How it is legal

Anonymised, your most confidential work is a legal, sellable asset.

Confidentiality law protects the identifiable secret: the name, the date of birth, the file number. Strip those, and what is left, the diagnosis, the dosage, the deal, the clause, is no longer protected. It is data. And data is legal to sell.

There is nothing shadowy about the buyers. It is a public, multi-billion-euro industry with catalogs, subscriptions and shopping carts, built on data that started as somebody’s confidential file.

We built Wysor so your data never enters that market in the first place.

The loophole

Anonymise it, and the law lets go.

The confidentiality you owe your clients, and the privacy law behind it, guard one thing: information that can be traced to a person. That is the whole hinge. Remove the name so no one can be traced, and the same file that was untouchable becomes a legal, sellable asset.

Strip the name, keep the value

The identifier is what the law protects: the name, the date of birth, the file number. Black it out and, legally, there is no secret left.

Everything of value stays: the diagnosis, the dosage, the deal, the clause. That is what a public market pays for.

At your desk

What that looks like in a practice and a law firm.

Nothing here needs a law broken or a licence you did not knowingly grant. It only needs your everyday work to have been collectable in the first place.

Medicine

You dictate a medical report

The history, the medication list and the lab trajectory, with the name removed, become one row in a real-world-evidence dataset.

Bought by a drug maker to watch how a medicine performs in the field.

Medicine

You record a diagnosis and a treatment

The pattern, condition, drug, dose, outcome, side-effect, is de-identified and pooled across millions of visits.

Sold as prescribing and adherence analytics back to pharma.

Law

You draft a contract or a clause

The drafting patterns and the know-how are lifted from the text, with no client named.

Mined into clause libraries and drafting assistants sold as a product.

Law

You file a case or plan a strategy

Parties, outcomes and timing are aggregated into analytics on judges, firms and opponents.

Sold back into the market, sometimes toward the other side of your case.

Your duty of confidentiality covered the name on the file. It never covered what the file is worth.

The buyers

You can browse the market for it right now.

This is not a black market. It is a public industry with catalogs, subscriptions and shopping carts. These companies buy de-identified data at population scale and sell what they build from it back to the same fields it came from.

Health data

De-identified prescription and clinical records

A roughly 16-billion-dollar business selling them to pharma

IQVIA revenue, 2025
Health data

A “Healthcare Map” of 330 million+ de-identified patients

Sold to life-science firms by subscription

Komodo Health
Health data

120 million+ de-identified patient records from health systems

Pooled and sold for research

Truveta
Health data

De-identified insurance claims on 70 million+ people

Licensed to drug makers and researchers

Optum
Health data

De-identifies and links patient records at scale

So they can be bought and combined across the industry

Datavant
The catalogs

De-identified patient datasets, listed for sale in public marketplaces (Snowflake, Datarade)

Browse, subscribe and buy, thousands of datasets

Snowflake Marketplace

The false comfort

“Anonymised” assumes it stays that way. It does not.

Taking the name off only helps if no one can work it back on. But a few small, harmless-looking details, an age, a postcode, a rare diagnosis, the time of a visit, together single out one person. A data broker only has to cross-reference them against public records or another dataset, and AI now does that matching cheaply, at scale, in seconds.

How the name comes back

Anonymised looks like scattered, harmless details: an age, a postcode, a lab value, a time.

Cross-reference them against other data, whether a broker by hand or an AI at scale, and they point back to one person.

2008

“Anonymised” Netflix ratings, undone

Researchers matched Netflix’s anonymised ratings of 500,000 subscribers against public IMDb profiles and put names back on the records.

Narayanan & Shmatikov
2006

A search history, traced to a person

AOL released “anonymised” search logs. A reporter identified user No. 4417749 as a named 62-year-old woman from her queries alone.

AOL search log release
2019

99.98% of people, re-identifiable

A Nature study found that almost any anonymised dataset can be undone: 99.98% of Americans were re-identifiable from just 15 attributes.

Nature Communications
AI

A language model, guessing who you are

ETH Zurich showed AI models can infer where you live, your age and your income from a few lines you wrote, with up to 85% accuracy and far cheaper than a person.

Staab et al., ETH Zurich
Metadata

Even your IP address counts

Europe’s top court ruled that a dynamic IP address is personal data in its own right, and an IP can place someone in a city before anyone reads a word of the file.

CJEU, Breyer, 2016

It has already happened

Not a hypothetical. To a doctor’s records, and to a court.

Medicine

A patient file with the name stripped off is still a patient.

A researcher re-identified a US state governor’s “anonymous” hospital records by lining them up against public voter rolls, and showed that roughly 87% of people can be picked out from ZIP code, date of birth and sex alone.

It is not only academic. When an NHS trust handed 1.6 million patient records to Google’s DeepMind, the UK regulator ruled the hospital had broken data-protection law, because patients were never properly told.

Law

Aggregated case data can be turned on the people inside it.

Court records are public, so companies mine them into analytics on judges, firms and parties. France decided that had gone too far: since 2019 it is a criminal offence, up to five years in prison, to use judges’ identity data to analyse or predict their rulings.

The lesson is not that this is rare. It is that it became invasive enough for a government to make one slice of it a crime.

How it is legal

Four steps, and not one of them breaks a law.

The fine print

You gave permission.

Somewhere in the terms you accepted, many services take a broad licence to use, copy and reuse what you upload, not only to run the service for you but for their own purposes. Nothing is stolen. You agreed to it.

Privacy law

Anonymised data is nobody’s secret.

Privacy law protects information that can be traced to a person. Remove every identifier so no one can be, and it stops applying: truly anonymous data is outside the law. What remains is not personal, and not confidential. It is inventory.

Data-protection law, Recital 26
Change of hands

When a company changes hands, the data goes with it.

In an acquisition or a wind-down, a company’s data is treated as an asset like any other: it passes to the buyer, or it is realised to pay creditors. The law adds conditions here, such as notice, rather than a ban on the transfer.

Norton Rose Fulbright
The limit

The law only stops the half-measure.

Swap a name for a code and the data is merely pseudonymised: still personal, still protected, and regulators enforce that line. In 2026 France’s data authority fined a health-data broker 5 million euros for treating pseudonymised prescriptions as if they were anonymous. The wall is real, and it is narrow. It stops the sloppy version, not the full anonymisation the whole market runs on.

CNIL, 2026

This is not hypothetical, and not new. Germany has already fought over it: pharmacies were reported passing insufficiently anonymised prescription data to brokers. heise online The lesson is the loophole itself: the clean, unchallenged move is full anonymisation, and then the sale is simply legal.

On the record

“While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models.”

OpenAI, September 2026, after two mathematicians asked whether their use of its tools had fed the model. CNN, 2026

If a frontier lab cannot promise your work never reached its model, a line in a privacy policy will not save you. It has to be written into the contract and built into the architecture.

The way out

The only data that cannot be sold is data no one was allowed to touch.

Every step above runs on one thing: a working copy of your content that someone is allowed to reuse. Take that away and the whole chain has nothing to start from. That is the design of Wysor.

No licence to your content

Wysor never takes a licence to reuse what you put in. We process it to run the service for you, and nothing else. There is no working copy for us to strip a name from and sell.

You own it, we only process it

Your data stays in your name. Wysor is only a processor acting on your instructions, and a processor cannot sell what it holds, anonymised or not.

Locked into the terms, not our goodwill

These protections live in our contract, not in our good intentions. They bind Wysor and anyone who could ever own it, so what happens to your data never depends on who is in charge.

It holds further down the stack too. Your data is encrypted, we never train on your content, and the AI providers behind Wysor run under zero data retention: your request is processed, then deleted. See how that works.

For anyone who owes someone else confidentiality.

Doctors and practices
Lawyers and notaries
Tax advisors and auditors
HR and personnel records
Finance and insurance
Public sector and research