Skip to content

Rights and contracts

Former employees' records: is their consent needed before licensing?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Former employees' consent is generally not needed to license the work records they created, such as tickets, code reviews and project emails, when the records belong to the company, are de-identified before delivery and fall within the policies those employees accepted. Exceptions include personal messages, HR files, recorded calls, separation agreement promises and places where employee privacy laws may apply.

Key takeaways

  • Work records departed staff created on company systems are generally company records, but ownership does not settle the privacy question.
  • IP assignment agreements, acceptable use policies and employee privacy notices are the documents that establish the company's position.
  • Direct messages, personal email, HR, payroll and monitoring records are excluded by default.
  • Stable role tokens replace names so workflows stay readable without identifying anyone.
  • Separation agreements and recorded calls are the most common reasons a specific record family needs a closer decision.

Former employees generally do not need to consent before the company licenses work records they created, because those records were made on company systems in the course of the job. Support tickets they resolved, code they reviewed, Jira issues they closed and project emails they sent sit in company systems under company policies.

Ownership and privacy are separate questions, though. The company may own an email thread, but the thread still carries the employee's name, signature and the occasional personal detail. De-identification is what makes ownership usable in practice, and a few record types carry privacy interests that de-identification alone does not resolve.

What makes departed staff records company records?#

The company's position on departed staff records usually rests on a stack of documents each employee accepted. Pull the versions in force while each group of former staff worked there, since handbooks and policies change over the years and an old version may say less than the current one.

Contractors deserve a separate pass. They were never covered by the employee handbook, and their agreements decide whether their work product and messages belong to the company.

  • Invention and IP assignment agreement: confirms that work product, including code and documents, belongs to the company.
  • Acceptable use and electronic communications policy: states that company systems and messages are company property and may be reviewed.
  • Employee privacy notice: describes how employee information is used, and may need updating for current staff.
  • Employee handbook: often repeats the systems and monitoring language and records acknowledgment.
  • Separation agreements: may contain promises about personal data, references or deletion.

Which former employee records are usually in scope?#

Former employee records fall into three groups: work records that usually stay after de-identification, mixed records that need filtering, and personal or HR records that stay out. The split follows the content of the record, not who created it.

Mixed records are where most of the effort goes. A work mailbox can hold a vendor negotiation, a doctor's appointment reminder and a benefits enrollment thread in the same week, so filters by sender, subject and folder come first and a sampled human review confirms they worked.

Which former employee records are usually in scope?
Record typeUsually in scope?Condition
Support tickets and case notesYesAgent names replaced with role tokens
Code reviews, commits and pull requestsYesUsernames and author email metadata replaced
Issue trackers and project documentsYesNames, signatures and personal asides removed
Public chat channelsUsuallySocial and personal channels excluded
Direct messagesRarelyOften excluded because personal content is mixed in
Work email threadsSometimesPersonal, medical, legal and HR messages filtered out
Recorded calls and meetingsReviewRecording consent and notice checked first
HR, payroll, performance and benefits filesNoExcluded
Badge, location and device monitoring logsNoExcluded

Consent or notice may still matter where a law, a contract or the nature of the record treats the former employee's interest as separate from the company's. These cases should go to counsel before a package that includes departed staff is scoped.

An item on this list does not mean licensing is barred. It means the record family needs a specific decision rather than the default. California is the moving target: its regulator opened preliminary rulemaking on employee and applicant data in April 2026, so check for new rules before scoping records about California staff.

  • Personal communications mixed into work systems, such as family, health or legal matters.
  • Former staff who worked in California, where the CCPA has applied fully to employee and contractor personal information since January 1, 2023, or in the EU or UK, where data protection law covers workers' data.
  • Separation agreements that promised deletion or limited use of the departing employee's information.
  • Collective bargaining or works council agreements that cover monitoring or data use.
  • Recorded calls or meetings where wiretap and recording laws may require consent from every party.
  • Policies that told employees their messages would be used only for a stated purpose.

How de-identification treats departed staff#

De-identification for departed staff replaces names with stable role tokens, such as Support agent A or Reviewer C, so a buyer can follow who handled what without learning who they were. The same person keeps the same token across tickets, reviews and threads, which preserves the workflow.

Metadata needs as much attention as text. Commit author emails, Git usernames, email signatures, out-of-office replies, calendar invites and profile photos all identify people, and they survive in exports long after the employee's account was deactivated.

Writing style and unusual role details can identify someone on a small team. Where one person held a distinctive role, generalize the role label rather than relying on the name swap alone.

Illustrative: a software company after a downsizing#

Illustrative: a fictional vertical software company downsized and retired several product lines. Many engineers and support agents have left, but their GitHub pull requests, Jira issues, Zendesk tickets and Slack messages remain.

The general counsel pulled the IP assignment agreements and acceptable use policies, and outside counsel agreed the work records were company property. Direct messages, social channels and the HR channel were excluded. A handful of separation agreements promised deletion of personal data on request, so the team checked the request log and removed every person who had asked.

The licensed package kept the engineering and support workflow intact, with each person replaced by a stable role token and every signature, username and email address removed.

Should you tell former employees anyway?#

Telling former employees is usually a judgment call rather than a default requirement. Some companies update their employee privacy notice for current staff and rely on de-identification for departed staff; others send a short notice to alumni to avoid surprises.

Reputation tends to decide it. In a small industry where former staff stay in touch, a clear explanation of what was licensed and how people were removed lands better than a rumor.

A useful notice is short and specific. It names the record types involved, such as tickets and code reviews, says that names, contact details and personal messages were removed before anything left the company, and gives a contact for questions. Vague notices tend to create more concern than they resolve.

How SourceX treats former employee records#

SourceX reviews employee-created records in the Rights step of the SourceX five-step transaction, which runs Supply, Rights, Preparation, Approval and Delivery, checking the policies and agreements that cover former staff. Preparation removes names, contact details and personal content and applies role tokens.

The privacy record in the SourceX Evidence Packet documents which channels and record types were excluded and how people were de-identified, so the company can answer a former employee's question with specifics.

Frequently asked questions

What if a former employee asks us to delete their data?

Check whether a law that may apply gives them a deletion right, what their separation agreement promised and what retention duties you have. If you honor the request, remove their records from future packages and note the removal in the privacy record.

Are contractors treated differently from employees?

Often, yes. A contractor's work belongs to the company only if the agreement assigns it, and some contracts grant only a license. Check each agreement before including records contractors authored, especially code and design documents. Agency staff add a third layer, because the agency's own contract with you may decide who owns what they produced.

Can a former employee claim ownership of code they wrote?

Usually not for work done within the job. US copyright law treats work an employee prepares within the scope of employment as a work made for hire owned by the employer, and IP assignment agreements usually reinforce that. Disputes do arise over side projects, pre-existing code and off-hours work, so exclude anything whose origin is unclear, especially repositories that began as someone's personal project.

Do we need to tell current employees before licensing?

Many companies update the employee privacy notice and acceptable use policy so current staff know work records may be licensed after de-identification. Whether notice is legally required depends on where employees work, so counsel should settle the wording.

Does a departed employee's personal email address on old threads matter?

Yes, as personal data to remove. Personal addresses show up in forwarded messages, cc lines and signatures. They come out with other contact details during preparation, along with any thread that was mainly personal.

Sources

  • The CCPA employee and business-to-business exemptions expired on January 1, 2023, so employee, applicant and contractor data held by covered businesses is fully within the CCPA. Source
  • The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 focused on how the CCPA applies to personal information of employees, job applicants and independent contractors. Source
  • Copyright Office Circular 30 explains that a work made for hire arises when an employee creates the work as part of regular duties, and the employer is then considered the author and copyright owner. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify