What your firm can and can't sell

Your own workflows and templates are usually yours to license. Client and personal data usually are not.

Three rules for every firm

Privacy law

Employee and customer records stay personal data under GDPR and US state laws, even inside a business archive.

Client contracts

Contracts and NDAs can limit what you do with client material, even after names are removed.

Buyers abroad

The US rule on bulk sensitive data (28 CFR Part 202) covers some data and some countries.

What goes in a first sale, and what stays out

The firm's own process documents
SOPs, playbooks, runbooks, templates, an internal wiki, training decks. Written by employees, or by contractors who signed over the rights. No client content, no third-party licensed text, no credentials.
Internal staff email, chat and meeting notes about how the work gets done
Messages between your own people about the work. Staff and client identifiers removed on your own computer. A thread that quotes client documents is dropped instead of masked. Staff notice given where local law needs it.
The firm's own operating records
Tickets and task histories about its own delivery, its own sales CRM stages and notes, its own ledgers, orders and dispatch status. Personal contact data, precise locations and credentials removed. Supplier contracts checked for confidentiality.
Client threads and client tickets
Client-facing email and ticket threads, such as MSP tickets or agency and consulting email. You review every client contract. Only clients whose contract permits the use, or who consent in writing, are included. The rest are dropped by client ID before redaction, because redaction does not cure a contract that forbids the use.
Mixed archives
that contain any regulated personal record.
Regulated personal records
patient health information, income-tax-return information and anything derived from it, consumer reports and candidate files, individual clients' nonpublic personal information, privileged matter material, call recordings and transcripts, and EU, UK or Vietnam personal data.

The rule for your industry

Open yours to see what can go into a sale and what stays out.

Client tax returns need each client's written consentAccounting firms · Tax preparation firms

Can go in

Your firm's own SOPs, templates and training documents, with no return information and nothing derived from income-tax returns.

Stays out

Returns, return information and anything derived from it, including workflow metrics and return counts, and client financial files, unless a counsel-approved consent path exists for each client.

Patient information cannot be sold without authorizationMedical billing and revenue cycle companies · Medical practices

Can go in

Process documents that hold no patient health information, such as SOPs, billing procedures and training material.

Stays out

Patient-level and claim-level data, protected health information, and anything a business associate agreement does not permit.

Claims files usually belong to the carrierClaims adjusters and TPAs

Can go in

Your firm's own SOPs, templates and training material, where your contracts allow.

Stays out

Claim files and claimant records that your service contracts assign to the carrier or client.

Policyholder data is regulated customer informationInsurance agencies and brokers · Employee benefits brokerages

Can go in

Agency SOPs, service procedures and training material, where carrier agreements allow.

Stays out

Policyholder identities, applications and loss runs tied to a person or business.

Candidate and employee records are personal dataStaffing and recruiting agencies · Executive search and RPO firms · Payroll companies and PEOs

Can go in

Job orders, process steps, interview and submittal workflows, and placement outcomes, with every candidate and client identifier removed.

Stays out

Candidate profiles, CVs, contact details and any background or screening report.

Client financial information is regulatedWealth management firms and RIAs

Can go in

Firm SOPs and compliance procedures, with no client information.

Stays out

Account data, statements and anything tied to an identifiable client.

Client-owned code stays with the clientSoftware development agencies

Can go in

Your own repositories, internal tools, scripts and review histories, and client code where your contract assigns the rights to you.

Stays out

Client-owned repositories, secrets and credentials, and anything under a license that forbids it.

Client contracts decide what client material can be usedBookkeeping and outsourced accounting firms · Managed IT service providers (MSPs) · IT consulting and cybersecurity firms · Engineering and architecture firms

Can go in

Your firm's own workflows, templates, internal communications and process records, with client and personal details removed.

Stays out

Client deliverables and data your contracts restrict, until the client agrees.

See what your records could be worth

Seven questions. No files.

Get your estimate

Based on US federal rules and professional guidance.

More on how a sale runs and how we protect your data.