Skip to content

Privacy and preparation

Privacy enforcement and AI training data, 2025-2026: what matters for data suppliers

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Privacy enforcement in 2025 and 2026 gives data suppliers a short list of lessons: honor opt-outs, say plainly what you do with personal information, put the required terms in contracts with recipients, and treat sensitive data and new uses such as AI training with extra care. Licensing company records raises each of these questions.

Key takeaways

  • The enforcers that matter most for data suppliers are state privacy regulators, state attorneys general, the Federal Trade Commission and private plaintiffs.
  • Recurring problems in public actions include broken opt-out handling, missing contract terms with recipients and uses of data that notices did not cover.
  • Promises made when data was collected can travel with it: the FTC has asked buyers of personal data to honor the privacy policy it was collected under.
  • Remedies often reach beyond penalties into required audits, contract reviews and deletion duties.
  • Licensing de-identified operational records avoids many of these issues, but only if the de-identification and the contracts hold up.

Who enforces privacy rules that touch AI training data?#

Privacy rules that touch AI training data are enforced by several bodies at once, each with different tools. For a US company licensing its records, the ones to watch are state privacy regulators, state attorneys general, the Federal Trade Commission and private plaintiffs.

These enforcers do not coordinate every case, but their concerns overlap. A practice criticized by one is a reasonable signal of what the others will ask about, so a supplier's review should read across all of them rather than track a single agency.

Who enforces privacy rules that touch AI training data?
EnforcerMain toolWhat it tends to examine
California Privacy Protection AgencyAdministrative enforcement of the CCPAOpt-out handling, notices, contracts with recipients, data broker registration
State attorneys generalState comprehensive privacy laws and consumer protection statutesSales of personal data, sensitive data, accuracy of notices
Federal Trade CommissionIts authority over unfair or deceptive practicesPromises in privacy policies, sales of sensitive data, changes to how data is used
Private plaintiffsClass actions under wiretap, recording and consumer statutesRecording without consent, tracking technologies, vendor data use

Recurring themes in recent public actions#

Recent public actions return to a small set of practices. None of them is specific to AI, which is the point: AI training data is judged by the same rules as any other use of personal information.

The final theme in the list below matters most for AI training, because licensing records for training is usually a new use of data collected for another purpose. A notice rewritten after the fact is a weak basis for that use, and regulators have said so publicly.

  • Opt-out requests that were hard to submit, demanded unnecessary information, or ignored browser-based opt-out signals.
  • Consent and cookie choices designed to steer people toward sharing.
  • Contracts with recipients of personal information that lacked the terms the law requires.
  • Sensitive information, such as health-related inferences or precise location, shared beyond what people expected.
  • Companies operating as data brokers without registering where registration is required.
  • Privacy policies changed, or applied retroactively, to permit new uses of data people had already provided.

Dated public signals to track, 2024-2026#

Several dated public signals from regulators and lawmakers bear directly on licensing records for AI training. The list is selective, not a complete record of enforcement actions, so check each regulator's announcements page for anything newer before relying on it.

Read the rows together. Promises made when data was collected follow the data, more states now give people rights over how their data is sold, and AI developers face their own documentation duties that they will pass back to suppliers.

Dated public signals to track, 2024-2026
DatePublic signalWhat it means for a supplier
February 13, 2024FTC staff warned that quietly changing terms of service or a privacy policy to allow AI training on data already collected may be unfair or deceptiveDo not rely on a retroactive notice change to license records collected under older notices
March 31, 2025In the 23andMe bankruptcy, FTC Chairman Andrew Ferguson wrote to the U.S. Trustee that any purchaser should expressly agree to be bound by the company's privacy policiesCollection-time promises travel with the data, so a licensee should accept the same limits
January 1, 2026Comprehensive privacy laws took effect in Indiana, Kentucky and Rhode Island, bringing the states with such laws in effect to 20 by MultiState's count, which includes Florida's narrower lawMap where the people in your records live before assuming one state's rules
January 1, 2026California AB 2013 deadline for generative AI developers to post training data documentation, including whether datasets were purchased or licensed and whether they include personal informationExpect buyers to ask suppliers to document licensing status and personal information content
April 20, 2026The California Privacy Protection Agency opened preliminary rulemaking on how the CCPA applies to employee, job applicant and contractor data, with comments accepted through May 20, 2026Treat HR and workforce records as an area where rules may tighten

What each theme means for a company licensing its records#

Each enforcement theme translates into a concrete check for a data supplier. Run these checks during the rights review, before any records are prepared, and keep the answers in the deal file.

What each theme means for a company licensing its records
ThemeQuestion for your recordsPractical step
Opt-out handlingDid anyone whose data is in scope opt out of sale or sharing?Exclude opted-out individuals, or license only de-identified records
Notice accuracyDid the notice in force at collection describe this kind of use?Assemble notice versions by date and match them to record dates
Recipient contractsDoes the license carry the terms the law expects for recipients?Include permitted-use limits, no re-identification and onward-transfer terms
Sensitive dataDo records contain health details, location, ID numbers or similar?Remove or exclude sensitive fields and narratives
Data broker statusCould licensing make the company a data broker anywhere?Have counsel check registration rules before signing
New use of old dataWere records collected before any mention of AI or licensing?Prefer de-identified internal records over retroactive notice changes

Why the AI training angle draws attention#

AI training draws attention because it is a new use of data collected for something else, and because its effects are hard to reverse. Once personal information has shaped a model, removing it from the dataset may not undo its influence. Regulators have in some past cases required companies to delete models or algorithms built from improperly obtained data, a remedy that worries buyers as much as suppliers.

For a supplier, that moves the burden forward. Careful buyers ask for evidence that personal details were removed and that the supplier had the right to license what remains. A supplier that can show its notice history, de-identification method and contract terms stands on firmer ground than one that can only point to a clean-looking sample.

Operational records about how work gets done, such as job notes, order exceptions, engineering issues and support resolutions, can often be licensed with personal details removed. That is a different risk profile from selling consumer profiles, and the deal file should document the difference.

How to read an enforcement announcement#

An enforcement announcement is a starting point, not a summary of the law. Press releases compress the facts, and the complaint or order usually says far more about what the regulator found wrong and what the company must now do.

The required conduct is often the most useful part for a supplier. Terms that oblige a company to review every contract with recipients, rebuild its opt-out process or delete data collected without a proper basis show what a regulator considers the fix, and they make a practical checklist for your own licensing file.

  • Read the complaint, order or settlement, not only the press release.
  • Identify the statute relied on and the specific practice challenged.
  • Note the non-monetary terms: audits, contract reviews, deletion duties and compliance reporting.
  • Ask whether the same practice exists anywhere in your systems or vendor setup.
  • Record the review in your privacy file with a date and an owner.

Illustrative: a staffing firm adjusts its licensing scope#

Illustrative: a fictional IT staffing firm is preparing to license records from its applicant tracking system and its internal recruiter playbooks. During the rights review, its general counsel reads a regulator's announcement about a company that mishandled opt-out requests and demanded too much information to process them.

She checks the firm's own process and finds that candidate opt-out requests arrived by email and were never linked to ATS profiles. Rather than reconstruct that history, the firm removes candidate profiles, resumes and interview notes from scope. It keeps client job requirements, placement timelines and recruiter process documents, with client and candidate names removed and a no re-identification clause in the draft license.

The firm also fixes its opt-out workflow going forward. The licensing project ends up smaller, but every record in it has a documented basis.

How SourceX reflects enforcement lessons#

SourceX applies these lessons early in the SourceX five-step transaction. During Rights, notice history, opt-out records and customer contracts are checked before a single record is prepared, and Preparation strips personal and confidential details as its starting position.

Each package's SourceX Evidence Packet then records the method used to remove identifiers, what was excluded and the promises the licensee makes, such as staying within permitted use and never attempting re-identification. Which laws govern a deal remains a call for the supplier's counsel.

Frequently asked questions

Does licensing de-identified data avoid these enforcement risks?

It reduces them, but only if the data truly meets the applicable de-identification standard and the contract binds the recipient not to re-identify it. Regulators look at substance, so a dataset with stray names or unique details can still be personal information. Document the method and test the output.

Are business-to-business records outside enforcement focus?

Not reliably. Business records still contain individuals, such as customer contacts, agents and employees. California's exemptions for employee and business-to-business data expired on January 1, 2023, while laws such as Virginia's and Colorado's generally exclude people acting in a commercial or employment context. The safer course is to remove personal details from operational records either way.

Should we pause a licensing project after a new enforcement action?

Not automatically. Read the action, compare the practice to your own, and adjust scope or process where they overlap. Many actions concern practices, such as opt-out handling or website tracking, that a carefully scoped licensing project does not touch.

Who should track enforcement for a company licensing data?

Usually the general counsel or privacy lead, with a short review whenever a regulator publishes an action involving sales of personal data, sensitive data or AI. Keep a dated log of what was reviewed and what changed, so the record shows the company kept its practices current.

Do these lessons apply outside California?

Yes. By MultiState's count, 20 states had comprehensive privacy laws in effect in January 2026, many with opt-out rights, sensitive data rules and contract requirements, and the FTC's authority is national. Which laws apply depends on where the company operates and whose data it holds, so assess each deal with counsel.

Sources

  • On February 13, 2024, FTC staff warned that a company adopting more permissive data practices, such as using consumers' data for AI training, and telling consumers only through a surreptitious, retroactive change to its terms of service or privacy policy may be engaging in unfair or deceptive practices. Source
  • On March 31, 2025, FTC Chairman Andrew N. Ferguson sent a letter to the U.S. Trustee in the 23andMe bankruptcy stating that any purchaser should expressly agree to be bound by and adhere to 23andMe's privacy policies. Source
  • Comprehensive consumer privacy laws in Indiana, Kentucky and Rhode Island took effect on January 1, 2026, bringing the number of states with such laws in effect to 20 by MultiState's count, which includes Florida's narrower law. Source
  • California AB 2013 requires developers of generative AI systems released on or after January 1, 2022 to post training-data documentation on or before January 1, 2026, including whether datasets were purchased or licensed and whether they include personal information. Source
  • The California Privacy Protection Agency initiated preliminary rulemaking on April 20, 2026 on how the CCPA applies to personal information of employees, job applicants and independent contractors, with comments accepted through May 20, 2026. Source
  • The CCPA employee and business-to-business personal information exemptions expired on January 1, 2023. Source
  • The Colorado Privacy Act does not cover personal data of individuals acting in a commercial or employment context. Source
  • The Virginia Consumer Data Protection Act generally does not apply to information about a natural person acting in a commercial (B2B) or employment context. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify