Privacy and preparation
FTC algorithmic disgorgement: what it means for data you license
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Algorithmic disgorgement is a remedy in which the FTC requires a company to delete not only improperly obtained data but also the models and algorithms built with it. For a company licensing data, the lesson is practical: buyers will ask for provenance and privacy warranties, and documented rights, notices and preparation records are what let you give them accurately.
Key takeaways
- The FTC has used consent orders to require deletion of models and algorithms built from data it alleged was improperly collected or used.
- A model developer's disgorgement risk flows upstream to suppliers through warranties, indemnities and cooperation clauses.
- The records that protect a supplier are ordinary ones: dated privacy notices, contract terms, consent records and a log of how data was prepared.
- Excluding records whose collection history cannot be documented is usually safer than warranting them.
What is algorithmic disgorgement?#
Algorithmic disgorgement is an FTC remedy that requires a company to delete models, algorithms or other work products built from data the agency alleges was collected or used unlawfully, in addition to deleting the data itself. The FTC has included this kind of requirement in several consent orders in recent years, typically where it alleged that data was gathered deceptively or without a consent the law required.
The logic is that deleting raw data achieves little if the value extracted from it survives in a trained model. Ordering the model deleted removes that benefit. For an AI developer that can mean losing a product, not just a dataset, which is why the remedy draws attention well beyond the companies directly involved.
How the FTC applies the remedy depends on the facts of each matter and on the agency's authority under the statutes involved. Counsel should assess how it bears on any specific license.
Why disgorgement matters to a company that licenses data#
Disgorgement matters to a data supplier because a buyer's model risk depends on the history of every dataset it trained on. If licensed records turn out to have been collected in a way that contradicted the supplier's privacy notice, or included personal data the supplier had no right to share, the buyer may need to remove that data and possibly retrain or retire a model.
Buyers respond by moving the risk upstream. Training data licenses commonly include provenance warranties, privacy compliance representations, cooperation obligations if a regulator asks questions, and indemnities. A supplier that cannot show where its records came from either cannot give those promises or gives them blind.
The supplier carries its own exposure as well. Licensing personal information in a way that breaks earlier promises to customers or employees can create direct regulatory risk, separate from anything that happens to the buyer's model.
What data problems lead to deletion orders?#
Deletion orders generally follow data practices a regulator considers unfair or deceptive. For an operating company the useful translation is a list of collection and use patterns to look for before licensing anything.
- Data used for a purpose the privacy notice did not disclose, or contradicted.
- Recordings, images or biometric data captured without the notice or consent a law required.
- Data about children or other groups that carry heightened consent rules.
- Data kept after the company said it would delete it, or after a person asked for deletion.
- Customer data held as a service provider under contract terms that limit the provider's own use.
- Data obtained from a third party whose own right to share it is unclear.
What provenance warranties do buyers ask for?#
Provenance warranties ask the supplier to confirm, in the license, where records came from and that sharing them for the stated use is permitted. Buyers ask because their own regulators, customers and investors increasingly put the same questions to them.
Industry standards point the same way. The Use group of the Data & Trust Alliance's Data Provenance Standards includes elements for consent documentation location, privacy-enhancing technologies applied, license to use and intended data use, which reads much like the checklist a careful buyer works through. Researchers behind the Data Provenance Initiative have also audited sources, licenses and creators across large collections of fine-tuning datasets, which has made licensing history a mainstream question in AI development.
| Buyer request | What it covers | Supplier records that support it |
|---|---|---|
| Provenance warranty | Records were generated or lawfully obtained by the supplier | System inventory, export logs, acquisition documents |
| Rights warranty | The supplier may license the records for the stated use | Customer contracts, vendor terms, IP assignments |
| Privacy compliance representation | Collection and sharing were consistent with applicable law and notices | Dated privacy notices, employee notices, consent records |
| De-identification statement | Personal details were removed to an agreed standard | Method description, tool settings, review results |
| Cooperation clause | The supplier helps answer a regulator or remove records | Record-level identifiers that let specific items be traced |
| Indemnity | The supplier covers losses from a breached warranty | All of the above, plus an insurance review |
How clean rights and privacy records protect both sides#
Clean rights and privacy records protect both sides because they let the supplier make accurate promises and let the buyer rely on them. If a question arises later, documented provenance narrows the problem to specific records instead of the whole dataset.
The useful records are rarely new documents. They are the versions of privacy notices with the dates each was in force, the customer contract templates used in each period, employee notice and handbook language, consent logs, and a description of how personal details were removed. Keeping record-level identifiers in the delivery manifest lets a buyer find and remove specific items rather than discarding everything.
Excluding records is often cheaper than defending them. Where a period of call recordings, a system inherited in an acquisition or a customer segment with restrictive contracts cannot be documented, leaving it out keeps the warranty honest.
Contract terms worth negotiating#
Contract terms on provenance and removal are negotiable, and a supplier can reasonably ask that its promises match what its records can show. The right position depends on the deal and should be set with counsel.
| Term | Supplier concern | Common approach |
|---|---|---|
| Scope of warranties | Promising facts no one can verify | Limit to the supplier's knowledge after a reasonable review |
| Definition of de-identified | The standard shifts after delivery | Define the method and standard in the license itself |
| Indemnity | Open-ended exposure for model-level losses | Cap it and tie it to breach of specific warranties |
| Removal requests | Obligations with no end point | A defined process for removing identified records, with costs allocated |
| Regulatory cooperation | Unlimited time and document demands | Reasonable cooperation with notice and cost terms |
| Permitted use | Records used beyond the agreed purpose | A specific use, no re-identification and no resale |
Illustrative: a home services company narrows its warranties#
Illustrative: a fictional HVAC and plumbing company with a ServiceTitan history of estimates, jobs, invoices and warranty callbacks is asked by a buyer for broad provenance and privacy warranties. The archive also holds call recordings from the company's customer service line.
Counsel finds that the privacy notice and the recorded phone greeting changed partway through the archive: earlier recordings were captured under wording that mentioned quality assurance only. The company excludes all call recordings, keeps job and invoice records with customer details removed, and limits its warranties to the records its notices and contracts support. The license adds a defined process for removing specific records by manifest identifier if a question ever arises.
How SourceX approaches provenance#
SourceX builds the answers to provenance questions into the transaction. The Rights step of the SourceX five-step transaction reviews contracts, notices and vendor terms before Preparation begins, and records that cannot be documented are excluded rather than warranted.
The SourceX Evidence Packet then ties each warranty to a record: provenance, licensing rights, permitted use, the privacy record and release authorization. Delivery manifests keep record-level identifiers, so if a removal request ever arrives, the supplier and buyer can locate the affected items instead of debating the whole dataset.
Frequently asked questions
Can the FTC order a data supplier to delete its own records?
Deletion orders apply to the companies named in an FTC matter. A supplier could be affected directly if its own practices were at issue, or indirectly through license terms that require it to help a buyer remove records. The reach of any order depends on the facts and the agency's authority, which counsel should assess.
Does de-identification remove disgorgement risk?
It reduces it. Records that no longer identify people carry less privacy exposure, but de-identification does not cure every problem, such as data used against a contract term or collected without a required consent. The standard used, and how it was verified, should be documented and agreed in the license.
Are only consumer data deals affected?
Consumer data draws the most attention, but business records hold personal information too: customer contacts, call recordings, employee names and service addresses. Any license that includes personal information, even in de-identified form, benefits from the same provenance and notice review.
Should we check insurance before giving warranties?
It is worth doing. Coverage for contractual indemnities under cyber and technology errors and omissions policies varies, and some policies exclude liabilities assumed by contract. Ask your broker how existing policies treat data licensing before signing, not after a claim.
How long should provenance records be kept?
At least as long as the license and any survival period for warranties and indemnities, and longer if a dispute or regulatory inquiry is possible. Agree the period with counsel and record it in your retention schedule so the records are not deleted in a routine cleanup.
Sources
- The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
- The Data Provenance Initiative, a multi-disciplinary volunteer effort, released a first audit covering 44 data collections that span more than 1,800 fine-tuning text-to-text datasets. The audit documents their sources, licenses, creators and other metadata, and the initiative's tools generate a 'Data Provenance Card' for any filtered subset. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.