Skip to content

Getting started

Can you license records collected before current privacy laws took effect?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Records collected before a privacy law took effect are generally not exempt from it when you license them, because most privacy laws regulate current processing and disclosure, not the collection date. Licensing is a new use that happens today, so treat old archives under current law: check old notices, honor past requests, and remove personal details first.

Key takeaways

  • Privacy laws generally attach to what you do with personal information now, so an archive's age is rarely a defense.
  • Licensing is usually a new purpose and a disclosure, which old privacy notices almost never anticipated.
  • Past deletion and opt-out requests still bind you inside backups, exports and archives.
  • Removing personal details before delivery is the main lever that makes older archives workable.

Do privacy laws apply to data you collected before they existed?#

Privacy laws generally apply to personal information you hold and use after they take effect, even when you collected it years earlier. Most modern frameworks, including GDPR and the US state laws that followed the CCPA, attach duties to processing, which covers storing, using, disclosing and sharing, not only to the moment of collection.

For licensing, the practical point is timing. The license, the preparation work and the delivery all happen now, and those acts are assessed under whatever laws apply on the day they occur. An archive's age rarely works as a shield.

Some laws phase in obligations or contain transition provisions, and a few rules do draw a line by date. For example, under the CPRA amendments in California, an employee's right to request the specific pieces of personal information an employer holds reaches information generated on or after January 1, 2022. A date line like that limits one specific right; it does not exempt older records from the law as a whole. Whether any such provision helps with a given archive is a question for counsel, assessed deal by deal.

Why licensing counts as a new use of old records#

Licensing counts as a new use because records gathered to run support, sales or operations were not gathered to train AI models. Many privacy frameworks ask whether a new purpose is compatible with the original one, or whether people were told about it, and an old notice almost never mentions model training.

Disclosure is the second issue. Delivering records to a model developer is a disclosure to a third party, and several state laws give consumers rights around the sale or sharing of personal information. How those definitions apply to a particular license is fact-specific.

Business contact data and employee data add their own wrinkles, and they show why an exemption remembered from an earlier review may no longer hold. The Virginia Consumer Data Protection Act generally does not apply to people acting in a commercial (B2B) or employment context. California took a different path: once its temporary exemptions lapsed, it became the first state to apply comprehensive privacy restrictions to employee and B2B information. A CRM archive of business contacts may therefore be outside one state's law and inside another's, so map where the people in the records were located.

What current law means for each kind of historical archive#

Historical archives fall into a few recurring situations, and each one points counsel to different questions. The table is a starting map for that review, not a conclusion about any specific law or archive.

What current law means for each kind of historical archive
Archive situationWhat generally matters nowWhat to check
Support tickets older than your current privacy noticeCurrent law governs the license, not the older notice aloneEvery notice version in force while the records were created
Records of people who later asked for deletion or opted outPast requests still bind youRequest logs, suppression lists and whether the archive honored them
CRM contacts at business customersBusiness contact data may be covered under some state lawsWhich state laws may apply and any exemptions still in effect
Employee email, chat and HR-adjacent recordsEmployee data rules and workplace policies may applyAcceptable-use policies, employee notices and state-specific rules
Records involving people outside the USForeign laws such as GDPR may apply regardless of record ageWhere individuals were located and any cross-border transfer rules
Records from an acquired companyThe acquired company's notices and contracts travel with the dataPurchase agreement terms and the target's privacy notices
Records with personal details removedProperly de-identified data is often treated differentlyThe legal standard used and leftover identifiers in free text

What old notices and consents can and cannot do#

Old privacy notices matter because they show what people were told, but they rarely authorize a use their authors never imagined. Pull every version of your website privacy notice, customer terms and employee policies that covered the archive's date range, and file them with the archive.

A broad clause about improving services or sharing with service providers is usually not a clean basis for licensing records to an outside model developer. Counsel may find that notice language helps for some records and not others, which is one reason scope often narrows to record types where personal information can be removed.

Fresh consent from historical contacts is seldom practical at scale. That pushes most programs toward de-identification and exclusion rather than asking past customers for permission again.

De-identification is usually the deciding lever#

De-identification is usually the deciding lever for older archives, because records stripped of personal details often fall wholly or partly outside privacy obligations. Standards differ by law, and many look at both the technical removal and the controls that stop anyone from re-identifying people later.

Old records are harder to clean than new ones. Free-text fields carry names, phone numbers and addresses typed by agents long ago, signatures sit at the bottom of email threads, and attachments hold scanned forms. Automated detection helps but misses things, so sampling and human review stay part of preparation.

Remove confidential business details too, such as a customer's pricing or a named project, even where privacy law may not require it. Customer contracts often do.

Illustrative: a software company with a pre-notice ticket archive#

Illustrative: a fictional B2B software company held a Zendesk archive reaching back to its founding, long before its current privacy notice and data processing addendum. Its general counsel was asked whether the oldest tickets could be part of a license.

Counsel gathered every notice version, pulled the deletion-request log, and found that the older tickets had never been checked against it. Customer contracts from the early years had broad confidentiality clauses but no data-use language, and some tickets came from users in Europe.

The company excluded tickets from European users, applied past deletion requests to the whole archive, and limited scope to de-identified ticket threads with customer names and product configurations removed. The oldest years stayed in, but only after the same preparation as recent ones.

Questions counsel should answer before licensing an older archive#

Counsel's review of an older archive comes down to a short set of questions about who appears in the records, what those people were told and what the license will do with the records.

  • Which individuals appear in the records: customers, end users, business contacts, employees or third parties?
  • Where were those individuals located, and which state or foreign laws may apply today?
  • Which notices, terms and policies were in force during the archive's date range?
  • Have all past deletion, opt-out and correction requests been applied to the archive?
  • Will personal details be removed before delivery, and to what standard?
  • Do customer contracts or NDAs restrict use of confidential information in the records?
  • What permitted-use, no-re-identification and deletion terms will the license contain?

How SourceX approaches older records#

SourceX handles older archives through the Rights and Preparation steps of the SourceX five-step transaction, applying the same review whatever the records' age. Personal and confidential details are removed during preparation, and the supplier approves the scope before anything is released.

The SourceX Evidence Packet keeps the privacy record alongside provenance, licensing rights, permitted use and release authorization, so the reasoning behind including older records is written down rather than remembered.

Frequently asked questions

Is there a grandfather clause for old data in US privacy laws?

Generally not in the sense of a permanent exemption for data collected earlier. Some laws phase in obligations or include transition provisions, and those deserve a careful read. In most cases, though, what you do with the records today is assessed under the law in force today, so counsel should review the license itself.

Do deletion requests from years ago still apply to an archive?

In most cases, yes. A deletion request covers the person's data wherever you still hold it, including archives and exports made before the request arrived. If the archive was never checked against the request log, do that before any licensing work, and record how it was done.

Does it matter that the records were collected lawfully at the time?

Lawful collection helps but does not settle the question. A record collected properly for customer support can still raise issues if it is later disclosed for a different purpose. Lawful collection is where the analysis starts, not where it ends.

Do we need to notify past customers before licensing old records?

It depends on the laws that may apply, your notices, your contracts and whether personal details are removed first. Where records are properly de-identified, notice may not be required, though some companies update their notices for future records anyway. Decide with counsel, deal by deal.

Are records of former employees treated differently?

They can be. Employee and applicant data may fall under specific state rules, workplace policies and employment agreements. Internal email and chat from former staff also tends to mention customers and colleagues, so it usually needs the same de-identification as customer-facing records.

Sources

  • Under the CPRA amendments, an employee may request the specific pieces of personal information an employer holds about them that were generated on or after January 1, 2022. Source
  • The Virginia Consumer Data Protection Act generally does not apply to information about a natural person acting in a commercial (B2B) or employment context. Source
  • Colorado, Connecticut, Utah and Virginia's comprehensive privacy laws do not apply to employment-context data, making California the first state to apply comprehensive restrictions to employee and B2B information. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify