Skip to content

Rights and contracts

Handling deletion requests after data has been licensed

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

When a deletion request arrives after data has been licensed, first check whether the person's information reached the licensee in identifiable form. Properly de-identified or anonymized records are generally outside deletion rights under laws such as the CCPA and GDPR. For anything still identifiable, a flow-down clause should require the licensee to delete the matching records and confirm it.

Key takeaways

  • The first question is not whether data was licensed but whether the licensed copy still identifies the person.
  • De-identified data is generally outside deletion rights, but pseudonymized data that can be linked back usually remains personal data.
  • A flow-down clause should let the supplier pass deletion requests to the licensee by record ID.
  • Deletion terms often cover training copies rather than trained model weights, so preparation before delivery is the main safeguard.
  • A delivery manifest lets you answer quickly, but it must be protected so it does not become a re-identification key.

Does a deletion request reach data you already licensed?#

A deletion request reaches licensed data only if the licensed copy still contains information that identifies the person. If preparation removed names, contact details and other identifiers to the standard the applicable law sets, the licensed records generally fall outside the request, while the original records in your own systems remain in scope.

Residual identifiable data is where the work sits. Email signatures, employee names in Slack threads, account numbers quoted in free text and photos attached to tickets can survive automated redaction and keep a record personal.

Where identifiable personal information did reach a licensee, privacy law may require you to pass the request on. The CCPA, for example, generally requires a business that sold or shared personal information to notify the third parties that received it to delete it, unless that proves impossible or involves disproportionate effort, and the GDPR asks controllers to tell each recipient about an erasure on similar terms.

Requests can also come from people who were never your customers, such as a vendor's employee named in an email thread or a job applicant mentioned in a Slack channel. Handle them the same way, since the question is still whether the licensed copy identifies them.

When de-identified data is outside deletion rights#

De-identified data is generally outside deletion rights because privacy laws define their scope around information that identifies, or can reasonably be linked to, a person. Laws such as the CCPA treat properly de-identified information as outside personal information when the business takes the measures the law describes, including a public commitment to keep it de-identified and contractual commitments from recipients not to re-identify it.

GDPR draws the line in different words but to similar effect: anonymous data falls outside its scope, while pseudonymized data remains personal data at least for any party able to link it back with additional information. Which laws may apply, and whether a package meets their standard, is a deal-by-deal question for counsel.

When de-identified data is outside deletion rights
State of the licensed copyGenerally within deletion rights?Typical action
Identifiable recordsYesFlow down the request and confirm deletion
Pseudonymized, and the supplier keeps the keyUsually yes, since the data can be linked backFlow down by record ID, or delete the key mapping where counsel advises
Pseudonymized, and no one keeps a keyDepends on re-identification riskCounsel assesses against the applicable standard
De-identified to the applicable standardGenerally noDelete from source systems and document the basis
Aggregated statisticsGenerally noNo action beyond source systems

Write the flow-down clause before delivery#

A flow-down clause is the contract term that lets a supplier pass deletion requests to the licensee. It has to be in the license before delivery, because a licensee has little reason to accept new obligations afterward.

  • The licensee deletes or suppresses identified records within a set period after notice.
  • Records are identified by a delivery record ID, never by personal details.
  • Deletion reaches backups and derived datasets on the licensee's normal backup cycle.
  • The licensee confirms deletion in writing.
  • The duty extends to affiliates and contractors that received the data.
  • The licensee may not try to re-identify anyone in order to process a request.
  • The parties state how trained models are treated instead of leaving it unclear.

How to run a request step by step#

A request after licensing runs through your normal privacy request process, with a few added checks at the end. Keep the order the same every time, so each request leaves the same trail for an auditor or regulator.

  • Verify the requester's identity under your existing process.
  • Find and handle the person's records in source systems such as Zendesk, Salesforce or Slack.
  • Check the delivery manifest to see whether any of those records were in a licensed package.
  • Determine the state of the licensed copy from that package's privacy record.
  • If identifiable data reached the licensee, send a flow-down notice listing the record IDs.
  • Add the person to the suppression list for future packages.
  • Log the outcome and the licensee's confirmation.

What happens to models already trained on the data?#

Models already trained on licensed data are the hardest part of any deletion question. Deleting training copies is straightforward; removing the influence of specific records from trained model weights is generally not practical, and license terms often focus on copies rather than weights.

That gap is the strongest argument for thorough preparation before delivery. If personal details never reach the licensee, a later request has nothing to chase. Some licenses also bar future training runs on records that were the subject of a request, which narrows the gap going forward.

Where a buyer will not accept limits on retraining, ask at least for a commitment to take reasonable steps to block outputs that reproduce a record once the licensee has been notified of a request about it.

Records to keep so you can answer quickly#

The records that make requests manageable are a delivery manifest, a preparation log and a suppression list. Each needs access controls, because the manifest in particular could act as a re-identification key if it links delivered records back to named people.

Set retention for these records in your data retention schedule, so they last as long as the license obligations they support and no longer.

Records to keep so you can answer quickly
RecordWhy it mattersHow to protect it
Delivery manifestLinks delivered record IDs to source record IDsRestricted access, or one-way hashes where counsel advises
Preparation logShows which fields and patterns were removed, and with which toolKept with each package's privacy record
Suppression listKeeps a person's records out of future packagesStored with the privacy request log
Licensee contact and notice methodLets you send flow-down notices quicklyRecorded in the contract file

Illustrative: a home services company receives a request#

Illustrative: a fictional residential HVAC company licensed de-identified job records from Housecall Pro covering diagnoses, parts used and repeat visits. Homeowner names, addresses and phone numbers were removed and technician notes were redacted before delivery.

A former customer asks the company to delete her information. The privacy lead deletes her records from Housecall Pro and the CRM, then checks the manifest and finds her jobs were in the package. The privacy record shows the identifiers were removed, but a spot check finds one technician note that still includes her street name.

The privacy lead sends the licensee a flow-down notice listing that record ID, receives written confirmation of deletion, adds her to the suppression list and tightens the redaction pattern for street names in future packages.

How SourceX approaches deletion obligations#

SourceX treats deletion as a preparation question first. In the SourceX five-step transaction, personal and confidential details come out during Preparation, ahead of Approval and Delivery, and the package's SourceX Evidence Packet documents the methods used in its privacy record.

Flow-down and deletion terms are set in the license, which the supplier approves, so the path for a later request is agreed before any records leave the supplier's systems.

Frequently asked questions

Do we have to tell the person that their data was licensed?

Disclosure duties vary with the laws that may apply and with your privacy notice. Some laws require businesses to describe categories of recipients in privacy notices or access responses, and the answer may differ if the licensed copy was de-identified. Counsel should review how licensing is described in your notice.

Can we refuse a deletion request because the data is under license?

A license with a third party generally does not override an individual's rights under privacy law, and some laws expect you to pass a request on to recipients of identifiable data. The usual approach runs the other way: draft the license so the supplier can meet its obligations, through de-identification before delivery and a flow-down clause for anything that remains identifiable.

Who pays for processing flow-down deletions?

The license should say. A common approach is that each party bears its own costs for occasional requests, with a separate mechanism if volumes become unusual. Leaving the point unstated invites a dispute when the first request arrives.

Do employee deletion requests work the same way?

The steps are similar, but whether employees have deletion rights turns on the laws that may apply, and some employment records must be kept for set periods. Employee names in Slack or email are a frequent residual risk, so review them closely during preparation.

How long should we keep the delivery manifest?

Keep it for as long as license obligations, including deletion and flow-down rights, can still be exercised, and then delete it. Holding it longer adds re-identification risk without any benefit. Record the period in your retention and deletion schedule.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify