Provenance, rights and permitted use
Employee-Authored Records in Training Data: Ownership, Policies and Notice Checks
Quick answer
A company can usually license what its employees wrote at work, but only the parts it actually owns and only under policies that do not contradict the new use. In the US, work created within the scope of employment is generally a work made for hire owned by the employer. Buyers still need evidence for three separate questions: who authored each record, which acceptable-use and monitoring policies applied when it was written, and whether non-US staff or works councils had rights over the systems that captured it.
By SourceX Editorial · Updated
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
Why work-made-for-hire covers less of a corpus than suppliers assume
Work-made-for-hire status settles copyright only for records employees created within the scope of their jobs, and a typical email or Slack export contains much more than that. Under 17 U.S.C. §201(b) the employer is considered the author of a work made for hire and owns it unless a signed writing says otherwise. The §101 definition has two routes: works by employees within the scope of employment, and nine categories of specially commissioned works backed by a signed agreement. Contractor output outside those categories needs a written assignment, not a work-for-hire label.
"Scope of employment" is a fact question. The Ninth Circuit's model instruction asks whether the work is the kind the employee was hired to create, whether it was made substantially within authorized time and space, and whether it served the employer at least in part. A support engineer's ticket replies pass easily; a sales rep's personal blog drafts saved to a shared drive may not.
The larger gaps come from authors who were never employees:
- Inbound customer and vendor messages. A Zendesk ticket thread or a Gmail archive holds text written by outsiders, whose rights flow from customer contracts and terms, not employment. See customer contracts and DPAs.
- Contractors, agencies and BPO staff. Outsourced support agents often author most of a ticket history. Ask for the master services agreement's IP assignment clause.
- Acquired-company archives. Mailboxes inherited in an acquisition carry the predecessor's policies and its chain of title; see chain of title for AI training data.
- Embedded third-party material. Pasted articles, vendor PDFs and screenshots keep their own copyright; copyright in operational business records covers how thin protection on routine records interacts with that.
Separating ownership from permission to use
Owning the copyright in employee work does not by itself permit licensing records that are also personal data about those employees. Copyright answers "can the supplier grant a license"; employment, privacy and consumer-protection law answer "may this information be used this way." A Slack export is simultaneously a set of employer-owned works and a log of named individuals' health remarks, performance disputes and private plans.
Treat the two as separate evidence tracks in diligence. The privacy track, including how names, handles and signature blocks are removed, belongs with employee communications privacy for training data. This page covers the ownership and notice track. Provenance definitions such as CASRAI's list the consent basis alongside source and licensing, so record the notice basis in the same file [6].
Policies to request for every year of the corpus
Ask for every version of the policies that governed the source systems across the full date range of the records, not just the current handbook. A 2026 policy that mentions AI training says nothing about messages written in 2019. Match each record's timestamp to the policy version in force, using the approach in matching records to the notice in force at collection.
The policies that usually matter:
- Acceptable-use or electronic communications policy. Look for language that company systems and their contents belong to the company and carry no expectation of privacy.
- Monitoring notices. As of October 2026, some states require them. New York's Civil Rights Law §52-c requires private employers that monitor employee email, phone or internet use to give written notice at hiring, obtain an acknowledgment and post the notice [1]. Delaware requires notice before monitoring telephone, email or internet use [2]. Signed acknowledgments are strong evidence that employees knew the employer accessed these systems.
- Records retention and legal hold schedules. They show whether data that should have been deleted is in the export, a sign the supplier is not in control of its own archive.
- Employee privacy notice (non-US staff). Under GDPR the notice must name purposes; licensing to a third party for model training is a new purpose that needs a compatibility analysis or a fresh basis [4].
- IP and confidentiality agreements. Invention assignment and confidentiality agreements confirm ownership of employee work beyond the statutory default.
A monitoring notice is not an AI-training notice. It tells employees the employer may read their messages, not that a buyer will train on them. The FTC has warned that quietly adopting more permissive data practices, such as AI training, through retroactive policy changes may be unfair or deceptive [5]. Its post addresses consumer terms, but the same logic is a reason to be skeptical of a supplier that updated its handbook last month and applied it to ten years of mail.
Personal messages inside work systems
Every workplace archive contains non-work content, and the buyer needs a written exclusion rule, not a promise that "most of it is business." Typical leakage includes personal Gmail forwarded to work accounts, Slack DMs about medical appointments, family photos in shared drives, and union or HR grievance threads. Ownership of these records is doubtful under the scope-of-employment test described above, and they are the most sensitive content in the corpus.
Ask how the supplier identified and removed them: channel allowlists (for example, only public Slack channels and ticket queues), folder exclusions (Personal, HR, Legal, Benefits), keyword and classifier filters, and a reviewed sample. The supplier should record what was excluded and why, at the same granularity as the record-level provenance you hold for the rest of the data.
Works councils and non-US employees
If any authors worked outside the US, local labor law may give employee representatives rights over the systems that produced the data, and sometimes over its new use. In Germany, §87(1) No. 6 of the Works Constitution Act (BetrVG) gives works councils co-determination rights over technical devices objectively suitable for monitoring conduct or performance, and courts read it broadly enough to cover email and collaboration software. Practitioners recommend works agreements that fix scope, purposes, access roles and retention for such systems, and systems rolled out across several establishments may fall to the central (company-level) works council, or to the group works council when deployed group-wide.
That has two consequences for a buyer. First, an existing works agreement may restrict the purposes for which mailbox or chat data may be processed, and licensing for model training may fall outside them. Second, EU regulators have long held that employee consent is rarely a valid basis because of the imbalance of power in employment, so "employees agreed" is weak evidence on its own [3]. Ask for the works agreement, any consultation record, and a country-by-country list of where authors were based. Verify the rules for each country with local counsel; France, the Netherlands and Austria have their own consultation regimes.
Diligence checklist for employee-authored corpora
The checklist below turns the questions above into evidence requests a governance lead can attach to the purchase file.
Illustrative example: invented to show structure; it does not describe an available dataset.
| Check | Evidence to request | Red flag |
|---|---|---|
| Author mix | Share of records by author type: employee, contractor, customer, vendor, unknown | "All employee-authored" for a support ticket export |
| Employment status | HRIS extract mapping author IDs to employee or contractor status by date | Author IDs that cannot be resolved |
| Contractor IP | MSA or SOW assignment clauses for each outsourcing vendor | Assignment limited to deliverables, silent on communications |
| Policy timeline | Every acceptable-use, monitoring and privacy notice version with effective dates | Single current policy offered for a multi-year corpus |
| Monitoring acknowledgments | Signed acknowledgments where state law requires them (for example, NY, DE) | No acknowledgments for staff in notice states |
| AI-use notice | Notice or policy language covering third-party licensing for model training, with date | Change made shortly before sale and applied retroactively |
| Personal-content exclusion | Written rule, filters used, sample review result | Exclusion described as "manual where noticed" |
| Non-US authors | Country list, works agreements, consultation records | EU or German staff present, no works-council review |
| Acquired archives | Acquisition agreement schedules transferring the data and predecessor policies | Predecessor mailboxes with no policy history |
| Attestation | Signed rights attestation covering the points above | Refusal to attest to author mix |
A supplier-signed data rights attestation should restate the answers, and your training data use register should record any restriction, such as "no records from German entities" or "public channels only."
Recordings and screen captures of employees
Employee-authored records include more than text, and recordings add consent rules that copyright ownership does not resolve. Call recordings with employees on the line are governed by state wiretap and recording statutes; see call-recording consent for AI training. Video of staff doing hands-on work raises notice, likeness and sometimes biometric questions covered in recording employees on video. Screen captures of employees working in third-party software carry their own rights questions, set out in screen-recording third-party content rights.
How SourceX handles employee-authored records
SourceX sources operational datasets, including support and sales histories, engineering records, documents and new recordings of hands-on work, from US companies and manages the licensing process. Every dataset is rights-reviewed for ownership and consents and delivered under a license that defines the records, allowed uses, term and delivery. Names, emails, phone numbers and account numbers are removed or replaced before delivery, the method is recorded and a sample is checked, though no method is perfect. Each release is approved by the supplying company. Buyers can describe the data they need on the SourceX buyers page.
For the wider framework, start with the provenance hub or the AI data overview. Related reading includes whether employees' work data can be sold to AI companies, whether you need employee consent to license Slack messages and licensing email archives.
Sourcing employee-authored records with documented rights
SourceX sources workplace datasets on request from US businesses that hold them, after reviewing ownership and consents, and nothing is contracted until the supplying company agrees. A request does not guarantee a match. Describe the records, date range and intended use on the SourceX buyers page.
Sources
- New York Public Law (public.law), "N.Y. Civil Rights Law Section 52-C*2 (electronic monitoring notice)". https://newyork.public.law/laws/n.y._civil_rights_law_section_52-c*2
- Delaware General Assembly, "Delaware Code Title 19, Chapter 7, Subchapter I (including 19 Del. C. 705, electronic monitoring notice)". https://delcode.delaware.gov/title19/c007/sc01/index.html
- Article 29 Data Protection Working Party, European Commission, "Opinion 2/2017 on data processing at work (WP249)" (2017). https://ec.europa.eu/newsroom/article29/items/610169
- European Parliament and Council of the European Union (Official Journal of the EU, via EUR-Lex), "Regulation (EU) 2016/679 (General Data Protection Regulation)" (2016). https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng
- Federal Trade Commission, Office of Technology, "AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive" (2024). https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2024/02/ai-other-companies-quietly-changing-your-terms-service-could-be-unfair-or-deceptive
- CASRAI, "Training data provenance". https://casrai.org/dictionary/term/training-data-provenance
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.