Leadership and readiness
Does de-identification protect trade secrets?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
No, de-identification does not protect trade secrets. De-identification removes or masks details about people, while trade secrets are business information, such as pricing logic, process settings and source code, that stays intact after names are removed. Before licensing records, run two separate passes: a privacy pass and a confidentiality pass, each with its own reviewer and sign-off.
Key takeaways
- Personal data removal and confidentiality review look for different things and need different reviewers.
- A fully de-identified record can still reveal margins, supplier terms, process parameters or security details.
- Automated PII tools are built to find personal details, not business secrets, and their own documentation says they can miss data.
- For each confidential item, decide to redact, generalize or exclude, and record the decision.
Why de-identification and trade secret protection are different reviews#
De-identification and trade secret protection are different reviews because one targets information about people and the other targets information about the business. A support ticket with every customer name masked can still state the discount floor your sales team is allowed to offer.
In the US, trade secret protection generally depends on two things: the information has value because it is not generally known, and the owner takes reasonable steps to keep it secret. Privacy laws set different tests. The CCPA's definition of deidentified information, for example, pairs technical measures with a public commitment not to re-identify and contractual limits on recipients. Neither test answers the other, and which rules may apply to a given license is assessed deal by deal with counsel.
| Review | What it looks for | Typical reviewer | Typical method |
|---|---|---|---|
| Privacy pass | Names, contact details, account numbers and free-text mentions of people | Privacy lead or trained preparer | Automated detection plus human sampling |
| Confidentiality pass | Pricing, margins, supplier terms, formulas, process settings, code, security details and plans | Owners of each record family, with counsel | Field rules plus reading samples in context |
What confidential information survives personal data removal?#
Confidential business information survives personal data removal because it rarely sits in the fields privacy tools target. It lives in notes, comments, attachments and free text written by staff who assumed the record would never leave the company.
Some of these items are your own secrets; others belong to customers or suppliers who shared them under confidentiality terms. Both kinds need the confidentiality pass, and third-party material usually has to be excluded rather than masked.
- CRM opportunity notes that record discount approvals, walk-away prices or competitor pricing.
- Job costing and estimate records that expose labor rates, markups and margin targets.
- Nonconformance reports and corrective actions that state process parameters, tolerances or supplier defects.
- Engineering tickets and code reviews that contain source code, architecture decisions or unreleased features.
- Proposals and statements of work that reveal bid strategy and staffing models.
- IT and support threads that contain credentials, network details or known security weaknesses.
- Purchasing emails with negotiated supplier terms that are themselves under NDA.
Why automated redaction tools miss business secrets#
Automated redaction tools miss business secrets because they are built to recognize patterns such as names, emails, phone numbers and card numbers, not the meaning of a price floor or a cure temperature. A detector cannot know which numbers in a ticket are commercially sensitive.
Even for personal data, toolmakers are candid about limits. The documentation for Presidio, an open-source toolkit for detecting and anonymizing personal data, warns that because it relies on automated detection there is no guarantee it will find all sensitive information, and that additional systems and protections should be used. That advice applies with more force to business confidentiality, where there is often no pattern to match.
Industry metadata standards also keep the two topics apart. The Data & Trust Alliance's Data Provenance Standards list confidentiality classification and the privacy-enhancing technologies applied as separate elements of a dataset's Use metadata.
Credentials are the one kind of business secret with patterns to match. Open-source secret scanners such as Gitleaks and TruffleHog look for passwords, API keys and tokens in repositories and files, and they belong in any preparation that touches code or IT threads. TruffleHog can also check whether a found secret is live by attempting to log in with it, which needs care. Neither tool will recognize a discount floor or a cure temperature.
How to run a two-pass review#
A two-pass review runs the privacy pass and the confidentiality pass as separate steps with separate sign-offs, on the same defined set of records. Combining them tends to let one reviewer's focus crowd out the other's.
Order matters less than independence. Many teams run the privacy pass first, because it reduces the personal details the confidentiality reviewers see and limits internal exposure.
- Define the package: system, record family, date range and fields.
- Classify each field and free-text area as personal, confidential, third-party confidential or neither.
- Run the privacy pass: automated detection, masking or removal, then human sampling.
- Run the confidentiality pass: record owners read samples in context and flag sensitive content.
- Apply a treatment to every flagged item: redact, generalize or exclude.
- Re-sample the prepared output and record what was found and fixed.
- Collect written sign-off from both reviewers before release.
Redact, generalize or exclude: a decision table#
The right treatment for confidential content depends on whether the record still teaches something useful once the secret is removed. If it does not, exclusion is cleaner than heavy redaction that leaves a record full of gaps.
Document each decision by content type rather than record by record. A rule such as exclude any nonconformance report tied to a customer-owned design is easier to apply consistently and to explain later.
| Content | Usual treatment | Reason |
|---|---|---|
| Specific prices, rates or margins in notes | Generalize or redact the figure | The decision logic can stay useful without the number |
| Process parameters and formulas | Exclude the record or the field | The value of the secret is the parameter itself |
| Source code and credentials | Exclude unless code is the licensed scope; always remove credentials | Secrets inside code are hard to mask reliably |
| Customer-owned designs or deliverables | Exclude | Rights usually belong to the customer |
| Supplier terms under NDA | Exclude | Third-party confidentiality obligations apply |
| Internal strategy and unreleased plans | Redact, or exclude by date range | Sensitivity often fades once plans become public |
Illustrative: a contract manufacturer's quality records#
Illustrative: a fictional contract manufacturer considers licensing nonconformance reports and corrective and preventive actions from its quality system, linked to work orders in its ERP. The privacy pass removes operator names, inspector initials and supplier contact details.
The confidentiality pass, led by the quality manager, finds machine settings and tolerances in root-cause narratives and customer part numbers that identify programs. Settings are generalized where the narrative still makes sense, records tied to customer-owned designs are excluded, and the remaining package describes defect, cause and corrective action without the process recipe. Both reviewers sign off before release.
Contract terms that back up the review#
Contract terms back up the two-pass review by limiting what the licensee may do with anything that slips through. Preparation reduces exposure; the license sets the rules for whatever remains.
Terms counsel commonly look at include a defined permitted use, confidentiality obligations covering the licensed records, a prohibition on attempts to re-identify people or extract specific business facts, limits on onward sharing, security requirements, deletion with certification at the end of the term and a notice process if sensitive content is found. Whether those terms are enforceable and sufficient is a question for counsel in each deal.
How SourceX handles both passes#
SourceX runs the privacy pass and the confidentiality pass as separate checks within Preparation, the third step of the SourceX five-step transaction. Personal details and confidential business details are removed or excluded before the supplier is asked to approve release.
The SourceX Evidence Packet carries the privacy record and the supplier's release authorization for each package, so counsel has a written record of how the package was prepared and who approved it, rather than an assurance that the records were cleaned.
Frequently asked questions
Is de-identified data still confidential information under our customer contracts?
It often can be. Many customer agreements define confidential information by its source or subject, not by whether it names a person. Removing names may not take records outside those definitions, so the rights review should read the confidentiality and data-use clauses for each customer whose records are in scope.
Does licensing confidential records waive trade secret protection?
Licensing under confidentiality terms is a common way businesses share secrets while trying to preserve protection, but outcomes depend on the facts, the contract and how the information is handled. Excluding the most sensitive material and keeping strong terms on the rest narrows the question. Counsel should assess it for each deal.
Can aggregation solve both problems at once?
Aggregation helps with some privacy risks and can hide individual prices, but it often strips out the decision-level detail that makes operational records useful for AI. Aggregated summaries can also reveal secrets, such as average margins by product line. Treat aggregation as one treatment option, not a substitute for the confidentiality pass.
Who should run the confidentiality pass?
The people who own each record family, such as the sales lead for CRM notes, the quality manager for nonconformance reports or the engineering lead for code reviews, with counsel available for third-party obligations. They recognize sensitive content that a privacy reviewer or an outside preparer would read as ordinary text.
Should we tell customers or suppliers whose information is excluded?
Usually there is nothing to tell if their material is excluded and never leaves the company. Where a contract requires notice or consent for any use of their information, the rights review will flag it, and the choice becomes asking for consent or excluding the records.
Sources
- Presidio's documentation warns that because it uses automated detection mechanisms there is no guarantee it will find all sensitive information, so additional systems and protections should be employed. Source
- The Use group of the Data & Trust Alliance Data Provenance Standards includes separate elements for confidentiality classification and privacy-enhancing technologies applied. Source
- Gitleaks is an MIT-licensed tool for detecting secrets such as passwords, API keys and tokens in git repositories, files and stdin. Source
- TruffleHog is an open-source secret scanner that, for each secret it can classify, can log in to confirm whether the secret is live. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.