Privacy and preparation
Excluding customers who opted out of sale or sharing
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Customers who opted out of the sale or sharing of their personal information are best excluded from a licensed dataset, even when the records are years old. Gather opt-outs from every channel, including web forms and Global Privacy Control signals, match them to the archive, exclude matched records before de-identification, and document what could not be matched.
Key takeaways
- An opt-out of sale or sharing is a different request from deletion or a marketing unsubscribe, and each needs its own written rule in a licensing project.
- Opt-outs live in web forms, consent tools, CRM fields and privacy inboxes, so no single system holds the full list.
- A Global Privacy Control signal can be matched to a person only when the visitor was signed in or otherwise identified.
- Exclusion must run before de-identification, because matching is impossible once names and emails are gone.
- Log opt-outs you could not match instead of guessing identity from IP addresses or device data.
Why an old opt-out still applies to a license#
An old opt-out of sale or sharing may still apply to a license, because licensing identifiable records to another company for a fee is the kind of disclosure many state privacy laws may treat as a sale. Whether a de-identified package counts as a sale is a question counsel answers deal by deal, and the answer can differ by state.
Most licensing projects adopt a simpler operating rule: a customer who opted out does not appear in any licensed package, identifiable or not. The rule rarely changes what a package can show, since workflows, decisions and outcomes remain, and it removes an argument nobody wants to have with a customer who later learns about the license.
The rule also avoids a timing trap. A person who opted out after their records were created still expects the preference to govern disclosures made from then on, and a license signed today is a disclosure made today.
Opt-out, deletion and unsubscribe are different requests#
Opt-outs, deletion requests and unsubscribes ask for different things, and mixing them leads either to over-removal or to gaps. A shared table helps support, marketing and privacy teams agree on what each one means for the licensed package.
Write down which treatment your company follows for each row before the work starts. Changing a rule halfway through a project means re-running matching across everything already prepared.
| Request | What the person asked | Treatment in a licensed package |
|---|---|---|
| Opt-out of sale or sharing | Do not disclose my information to others for value or for cross-context advertising | Exclude the person's records from every package |
| Deletion request | Remove my information | Exclude, and run the deletion process as well |
| Limit use of sensitive information (a California right) | Use sensitive details only for the service I asked for | Strip sensitive fields, or exclude the record if they cannot be separated |
| Marketing unsubscribe | Stop sending me marketing email | Not an opt-out of sale by itself; follow a written policy |
| Do not call or do not contact | Stop contacting me | No effect on licensing unless your policy says otherwise |
Where opt-out records live#
Opt-out records live wherever the company accepted them, which is usually several places. A business that added a do not sell or share link to its website may have taken requests by form, email, phone and through a consent tool, each with its own export.
Global Privacy Control deserves its own note. A number of state privacy laws, California's among them, expect businesses to treat a browser opt-out preference signal such as Global Privacy Control as a valid opt-out. The signal comes from a browser, not from a named person, so it can be tied to a customer only when the visitor was signed in, submitted a form in that session or was otherwise identified. Record the signals you could match, and say plainly in the privacy record that anonymous signals could not be linked to archive records.
- Form submissions behind the do not sell or share link, often routed to a shared inbox.
- Consent or cookie management platform logs, including any record of opt-out preference signals.
- Global Privacy Control signals your site recorded, with the account or session each was tied to.
- CRM and marketing automation fields set when a contact opted out.
- Privacy inbox emails, phone requests logged by support and requests made by authorized agents.
- Opt-out records from acquired brands or retired websites.
Matching opt-outs to historical records#
Matching opt-outs to historical records follows the same discipline as any suppression step: strongest identifiers first, human review for weak matches and a written rule for edge cases. The edge cases are where opt-out matching differs from deletion matching.
Business contacts need a deliberate rule. California's temporary exemptions for employee and business contact data expired on January 1, 2023, so a purchasing manager in California who opted out deserves the same treatment as a household customer. Most other comprehensive state laws, such as Virginia's and Colorado's, generally leave out people acting in a commercial or employment role, but excluding every contact who opted out is simpler than sorting them by state, and it costs a licensed package very little.
| Situation | Suggested treatment |
|---|---|
| Customer opted out after the records were created | Exclude; the preference governs disclosures made now |
| One member of a household opted out | Exclude records tied to that person, and ask counsel about shared household accounts |
| A business contact opted out for themselves | Exclude that contact's records and redact mentions in colleagues' records |
| The customer later withdrew the opt-out | Follow the latest documented preference and keep the evidence |
| Opt-out came from an anonymous browser signal | Record as unmatched; never guess at identity |
Put exclusion before de-identification#
Exclusion has to run before de-identification because de-identification removes the identifiers used to match. Once names, emails and account numbers are replaced with placeholders, there is no reliable way to find an opted-out customer's records in the prepared package.
A sound sequence is to freeze the archive extract, apply deletion and opt-out suppression, review the exclusions, then de-identify what remains. Keep the suppression lists outside the package and outside the buyer's reach, with access limited to the privacy team.
Re-run the exclusion before each delivery of a multi-part package. Opt-outs keep arriving, and the privacy record should show that the latest list was applied to every release, not only the first.
Illustrative: an HVAC contractor with a customer portal#
Illustrative: a fictional HVAC and plumbing contractor runs its jobs in ServiceTitan and takes online bookings through a customer portal. It plans to license several years of service records, including technician notes, estimates and callbacks, after de-identification.
The privacy lead pulls opt-out form submissions from a shared inbox, opt-out flags from the marketing platform and the consent tool's log of Global Privacy Control signals. Signals from signed-in portal users are matched to customer accounts; anonymous signals are logged as unmatched.
Every job, estimate and invoice tied to a matched household is excluded before the de-identification pass. The owner approves the rule, the privacy record lists each source and the unmatched signals, and the step is scheduled to run again before the second delivery.
How SourceX handles opt-outs#
SourceX applies opt-out exclusions during Preparation in the SourceX five-step transaction, after Rights confirms what the company may license and before the supplier's Approval. The supplier sets the exclusion rules and approves the result.
Each run is documented in the privacy record of the SourceX Evidence Packet, so buyer and supplier see the same account of which opt-out sources were applied. Whether a particular state's opt-out rules reach a given package is a question for the supplier's counsel.
Frequently asked questions
Does Global Privacy Control apply to records collected before the signal was sent?
Counsel will read the applicable law, but the practical approach is to treat a matched signal as the customer's current preference for any disclosure made after it was received. A license signed after the signal is such a disclosure, so excluding the customer's older records is the safer reading.
What if we cannot match an opt-out to any record?
Log it as unmatched with the reason, such as an anonymous browser signal or an email address that appears nowhere in the archive. Do not try to infer identity from IP addresses or device data, which creates new processing of personal data. The privacy record should describe the unmatched sources plainly.
Does de-identification make opt-outs irrelevant?
Legally it may change the analysis, since de-identified data often falls outside the definition of personal data. Practically, many companies exclude opted-out customers anyway, because the exclusion is cheap, easy to explain and removes doubt about whether the de-identification would hold up under scrutiny.
Should we update our privacy notice before licensing?
Possibly. Whether a notice must mention licensing depends on what you license, whether it is de-identified and which laws apply. Review the notice with counsel during the rights review, before any package is prepared, so the notice and the exclusions tell the same story.
Do employees count as customers who can opt out?
Employees are usually handled through employment notices rather than consumer opt-out channels, and most state consumer privacy laws exclude people acting in an employment role. California is the main exception, since its employee data exemption expired in 2023, so review California employee records with counsel before including them in any package.
Sources
- The California legislature did not extend the CCPA employee and business-to-business exemptions, so they expired on January 1, 2023. Source
- The Virginia Consumer Data Protection Act generally does not apply to information about a person acting in a commercial (B2B) or employment context, with no sunset on this exemption. Source
- The Colorado Privacy Act covers residents acting in an individual or household context and does not cover people acting in a commercial or employment context. Source
Related resources
- IndustryHealthcare data
- QuestionDo AI companies buy private business data?
- QuestionDo AI labs buy legal documents?
- InsightHow do I de-identify contracts and legal documents for AI training?
- InsightHow do I de-identify internal documentation for AI training?
- InsightHow do I de-identify knowledge base articles for AI training?
See if your company qualifies
A short company assessment. No data uploads are needed.