HomeGuides › Privacy and rights

Guide · Privacy & rights

Privacy and rights before you license business data

“It is business data, not consumer data” is the most common assumption in this market, and it is often wrong. Invoices name approvers, expense lines name employees, and supplier files include sole traders who are individuals. The safest licensing programs start by finding that personal data and taking it out.

De-identified is a legal test, not a feeling

California (CCPA). Information is “deidentified” only if it cannot reasonably be used to infer information about, or be linked to, a particular consumer, and the business holding it (1) takes reasonable measures so it cannot be associated with a consumer or household, (2) publicly commits to keep it de-identified and not attempt re-identification, and (3) contractually obligates any recipients to comply (California Civil Code § 1798.140 (CCPA definitions, incl. “deidentified”)). Point three means the licence itself must carry the obligation.

EU and UK (GDPR). Personal data that has been pseudonymised but could be attributed to a person with additional information is still personal data. Whether someone is identifiable is judged by all means reasonably likely to be used, taking into account cost, time and available technology. Only anonymous information falls outside the regulation (GDPR Recital 26, “Not applicable to anonymous data”). The UK ICO’s anonymisation guidance explains how to assess that in practice (UK ICO guidance on anonymisation).

Method. NIST SP 800-188 describes de-identification techniques and the trade-off between disclosure risk and usefulness (NIST SP 800-188, De-Identifying Government Datasets). Aggregation to category and period level is often the most defensible choice for spend data.

When data-broker rules come into play

California requires data brokers — broadly, businesses that sell personal information of consumers they do not have a direct relationship with — to register. Under the Delete Act, since August 1, 2026 registered data brokers must check the state’s deletion platform at least every 45 days and process consumer deletion requests (California Privacy Protection Agency — Data broker registration and the Delete Act). Other states have their own registration laws. A licence of genuinely de-identified or aggregated business data is a different activity, which is one more reason to remove personal data before any dataset leaves your systems.

Who the buyer is matters, too

The U.S. Department of Justice’s Data Security Program, in effect since April 8, 2025, works like an export control: it prohibits or restricts certain transactions that could give countries of concern, and persons subject to their jurisdiction, ownership or control, access to Americans’ bulk sensitive personal data — including financial data — or U.S. Government-related data (U.S. Department of Justice, National Security Division — Data Security Program; regulation at 28 C.F.R. Part 202 (eCFR)). If a dataset could contain personal financial data, know the buyer’s ownership and where the data will be accessed.

Your own promises still bind you

The FTC has said companies must honour the privacy and confidentiality commitments they made, however those commitments were made, and that retroactively changing terms to allow new uses of data already collected can be unfair or deceptive (FTC Technology Blog, “AI Companies: Uphold Your Privacy and Confidentiality Commitments” (Jan. 2024); FTC Technology Blog, “AI (and other) Companies: Quietly Changing Your Terms of Service Could Be Unfair or Deceptive” (Feb. 2024)). Its general guide for businesses on protecting personal information is a sensible baseline for handling any sample (FTC, “Protecting Personal Information: A Guide for Business”).

Clauses to insist on in any data licence

Where we draw lines. We will not introduce datasets containing patient or health-claims information, material about minors, privileged legal material, or anything a customer gave you in confidence. Personal data in a package means we stop until it is removed.

This guide is general information, not legal advice. Have your own counsel review your contracts and any licence.

Who is writing this. MyDataWorth is an independent introduction desk. We are not a data buyer, a marketplace, a law firm or an agent of any buyer, and we never receive, hold or resell a company’s data. We review whether a company looks ready for a data-licensing conversation and, only with its written go-ahead, introduce it to programs that license business data. When an introduction leads to an engagement we may be paid a referral fee by that program; we tell you who, and on what basis, before your name goes anywhere.

Request a free readiness review →