CCPA deletion requests and licensed AI training data: what happens to records?
Under the CCPA, a deletion request reaches personal information a covered business holds about the person asking. Records properly de-identified before a license generally fall outside that reach, while identifiable records need a request-handling process settled before delivery. That makes deletion rights a scoping decision for counsel, not a reason to rule out licensing.
The short answer
A CCPA deletion request reaches personal information a covered business holds about the person asking. Records that have been properly de-identified before a license generally sit outside that reach, while identifiable records need a way to honor requests before anything is delivered. So the right response to the objection is a scoping decision, not a refusal to consider licensing.
The worry behind the objection is fair. Once records have been used to train a model, taking one person's contribution back out is not a simple delete; researchers call the problem machine unlearning, and it remains hard. That is exactly why the decision about identifiable data has to be made before delivery, not after.
What the CCPA actually provides
The California Attorney General's CCPA overview lists the core rights: to know what personal information a business collects, to delete it, to opt out of its sale or sharing, and not to be discriminated against for using these rights. Since January 1, 2023, consumers can also correct inaccurate information and limit the use of sensitive personal information. The law applies to for-profit businesses that do business in California and meet any one of three tests, and rulemaking now sits with the California Privacy Protection Agency.
Three points follow for workplace and customer records:
- Whether the statute reaches applicants, employees and former employees who live in California is a point to confirm with counsel; assume workforce records can be in scope.
- The right to delete has statutory exceptions; which ones apply to a given record is a question for counsel.
- Consumers generally cannot sue under the CCPA except over certain data breaches, so enforcement mostly runs through regulators.
This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.
How record status changes the deletion question
| Record status | Deletion exposure | What to do before delivery |
|---|---|---|
| Identifiable raw records | Requests apply | Exclude them, or build a request-handling process first |
| Pseudonymized: names swapped for codes, key retained | Usually still personal information | Treat as identifiable |
| De-identified to the statutory standard, with controls against re-identification | Generally outside the right | Document the method and keep contractual no-re-identification terms |
| Aggregated statistics | Outside | No individual handling needed |
Pseudonymization is the trap. Replacing names with codes while keeping the lookup table leaves the data linkable, and therefore inside the request process.
De-identification is a process, not a label. Counsel will usually want to see what was removed or transformed, how free-text fields such as ticket comments and email bodies were handled, and which contract terms stop the recipient from trying to re-link the data. Keep that record with the license file, because it is the evidence that a later request does not reach the delivered dataset.
How to answer the owner
The default exclusion list shows which categories never enter a scope at all.
If the concern is valid
Some records cannot be fully de-identified. Voices in call audio, and small teams where a job title points to one person, are common examples. In those cases:
- Pull every deletion request received during the history period and suppress those people's records before any export.
- Exclude audio, or any record type, that cannot be de-identified to counsel's standard.
- Fix a scope cut-off date and agree with counsel how requests received after it will be handled.
- File the method, the dates and counsel's sign-off alongside the data inventory.
Other jurisdictions add their own questions. The guide to state AI laws in 2026 covers US developments, and the EU AI Act training data summary guide explains what developers disclose about licensed datasets.
What partners should say
When an owner raises deletion rights, answer in one sentence: de-identification rules are agreed before work begins, and anything identifiable is excluded or handled first. Do not offer a legal opinion or predict an outcome; the scoping call belongs to the company and its advisers. Then let SourceX and the company's counsel take it from there. The company fit checker is a useful first step before that conversation.
Next step
Register as a partner to introduce a company whose owner has raised this question, and share how it works so they can see each stage before any data moves.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Do former employees have CCPA deletion rights?
Former employees who are California residents may be able to make requests to a covered business, including deletion requests, subject to the statute's exceptions; counsel should confirm how the law applies to workforce records. Employers often keep some records for legal, tax or litigation reasons that may fall within those exceptions. For licensing, the practical step is to suppress the records of anyone who has asked for deletion before an export is prepared.
What happens if a deletion request arrives after the data has been delivered?
If the delivered records were properly de-identified, nothing should link them to the requester, so the request is handled in the company's own systems. If any identifiable data was in scope, the license agreement should already say how such requests are handled. That is a term the company and its counsel negotiate before signing, not something to improvise afterward.
Is machine unlearning a reliable way to honor deletion requests?
It is not something to rely on. Removing a specific person's influence from a trained model is an active research area, and a data supplier cannot control or verify it. The dependable approach sits upstream: de-identify records before delivery, exclude what cannot be de-identified and suppress the records of people who have already asked for deletion.
Does every company have to honor CCPA requests?
No. The CCPA applies to for-profit businesses doing business in California that meet at least one of three thresholds, based on annual revenue, the volume of personal information handled, or revenue from selling or sharing it. A company below all three may not be covered, though other state laws, contracts or promises in its own privacy notices can still apply.
Is pseudonymized data enough to avoid deletion requests?
Usually not. If names are replaced with codes but the company keeps the key, the records can still be linked back to individuals and are generally treated as personal information. Treat pseudonymized data as identifiable for scoping purposes, and ask counsel which de-identification method and safeguards would meet the statute's standard.
Related pages
- What data should be excluded from AI training? A default exclusion list
- State AI laws in 2026 that touch AI training data: what to check before licensing
- EU AI Act training data summary: what it means if you license your company's data
- Check Company Fit for Data Licensing
- How SourceX US company data referrals work
Free resources
- MOIC calculator — Multiple on invested capital from realized and unrealized value.
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment