Privacy law
Employee and customer records stay personal data under GDPR and US state laws, even inside a business archive.
Your own workflows and templates are usually yours to license. Client and personal data usually are not.
Employee and customer records stay personal data under GDPR and US state laws, even inside a business archive.
Contracts and NDAs can limit what you do with client material, even after names are removed.
The US rule on bulk sensitive data (28 CFR Part 202) covers some data and some countries.
Open yours to see what can go into a sale and what stays out.
Your firm's own SOPs, templates and training documents, with no return information and nothing derived from income-tax returns.
Returns, return information and anything derived from it, including workflow metrics and return counts, and client financial files, unless a counsel-approved consent path exists for each client.
Matter-free SOPs, templates, training and billing-process documents, after your own ethics counsel confirms they hold no matter content.
Email, matter files, advice, intake and privileged material, unless each client consents and a privilege review clears them.
Process documents that hold no patient health information, such as SOPs, billing procedures and training material.
Patient-level and claim-level data, protected health information, and anything a business associate agreement does not permit.
Your firm's own SOPs, templates and training material, where your contracts allow.
Claim files and claimant records that your service contracts assign to the carrier or client.
Agency SOPs, service procedures and training material, where carrier agreements allow.
Policyholder identities, applications and loss runs tied to a person or business.
Job orders, process steps, interview and submittal workflows, and placement outcomes, with every candidate and client identifier removed.
Candidate profiles, CVs, contact details and any background or screening report.
Firm SOPs and compliance procedures, with no client information.
Account data, statements and anything tied to an identifiable client.
Your own repositories, internal tools, scripts and review histories, and client code where your contract assigns the rights to you.
Client-owned repositories, secrets and credentials, and anything under a license that forbids it.
Your firm's own workflows, templates, internal communications and process records, with client and personal details removed.
Client deliverables and data your contracts restrict, until the client agrees.
Seven questions. No files.
Based on US federal rules and professional guidance.
More on how a sale runs and how we protect your data.