CCPA deletion requests and licensed AI training data: what happens to records?

Under the CCPA, a deletion request reaches personal information a covered business holds about the person asking. Records properly de-identified before a license generally fall outside that reach, while identifiable records need a request-handling process settled before delivery. That makes deletion rights a scoping decision for counsel, not a reason to rule out licensing.

The short answer

A CCPA deletion request reaches personal information a covered business holds about the person asking. Records that have been properly de-identified before a license generally sit outside that reach, while identifiable records need a way to honor requests before anything is delivered. So the right response to the objection is a scoping decision, not a refusal to consider licensing.

The worry behind the objection is fair. Once records have been used to train a model, taking one person's contribution back out is not a simple delete; researchers call the problem machine unlearning, and it remains hard. That is exactly why the decision about identifiable data has to be made before delivery, not after.

What the CCPA actually provides

The California Attorney General's CCPA overview lists the core rights: to know what personal information a business collects, to delete it, to opt out of its sale or sharing, and not to be discriminated against for using these rights. Since January 1, 2023, consumers can also correct inaccurate information and limit the use of sensitive personal information. The law applies to for-profit businesses that do business in California and meet any one of three tests, and rulemaking now sits with the California Privacy Protection Agency.

Three points follow for workplace and customer records:

  • Whether the statute reaches applicants, employees and former employees who live in California is a point to confirm with counsel; assume workforce records can be in scope.
  • The right to delete has statutory exceptions; which ones apply to a given record is a question for counsel.
  • Consumers generally cannot sue under the CCPA except over certain data breaches, so enforcement mostly runs through regulators.

This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

How record status changes the deletion question

Record statusDeletion exposureWhat to do before delivery
Identifiable raw recordsRequests applyExclude them, or build a request-handling process first
Pseudonymized: names swapped for codes, key retainedUsually still personal informationTreat as identifiable
De-identified to the statutory standard, with controls against re-identificationGenerally outside the rightDocument the method and keep contractual no-re-identification terms
Aggregated statisticsOutsideNo individual handling needed

Pseudonymization is the trap. Replacing names with codes while keeping the lookup table leaves the data linkable, and therefore inside the request process.

De-identification is a process, not a label. Counsel will usually want to see what was removed or transformed, how free-text fields such as ticket comments and email bodies were handled, and which contract terms stop the recipient from trying to re-link the data. Keep that record with the license file, because it is the evidence that a later request does not reach the delivered dataset.

How to answer the owner

The default exclusion list shows which categories never enter a scope at all.

If the concern is valid

Some records cannot be fully de-identified. Voices in call audio, and small teams where a job title points to one person, are common examples. In those cases:

  1. Pull every deletion request received during the history period and suppress those people's records before any export.
  2. Exclude audio, or any record type, that cannot be de-identified to counsel's standard.
  3. Fix a scope cut-off date and agree with counsel how requests received after it will be handled.
  4. File the method, the dates and counsel's sign-off alongside the data inventory.

Other jurisdictions add their own questions. The guide to state AI laws in 2026 covers US developments, and the EU AI Act training data summary guide explains what developers disclose about licensed datasets.

What partners should say

When an owner raises deletion rights, answer in one sentence: de-identification rules are agreed before work begins, and anything identifiable is excluded or handled first. Do not offer a legal opinion or predict an outcome; the scoping call belongs to the company and its advisers. Then let SourceX and the company's counsel take it from there. The company fit checker is a useful first step before that conversation.

Next step

Register as a partner to introduce a company whose owner has raised this question, and share how it works so they can see each stage before any data moves.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

Do former employees have CCPA deletion rights?

Former employees who are California residents may be able to make requests to a covered business, including deletion requests, subject to the statute's exceptions; counsel should confirm how the law applies to workforce records. Employers often keep some records for legal, tax or litigation reasons that may fall within those exceptions. For licensing, the practical step is to suppress the records of anyone who has asked for deletion before an export is prepared.

What happens if a deletion request arrives after the data has been delivered?

If the delivered records were properly de-identified, nothing should link them to the requester, so the request is handled in the company's own systems. If any identifiable data was in scope, the license agreement should already say how such requests are handled. That is a term the company and its counsel negotiate before signing, not something to improvise afterward.

Is machine unlearning a reliable way to honor deletion requests?

It is not something to rely on. Removing a specific person's influence from a trained model is an active research area, and a data supplier cannot control or verify it. The dependable approach sits upstream: de-identify records before delivery, exclude what cannot be de-identified and suppress the records of people who have already asked for deletion.

Does every company have to honor CCPA requests?

No. The CCPA applies to for-profit businesses doing business in California that meet at least one of three thresholds, based on annual revenue, the volume of personal information handled, or revenue from selling or sharing it. A company below all three may not be covered, though other state laws, contracts or promises in its own privacy notices can still apply.

Is pseudonymized data enough to avoid deletion requests?

Usually not. If names are replaced with codes but the company keeps the key, the records can still be linked back to individuals and are generally treated as personal information. Treat pseudonymized data as identifiable for scoping purposes, and ask counsel which de-identification method and safeguards would meet the statute's standard.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment