Skip to content

Privacy and preparation

What counts as deidentified data under US state privacy laws?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Under most US state privacy laws, data counts as deidentified only when it cannot reasonably be linked to a person and the holder also takes reasonable safeguards, publicly commits not to reidentify it, and binds recipients by contract to the same terms. Miss any element and the records may still count as personal data.

Key takeaways

  • Deidentification is a status you maintain through safeguards, a public commitment and contracts, not a one-time scrub.
  • Pseudonymized records with a retained key are generally still personal data, even where some laws relax certain rights for them.
  • Free text such as support tickets and email is harder to deidentify than structured fields and needs both automated and human review.
  • California's law reaches employee and business contact data, so the deidentification question covers more of your records there.
  • Every license for deidentified data should carry a no-reidentification clause that flows down to the buyer's contractors.

The test most state laws share#

The deidentification test most state privacy laws share has a technical part and a commitment part. The technical part asks whether the data can reasonably be linked to an identified or identifiable person, or to a device linked to that person. The commitment part asks what the holder does to keep it that way.

Regulators and counterparties look at all three commitments. A dataset scrubbed of names but shipped without a no-reidentification clause can fall short of the definition, which means it may still be personal data under the laws that apply.

  • Reasonable measures: technical and organizational safeguards that keep the data from being associated with a person.
  • Public commitment: a published statement that the business will maintain and use the data only in deidentified form and will not try to reidentify it.
  • Contract flow-down: written obligations on every recipient to follow the same rules.

How California compares with other state laws#

California's CCPA uses a similar three-part structure, but its scope makes deidentification matter for more records. California treats employees, job applicants and business contacts as consumers, while most other comprehensive state laws exclude people acting in an employment or commercial context.

Definitions are amended often, and some laws add their own wording on how the public commitment must be made. California also lets a business attempt reidentification solely to test whether its own deidentification process works, a narrow exception worth documenting if your team runs such tests. Use the table as a map for the conversation with counsel, then confirm the current text of each law that may apply.

How California compares with other state laws
ElementCalifornia (CCPA)Most other comprehensive state lawsWhat to check
Linkability testInformation cannot reasonably be used to infer information about, or be linked to, a particular consumerData cannot reasonably be linked to an identified or identifiable individual or a linked deviceWhether free text, rare events or small groups make linking reasonable
SafeguardsReasonable measures so the information cannot be associated with a consumer or householdReasonable measures so the data cannot be associated with an individualAccess controls, separation from source systems, logging
Public commitmentRequiredRequiredWhere the statement is published and whether practice matches it
Contracts with recipientsRequiredRequiredNo-reidentification, flow-down and notice clauses
Whose records are in scopeIncludes employees and business contactsGenerally excludes employment and commercial contextsWhich people in your records are covered at all
Pseudonymous dataGenerally still personal informationSeveral laws relax some consumer rights when the key is kept separately under controlsWhether you keep a re-linking key

Deidentified, pseudonymous and aggregate are not the same#

Deidentified, pseudonymous and aggregate data sit at different points on the identifiability scale, and a license should name which one the buyer receives.

Pseudonymous records are a common trap. Replacing names with tokens is a useful preparation step, but if the supplier keeps the lookup table, the data is still personal data in the supplier's hands. Either the license reflects that, or the key is destroyed before release.

Aggregate outputs carry their own risk when groups are small. A count of warranty claims by technician at a branch with two technicians describes individuals rather than a group, so agree a minimum group size with counsel and suppress any smaller cells before release.

Deidentified, pseudonymous and aggregate are not the same
Data stateExample in operational recordsUsually personal data?
PseudonymousTechnician names replaced with IDs while the mapping table is keptYes, because the holder can re-link
DeidentifiedNames, contact details and unique facts removed, no key kept, commitments and contracts in placeGenerally no, if every element is met
AggregateMonthly counts of callbacks by equipment typeGenerally no, if groups are not small enough to single out a person

Why free text makes the test harder#

Free text makes the linkability test harder because people identify themselves in ways no field mapping anticipates. Email signatures, a customer describing a one-off event, a job site address mentioned in passing, or a small team where one person handles a certain task can all point back to an individual.

Automated detection helps but does not settle the question. The open-source Presidio project, a toolkit for finding and anonymizing personal information in text, warns in its own documentation that automated detection cannot guarantee finding all sensitive information and that additional protections should be used. Pair automated passes with sampling and human review for every record family.

Structured risk checks exist for tabular fields. Google's Sensitive Data Protection API, for example, offers re-identification risk metrics including k-anonymity, l-diversity, k-map and delta-presence. These help with fields such as region, role and dates, but they do not read the meaning of a support conversation.

Contract terms that keep data deidentified downstream#

Contract terms are where most suppliers satisfy the third element, and buyers licensing deidentified data generally expect them.

Several state laws also expect a business that discloses deidentified or pseudonymous data to exercise reasonable oversight of the recipient's contractual commitments and to act on breaches. A practical way to show oversight is a periodic written confirmation from the buyer, kept with the license file.

Keep the public commitment and the contract language consistent with each other and with what your team actually does. A mismatch is easy for a regulator or a buyer's counsel to spot.

  • No attempt to reidentify any person, alone or by combining the data with other sources.
  • Flow-down of the same obligation to contractors, affiliates and anyone else the buyer lets use the data.
  • Prompt notice to the supplier if reidentification happens by accident, with deletion of the affected records.
  • Limits on publishing raw records or excerpts that could identify a person.
  • Return or deletion of working copies at the end of the term, where the contract calls for it.

Illustrative: a distributor prepares order exception records#

Illustrative: a fictional industrial distributor wants to license order exception records from NetSuite, together with the customer service emails that resolved each exception. The records cover backorders, damaged shipments, substitutions and credit decisions.

Preparation removes buyer names, emails, phone numbers and street addresses, generalizes ship-to locations to region, and replaces account numbers with random tokens. The team keeps the token key during quality checks, then destroys it before release so the package is not pseudonymous. A reviewer samples email threads for names hidden in greetings and signatures.

The distributor adds a deidentification statement to its privacy notice, and the license includes no-reidentification and flow-down clauses. Counsel concludes the package can be treated as deidentified under the laws that may apply, and the reasoning goes into the release file.

How SourceX approaches deidentified packages#

SourceX handles deidentification in the Preparation step of the SourceX five-step transaction, after the Rights step has set what may be licensed. Personal and confidential details are removed, a sample is reviewed, and the supplier approves the prepared package before anything is delivered.

The privacy record in the SourceX Evidence Packet documents the methods used, the review results, the public commitment and the contract terms, so a deidentification claim rests on records rather than assertion.

Frequently asked questions

Does hashing email addresses make records deidentified?

Usually not. A hash of an email address can often be matched by anyone holding the same address, so it behaves like a persistent identifier. Hashing is a pseudonymization technique. Remove the field, or replace it with a random token and destroy the key, if the goal is deidentified data.

Do we need a separate public commitment if we already have a privacy policy?

Check whether the existing policy contains the commitment the laws describe: that you will keep and use the data in deidentified form and will not attempt to reidentify it. Many privacy policies say nothing about deidentified data, so a short added section is common.

What happens if the buyer reidentifies someone anyway?

The contract should require notice, deletion and cooperation, and it allocates responsibility between the parties. Under the laws that may apply, a buyer that reidentifies data may hold personal data with obligations of its own. Counsel should review remedies and indemnities before signing.

Does the HIPAA deidentification standard apply to operational records?

HIPAA applies to covered entities and their business associates handling protected health information. Most operating companies are neither, but health details can still appear in tickets or emails. If they do, raise it with counsel early, since state laws may treat health information as sensitive.

Is licensing deidentified data a sale?

Under most state laws, deidentified data is outside the definition of personal data, so licensing it generally falls outside sale rules, provided every element of the definition is met. The analysis turns on details, which is why it deserves its own review with counsel.

Sources

  • Presidio's documentation warns that because it uses automated detection mechanisms, there is no guarantee it will find all sensitive information, and additional systems and protections should be employed. Source
  • Google's Sensitive Data Protection API offers re-identification risk-analysis metrics including k-anonymity, l-diversity, k-map estimation and delta-presence estimation. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify