Skip to content

Privacy and preparation

Data protection assessments before selling data: which states require them

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

A data protection assessment is a written risk review that most comprehensive US state privacy laws, including those of Virginia, Colorado, Connecticut and Texas, require before a business sells personal data. Licensing records that meet the legal definition of de-identified data usually falls outside that trigger, but counsel should record why. If personal data remains, plan for an assessment.

Key takeaways

  • Most comprehensive state privacy laws built on the Virginia model list the sale of personal data among activities that need a documented assessment.
  • An assessment is usually an internal record, but state attorneys general can generally ask to see it during an investigation.
  • Records that meet a state's definition of de-identified data are generally not personal data, so licensing them usually avoids the sale trigger.
  • Pseudonymized fields can pull a package back into personal data and assessment scope; B2B contacts and employee names do so mainly under California's law.
  • Which law applies depends on where the people in the records live and whether your company meets each law's thresholds.

What is a data protection assessment?#

A data protection assessment is a written analysis that weighs the benefits of a specific processing activity against the risks it creates for the people whose data is involved, and records the safeguards that reduce those risks. US state laws use the term for a document the business keeps on file rather than one it submits for approval.

The concept resembles the data protection impact assessment under GDPR, but the triggers differ. GDPR asks for an impact assessment when processing is likely to be high risk. The US state laws instead list categories of processing that need an assessment, and selling personal data is one of the most common entries on that list.

For a company considering a data license, the practical question is narrow: will the package contain personal data, and does the license count as a sale under the laws that apply to you?

Which state laws require an assessment before a sale?#

Most comprehensive state privacy laws modeled on Virginia's include an assessment requirement, and the sale of personal data is a commonly listed trigger. A few laws are generally described as having no assessment requirement, and California has added its own risk assessment rules under the CCPA. By MultiState's count, 20 states had comprehensive privacy laws in effect once the Indiana, Kentucky and Rhode Island laws took effect on January 1, 2026, a figure that includes Florida's narrower law.

Treat the table as a starting map, not a conclusion. Laws are amended, applicability thresholds differ, and the same company can fall under several laws at once because coverage follows the residents in the records, not the company's headquarters.

Which state laws require an assessment before a sale?
LawAssessment for selling personal dataWhat to confirm with counsel
Virginia Consumer Data Protection ActSale is a listed triggerWhether the package holds personal data or de-identified data
Colorado Privacy ActCovered as heightened-risk processingColorado's regulations, which describe assessment contents in more detail
Connecticut Data Privacy ActSale is a listed triggerHow the law treats pseudonymous data in your package
Texas Data Privacy and Security ActSale is a listed triggerWhether your company meets the law's applicability rules
Oregon Consumer Privacy ActCovered as heightened-risk processingWhether employee or B2B records fall in scope
Montana, Indiana, Tennessee, Delaware, Kentucky and Rhode Island lawsGenerally included on the same modelEffective dates, thresholds and any recent amendments
New Jersey, New Hampshire, Nebraska, Maryland and Minnesota lawsGenerally included as sale or heightened-risk processingState-specific assessment content, effective dates and thresholds
Utah and Iowa consumer privacy lawsCommonly described as having no general assessment requirementWhether another state's law also covers the same records
California Consumer Privacy ActNewer risk assessment rules list selling or sharing personal informationReporting obligations to the state privacy agency

When does a data license count as a sale?#

A data license counts as a sale under most state definitions when personal data is made available to another party in exchange for money or other value. Some laws limit a sale to exchanges for money, while others include any valuable consideration. A license fee for records that contain personal data fits either reading.

The exceptions in these definitions rarely help a licensing deal. Transfers to a processor acting on your instructions, transfers in a merger, and disclosures the consumer directs are common carve-outs, but an AI developer licensing records for its own model training is acting for itself, not for you.

That is why the decisive question is usually upstream: whether the records still count as personal data when they leave.

Selling is not the only trigger. Processing sensitive data, such as health details, precise location or information about children, is a separate listed trigger in many of these laws, and several require consent before sensitive data is processed at all. Operational records can carry such details in free text, so the inventory should look for them as well.

Why de-identified licensing usually avoids the trigger#

De-identified data that meets the statutory definition is generally excluded from personal data, so a license of properly de-identified records is usually not a sale of personal data at all. Most of these laws attach conditions to that status, typically reasonable technical measures, a public commitment not to re-identify, and contract terms that bind recipients to the same promise.

The conditions matter for a license. The agreement should bar the recipient from re-identifying anyone or combining the records with other data to do so, and your privacy notice or website may need the public commitment. Without those pieces, a carefully cleaned dataset can still fall short of the legal definition.

Three kinds of residue most often pull a package back into scope. Pseudonymized identifiers where someone keeps the key remain personal data under most of these laws. Named business contacts in CRM exports and employee names in internal threads are covered mainly by California's law, because most other states exclude people acting in a commercial or employment context. Each can be removed during preparation.

What should an assessment cover?#

An assessment for a licensing transaction should describe the processing plainly enough that a regulator could follow the decision without a meeting. Counsel usually drafts it with input from the privacy lead, the system owners and whoever runs preparation.

Even when counsel concludes that no assessment is legally required because the data is de-identified, a shorter memo with the same structure is worth keeping. It records the reasoning at the time of the decision.

  • Purpose and scope: which record families, systems, date ranges and recipients are involved.
  • Data categories: what personal data exists in the source records and what remains after preparation.
  • Context: what the privacy notices said when the records were collected and what people would reasonably expect.
  • Benefits: to the business, to the recipient and, where relevant, to customers or the public.
  • Risks: re-identification, use beyond the license, exposure of sensitive data, and loss of consumer rights.
  • Safeguards: de-identification method, QA results, contract restrictions, access controls and deletion terms.
  • Decision and sign-off: who approved, on what date, and when the assessment will be reviewed.

Illustrative: a regional distributor documents its decision#

Illustrative: a fictional industrial distributor with a decade of history runs orders and returns in Epicor, keeps account notes in Salesforce, and logs delivery exceptions from Samsara-equipped trucks. Its customers are mostly businesses, but some are sole-proprietor contractors whose business name is their own name.

Counsel maps the package against the laws that could apply. Order exceptions and resolution notes carry most of the value. Buyer contact names, contractor names, driver names and delivery addresses carry most of the privacy risk and almost none of the value.

The decision: remove names, emails, phone numbers and street addresses, replace account numbers with tokens that have no retained key, and put a no-re-identification clause in the license. Counsel writes a short memo concluding that the package is de-identified and that the sale trigger does not apply, using the assessment outline so the reasoning can be extended if a later package keeps any identifiers.

How SourceX handles assessment questions#

SourceX does not decide whether an assessment is legally required; the supplier's counsel does. What SourceX contributes is the factual input that decision needs. During the Rights and Preparation steps of the SourceX five-step transaction, the team documents which record families are in scope, which personal details were removed and how, and what remains.

That material forms the privacy record, one of five parts of the SourceX Evidence Packet alongside provenance, licensing rights, permitted use and release authorization. Counsel can lift it directly into an assessment or a no-assessment memo, and the supplier approves the package only after that review.

Frequently asked questions

Do we have to file a data protection assessment with a state?

Generally no. Under most state laws the assessment stays in your files, and the attorney general can request it during an investigation. California's newer CCPA rules add a reporting element to the state privacy agency, so confirm with counsel what applies to your company and when.

Can a GDPR impact assessment double as a state assessment?

Often in part. The structure is similar, but the state laws list specific triggers and some, such as Colorado's regulations, ask for particular content. Counsel can usually adapt an existing GDPR document by adding the state-specific elements rather than starting over.

Do we need a new assessment for every licensing deal?

Not necessarily. Several state laws allow one assessment to cover comparable processing activities. If a later license involves the same record families, the same preparation method and similar contract terms, counsel may extend the existing assessment. New fields, new recipients or retained identifiers usually call for an update.

Who should sign the assessment?

The privacy lead or counsel usually prepares it, and a business owner with authority over the processing signs it. Keep each version with its date, the scope it covered and the evidence it relied on, so a later reviewer can see exactly what was decided.

Do these laws cover business-to-business records?

Mostly not outside California. Virginia's law and the Colorado Privacy Act, for example, generally do not cover people acting in a commercial or employment context, while California's law has covered B2B contacts and employees since January 1, 2023. Map the people in your records first: consumers, customer employees, your own staff and contractors, then check each law's scope with counsel.

Sources

  • Comprehensive consumer privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026, bringing the number of states with such laws in effect to 20 by MultiState's count, which includes Florida's narrower law. Source
  • The Virginia Consumer Data Protection Act generally does not apply to information about a natural person acting in a commercial (B2B) or employment context, with no sunset on this exemption. Source
  • The Colorado Attorney General states that the Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context. Source
  • The CCPA employee and business-to-business exemptions expired on January 1, 2023. Source
  • Post-CPRA, Cal. Civ. Code 1798.140(m) treats information as deidentified only if the business takes reasonable measures, publicly commits not to reidentify it, and contractually obligates recipients to comply. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify