers actually want, see what data AI labs buy.
Which information is yours to license?
Generally, material you created for your own business and hold for your own purposes: internal procedures, checklists, playbooks, templates you wrote. Material produced for a client, or kept on their behalf, may belong to them or be covered by confidentiality. Your contract, not the file’s location, decides.
Client contracts often say who owns work product, what counts as confidential information and what you may do with client data. Look for clauses on confidentiality, intellectual property, data protection, and any wording about using data to improve your services or for other purposes. If you are a managed service provider, ticket histories deserve extra care; see the MSP ticket guide. For procedures and playbooks that are plainly your own, see licensing SOPs.
Does UK GDPR apply to the data you want to license?
If it contains information about identifiable people, such as customers, client staff or your own employees, yes, UK GDPR is likely to apply. Anonymous information falls outside it, but removing names is not always enough. If you cannot realistically remove the personal data, leave that material out.
If you handle personal data for a client under their instructions, you are probably their processor. The ICO says a processor should only process personal data in line with the controller’s instructions, and that one acting outside them can become a controller for that processing (ICO, “What are controllers and processors?”, guidance last noted as updated 29 September 2023 and under review because of the Data (Use and Access) Act; ico.org.uk, read 9 October 2026). Licensing that data to an AI developer is unlikely to be something the client instructed.
On removing personal data, the ICO’s anonymisation guidance, published 28 March 2025 and also under review, says anonymisation is possible in many circumstances but depends on the techniques used, and discusses “reasonably likely” identification and a “motivated intruder” test (ico.org.uk, read 9 October 2026). We have not found ICO guidance that addresses licensing business data to AI developers, so we don’t describe an ICO position on it. See also our privacy notice for how we handle information.
What about staff messages and third-party material?
Treat staff messages and emails as personal data and as material other people wrote: they are rarely yours to hand over wholesale. Vendor documentation, licensed templates and bought-in training materials usually belong to someone else. Unless the licence says you may, leave them out.
Chat logs and email threads mix client details, staff opinions and personal information, which makes them hard to clean reliably. The cleaner route is usually the procedure you derived from them, written fresh, rather than the messages themselves. Check licence terms for anything you did not write.
How do you decide? A decision tree
Work through these questions in order for each type of material, not for the company as a whole. Stop at the first outcome you reach. When you are unsure at any step, take the more cautious branch and ask someone who can read the contract.
1. Did you write it yourselves, for your own business, without using a client’s or supplier’s material?
If no → go to 6 (third-party content). If yes → go to 2.
2. Does it contain any client’s name, data, systems or confidential detail?
If yes → go to 5 (your contracts). If no → go to 3.
3. Does it contain personal data: customers, client staff, your own employees?
If yes → go to 4. If no → go to 5.
4. Can the personal data realistically be removed, and checked, so people can’t reasonably be identified?
If no → Outcome C: leave it out. If yes → go to 5.
5. Do your contracts and confidentiality clauses clearly allow this use, or has the client agreed in writing?
If yes → Outcome A: likely yours to license. If unclear or no → Outcome B: needs permission or advice first.
6. Is it vendor documentation, a licensed template or someone else’s content?
If your licence clearly lets you share it → go to 5. If not, or you don’t know → Outcome C: leave it out.
Outcome A: likely yours to license, subject to a solicitor confirming. Outcome B: needs the client’s permission, or advice, before it goes anywhere. Outcome C: leave it out.
This is a prompt for the right conversation, not a legal test. Edge cases, regulated sectors and unusual contracts need advice.
Who should you ask?
Ask your solicitor about the contracts, your data protection officer if you have one about personal data, and the client when the material touches their information. Get permission in writing. Do this before you apply to any programme, not after an offer arrives.
- Your solicitor: what the contract allows, and what the licence you would sign requires of you.
- Your DPO, if you have one: whether personal data is involved, and whether it can be removed.
- The client: whether they are content for specific material to be used, in writing.
How Orca fits in: the free three-minute check asks what records you hold and whether they are mostly yours or your clients’. Personal and client information is kept out of anything shared, we only recommend programmes that work this way, and nothing is shared without your go-ahead. The check is free; we only charge a success fee if a deal closes, agreed in writing first, and programmes may also pay us a referral fee, which we tell you about first. Neither decides what we recommend (see disclosures). For how programmes work, see how AI data programmes work, and for pricing see what company data is worth to AI (an estimate, not an offer). All our guides are on the guides page.
This is general information, not legal advice. It does not cover every contract or sector. Take advice from a solicitor on your own contracts before licensing anything.
Common questions
Is it fine if I just remove names?
Not automatically. Removing names is one step, but details such as job titles, dates, locations or free text can still point to a person. The ICO’s anonymisation guidance asks whether identification is reasonably likely. If you can’t be confident, treat the material as personal data or leave it out.
What if my client contract says nothing about AI?
Silence doesn’t settle it. Read the confidentiality, intellectual property, data protection and “use of data” clauses together, and ask who owns what you create while serving the client. If it’s unclear, ask the client or take advice before including the material.
Do I need to tell my staff?
If staff are identifiable in what’s shared, such as their messages or names, you are dealing with personal data, which brings transparency duties. The simpler route is to share only process material with people removed. A solicitor can tell you what your own staff notices and contracts require.
Does a programme or buyer take on this risk for me?
No. The rights to what you share are yours to confirm, and you would normally be asked to say so in the contract. That is why it is worth settling this before you apply, not after.