Skip to content

Privacy and preparation

Is licensing de-identified data a sale under state privacy laws?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Licensing de-identified data is generally not a sale under state privacy laws, because properly de-identified data is not personal information. Licensing personal information for money or other value generally is a sale under California's definition, even though ownership never changes hands. The answer turns on whether every de-identification condition is met and what else travels with the dataset.

Key takeaways

  • A paid license of personal information generally fits California's definition of a sale, even though ownership never transfers.
  • Properly de-identified data is not personal information, so licensing it is generally not a sale of personal information.
  • Some state laws count only monetary consideration as a sale; California and several other states also count other valuable consideration.
  • Retained keys, leftover contact fields and linkable metadata are the usual reasons a de-identified license slips back toward a sale.

Is a data license a sale if ownership never transfers?#

A data license can be a sale under state privacy laws even though ownership never transfers, because those laws define a sale by what happens to the data rather than by who owns it afterward. California's definition broadly covers selling, renting, releasing, disclosing, making available or otherwise communicating personal information to a third party for monetary or other valuable consideration.

Commercial lawyers distinguish a license from a sale; privacy statutes mostly do not. A paid license that gives a buyer access to personal information generally looks like a sale for privacy purposes, with the duties that come with one.

That is why data licensing for AI usually aims at de-identified records. If the dataset no longer contains personal information, the sale definition, which applies only to personal information, generally does not reach it.

How do state definitions of sale differ?#

State definitions of sale differ mainly on consideration. Some state laws limit a sale to an exchange for monetary consideration, while California and several others also count other valuable consideration, such as services, credits or data given in return.

The definitions also differ in their exceptions, such as disclosures to processors or service providers, transfers to affiliates, and transfers as part of a merger, acquisition or bankruptcy. Check the current text in each state where your company meets the applicability thresholds.

How do state definitions of sale differ?
ArrangementMonetary-only definitionsMonetary or other valuable consideration definitions
Paid license of personal informationGenerally a saleGenerally a sale
Personal information exchanged for tools, credits or reciprocal dataMay fall outside; check the textGenerally a sale
Disclosure to a processor or service provider under a compliant contractGenerally not a saleGenerally not a sale
Transfer as part of a merger or acquisitionOften exceptedOften excepted, with conditions
License of properly de-identified dataNot personal data, so generally not a saleNot personal information, so generally not a sale

What takes de-identified data outside the definition?#

De-identified data falls outside the sale definition when it meets the state's de-identified standard, because sale duties attach only to personal information. In California that standard sits in Cal. Civ. Code section 1798.140(m): the data must not reasonably be linkable to a consumer, and the business must take reasonable measures, publicly commit not to reidentify it and bind recipients by contract. Many other states use a similar structure with different wording.

For the sale question, the useful point is that the license itself is part of the test. A dataset scrubbed thoroughly but licensed without a no-reidentification clause, or by a company with no public commitment, may still be treated as personal information, and then the paid license looks like a sale again. The contract that creates the consideration is also the contract that has to carry the recipient obligations.

Document both the technical work and the commitments before the license is signed. That evidence is what a regulator or the buyer's counsel will ask to see, and it is far easier to assemble during preparation than after a question arrives.

Edge cases that pull a license back toward a sale#

Edge cases that pull a license back toward a sale usually involve something other than the main records traveling with the dataset. Each one can turn a de-identified package into one that still holds personal information.

Each has a fix: destroy or never share keys, strip contact fields, review free text by hand, coarsen or tokenize linkable metadata, send samples only under a sample agreement, and describe every form of consideration in the contract.

  • Pseudonymized identifiers with a key the supplier or buyer can use to reverse them.
  • Business contact details left in email signatures, CRM fields or ticket headers, which California has covered as personal information since its business-to-business exemption expired on January 1, 2023.
  • Free-text remarks that still point to one person, such as a named customer's unusual complaint.
  • Linkable metadata, such as account IDs, device IDs, IP addresses or exact timestamps the buyer could join to other data.
  • Evaluation samples sent before contracts are signed, which can be a disclosure on their own.
  • Bundled consideration, such as model access or credits received in return for the data.

What duties follow if the license is a sale?#

If a license is a sale of personal information, the supplier generally takes on sale duties under each applicable state law. These usually include disclosing the sale in privacy notices, offering and honoring opt-outs, including opt-out preference signals where the law requires them, and contract terms that limit what the buyer may do with the data.

Sensitive data raises the bar further, because some states require opt-in consent before it is processed, and data about minors carries stricter rules. Anyone who has already opted out has to be removed from a licensed set that counts as a sale.

For many operating datasets, those duties make an identifiable license impractical. That is the commercial reason behind de-identification, alongside the legal one.

A decision path for the sale question#

A decision path for the sale question runs through four checks in order, and the first check that ends the analysis usually settles it. Work through the path per dataset and per state, because the answer can differ between a support archive and an order history, or between California and a state with a monetary-only definition.

Record each answer with the evidence behind it. A short memo per dataset, kept with the release record, answers most later questions from buyers, auditors and regulators without reopening the whole analysis.

A decision path for the sale question
CheckIf yesIf no
Does the delivered dataset contain personal information?Go to the next checkGenerally not a sale; keep the de-identification evidence
Is the recipient a service provider or processor under a compliant contract?Generally not a saleGo to the next check
Does the supplier receive money or other value in return?Go to the next checkCheck the state's definition; the arrangement may fall outside it
Does an exception, such as a transfer in a merger, apply?Follow the exception's conditionsTreat the license as a sale and apply sale duties

Illustrative: a roofing contractor tests its license against the sale definition#

Illustrative: a fictional commercial roofing and restoration contractor plans to license several years of job files from its field service and project software: inspection notes, estimates, change orders, photos and the email threads with property managers. The buyer proposes paying partly in fees and partly in credits for its AI tools.

The general counsel works through the edge cases. Property managers' names, phone numbers and signatures are stripped, building addresses are generalized to the metro area, photo location metadata is removed, and photos showing people or vehicle plates are excluded. Building owner names become tokens, and the token key is destroyed after preparation. The privacy policy already carries a no-reidentification commitment, the draft license adds matching recipient terms, and the credits are written into the payment clause so every form of consideration is on the record.

With those steps documented, counsel concludes that the delivered dataset is de-identified under the laws that apply to the company, so the license is not a sale of personal information despite the mixed consideration. The analysis and its evidence are filed with the release record.

How SourceX approaches the sale question#

SourceX approaches the sale question by keeping identifiable personal information out of licensed datasets wherever possible and documenting why. Within the SourceX five-step transaction, Rights and Preparation produce the evidence, and Approval is where the supplier and its counsel confirm the characterization.

The SourceX Evidence Packet records the de-identification method, the public commitment, the recipient obligations and the permitted use, so the analysis can be checked against the dataset actually delivered rather than an earlier plan.

Frequently asked questions

Does a free pilot dataset count as a sale?

It can, if the pilot contains personal information and the supplier receives something of value, such as the prospect of a paid license or other consideration. Treat pilot samples like the full dataset: prepare them to the same standard and send them under a written sample agreement.

Does restricting resale change whether a license is a sale?

Generally no. Resale limits and permitted-use clauses shape what the buyer can do, but the sale question turns on whether personal information was made available for consideration. Those clauses still matter, because many state laws require contract terms limiting the buyer's use when a sale does occur.

Is employee data in a licensed dataset treated differently?

In California, employee personal information has been covered like other personal information since January 1, 2023, so the same sale analysis applies. Most other state comprehensive privacy laws leave out employment data, as the Colorado Attorney General's guidance on the Colorado Privacy Act shows. Other employment and contract rules may still apply, and de-identifying employee content removes most of the question.

What if some consumers have already opted out of sales?

If the licensed data is properly de-identified, earlier opt-outs generally do not reach it, because it is no longer personal information. If any identifiable data remains, those consumers must be excluded. Keep the opt-out list current in case the dataset scope changes later.

Does sharing data with a preparation vendor count as a sale?

Generally not, when the vendor acts as a service provider or processor under a contract that meets the law's requirements and uses the data only to perform the service. Check that the contract carries the required terms before any records move to the vendor.

Sources

  • Under Cal. Civ. Code 1798.140(m), as amended by the CPRA, information is deidentified only if it cannot reasonably be linked to a particular consumer and the business takes reasonable measures, publicly commits not to reidentify it, and contractually obligates recipients to comply. Source
  • The CCPA employee and business-to-business exemptions expired on January 1, 2023 after the legislature did not extend them. Source
  • The Colorado Attorney General states that the Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify