Privacy and preparation
Sensitive data consent under state privacy laws: when opt-in is required
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Under most US state privacy laws, processing sensitive data, such as health information, precise geolocation, biometric data, racial or ethnic origin, religious beliefs, sexual orientation, immigration status or a known child's data, requires opt-in consent. Consent for a new use is rarely obtainable after the fact, so the practical licensing rule is to find and exclude sensitive categories.
Key takeaways
- Most comprehensive state privacy laws require opt-in consent before sensitive data is processed, and processing generally includes disclosure.
- Definitions differ: some states add categories such as government identification numbers, account log-in details or the contents of private communications.
- Sensitive data turns up in ordinary operational records: access notes, accommodation requests, telematics trails and HR threads.
- Excluding sensitive categories is usually more practical than seeking new consent from everyone in historical records.
What counts as sensitive data under state privacy laws?#
Sensitive data under state privacy laws is a defined set of categories that carry stricter rules than ordinary personal data. The core list is similar across most states, though each law words it differently.
Some states define the category more broadly, for example by adding government identification numbers, financial account log-in details, union membership or the contents of private communications, and newer laws have added categories such as status as a crime victim. Check the definition in each law that may apply rather than relying on a combined list.
- Racial or ethnic origin, religious beliefs, and sex life or sexual orientation.
- Mental or physical health conditions, treatment or diagnosis.
- Citizenship or immigration status.
- Genetic data, and biometric data processed to identify a person.
- Precise geolocation.
- Personal data collected from a known child.
When is opt-in consent required?#
Opt-in consent is required under most comprehensive state privacy laws before a company processes sensitive data, and processing is usually defined broadly enough to cover collecting, using, storing and disclosing. Licensing a dataset that contains sensitive data would likely be treated as a new purpose that any original consent did not cover.
Consent must generally be specific, informed and unambiguous; acceptance of broad terms or a pre-checked box typically does not qualify. Rules for children's data usually require a parent's consent and sit alongside federal COPPA obligations. Separate consumer health data laws, such as Washington's, can apply on top of the comprehensive laws and set their own consent rules for sharing health information. Not every comprehensive law follows the opt-in model, as the table shows.
| Model | Where it appears | How it generally works | Implication for a licensing dataset |
|---|---|---|---|
| Opt-in consent | The large majority of comprehensive laws, including those of Virginia, Colorado, Connecticut, Oregon and Texas | Clear, affirmative consent before processing | Consent would need to cover licensing, which historical records rarely have |
| Right to limit | California | People can direct a business to limit its use and disclosure of sensitive personal information | Notice and limits still apply; review with counsel |
| Notice and opt-out | Utah and Iowa | Notice and an opportunity to opt out before processing | A lighter test, but other states' rules may still apply to the same records |
| Stricter limits | Maryland, for example | Processing limited to what is strictly necessary for a requested service, with sale of sensitive data prohibited | Consent may not be enough; exclusion is the safe path |
Where does sensitive data hide in business records?#
Sensitive data hides in fields and notes no one designed for it. Operational systems collect it incidentally, which is why a schema review alone misses most of it and a free-text review is needed.
Attachments and images add more: a photo with prescription bottles on a counter, scanned insurance paperwork, or a whiteboard showing an employee's leave dates. If attachments are in scope, they need their own review.
| Record type | Sensitive content that appears | Example |
|---|---|---|
| Support tickets and chats | Health conditions, accessibility needs | A customer explains a disability when asking for a feature |
| Field service job notes | Health and household details | An access note mentions a resident's oxygen equipment |
| Fleet telematics and dispatch | Precise geolocation | Technician GPS trails between jobs and home |
| HR threads in email or chat | Health, union activity, immigration status | Leave requests, visa sponsorship discussions |
| Call recordings | Voice data, spoken health details | A caller describes a medical reason for an urgent visit |
| CRM notes | Religious beliefs, family circumstances | Scheduling around a religious observance |
Why exclusion is the practical rule for licensing#
Exclusion is the practical rule because a company licensing historical records cannot realistically go back to every customer, employee and contact for opt-in consent to a new use. Buyers of operational records rarely want sensitive categories anyway; the workflow and outcome survive without them.
Write the exclusions as rules rather than one-off edits, so they can be reviewed by counsel and rerun on the next export.
- Drop fields designed to hold sensitive data, such as medical notes or accommodation forms.
- Scan free-text fields for health, religious, immigration and similar terms, then remove or generalize matching passages.
- Coarsen location to city or region, and drop GPS trails entirely.
- Exclude HR, benefits and leave records, and the channels where they are discussed.
- Exclude records about known children.
- Record each exclusion rule in the privacy record so it can be reviewed and rerun.
Do employee and business contact records change the analysis?#
Employee and business contact records change the analysis state by state. Many consumer privacy laws leave out people acting in an employment or commercial context, but California's law reaches employees and business contacts, and biometric, medical-information and employment laws may apply to the same records separately.
Employee records are also where much sensitive data lives: leave, accommodations, benefits and background checks. Even where a consumer privacy law does not reach them, excluding those categories from a licensing dataset is the cautious default.
Business contact records are usually less sensitive, but notes attached to them can still mention a contact's health, family or religious observance. Apply the same free-text scan to CRM notes and email threads.
Illustrative: a restoration contractor removes sensitive details from job records#
Illustrative: a fictional water and fire restoration contractor wants to license job histories from its field service system and its fleet telematics platform. The records show how losses were assessed, scoped, dried out and closed.
A review finds sensitive content in three places: access notes describing residents' medical equipment and mobility needs, claim notes mentioning health effects of mold exposure, and GPS trails that show technicians' routes home. Counsel advises that consent for licensing is not available for this history.
The company drops the access notes field, runs a term scan on claim notes and removes matching passages, keeps job locations only at city level and excludes telematics trails. The remaining records still show the full mitigation workflow and its outcome.
What to record for counsel and the buyer#
A short written record turns a sensitive data review into something counsel can approve and a buyer can rely on. Keep it with the dataset's documentation, not in someone's inbox.
- The laws identified as possibly applicable, and the states involved.
- The sensitive categories searched for and the method used, such as field exclusion or term scans.
- The fields and record types excluded entirely.
- Sample review results, including any sensitive content found after exclusion and how it was handled.
- Who approved the exclusion rules, and on what date.
How SourceX approaches sensitive categories#
SourceX treats sensitive categories as excluded by default. The Rights step of the SourceX five-step transaction identifies which laws may apply and where sensitive data may sit; the Preparation step removes it.
The exclusion rules and review results are written into the privacy record of the SourceX Evidence Packet, and the supplier approves them before release. If a buyer's request would require sensitive categories, the request is not pursued unless the supplier's counsel confirms a lawful basis.
Frequently asked questions
Does removing names make sensitive data safe to license?
Not necessarily. If the remaining data still relates to an identifiable person, it can remain sensitive personal data, and detailed health notes, rare circumstances or precise locations can identify someone from context. A dataset that satisfies a law's de-identification standard is usually handled differently, but whether it does is assessed with counsel.
Can we rely on consent in our terms of service?
Usually not for sensitive data. Most state laws require consent that is specific, informed and unambiguous, and many treat acceptance of broad terms as insufficient. Historical terms also rarely mention licensing records to AI developers.
Are voice recordings biometric data?
A recording is generally treated as biometric data when it is processed to identify a specific person, for example through a voiceprint. A plain recording may not be biometric, but what the caller says can still be sensitive. Separate biometric privacy laws in some states add their own rules.
Do we need a data protection assessment?
Many state laws require a documented assessment before processing sensitive data or selling personal data. If a dataset excludes sensitive categories and personal details, the question may not arise, but counsel should confirm for each law that may apply.
What if a buyer specifically wants health or location data?
Treat that as a different project with a much higher bar. It would need a lawful basis under each applicable law, often specific consent, and possibly other sector rules. For most operating companies the simpler answer is to decline and license the workflow records without those categories.
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.