Skip to content

Procurement, samples and ongoing supply

Sourcing U.S. Company Data from Outside the U.S.: Procurement Considerations

Quick answer

A non-U.S. AI team can license operational data from U.S. companies, but the deal needs more upfront structure than a domestic purchase. Decide which of your legal entities signs and under which governing law, write down where the data will be stored, processed and accessed, screen the deal against the U.S. Department of Justice bulk sensitive data rule and export controls, and settle currency, withholding and indirect tax with advisers before signature. Delivery and support plans should account for time zones.

By SourceX Editorial · Updated

This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.

Pick the contracting entity and governing law before you talk price

The entity that signs determines whose approvals, tax position and data protection law apply, so choose it first. Many non-U.S. labs have a U.S. subsidiary, and signing through it can make the supplier's counsel more comfortable, but it also makes that subsidiary the licensee responsible for onward transfers to the parent. Signing through the parent, for example a GmbH, SAS or UK Ltd, keeps the license where the training happens, though the supplier may push for New York or Delaware law and U.S. courts.

Treat governing law and dispute forum as a package. A common compromise is the supplier's state law with arbitration seated in a neutral venue, which matters because a court judgment from one country is not automatically enforceable in another. Record the decision in your intake form so legal, tax and security reviewers start from the same facts. For the wider procurement sequence, see the AI training data procurement hub.

Screen the deal against the DOJ bulk sensitive data rule

As of October 2026, U.S. suppliers selling to foreign buyers have to check whether the data falls under the DOJ rule implementing Executive Order 14117, which prohibits and restricts certain transactions in bulk U.S. sensitive personal data with countries of concern and covered persons [1]. DOJ explicitly framed the risk as countries of concern using bulk U.S. data to build AI capabilities [1]. Expect a U.S. supplier's counsel to ask about your ownership, your affiliates and where your staff and vendors sit.

The rule's categories include personal health data, personal financial data, biometric identifiers, precise geolocation, human 'omic data and covered personal identifiers, each with a volume threshold, plus government-related data [1]. Operational records such as support tickets or claims files can cross a threshold quickly if they carry account numbers or health details. Even for buyers outside any country of concern, the rule expects U.S. parties in covered data brokerage deals with a foreign person to include contract terms barring onward transfer of the licensed data to countries of concern; read those clauses against your own annotation vendors, cloud regions and affiliates before you accept them.

Removing personal fields before delivery shrinks this exposure but does not end the analysis. Ask the supplier which method was used, what was checked, and what residual identifiers remain; tools such as Microsoft Presidio state plainly that automated detection cannot guarantee it finds all sensitive information [10]. Health records need HIPAA de-identification under 45 CFR 164.514, either Safe Harbor or Expert Determination [11]; the owner page on licensing medical records for AI training covers that path.

Ask whether any records are export-controlled technology

Most business records are not export-controlled, but engineering records can be. Design files, manufacturing process documents and source code from aerospace, defense, semiconductor or encryption work may be "technology" or "software" under the Export Administration Regulations, and BIS treats releasing controlled technology to a foreign person as an export to that person's country, even inside the United States [2]. That means a license, delivery to your foreign staff, or a U.S.-based foreign national engineer opening the bucket can all be relevant events.

Ask the supplier to confirm an export classification for any engineering or technical corpus, and flag anything that might fall under ITAR to counsel. Screen the supplier and its owners against sanctions lists on your side as well. If a corpus needs a license to reach you, drop it from scope rather than redesigning delivery around it.

State where the data is stored, processed and accessed

A written data location statement settles most security and privacy questions before they reach redlines. Name the cloud provider and region for landing, the region where training runs, the countries where annotation or evaluation vendors work, and the roles that can read raw records. If your team is in the EU, the GDPR applies to personal data your EU entity processes, and the AI Act itself confirms that Union data protection law continues to apply alongside it [3]; residual personal data about U.S. individuals still needs a lawful basis, retention rules and security controls once it lands in your environment.

Data moving from a U.S. supplier to you is not usually an EU transfer problem, but onward flows are. If your EU entity later sends records containing personal data to a U.S. or Indian annotation vendor, that onward transfer may need standard contractual clauses under Decision (EU) 2021/914 [7]. Map the full path, not just the first hop.

Build training-data documentation duties into the request

Your home regulators and your markets decide what you must later disclose about this data, so request the metadata now. Providers placing general-purpose AI models on the EU market, wherever they are based, must keep a copyright compliance policy and publish a summary of training content, duties that have applied since 2 August 2025 [4]; the GPAI Code of Practice copyright chapter describes one way to evidence that policy [5]. If your generative AI product is available in California, AB 2013 requires posted documentation about training data, including whether datasets were purchased or licensed and whether they contain personal information [6].

Ask each supplier for a datasheet that records the source system, collection period, consent basis, preparation steps and permitted uses. These fields map directly into a training-content summary and an AB 2013 disclosure, and they are far easier to collect at signature than reconstruct a year later. The provider due diligence questionnaire lists the questions in full.

Route payment, withholding and indirect tax to advisers early

Payment terms are a tax question first and a treasury question second, so bring advisers in before the price is final. Many countries tax royalties paid to non-residents at source, and whether a data license payment is a royalty, a service fee or a purchase of goods changes the answer. A U.S. supplier claiming treaty relief may need to provide a certificate of U.S. tax residency, and you may need to self-assess VAT or GST on an imported service.

Agree the invoicing currency, who bears foreign exchange movement, whether prices are gross or net of any withholding, and how wire fees are split. Ongoing purchases with quarterly refreshes multiply small frictions, so write them into the order form once. For comparing offers on a common basis, see normalizing data vendor quotes.

Cross-border procurement decision sheet

A one-page decision sheet keeps legal, tax, security and research aligned before the first draft license. Fill it in before requesting samples.

Illustrative example: invented to show structure; it does not describe an available dataset.

FieldExample entryOwnerWhy it matters
Contracting entityParent GmbH (Germany); U.S. subsidiary not a partyLegalSets licensee, data protection regime and tax position
Governing law and forumNew York law; ICC arbitration seated in LondonLegalEnforceability across borders
Data categoriesSupport ticket threads, product telemetry notes; no health or payment fieldsResearch leadDrives DOJ rule and HIPAA screening
Estimated U.S. persons coveredUnder supplier's stated volume after field removalPrivacyTests bulk thresholds [1]
Export classificationSupplier to confirm; no engineering drawings in scopeExport complianceAvoids deemed-export events [2]
Landing and training regionsAWS us-east-1 landing, eu-central-1 trainingSecurityDefines storage and access statement
Onward vendorsAnnotation vendor in Portugal; no other transfersPrivacyOnward transfer clauses and SCCs [7]
Disclosure metadataSource system, period, consent basis, preparation methodPolicyArticle 53 summary and AB 2013 [4][6]
PaymentUSD, net 45, withholding position per tax memoFinanceRoyalty characterization and VAT
Delivery and support windowTwo-hour overlap, 14:00–16:00 UTC, named contactsData engineeringCross-time-zone issue handling

Plan delivery and support across time zones

Delivery is where cross-border deals stall, so agree the mechanism and the support window in the order form. A common pattern is the supplier writing to a bucket and granting your account read access through a bucket policy scoped to a delivery prefix [8], or the reverse, with you granting write access to a landing bucket. Specify file format, for example Parquet with a schema file, since its footer metadata records the schema and column chunk locations, so you can check structure without scanning the whole file [9].

Agree a manifest with record counts and checksums per file, a named contact on each side, and an overlap window for issue triage. A nine-hour gap between California and Central Europe turns a one-line schema question into a two-day delay without one. If delivery fails, the remedies page on re-delivery, replacement records and credits covers what to write in advance.

How SourceX supports buyers outside the U.S.

SourceX serves AI teams wherever they are based and sources operational datasets from U.S. companies on request, managing the commercial process including licensing agreements and ongoing purchases. Data is not held in stock, so a request does not guarantee a match; buyers describe the data, and every release is approved by the supplying company. Each dataset is rights-reviewed for ownership and consents, personal details are removed or replaced with the method recorded and a sample checked, and delivery runs through private, access-controlled workflows only after an executed agreement. Read how non-U.S. labs license data and the guide for buyers outside the U.S., or start a request on the SourceX buyer page.

Ready to license U.S. company data from abroad

Describe the records, uses and delivery your team needs, and SourceX will look for U.S. businesses that hold that data. The process runs Find, Assess, Agree, Transact and Manage, and nothing is contracted until a supplier agrees. Describe the U.S. data your team needs.

Sources

  1. White & Case LLP, "DOJ issues final rule prohibiting and restricting transfers of bulk sensitive personal data" (2025). https://www.whitecase.com/insight-alert/doj-issues-final-rule-prohibiting-and-restricting-transfers-bulk-sensitive-personal
  2. U.S. Bureau of Industry and Security, "Deemed exports". https://www.bis.gov/deemed-exports
  3. EUR-Lex (European Parliament and Council), "Regulation (EU) 2024/1689 (AI Act), Article 2: Scope" (2024). https://eur-lex.europa.eu/eli/reg/2024/1689/art_2/oj
  4. European Commission, AI Act Service Desk, "AI Act Article 53: Obligations for providers of general-purpose AI models". https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-53
  5. European Commission (AI Office), "General-Purpose AI Code of Practice: Contents of the Code (Copyright chapter)" (2025). https://digital-strategy.ec.europa.eu/policies/contents-code-gpai
  6. California Legislature, "AB-2013 Generative artificial intelligence: training data transparency" (2024). https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
  7. European Commission, "Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries". https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj
  8. Amazon Web Services, Amazon S3 User Guide, "Example 2: Bucket owner granting cross-account bucket permissions". https://docs.aws.amazon.com/AmazonS3/latest/userguide/example-walkthroughs-managing-access-example2.html
  9. The Apache Software Foundation (Apache Parquet), "File Format". https://parquet.apache.org/docs/file-format/
  10. Microsoft (microsoft/presidio), indexed on pkg.go.dev, "Presidio - Data Protection API". https://pkg.go.dev/github.com/microsoft/presidio
  11. eCFR, Office of the Federal Register / HHS, "45 CFR 164.514 - Other requirements relating to uses and disclosures of protected health information". https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data