How it is legal
Anonymised, your most confidential work is a legal, sellable asset.
Confidentiality law protects the identifiable secret: the name, the date of birth, the file number. Strip those, and what is left, the diagnosis, the dosage, the deal, the clause, is no longer protected. It is data. And data is legal to sell.
There is nothing shadowy about the buyers. It is a public, multi-billion-euro industry with catalogs, subscriptions and shopping carts, built on data that started as somebody’s confidential file.
We built Wysor so your data never enters that market in the first place.
The loophole
Anonymise it, and the law lets go.
The confidentiality you owe your clients, and the privacy law behind it, guard one thing: information that can be traced to a person. That is the whole hinge. Remove the name so no one can be traced, and the same file that was untouchable becomes a legal, sellable asset.
The identifier is what the law protects: the name, the date of birth, the file number. Black it out and, legally, there is no secret left.
Everything of value stays: the diagnosis, the dosage, the deal, the clause. That is what a public market pays for.
At your desk
What that looks like in a practice and a law firm.
Nothing here needs a law broken or a licence you did not knowingly grant. It only needs your everyday work to have been collectable in the first place.
You dictate a medical report
The history, the medication list and the lab trajectory, with the name removed, become one row in a real-world-evidence dataset.
Bought by a drug maker to watch how a medicine performs in the field.
You record a diagnosis and a treatment
The pattern, condition, drug, dose, outcome, side-effect, is de-identified and pooled across millions of visits.
Sold as prescribing and adherence analytics back to pharma.
You draft a contract or a clause
The drafting patterns and the know-how are lifted from the text, with no client named.
Mined into clause libraries and drafting assistants sold as a product.
You file a case or plan a strategy
Parties, outcomes and timing are aggregated into analytics on judges, firms and opponents.
Sold back into the market, sometimes toward the other side of your case.
Your duty of confidentiality covered the name on the file. It never covered what the file is worth.
The buyers
You can browse the market for it right now.
This is not a black market. It is a public industry with catalogs, subscriptions and shopping carts. These companies buy de-identified data at population scale and sell what they build from it back to the same fields it came from.
De-identified prescription and clinical records
A roughly 16-billion-dollar business selling them to pharma
IQVIA revenue, 2025A “Healthcare Map” of 330 million+ de-identified patients
Sold to life-science firms by subscription
Komodo Health120 million+ de-identified patient records from health systems
Pooled and sold for research
TruvetaDe-identified insurance claims on 70 million+ people
Licensed to drug makers and researchers
OptumDe-identifies and links patient records at scale
So they can be bought and combined across the industry
DatavantDe-identified patient datasets, listed for sale in public marketplaces (Snowflake, Datarade)
Browse, subscribe and buy, thousands of datasets
Snowflake MarketplaceThe false comfort
“Anonymised” assumes it stays that way. It does not.
Taking the name off only helps if no one can work it back on. But a few small, harmless-looking details, an age, a postcode, a rare diagnosis, the time of a visit, together single out one person. A data broker only has to cross-reference them against public records or another dataset, and AI now does that matching cheaply, at scale, in seconds.
Anonymised looks like scattered, harmless details: an age, a postcode, a lab value, a time.
Cross-reference them against other data, whether a broker by hand or an AI at scale, and they point back to one person.
“Anonymised” Netflix ratings, undone
Researchers matched Netflix’s anonymised ratings of 500,000 subscribers against public IMDb profiles and put names back on the records.
Narayanan & ShmatikovA search history, traced to a person
AOL released “anonymised” search logs. A reporter identified user No. 4417749 as a named 62-year-old woman from her queries alone.
AOL search log release99.98% of people, re-identifiable
A Nature study found that almost any anonymised dataset can be undone: 99.98% of Americans were re-identifiable from just 15 attributes.
Nature CommunicationsA language model, guessing who you are
ETH Zurich showed AI models can infer where you live, your age and your income from a few lines you wrote, with up to 85% accuracy and far cheaper than a person.
Staab et al., ETH ZurichEven your IP address counts
Europe’s top court ruled that a dynamic IP address is personal data in its own right, and an IP can place someone in a city before anyone reads a word of the file.
CJEU, Breyer, 2016It has already happened
Not a hypothetical. To a doctor’s records, and to a court.
A patient file with the name stripped off is still a patient.
A researcher re-identified a US state governor’s “anonymous” hospital records by lining them up against public voter rolls, and showed that roughly 87% of people can be picked out from ZIP code, date of birth and sex alone.
It is not only academic. When an NHS trust handed 1.6 million patient records to Google’s DeepMind, the UK regulator ruled the hospital had broken data-protection law, because patients were never properly told.
Aggregated case data can be turned on the people inside it.
Court records are public, so companies mine them into analytics on judges, firms and parties. France decided that had gone too far: since 2019 it is a criminal offence, up to five years in prison, to use judges’ identity data to analyse or predict their rulings.
The lesson is not that this is rare. It is that it became invasive enough for a government to make one slice of it a crime.
How it is legal
Four steps, and not one of them breaks a law.
You gave permission.
Somewhere in the terms you accepted, many services take a broad licence to use, copy and reuse what you upload, not only to run the service for you but for their own purposes. Nothing is stolen. You agreed to it.
Anonymised data is nobody’s secret.
Privacy law protects information that can be traced to a person. Remove every identifier so no one can be, and it stops applying: truly anonymous data is outside the law. What remains is not personal, and not confidential. It is inventory.
Data-protection law, Recital 26When a company changes hands, the data goes with it.
In an acquisition or a wind-down, a company’s data is treated as an asset like any other: it passes to the buyer, or it is realised to pay creditors. The law adds conditions here, such as notice, rather than a ban on the transfer.
Norton Rose FulbrightThe law only stops the half-measure.
Swap a name for a code and the data is merely pseudonymised: still personal, still protected, and regulators enforce that line. In 2026 France’s data authority fined a health-data broker 5 million euros for treating pseudonymised prescriptions as if they were anonymous. The wall is real, and it is narrow. It stops the sloppy version, not the full anonymisation the whole market runs on.
CNIL, 2026This is not hypothetical, and not new. Germany has already fought over it: pharmacies were reported passing insufficiently anonymised prescription data to brokers. heise online The lesson is the loophole itself: the clean, unchallenged move is full anonymisation, and then the sale is simply legal.
On the record
“While unlikely, we cannot rule out that de-identified data derived from their usage of our products helped improve our models.”
OpenAI, September 2026, after two mathematicians asked whether their use of its tools had fed the model. CNN, 2026
If a frontier lab cannot promise your work never reached its model, a line in a privacy policy will not save you. It has to be written into the contract and built into the architecture.
The way out
The only data that cannot be sold is data no one was allowed to touch.
Every step above runs on one thing: a working copy of your content that someone is allowed to reuse. Take that away and the whole chain has nothing to start from. That is the design of Wysor.
No licence to your content
Wysor never takes a licence to reuse what you put in. We process it to run the service for you, and nothing else. There is no working copy for us to strip a name from and sell.
You own it, we only process it
Your data stays in your name. Wysor is only a processor acting on your instructions, and a processor cannot sell what it holds, anonymised or not.
Locked into the terms, not our goodwill
These protections live in our contract, not in our good intentions. They bind Wysor and anyone who could ever own it, so what happens to your data never depends on who is in charge.
It holds further down the stack too. Your data is encrypted, we never train on your content, and the AI providers behind Wysor run under zero data retention: your request is processed, then deleted. See how that works.