Why is de-identification harder in a close-knit team?
Because in a small, long-tenured team, context identifies people even after names are gone. When twelve people share a project and one of them is the only person who ever writes about a particular client in a particular style, removing the name does not remove the person.
This page explains how that happens, which records are most exposed, and what reduces the risk. It is written for owners and sponsors deciding whether a license is safe for their workforce. It is general information, not legal, tax or financial advice, and privacy rules vary by state and data type, so confirm with your own counsel.
How do people get re-identified from cleaned records?
Re-identification works by linking details, not by finding a name. Critics of recent corporate data deals have argued that long careers and distinctive context make workers recognisable even after personal identifiers are stripped. Treat that as an argument to test against your own records, not a settled finding.
| Clue | Example in a cleaned record | Why a small team is exposed |
|---|---|---|
| Unique role | "As the only dispatcher on night shift..." | One person fits the description |
| Project detail | A named internal system or client code | Few people worked on it |
| Timing | Messages at consistent odd hours | Habits are distinctive |
| Writing style | Favourite phrases, sign-offs, formatting | Colleagues recognize it instantly |
| Tenure markers | "Back when we moved offices in 2016..." | Narrows the author to the people present then |
| Linked facts | A date plus a role plus a location | Combined, they point to one individual |
Which parts of a company are most at risk?
Not every unit is equally exposed. A 400-person company may have a handful of fragile pockets inside an otherwise robust dataset.
- Executive and finance teams of five or fewer people.
- Specialist groups where one person holds a unique title.
- HR, legal and compliance channels, where content is sensitive and the authors are few.
- Regional offices with a handful of staff.
- Long-tenured groups that share inside references accumulated over many years.
SourceX works with companies that have 50+ full-time employees at peak (contractors excluded), which gives more people to blend into, but the pockets above still need attention and a bigger headcount does not remove them.
What reduces the risk?
Controls stack. No single one is enough.
- Stronger redaction of roles and projects. Replace unique job titles with generic ones and mask internal system names and client codes, not just personal names.
- Exclude small units. Leave out any team below a size the company sets, along with HR, legal and executive channels.
- Aggregate or sample. Release workflows with broader date buckets instead of exact timestamps where the use case allows it.
- Shorten the exposure window. Limit the date range to the years that carry the training value.
- Contractual terms. Require the buyer not to attempt re-identification, not to link the data with other sources and not to redistribute it.
- Test before delivery. Review samples with people who know the team, because colleagues are the best judges of whether a message still sounds like someone.
Redaction rules are agreed with the company before work begins, and delivery follows only an executed agreement and the company's authorization. For how the cleaning itself is verified, see what independent scrubbing means.
A quick test for your own team
Use a "colleague read" before approving any sample.
- Give five long-serving staff a set of cleaned messages and ask who wrote each.
- If more than a couple are guessed correctly, strip more context or exclude the unit.
- Repeat with the redaction rules revised.
- Record the result and the decision.
Illustrative: a fictional 90-person engineering firm runs this test on its platform team of six and finds nearly every message is attributed correctly. It excludes that team, keeps the wider engineering archive, and proceeds.
What does this mean for liability and buyers?
Re-identification risk feeds directly into legal exposure and buyer diligence. Read whether licensing can get a company sued for the risk map, and what AI buyers do with licensed records to understand the use side. If the buyer is later breached, the breach question matters too. Employees will ask about all of this, so what employees think is worth reading before an announcement. Sponsors can add portfolio reputational risk to the same review.
What this means for referral partners
Partners never see or handle records, so your role is to raise the topic honestly, not to certify safety. If an owner mentions a tight team, encourage them to ask for the controls above. Partners earn 25% of the eligible platform fees SourceX actually collects from the referred company's licensing deals, capped at $100,000 per referred company. The reward is paid only after the buyer pays and SourceX receives its fee; an introduction, meeting or signed agreement alone does not trigger payment, and no reward is guaranteed. See the referral earnings calculator and the FAQ for how the program works.
When to walk away
Skip a license, or wait, when the dataset is mostly drawn from a very small group, when the owner cannot exclude fragile units, or when the company is unwilling to accept a re-identification ban in the contract.
Next step
If a US company you know has 50+ full-time employees at peak (contractors excluded), years of records and an authorized sponsor, register as a partner and introduce it. Owners can also apply at sourcex.si/apply.