No-re-identification clauses in data licenses and who is liable
A no-re-identification clause is a buyer's contractual promise not to identify individuals in de-identified data, link it to other datasets or extract identities from models. Statutory de-identification tests expect that commitment, and liability if it fails follows the contract, the buyer's sublicensing and the company's own de-identification work.
Why does a data license need a no-re-identification clause?
Removing names from records is a technical step; promising not to reverse it is a legal one. A no-re-identification clause is the buyer's contractual commitment that it will not try to work out who the individuals in a de-identified dataset are, and will not let anyone else do so. Without it, "de-identified" describes how the data looks on delivery, not how it can be used afterwards.
California's privacy law treats the contract as part of the definition. The CCPA statute text requires a business that sells or shares personal information, or discloses it to a service provider or contractor, to have a written agreement limiting use to specified purposes, and its definitions section sets out what counts as deidentified information. The three commitments a company must make are covered separately. This page is about the contract language that carries the promise. This is general information, not legal, tax or financial advice. Confirm the exact wording with your own counsel.
What should a strong buyer covenant cover?
A short sentence saying "buyer shall not re-identify" is a start, not a covenant. Look for these elements.
| Element | What it should say | Why it matters |
|---|---|---|
| Direct ban | No attempt to re-identify, de-anonymize or single out an individual | The core promise |
| Linkage | No combining the data with other datasets to infer identity | Linking is the usual route to re-identification |
| Model outputs | No prompting, probing or extracting from a trained model to recover individuals or company-specific records | Covers the AI-specific risk |
| Onward transfer | Any sublicensee, contractor or affiliate is bound by the same terms in writing | The promise must travel with the data |
| Notice | Buyer reports any suspected re-identification or leak promptly | Lets the company respond |
| Audit and certification | Buyer can be asked to certify compliance and give reasonable audit access | Makes the covenant checkable |
| Return or deletion | Data removed on termination, to the extent technically possible | Closes the loop |
The quasi-identifier problem sits underneath all of this: combinations of ordinary fields such as role, location and dates can single someone out. Read quasi-identifiers and re-identification risk in workplace data to see why the clause needs a linkage limb.
Who is liable if licensed data is re-identified?
Liability follows the contract and the facts, so there is no single answer. Several parties can be in play.
- The buyer, for breach of the covenant, and possibly for any statutory exposure its own conduct creates.
- A sublicensee or contractor of the buyer, if it was bound in writing; if it was not, the buyer is the one who failed to pass the restriction down.
- The company that licensed the data, if its de-identification was inadequate, if it promised more than it delivered, or if its original privacy notices did not allow the use.
- The intermediary, to the extent its own contract allocates responsibility.
The FTC has said in staff guidance that companies' promises about how customer data will or will not be used are enforceable, whether made in privacy policies, terms of service or promotional materials. That is staff guidance, not a rule, but it shows why a company should only promise what its contract and process can back up.
Practical allocation terms to look for are an indemnity from the buyer for breach of the covenant, a cap structure that does not water the covenant down, and a clear statement that the company's de-identification effort does not warrant that re-identification is impossible.
How does this connect to field of use and residuals?
Three clauses tend to be negotiated together. The no-re-identification clause bans a specific act. A field-of-use restriction limits what the data may be used for at all. A residuals clause can quietly widen what a buyer may keep, so check that it does not carve out an exception to the re-identification ban. Buyers also have their own reasons to want clean provenance, a theme explored in why buyers want licensed data after FTC disgorgement orders.
A checklist for reviewing the clause
Use this before the owner signs. Counsel makes the final call.
- The ban covers the buyer, its affiliates, employees and contractors.
- It names linkage with other datasets and extraction from model outputs.
- Sublicensees and processors must sign equivalent terms, and the buyer stays responsible for them.
- The company can ask for a compliance certification and has audit or inquiry rights.
- Breach notice runs on a stated clock.
- Remedies include injunctive relief, not only damages.
- The residuals clause, if any, does not override the ban.
- The survival period for the covenant is at least as long as the buyer keeps the data or any model trained on it.
- The company's own warranties about de-identification are limited to the process it agreed, not to a guarantee of anonymity.
What does this mean for a referral partner?
A partner never drafts, negotiates or describes contract terms, and never handles records. Your value is recognising that an owner who asks "what stops a buyer from figuring out who our customers are?" is asking a good question and deserves a real answer from the people who run the process.
Check your own professional rules on referral fees and disclosure before registering. The reward is a share of SourceX's fee and is never deducted from what the company receives. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed.
When does a covenant not solve the problem?
A contract cannot repair data that was never properly prepared. If the dataset is mostly consumer personal data with no licensing basis, or contains health information without authorization or de-identification, the clause is not the fix. In those cases, return to the scope. A related regulatory view for financial-sector clients is in GLBA reuse and redisclosure limits.
Next step
If you know an owner with 50+ full-time employees at peak (contractors excluded) and years of operational records, register as a partner and make the introduction. The owner can also screen the company first with the company fit checker, and the full sequence is on the how SourceX referrals work page.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Is a contractual ban on re-identification legally required?
For California's deidentified-information definition, a contractual commitment from recipients is one of the elements, according to the statute's definitions. Other regimes and company privacy promises can add their own expectations. Because requirements differ by data type and jurisdiction, ask counsel which apply to your records.
Does a no-re-identification clause make data anonymous?
No. The clause is a promise about future behavior and sits alongside technical de-identification. It reduces risk but does not make re-identification impossible, which is why a license should avoid warranting that the data can never be re-identified and should combine redaction, scope limits and contract terms.
What does the clause say about trained models?
A strong clause forbids using prompts, probing or extraction techniques to recover individuals or specific records from a model trained on the data. This model-output limb is newer than the classic linkage ban, so check that the license actually includes it and covers sublicensees.
Can the company audit the buyer?
Often through a certification and reasonable inquiry right rather than a full inspection. Whether audit rights are practical depends on negotiation, buyer standards and the data involved. Ask counsel to confirm what is realistic and what remedy exists if the buyer declines.
Do partners get involved in contract terms?
No. Partners introduce the company and share basic fit information only. Contract terms, redaction rules and delivery are agreed between the company and SourceX, with the company's own counsel reviewing, and nothing is binding until the company signs.
Related pages
- CCPA deidentified data: the three commitments a company must make
- Quasi-identifiers and re-identification risk in workplace data
- Field-of-use restrictions in data licenses explained
- What is a residuals clause, and why does it matter in a data license?
- FTC algorithmic disgorgement and why AI buyers want licensed, documented data
- GLBA reuse and redisclosure: can vendors use bank customer data?
Free resources
- AI readiness assessment — Ten questions, five dimensions, a score out of 100.
- EBITDA calculator — Reported and adjusted EBITDA from net income.
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment