Skip to content

Definitions and comparisons

What is purpose limitation, and does it stop you reusing old records?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Purpose limitation is the privacy principle that personal data collected for one stated purpose should not be reused for an unrelated purpose without a fresh basis. It does not freeze old records outright. Whether reuse is possible depends on what people were told, how compatible the new use is, and whether personal details are removed first.

Key takeaways

  • Purpose limitation governs personal data, so records with personal details removed face a different and usually narrower analysis.
  • The starting point is what your privacy notice, customer terms and employee notices said when the records were collected.
  • Compatibility turns on the link between purposes, the context of collection, the sensitivity of the data, the effect on people and the safeguards applied.
  • Rewriting a privacy notice today does not automatically reach records gathered under the old wording.
  • Contract limits, such as a customer DPA, can restrict reuse even where privacy law would not.

What does purpose limitation mean?#

Purpose limitation means personal data should be collected for specified, explicit purposes and not processed later in a way that is incompatible with them. GDPR states it as a core principle, and several US state privacy laws express a similar idea through purpose specification, data minimization and limits tied to what a consumer would reasonably expect.

The principle is about personal data, not about records in general. A support ticket is not off limits because it was created to fix a customer problem; the names, emails and account details inside it are what carry the purpose restriction. That distinction matters, because most of the value in operational records sits in the problem, the steps taken and the outcome, not in who raised it.

Which laws may apply depends on where the people in your records live, what kind of business you run and how the data was collected. Counsel assesses that deal by deal; no single answer covers every company.

Which old records does purpose limitation actually touch?#

Purpose limitation touches any old record that still contains information about an identifiable person. In a typical operating company that is a large share of the archive at first, and a much smaller share once personal details are removed.

Map record families before arguing about principles. The table shows where personal data usually sits in common business systems and how heavily the purpose question bears on each one.

Notice that the same system can hold both kinds of content. A Jira project may be almost entirely technical discussion, while its attachments include customer screenshots with names and emails. Scope the review at the level of fields and attachments, not whole systems.

Which old records does purpose limitation actually touch?
Record familyPersonal data usually insideWeight of the purpose question
Support tickets in Zendesk or IntercomCustomer names, emails, phone numbers, account IDs, signaturesHigh until de-identified
CRM histories in Salesforce or HubSpotContact details, call notes, opinions about individualsHigh until de-identified
Jira issues and code review commentsEmployee names and handles, occasional customer namesModerate, mainly employee notices
Job and dispatch records in ServiceTitanHomeowner names, addresses, access notesHigh until de-identified
Quality records such as NCRs and CAPAsInspector names, supplier contactsLow to moderate
SOPs, playbooks and internal wikisAuthor names, little elseLow

The compatible-use checklist#

A compatible-use review asks whether the new purpose is close enough to the original one that people would not be surprised by it. GDPR lists factors for that judgment, and US counsel tend to ask parallel questions about notice and reasonable expectations.

Work through each question in writing. The answers become the core of the privacy record for any license, and they show where de-identification has to do the heavy lifting.

  • Link: how closely does licensing for AI training or evaluation relate to the purpose stated at collection?
  • Context: what relationship did you have with the people involved, and what would they reasonably expect?
  • Nature of the data: does the record set include sensitive categories such as health, financial or precise location details?
  • Consequences: could the new use affect any individual, even indirectly?
  • Safeguards: will names, contact details and other identifiers be removed or transformed before anything leaves your systems?
  • Notice wording: did the privacy notice or terms mention product improvement, research, analytics or sharing with service providers?
  • Contract limits: do customer agreements or DPAs restrict use of their data to providing your service?

How de-identification changes the analysis#

De-identification changes the analysis because purpose limitation follows personal data, and properly de-identified records are generally no longer treated as personal data. The question may then shift from privacy law to contracts, confidentiality and ownership.

The shift depends on the method. Pseudonymized records, where names are swapped for consistent tokens and a key exists somewhere, are generally still personal data under GDPR. US state laws that define deidentified data tend to require reasonable technical measures plus commitments not to re-identify, so the label depends on conduct as well as content.

Free text is where the argument most often fails. A ticket that describes the only franchise location in a small town, or a CRM note about a named executive's health, can identify a person without any name present. A de-identification method that covers structured fields but not narrative notes will not carry the purpose analysis on its own.

How de-identification changes the analysis
State of the recordsDoes purpose limitation still bite?What else still governs
Raw records with names and contactsYes, fullyNotices, contracts, confidentiality
Pseudonymized with a retained keyGenerally yesSame, plus key controls
De-identified to a documented standardUsually much lessContracts, confidentiality, ownership
Aggregated statistics onlyRarelyContracts and small-group risk

Can you fix the problem by updating your privacy notice?#

Updating a privacy notice mainly helps with records collected after the change, not with the archive you already hold. Counsel will usually ask what the notice said when each batch of records was created, so keep dated copies of every version.

Quietly expanding terms to cover AI use of previously collected data can draw regulatory attention in the US, and a retroactive change can itself become the problem. The safer route for old records is usually to rely on de-identification and contract review rather than on new wording applied backward.

Two other fixes come up and rarely work on their own. Asking every past customer for fresh consent is impractical for a large archive and can alarm people about records they had forgotten. Relying on a vague clause about improving services stretches wording written for a different context. Both can support a review, but neither replaces it.

Illustrative: a mechanical contractor reviews ten years of service history#

Illustrative: a fictional commercial mechanical contractor holds a decade of ServiceTitan jobs, technician notes, estimates and recorded dispatch calls. Its privacy notice said customer information was used to schedule service, perform work and improve operations, and its call recordings carried a separate notice about quality and staff training.

Counsel concluded that technician diagnostic notes, equipment details and job outcomes could be licensed once customer names, addresses, phone numbers and site access notes were removed. Recorded calls were parked, because the voice itself identifies the caller and the recording notice was narrow. The company documented the compatibility review and licensed only the de-identified job records.

How SourceX handles purpose questions#

SourceX treats purpose limitation as part of the Rights step of the SourceX five-step transaction: Supply, Rights, Preparation, Approval and Delivery. Dated notices, customer terms and DPAs are reviewed against the proposed permitted use before any records are prepared, and the supplier approves the scope.

The resulting SourceX Evidence Packet records provenance, licensing rights, permitted use, the privacy record and release authorization. Buyers increasingly expect this kind of metadata: the Data and Trust Alliance's Data Provenance Standards include elements for intended data use and consent documentation location.

Frequently asked questions

Does purpose limitation apply to employee names in engineering records?

Yes, employee names and handles are personal data, so they carry the purpose restriction from your employee notices and policies. In practice, engineering records are usually prepared by replacing names with role labels or consistent tokens, which keeps the review history useful while removing the identity of the individual engineer.

Does purpose limitation cover data about businesses rather than people?

Purpose limitation in privacy law covers information about individuals. Data about companies, such as order volumes or equipment models, falls outside it, though business contacts named in those records are still people. Commercial data about customers can still be restricted by contracts and confidentiality terms.

Is AI training ever treated as compatible with the original purpose?

It can be, depending on the facts. A close link to product improvement, low sensitivity and strong safeguards all support compatibility. Counsel reaches that conclusion record family by record family, and many companies avoid relying on it by de-identifying first.

What should we keep on file for a purpose review?

Keep dated copies of privacy notices and terms, the customer agreements and DPAs that apply, a written compatibility assessment for each record family, and a description of the de-identification method. Those documents answer most questions a buyer, auditor or regulator would ask later.

Do old records lose their restrictions as they age?

No. Age alone does not remove a purpose restriction, though retention schedules may require older personal data to be deleted. Check your retention policy before planning to license an archive, because records that should already have been deleted raise a separate problem.

Sources

  • The Use group of the Data and Trust Alliance Data Provenance Standards includes elements for consent documentation location, license to use and intended data use. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify