Privacy, de-identification and sensitive data
Sending sensitive training data to annotation vendors: BAAs, offshore access and least privilege
Quick answer
Annotation vendors should reach licensed PHI or PII only when four conditions line up: your data license permits disclosure to contractors, the right contract is in place (a business associate agreement for PHI, an Article 28 processor agreement for EU personal data), annotator location clears transfer and national-security rules, and the tooling enforces least privilege. Masked views, no exports, named accounts and logged sessions do that. The cleanest option is often to de-identify first so the vendor never handles regulated data at all.
By SourceX Editorial · Updated
This page is general information, not legal advice. Confirm requirements with counsel for your jurisdiction and use case.
Start with the license: may you show this data to a labeling contractor at all?
Your inbound data license decides whether an annotation vendor can see the data, before any privacy law does. Many data licenses limit use to the licensee's "internal purposes" and then either permit or omit disclosure to contractors acting on the licensee's behalf; sample clauses show both patterns [8]. If the license is silent, assume the vendor is an unauthorized third party until the supplier says otherwise in writing.
Check four clauses before routing anything to a labeling queue:
- Authorized users or permitted recipients. Does the definition include contractors, and does it require them to sign terms at least as protective as yours?
- Purpose limits. "Training internal models" may not cover a vendor building its own QA classifiers or annotator-training sets from your records.
- Location or transfer limits. Some supplier agreements restrict processing or access outside the US.
- Flow-down and liability. You usually remain liable for the vendor's breach of the license, so the vendor contract has to mirror the license restrictions.
Treat the vendor as a named sub-recipient in your data inventory. The subcontractor and workforce disclosure guide covers how to ask suppliers and vendors who actually touches the data.
When a labeling vendor needs a BAA, and when it does not
A labeling vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity or business associate needs a business associate agreement, and market guidance on healthcare ML treats labeling firms that way [1]. HHS publishes sample BAA provisions covering permitted uses, safeguards under the Security Rule, reporting of breaches and security incidents, flow-down to subcontractors, and return or destruction of PHI at termination [2]. If you are yourself a business associate, the vendor becomes your subcontractor and needs a subcontractor BAA, not a side letter.
The BAA requirement falls away if the vendor only ever receives properly de-identified data. HHS has said a cloud provider that receives and maintains only information de-identified under the Privacy Rule is not a business associate for that information [3]. De-identification means Safe Harbor (removing 18 identifier types, with no actual knowledge that the remaining information could identify the individual) or Expert Determination [4], under the standard in 45 CFR 164.514(a)-(b) [5].
A limited data set sits in between. It strips 16 categories of direct identifiers but can keep dates and some geography, and it can be disclosed only for research, public health or health care operations under a data use agreement [5]. Whether model development qualifies as one of those purposes is a question for counsel, not the vendor.
Watch for health data outside HIPAA. Washington's My Health My Data Act defines consumer health data broadly, including inferences about health status and some location data [11], so support tickets or app logs can carry health signals with no BAA framework around them. See special category and sensitive data in operational datasets for where these fields hide.
GDPR: the annotation vendor is a processor with strict limits
Under the GDPR, an annotation vendor labeling EU personal data on your behalf is a processor, and Article 28 dictates the contract. The processor must act only on documented instructions, ensure annotators are bound by confidentiality, apply appropriate security, and engage sub-processors only with your prior written authorization [6]. If the vendor starts using the data for its own purposes, such as training its pre-labeling models, Article 28(10) treats it as a controller for that processing [6].
That last point is a frequent failure mode. Vendors that run model-assisted pre-labeling often want to keep corrections to improve their own models, and default platform terms may allow it. Strike that right, or record it explicitly as a separate controller activity your lawful basis covers.
Remote viewing by annotators outside the EEA is still a transfer under Chapter V of the GDPR [6] (EDPB Guidelines 05/2021), even if no file leaves your cloud tenant. You will need a transfer mechanism such as the Commission's standard contractual clauses plus a transfer impact assessment. Whether the data counts as personal data at all is covered in anonymised vs pseudonymised training data.
Offshore annotators: privacy transfer rules and the DOJ data security rule
Offshore annotation raises two separate questions: privacy-law transfer rules, and US national-security rules on who may access bulk sensitive data. HIPAA does not prohibit offshore business associates, but your BAA, security risk analysis and supplier license may. GDPR transfer obligations apply whenever annotators outside the EEA can view EU personal data.
As of October 2026, the DOJ rule at 28 CFR Part 202, in effect since April 8, 2025, treats vendor agreements and employment agreements that give countries of concern or covered persons access to bulk US sensitive personal data as restricted transactions [7]. Restricted transactions are permitted only with prescribed security requirements, and data brokerage to those parties is prohibited outright [7]. Bulk thresholds are low for some categories, such as personal health data and biometric identifiers, so a large annotation program can cross them quickly.
Practical controls for this question:
- Require the vendor to disclose annotator country, employer of record and any subcontracted workforce, then keep that list current.
- Contractually bar access from countries of concern and by covered persons, and verify with IP and device controls, not attestation alone.
- Count records and US persons per data category against the rule's thresholds before you size the queue.
For how the rule applies to the licensed data itself, see the DOJ bulk sensitive data rule and licensed training data.
Least-privilege annotation: what the environment should enforce
A secure annotation environment shows annotators the minimum each task needs and makes copying the rest difficult and visible. Contracts set the rules, but tooling is what prevents a contractor from screenshotting a chart note or exporting a CSV. Design the access model before choosing the vendor, using the options in access models for licensed training data.
Controls that matter in practice:
- Data stays in your tenant. Annotators work in a buyer-controlled workspace or virtual desktop; storage buckets have no vendor-side credentials. Shares that are read-only and do not copy data, such as Snowflake Secure Data Sharing [9], suit tabular review tasks.
- Masked or surrogate views by default. Pre-redact with a detector such as Presidio, which itself warns it cannot guarantee finding all sensitive data [10]. Show surrogates for names and account numbers, and reveal raw spans only to a small, named reviewer group. The choice of masking vs surrogate replacement also changes what the labels mean.
- No export paths. Disable downloads, clipboard and printing in the VDI; turn off bulk export APIs in the labeling tool; watermark the screen with the annotator ID.
- Named accounts and task scoping. SSO with MFA, no shared logins, and queue-level permissions so an annotator sees only assigned items.
- Logging you can read. Per-item view logs, session recording for sensitive queues, and alerts on unusual view volume.
- Media-specific redaction. Faces, screens and audio need their own handling; see PII in screen recordings and agent trajectories.
Vendor access schedule: a template to attach to the labeling SOW
A short access schedule attached to the statement of work turns these decisions into enforceable terms. Adapt the rows to your data classes and have counsel and security sign off.
Illustrative example: invented to show structure; it does not describe an available dataset.
| Data class in the queue | Required contract | Who may view | Allowed location | Tooling controls | Retention after task |
|---|---|---|---|---|---|
| PHI (raw clinical notes) | BAA or subcontractor BAA [2] | Named, background-checked reviewers only | US only; no covered persons [7] | Buyer VDI, no clipboard or export, session recording | Purge from vendor systems at task close; certificate of destruction |
| Safe Harbor de-identified notes | NDA plus license flow-down | Trained annotator pool | Per license and transfer review | Buyer tool, export off, view logs | None held by vendor |
| EU customer support tickets | Article 28 DPA [6] plus transfer clauses | Assigned queue only | EEA, or third country with SCCs and TIA | Surrogate names, masked emails and IBANs | Return or delete per DPA |
| Finance records with account numbers | NDA, license flow-down, security addendum | Assigned queue only | Per license | Account numbers tokenized before load | None held by vendor |
Pair the schedule with three standing questions at each quarterly review: who joined or left the annotator pool, which items were viewed in raw form and why, and whether the vendor changed subcontractors or locations.
Before the first batch: a pre-flight checklist
Run this check once per vendor and again whenever the data class, location or tooling changes.
- License clause permitting contractor disclosure located and cited in the ticket.
- BAA, DPA or NDA executed, with subcontractor flow-down and no vendor right to train on your data.
- De-identification or masking method recorded, with a sample checked for residual identifiers (see the de-identification evidence package).
- Annotator locations and employer of record listed; DOJ rule thresholds checked.
- Workspace tested: export, clipboard, print and bulk API all blocked.
- Logging on, retained, and someone named to review it.
- Incident path agreed, including what happens if an annotator spots unredacted data; the response playbook for personal data in a licensed dataset applies.
How data sourced through SourceX arrives before labeling
SourceX removes or replaces personal details such as names, emails, phone numbers and account numbers before delivery, records the method used and checks a sample, and no method is perfect. Health records require HIPAA de-identification by Safe Harbor or Expert Determination. Each dataset is rights-reviewed for ownership and consents and delivered under a license that defines the records, uses, term and delivery, so your contractor terms can be checked against it. You can describe the data you need through SourceX buyer intake and ask how the license treats contractors.
Delivery runs through private, access-controlled workflows, never email attachments, and only after an executed agreement and supplier approval. More on that is in how SourceX handles data security. Your own vendor controls still govern what happens after delivery.
Get sensitive data labeled under conditions you can defend
SourceX sources operational datasets from US companies and manages the licensing process, with personal details removed or replaced before delivery and every release approved by the supplying company. Data is sourced on request, so describe the records you need and the labeling you plan at SourceX for buyers.
For the wider privacy picture, start at the privacy and de-identification hub or the AI data guides.
Frequently asked questions
Does a labeling vendor that only sees de-identified data need a BAA?
Not for that data, according to HHS guidance on service providers holding only de-identified information [3]. The de-identification has to meet 45 CFR 164.514(b) [5]. If any queue contains PHI, a BAA is needed for that work.
Can annotators outside the US view US health or financial data?
HIPAA does not bar it, but your license, BAA and security analysis may, and the DOJ rule restricts access by countries of concern and covered persons to bulk sensitive data [7]. Confirm both the location and the identity of the annotator workforce.
Can the vendor use our corrections to improve its pre-labeling model?
Only if your license and contract allow it. Under the GDPR that use would make the vendor a controller for that processing [6], and many data licenses limit use to your internal purposes [8].
Sources
- Accountable, "HIPAA and Machine Learning: What You Need to Know to Build Compliant Healthcare AI". https://www.accountablehq.com/post/hipaa-and-machine-learning-what-you-need-to-know-to-build-compliant-healthcare-ai
- U.S. Department of Health and Human Services, "Business Associate Contracts (Sample Business Associate Agreement Provisions)". https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html
- U.S. Department of Health and Human Services, "If a CSP receives and maintains only information that has been de-identified in accordance with the HIPAA Privacy Rule, is it a business associate?". https://www.hhs.gov/hipaa/for-professionals/faq/2085/if-a-csp-receives-and-maintains-only-information-that-has-been-de-identified-in-accordance-with-the-hipaa-privacy-rule-is-it-is-a-business-associate/index.html
- U.S. Department of Health and Human Services, Office for Civil Rights, "Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule" (2012). https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification
- Electronic Code of Federal Regulations, "45 CFR 164.514 - Other requirements relating to uses and disclosures of protected health information". https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.514
- gdpr-text.com, "Article 28 GDPR: Processor". https://gdpr-text.com/en/read/article-28/
- U.S. Department of Justice, National Security Division, "Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons (Final Rule, NSD 104)" (2024). https://www.justice.gov/d9/2024-12/NSD%20104%20-%20Data%20Security%20-%201124-AA01%20-%20Final%20Rule_0.pdf
- Law Insider, "Data License Sample Clauses". https://www.lawinsider.com/clause/data-license
- Snowflake Inc., "About Secure Data Sharing". https://docs.snowflake.com/en/user-guide/data-sharing-intro.html
- Data Privacy Stack (GitHub Pages), "Presidio - Data Protection API". https://data-privacy-stack.github.io/presidio
- Washington State Legislature, "Chapter 19.373 RCW - Washington My Health My Data Act". https://app.leg.wa.gov/RCW/default.aspx?cite=19.373&full=true
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.