Rights and contracts
Is de-identified data still personal information under state laws?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
De-identified data is generally not personal information under US state privacy laws, but only while it cannot reasonably be linked to a person and its holder meets the attached conditions: reasonable safeguards, a public commitment not to re-identify, and contracts binding recipients. The status attaches to each copy, so source records and pseudonymous working copies remain personal information.
Key takeaways
- State privacy laws generally exclude de-identified data from personal information, but the exclusion is conditional and has to be maintained.
- California's definition pairs a linkability test with three duties on the holder: reasonable measures, a public commitment and contracts binding recipients.
- Status attaches to a copy, not to the records: the source systems stay personal information after a de-identified copy is made.
- Retained keys, linking by a recipient, identifying free text and unbound contractors can each pull a copy back into scope.
- The exclusion does not release customer confidentiality duties, and other regimes such as GDPR apply their own tests.
When is de-identified data not personal information?#
De-identified data falls outside personal information under state privacy laws when it meets the law's definition of de-identified at the time it is held and used. Personal information is defined broadly in these laws, usually as information that identifies or is reasonably linkable to a person or household, so the exclusion has to be earned rather than assumed.
California's definition, as amended by the CPRA, is the usual reference point. Information is deidentified only if it cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, and the business holding it takes reasonable measures to prevent association with a consumer or household, publicly commits to keep and use it only in deidentified form and not to re-identify it, and contractually obligates any recipients to comply. Many newer state comprehensive privacy laws use a broadly similar structure, though wording and scope vary.
The practical answer for a privacy lead is conditional: a copy that is properly de-identified and kept that way generally stops being personal information, and the same copy can come back into scope if the conditions lapse. Which state laws may apply depends on where the people in the records live and on the company's size and activities, and counsel assesses that deal by deal.
The conditions that keep a copy outside the definition#
State definitions commonly combine one technical test with organizational commitments. Meeting the technical test alone is usually not enough; the holder also has to behave in a way that keeps the data de-identified.
| Condition | What it generally asks | What a privacy lead should check |
|---|---|---|
| Cannot reasonably be linked | No reasonable way to tie the records, alone or combined with other available data, back to a person or household | Direct identifiers, free-text residue, rare combinations and outside datasets a recipient could join |
| Reasonable measures | Technical and organizational safeguards against re-identification | Access limits, separation of any keys, logging and staff instructions |
| Public commitment | Say openly that the data is held only in de-identified form and that no one will try to re-identify it | Whether the privacy notice says this and matches practice |
| Contract terms for recipients | Recipients are bound to the same commitments | A license clause banning re-identification and linking, with flow-down to contractors |
| Ongoing oversight | Some laws or regulators expect the holder to monitor compliance | Audit or attestation rights and a process for reported issues |
Status follows each copy, not the records#
De-identified status belongs to a particular copy held by a particular party, which is the point most often missed. Producing a clean licensed copy changes nothing about the helpdesk, CRM and email systems it came from, and a working copy that still has a key is pseudonymous, not de-identified.
Mapping each copy and its holder shows where personal information obligations still apply. The table follows support records from the source system to the buyer.
| Copy | Held by | Usually personal information? | What keeps or changes the status |
|---|---|---|---|
| Source tickets and chats in Zendesk or Intercom | Supplier | Yes, wherever they hold personal details | Nothing about licensing changes the originals |
| Working copy with a token key during preparation | Supplier | Usually yes, as pseudonymous data | Destroy the key, or never create one, for the licensed copy |
| Released licensed copy | Buyer | Generally no, while conditions hold | No re-identification and no linking terms, flow-down and a current public commitment |
| Licensed copy joined to the buyer's other data | Buyer | May become personal information again | A contract ban on linking, with notice and deletion if it happens |
| Copy passed to a buyer contractor or affiliate | Third party | Depends on whether the recipient is bound | Flow-down terms that name contractors and affiliates |
| Counts and statistics derived from the copy | Buyer or supplier | Generally no, unless groups are very small | Minimum group sizes before anything is reported |
What turns de-identified data back into personal information?#
De-identified data turns back into personal information when it becomes reasonably linkable again or when the holder stops meeting the conditions. Most of the triggers are ordinary operational events rather than deliberate misuse, and the risk is not theoretical: NIST's 2015 report on de-identifying personal information notes that researchers have shown some de-identified data can be re-identified.
Each trigger has a matching control. Destroying the key for the licensed copy, scanning and sampling free text, suppressing rare combinations, binding every recipient by contract and keeping the public statement current cover most of them. The supplier handles the first three before delivery; the last two depend on the license and on the supplier's own privacy notice.
- A recipient links the records with its own data, a purchased dataset or public sources.
- The supplier keeps a crosswalk or token table that can restore identities in the licensed copy.
- Free text still holds signatures, street addresses, phone numbers or unusual job details that point to one person.
- Rare events or very small groups make a single person stand out, even without names.
- Records pass to a contractor or affiliate that never agreed to the no re-identification terms.
- The public commitment is missing, out of date or contradicted by how the data is actually used.
What the exclusion removes, and what it leaves in place#
The de-identified exclusion removes a copy from state privacy rules aimed at personal information, but it leaves other duties untouched. Customer contracts, confidentiality promises and security commitments still apply to the content, because de-identification is a privacy concept, not a release from what the company agreed with its customers.
Other regimes also apply their own tests. GDPR, for example, treats pseudonymised data that could be attributed to a person by using additional information as information on an identifiable person, so records about people in the European Union are assessed separately from any US state analysis.
| Obligation | Identified or pseudonymous copy | De-identified copy |
|---|---|---|
| Requests to access, correct or delete | Generally apply, subject to each law's exceptions | Generally do not reach a copy that cannot be linked to the person |
| Opt-outs of sale or sharing | May apply to a disclosure to a buyer | Generally not engaged while the copy stays de-identified |
| Privacy notice | Applies | Still needs the public commitment not to re-identify |
| Safeguards | Security duties apply | Reasonable measures against re-identification are part of the definition |
| Customer contracts and confidentiality | Apply | Still apply in full |
| GDPR, sector laws and data broker rules | Their own definitions | Their own definitions; the state exclusion does not carry over |
Illustrative: a buyer asks to link a licensed copy#
Illustrative: a fictional field service management software company licensed a de-identified copy of its own help desk conversations with customers' office staff. Names, emails and phone numbers were removed, the free text was scanned and sampled, no token key was kept, and the license bans re-identification and linking.
A year into the license, the buyer asks to join the copy with a purchased firmographic dataset so each conversation carries company size and region. The privacy lead concludes that a record-level join could single out small customers and their staff, pulling the copy back toward personal information, so the request is declined as framed.
Instead, the supplier adds broad size and region bands itself before the next refresh, with minimum group sizes. While checking its own side, the team also finds an old working export that still pairs tokens with customer emails on a shared drive, deletes it and notes the deletion in the de-identification record.
How SourceX approaches de-identified status#
SourceX treats de-identified status as something to document, not assert. Preparation, the third stage of the SourceX five-step transaction, is where personal and confidential details come out of the records while they are still under the supplier's control, and the supplier approves both the method and the result.
The privacy record in the SourceX Evidence Packet lists the method, the sample review findings, whether any key exists and the recipient's commitment not to re-identify or link. That is the file a privacy lead reaches for if a regulator, customer or buyer later asks why the licensed copy is treated as de-identified.
Frequently asked questions
Do our original records stop being personal information once we make a de-identified copy?
No. The source records in your helpdesk, CRM and email systems remain personal information, with every obligation that already applied to them. De-identification describes the separate copy that meets the definition, so both the originals and any keyed working copies keep their existing status.
If a customer asks us to delete their data, does the buyer's de-identified copy have to go?
Generally, deletion rights attach to personal information, and a copy that genuinely cannot be linked to the person falls outside that definition. That is also why the copy must stay unlinkable: if it could be tied back to the requester, the request may reach it. Confirm the approach with counsel and record it.
Is de-identified data exempt from GDPR as well?
GDPR uses a different concept. Data that is truly anonymous falls outside GDPR, but pseudonymised data that can be attributed to a person with additional information is still treated as relating to an identifiable person. If records include people in the European Union, counsel should assess them under GDPR separately.
Who has to keep the data de-identified, the supplier or the buyer?
Both, for their own copies. The supplier shows the records met the standard when released and keeps its own commitments. The buyer has to hold and use its copy in a way that keeps it de-identified, which is why the license binds it, and its contractors, to no re-identification and no linking.
Can a buyer re-identify data to test our de-identification?
Only if the contract expressly allows it, and most suppliers prefer it does not. A buyer that wants to test re-identification risk can agree a defined test with the supplier, run by a named team, with results shared and no identities retained. Otherwise the general ban on re-identification should apply.
Sources
- Under Cal. Civ. Code 1798.140(m), as amended by the CPRA, information is deidentified only if it cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, and the business takes reasonable measures, publicly commits not to reidentify it, and contractually obligates recipients to comply. Source
- GDPR Recital 26 states that personal data which have undergone pseudonymisation, which could be attributed to a natural person by the use of additional information, should be considered to be information on an identifiable natural person. Source
- NIST Interagency Report 8053, De-Identification of Personal Information (October 2015), notes that researchers have shown some de-identified data can be re-identified. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.