Definitions and comparisons
Is an AI data buyer a controller, a processor or a third party?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
An AI data buyer that licenses records to train its own models usually decides why and how it uses them, so under GDPR it typically acts as an independent controller, and under the CCPA it is typically a third party rather than a service provider. The cleanest path is removing personal information before delivery, then confirming roles with counsel.
Key takeaways
- Under GDPR, whoever decides the purposes and means of processing is a controller, and a buyer training its own models usually fits that description.
- A buyer is closer to a processor or service provider only when it processes records on your behalf, for your purposes, under your instructions.
- Under the CCPA, disclosing personal information to a third party for valuable consideration may count as a sale, with notice and opt-out duties.
- Removing personal information before delivery narrows the role question, but the license should still bar re-identification and onward transfer.
Why does the buyer's role matter?#
The buyer's role matters because it decides which privacy duties attach to the transfer and which contract terms you need. The same delivery of support tickets can be a transfer between independent controllers, a processing arrangement or a disclosure to a third party, and each label brings different notices, contract clauses and rights for the people named in the records.
The question only arises if personal information remains in the delivered records. Many enterprise licenses are prepared so that customer and employee details are removed first, which narrows the analysis but rarely ends it, because free-text fields are hard to clean completely and some laws regulate de-identified data as well.
Getting the role wrong has practical consequences. A buyer labeled a processor in the contract but using the records for its own models leaves both parties with a document that does not match reality, and regulators and diligence teams tend to look at what the parties actually do, not only at the label.
Under GDPR, is the buyer a controller or a processor?#
Under GDPR, an AI data buyer that licenses records for its own model training is usually a controller, because it decides the purposes and means of that processing. A processor acts on behalf of a controller and follows its instructions, and a buyer building its own general-purpose model is not doing that for you.
Joint controllership can arise where both parties together decide purposes and means, for example in a co-development project. It is less common in a straightforward license but worth checking whenever a deal includes shared model work or shared use of the output.
The anonymization row is where most licenses aim, and it is a high bar. GDPR Recital 26 says that to decide whether a person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person, weighing factors such as cost and time against the technology available. A buyer that could link support tickets to other data it holds may defeat an anonymization that looked sound inside your company.
| Scenario | Likely GDPR role of the buyer | What it usually means |
|---|---|---|
| Buyer licenses records to train its own models | Independent controller | Each party answers for its own processing; the transfer needs a lawful basis and transparency |
| Buyer trains a model only for your company, on your instructions | Processor | A processing agreement covering instructions, security and deletion |
| You and the buyer jointly design and use a model | Possibly joint controllers | An arrangement allocating responsibilities between the parties |
| Records are anonymized before delivery | GDPR may not apply to the delivered data | Anonymization must hold up; pseudonymized data is generally still personal data |
Under the CCPA, is the buyer a service provider, contractor or third party?#
Under the CCPA, an AI data buyer that uses licensed records for its own purposes is usually a third party, not a service provider or contractor. Service providers and contractors process personal information on behalf of a business for a business purpose, under a contract that stops them from using it for their own ends.
If personal information goes to a third party for money or other valuable consideration, the disclosure may count as a sale under the CCPA's broad definition, which can bring notice and opt-out duties. That is one reason companies remove personal information before licensing. California also treats properly de-identified information differently, but that standard includes technical and contractual conditions counsel should confirm.
| Label | Typical fit | What it triggers |
|---|---|---|
| Service provider or contractor | A vendor processing only for your business purpose | Contract limits on retention, use and disclosure |
| Third party | A buyer using records for its own models | Possible sale or sharing duties, notices and opt-outs |
| No personal information delivered | Records prepared so no personal information remains | Contract terms still bar re-identification and onward misuse |
A five-question decision path#
A five-question decision path helps counsel and the deal team agree on roles before anyone drafts. Work through it for each record family, because support tickets, email archives and engineering records can land in different places.
If the answers show no personal information remains, the analysis shifts to de-identification standards and contract controls. If personal information remains and the buyer serves its own purposes, plan for controller or third-party terms and the notices that go with them.
- After preparation, does the delivered data still contain personal information about customers, employees or other contacts?
- Whose purposes does the processing serve: the buyer's own models, or a model built only for you?
- Who decides how the records are used, combined with other data and retained?
- Is the buyer giving money or other valuable consideration for the records?
- Which laws may apply, given where the people in the records live and where both companies operate?
What contract terms follow from each role#
Contract terms follow from the role the parties agree on. A license to an independent controller or third party usually limits use to the permitted purpose, prohibits re-identification and onward transfer, sets security expectations and requires deletion or return at the end of the term. A processing arrangement instead centers on documented instructions, audit rights and rules for subprocessors.
Whichever label applies, write it into the license rather than leaving it implied. Unclear roles are a common reason privacy reviews stall late in a deal, often after the commercial terms are already agreed.
Illustrative: a logistics software company scopes its support history#
Illustrative: a fictional logistics software company plans to license its support history to a model developer. The tickets come from shippers across the United States, including California, and from a small group of customers in the EU, and many contain names, email addresses and phone numbers.
Counsel concludes that the buyer would act as an independent controller under GDPR and a third party under the CCPA if personal information remained. The company removes names, contact details and account identifiers, excludes tickets from EU customers whose contracts restrict transfers, and adds re-identification and onward transfer bans to the license. The remaining analysis focuses on whether the preparation meets the relevant de-identification standards.
The license names the buyer's role, states the permitted purpose as training and evaluation of the buyer's own models, and requires written confirmation of deletion at the end of the term. The company also reviews its privacy notice to confirm it describes this kind of disclosure.
How SourceX handles role questions#
SourceX removes personal and confidential details during the Preparation step of the SourceX five-step transaction and records the method in the privacy record of the SourceX Evidence Packet. Role allocation itself is a legal judgment for the company's counsel and the buyer's counsel, made deal by deal.
The initial fit check uses only metadata, such as system names and record families, so no personal information leaves the company while it decides whether to proceed.
Frequently asked questions
Can a buyer be a processor if it pays us for the records?
It is unusual. A processor acts on your behalf and for your purposes, while a buyer paying for records usually wants them for its own models. Payment does not settle the role on its own, but it often signals that the buyer is pursuing its own purposes.
Does removing personal information end the analysis?
It narrows it. If records are truly anonymized, GDPR may not apply to the delivered data, and California treats de-identified information differently. Both standards are demanding, though, and residual details in free text are common, so counsel should review the preparation method and the contract controls together.
Do other US state privacy laws use the same labels?
Several state privacy laws use controller and processor terms similar to GDPR, while California uses service provider, contractor and third party. Definitions and duties vary by state, so counsel should check which laws may apply based on where the people in the records live.
What about employee details in email and chat archives?
Employee information is personal information too, and employment records can be especially sensitive. Email and chat archives usually need heavier preparation than support tickets. Check your employee privacy notices, and consider excluding HR channels and private messages from scope altogether.
Who should decide the role allocation?
Your counsel, working with the buyer's counsel, decides how roles are allocated in each deal. The deal team supplies the facts: what the records contain, how they will be prepared and what the buyer intends to do with them. Write the result into the license.
Does the buyer's role change if it also builds a model for us?
It can. Training its own models on licensed records points to an independent controller or third party, while building a model only for you, on your instructions, points toward a processor or service provider. If a deal includes both, document each activity and its role separately in the contract.
Sources
- GDPR Recital 26 says that, to decide whether a person is identifiable, account should be taken of all the means reasonably likely to be used, such as singling out, either by the controller or by another person, weighing objective factors such as cost and time of identification against available technology. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.