Skip to content

Logistics and distribution

Records logistics and distribution companies should keep out of an AI dataset

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Logistics and distribution companies should keep driver qualification files, drug and alcohol testing records, tax forms, bank details, credit files and export-controlled shipment data out of any AI dataset. Exclude these record classes at the source system rather than relying on redaction, and log each exclusion so counsel and the buyer can see what was left out and why.

Key takeaways

  • Exclude whole record classes at the source; redaction is for the records you keep, not for documents that should never be in scope.
  • Driver qualification files and drug and alcohol testing records carry confidentiality rules and add nothing a buyer needs.
  • Carrier packets, W-9s and remittance details hold tax IDs and bank data that also fuel payment fraud.
  • Export-controlled, defense and security-sensitive shipment records stay out entirely.
  • An exclusion log belongs in the dataset's documentation, not in someone's memory.

Which records belong on the exclusion list?#

The exclusion list for a logistics or distribution company covers records that are regulated, highly personal, financially sensitive or security-sensitive, and that add little to the operational value buyers want. The table lists the usual classes, where they live and how to keep them out.

Treat the list as a starting point. Client, shipper and carrier contracts may add classes, and counsel should confirm which laws may apply to each one, an assessment made deal by deal.

What usually remains is the operational core: load and order histories, exception and claims notes, warehouse adjustments, customer service threads and pricing decisions, prepared so names and contacts are removed. The exclusion list exists to protect that core, not to shrink it.

Which records belong on the exclusion list?
Record classWhere it usually livesWhy it stays outHow to exclude
Driver qualification filesSafety or HR system, scanned filesPersonal, medical and motor vehicle record dataExclude the system or folder entirely
Drug and alcohol testing recordsThird-party administrator portal, safety filesDisclosure limits under DOT testing rulesNever export; filter related email threads
Tax forms such as W-9sCarrier onboarding, vendor files in APTaxpayer identification numbersExclude the document type and TIN fields
Bank and remittance detailsAP, carrier setup, lockbox filesAccount and routing numbers and fraud riskDrop fields and attachments at extraction
Credit applications and reportsCredit department files, ERP attachmentsPersonal guarantees; consumer report rules may applyExclude the credit module and attachments
Export-controlled shipmentsTMS, ERP, customs broker filesEAR or ITAR restrictions may applyExclude by customer, commodity or classification flag
Driver-level telematics and videoTelematics and dashcam platformsLocation and images of identifiable peopleExclude raw feeds; discuss summaries with counsel
HR, payroll and workers' compensationHRIS and payroll providerEmployee personal and medical dataKeep outside the scope entirely

Why driver qualification and testing records stay out#

Driver qualification files and drug and alcohol testing records stay out because they combine personal, medical and regulated information, and none of it explains how freight moves. A DQ file can hold the employment application, motor vehicle records, the medical examiner's certificate, road test results and previous employer inquiries.

Several regimes may apply, including FMCSA rules on what must be kept and who may see it, DOT drug and alcohol testing rules that limit disclosure of results, the Driver's Privacy Protection Act for motor vehicle records, and the Fair Credit Reporting Act where background reports are involved. Counsel decides which apply; the operational answer is simpler, because no buyer scope needs these files.

The harder part is leakage. Testing results and medical status surface in dispatcher emails, safety meeting notes and HR tickets, so exclusions should cover those channels with sender and keyword rules, not just the safety system.

Carrier packets, W-9s, bank details and credit files#

Carrier packets, W-9s, bank details and credit files belong on the exclusion list because they hold tax IDs, account numbers and owner guarantees that serve no training purpose. Brokers collect carrier packets with operating authority, insurance certificates, W-9s and payment instructions; distributors collect credit applications with trade references and personal guarantees.

Payment details need particular care in freight, where fraudulent changes to carrier remittance instructions are a known problem. A dataset that pairs carrier names with banking or factoring details is exactly what a fraudster wants, so these fields are dropped at extraction rather than masked later.

Keep the useful part separate. Load records can still show carrier performance, such as on-time status, claims and check-call quality, once identifiers are removed or replaced; the packet itself never needs to travel with them.

Export-controlled, defense and security-sensitive shipments#

Export-controlled, defense and security-sensitive shipments stay out entirely, because technical data and shipment details for controlled items can carry restrictions under the EAR or ITAR. SourceX excludes defense and export-controlled work from scope, so these records are screened out before any review of what remains.

Finding them takes more than a commodity filter. Useful flags include customer accounts tied to defense programs, export classification fields in the ERP, customs broker files with license references and shipments moved under special security handling.

Ordinary freight carries security details too. High-value load routes, seal numbers, gate codes, alarm details and warehouse security procedures can help thieves even when no law restricts them, so they are removed from any notes that stay in scope.

Illustrative: a broker and distributor builds its exclusion list#

Illustrative: a fictional company runs a freight brokerage on McLeod and an electrical distribution business on Epicor Eclipse, sharing one email system and one accounts payable team. It wants to scope exception histories from both businesses for a licensing review.

The general counsel starts from the table above and adds company-specific classes: one large shipper's agreement forbids any use of its shipment data beyond services, and a handful of distribution customers buy for defense programs. Carrier packets, W-9s and remittance setups are excluded by document type, and driver-related email is filtered by sender and keyword.

The outcome is a scope with a written exclusion log listing each class, the rule used, the systems touched and who approved it. The log goes into the deal file, and the excluded records never leave the company's systems.

How to apply the exclusion list at the source#

The exclusion list works best when it is applied in the source system before extraction, rather than through redaction afterward. Record classes that never leave the system cannot leak through a missed field or an attachment nobody opened.

Within the SourceX five-step transaction, exclusions are set in Rights and enforced in Preparation, and you approve the result before anything is delivered. The exclusion log becomes part of the privacy record in the SourceX Evidence Packet, so the buyer can see what was left out and on what basis.

  • Name each excluded class and the systems, folders and mailboxes where it lives.
  • Exclude at extraction by module, document type, field, customer flag or sender rule.
  • Scan the remaining scope for leaked identifiers such as TINs, account numbers and license numbers.
  • Review a sample of free-text notes and email by hand for medical, testing or banking details.
  • Record every rule, its owner and its approval in an exclusion log.

Frequently asked questions

Can driver names stay if they are pseudonymized?

Sometimes, in operational records such as dispatch notes or exception logs, if a consistent pseudonym helps show who handled what and counsel agrees. Driver qualification, testing and medical records stay out regardless of pseudonymization, because the content itself is the sensitive part.

Are telematics and dashcam records always excluded?

Raw location traces and video are usually excluded, because they identify drivers and reveal routes. Some summarized safety or event data may be considered with counsel, depending on driver notices, vendor terms and any collective bargaining agreement. The telematics vendor's terms also govern what can be exported.

What about shipper and consignee addresses?

Business addresses are usually a confidentiality question under client or shipper contracts, while residential delivery addresses are personal data. Many scopes replace addresses with a region or facility type, which keeps lane patterns readable without identifying any customer or recipient.

Does excluding these records make the rest safe to license?

No. The exclusion list removes the highest-risk classes, but the remaining records still need a rights review, privacy preparation for names and contacts in notes, and your approval. Exclusions are one layer of the process, not a substitute for it.

Who should sign off on the exclusion list?

General counsel or outside counsel should own it, with input from the safety director, the controller and IT. The safety director knows where driver records hide, the controller knows where tax and bank data sit, and IT knows which rules can actually be enforced at extraction.

Should excluded records be deleted?

No. Exclusion from a dataset is not a retention decision. Many of these records must be kept under transportation, tax or employment rules for set periods, so they stay in their own systems under existing retention policies. Excluding them only means they never enter the licensing scope.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify