Skip to content

Rights and contracts

Is de-identified data still personal information under state laws?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

De-identified data is generally not personal information under US state privacy laws, but only while it cannot reasonably be linked to a person and its holder meets the attached conditions: reasonable safeguards, a public commitment not to re-identify, and contracts binding recipients. The status attaches to each copy, so source records and pseudonymous working copies remain personal information.

Key takeaways

  • State privacy laws generally exclude de-identified data from personal information, but the exclusion is conditional and has to be maintained.
  • California's definition pairs a linkability test with three duties on the holder: reasonable measures, a public commitment and contracts binding recipients.
  • Status attaches to a copy, not to the records: the source systems stay personal information after a de-identified copy is made.
  • Retained keys, linking by a recipient, identifying free text and unbound contractors can each pull a copy back into scope.
  • The exclusion does not release customer confidentiality duties, and other regimes such as GDPR apply their own tests.

When is de-identified data not personal information?#

De-identified data falls outside personal information under state privacy laws when it meets the law's definition of de-identified at the time it is held and used. Personal information is defined broadly in these laws, usually as information that identifies or is reasonably linkable to a person or household, so the exclusion has to be earned rather than assumed.

California's definition, as amended by the CPRA, is the usual reference point. Information is deidentified only if it cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, and the business holding it takes reasonable measures to prevent association with a consumer or household, publicly commits to keep and use it only in deidentified form and not to re-identify it, and contractually obligates any recipients to comply. Many newer state comprehensive privacy laws use a broadly similar structure, though wording and scope vary.

The practical answer for a privacy lead is conditional: a copy that is properly de-identified and kept that way generally stops being personal information, and the same copy can come back into scope if the conditions lapse. Which state laws may apply depends on where the people in the records live and on the company's size and activities, and counsel assesses that deal by deal.

The conditions that keep a copy outside the definition#

State definitions commonly combine one technical test with organizational commitments. Meeting the technical test alone is usually not enough; the holder also has to behave in a way that keeps the data de-identified.

The conditions that keep a copy outside the definition
ConditionWhat it generally asksWhat a privacy lead should check
Cannot reasonably be linkedNo reasonable way to tie the records, alone or combined with other available data, back to a person or householdDirect identifiers, free-text residue, rare combinations and outside datasets a recipient could join
Reasonable measuresTechnical and organizational safeguards against re-identificationAccess limits, separation of any keys, logging and staff instructions
Public commitmentSay openly that the data is held only in de-identified form and that no one will try to re-identify itWhether the privacy notice says this and matches practice
Contract terms for recipientsRecipients are bound to the same commitmentsA license clause banning re-identification and linking, with flow-down to contractors
Ongoing oversightSome laws or regulators expect the holder to monitor complianceAudit or attestation rights and a process for reported issues

Status follows each copy, not the records#

De-identified status belongs to a particular copy held by a particular party, which is the point most often missed. Producing a clean licensed copy changes nothing about the helpdesk, CRM and email systems it came from, and a working copy that still has a key is pseudonymous, not de-identified.

Mapping each copy and its holder shows where personal information obligations still apply. The table follows support records from the source system to the buyer.

Status follows each copy, not the records
CopyHeld byUsually personal information?What keeps or changes the status
Source tickets and chats in Zendesk or IntercomSupplierYes, wherever they hold personal detailsNothing about licensing changes the originals
Working copy with a token key during preparationSupplierUsually yes, as pseudonymous dataDestroy the key, or never create one, for the licensed copy
Released licensed copyBuyerGenerally no, while conditions holdNo re-identification and no linking terms, flow-down and a current public commitment
Licensed copy joined to the buyer's other dataBuyerMay become personal information againA contract ban on linking, with notice and deletion if it happens
Copy passed to a buyer contractor or affiliateThird partyDepends on whether the recipient is boundFlow-down terms that name contractors and affiliates
Counts and statistics derived from the copyBuyer or supplierGenerally no, unless groups are very smallMinimum group sizes before anything is reported

What turns de-identified data back into personal information?#

De-identified data turns back into personal information when it becomes reasonably linkable again or when the holder stops meeting the conditions. Most of the triggers are ordinary operational events rather than deliberate misuse, and the risk is not theoretical: NIST's 2015 report on de-identifying personal information notes that researchers have shown some de-identified data can be re-identified.

Each trigger has a matching control. Destroying the key for the licensed copy, scanning and sampling free text, suppressing rare combinations, binding every recipient by contract and keeping the public statement current cover most of them. The supplier handles the first three before delivery; the last two depend on the license and on the supplier's own privacy notice.

  • A recipient links the records with its own data, a purchased dataset or public sources.
  • The supplier keeps a crosswalk or token table that can restore identities in the licensed copy.
  • Free text still holds signatures, street addresses, phone numbers or unusual job details that point to one person.
  • Rare events or very small groups make a single person stand out, even without names.
  • Records pass to a contractor or affiliate that never agreed to the no re-identification terms.
  • The public commitment is missing, out of date or contradicted by how the data is actually used.

What the exclusion removes, and what it leaves in place#

The de-identified exclusion removes a copy from state privacy rules aimed at personal information, but it leaves other duties untouched. Customer contracts, confidentiality promises and security commitments still apply to the content, because de-identification is a privacy concept, not a release from what the company agreed with its customers.

Other regimes also apply their own tests. GDPR, for example, treats pseudonymised data that could be attributed to a person by using additional information as information on an identifiable person, so records about people in the European Union are assessed separately from any US state analysis.

What the exclusion removes, and what it leaves in place
ObligationIdentified or pseudonymous copyDe-identified copy
Requests to access, correct or deleteGenerally apply, subject to each law's exceptionsGenerally do not reach a copy that cannot be linked to the person
Opt-outs of sale or sharingMay apply to a disclosure to a buyerGenerally not engaged while the copy stays de-identified
Privacy noticeAppliesStill needs the public commitment not to re-identify
SafeguardsSecurity duties applyReasonable measures against re-identification are part of the definition
Customer contracts and confidentialityApplyStill apply in full
GDPR, sector laws and data broker rulesTheir own definitionsTheir own definitions; the state exclusion does not carry over

Illustrative: a fictional field service management software company licensed a de-identified copy of its own help desk conversations with customers' office staff. Names, emails and phone numbers were removed, the free text was scanned and sampled, no token key was kept, and the license bans re-identification and linking.

A year into the license, the buyer asks to join the copy with a purchased firmographic dataset so each conversation carries company size and region. The privacy lead concludes that a record-level join could single out small customers and their staff, pulling the copy back toward personal information, so the request is declined as framed.

Instead, the supplier adds broad size and region bands itself before the next refresh, with minimum group sizes. While checking its own side, the team also finds an old working export that still pairs tokens with customer emails on a shared drive, deletes it and notes the deletion in the de-identification record.

How SourceX approaches de-identified status#

SourceX treats de-identified status as something to document, not assert. Preparation, the third stage of the SourceX five-step transaction, is where personal and confidential details come out of the records while they are still under the supplier's control, and the supplier approves both the method and the result.

The privacy record in the SourceX Evidence Packet lists the method, the sample review findings, whether any key exists and the recipient's commitment not to re-identify or link. That is the file a privacy lead reaches for if a regulator, customer or buyer later asks why the licensed copy is treated as de-identified.

Frequently asked questions

Do our original records stop being personal information once we make a de-identified copy?

No. The source records in your helpdesk, CRM and email systems remain personal information, with every obligation that already applied to them. De-identification describes the separate copy that meets the definition, so both the originals and any keyed working copies keep their existing status.

If a customer asks us to delete their data, does the buyer's de-identified copy have to go?

Generally, deletion rights attach to personal information, and a copy that genuinely cannot be linked to the person falls outside that definition. That is also why the copy must stay unlinkable: if it could be tied back to the requester, the request may reach it. Confirm the approach with counsel and record it.

Is de-identified data exempt from GDPR as well?

GDPR uses a different concept. Data that is truly anonymous falls outside GDPR, but pseudonymised data that can be attributed to a person with additional information is still treated as relating to an identifiable person. If records include people in the European Union, counsel should assess them under GDPR separately.

Who has to keep the data de-identified, the supplier or the buyer?

Both, for their own copies. The supplier shows the records met the standard when released and keeps its own commitments. The buyer has to hold and use its copy in a way that keeps it de-identified, which is why the license binds it, and its contractors, to no re-identification and no linking.

Can a buyer re-identify data to test our de-identification?

Only if the contract expressly allows it, and most suppliers prefer it does not. A buyer that wants to test re-identification risk can agree a defined test with the supplier, run by a named team, with results shared and no identities retained. Otherwise the general ban on re-identification should apply.

Sources

  • Under Cal. Civ. Code 1798.140(m), as amended by the CPRA, information is deidentified only if it cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, and the business takes reasonable measures, publicly commits not to reidentify it, and contractually obligates recipients to comply. Source
  • GDPR Recital 26 states that personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information, should be considered to be information on an identifiable natural person. Source
  • NIST Interagency Report 8053, De-Identification of Personal Information (October 2015), notes that researchers have shown some de-identified data can be re-identified. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify