Compliance · Data licensing
Can a business legally license its own customer data?
The question almost every owner asks first, and the answer is more specific than either yes or no. It turns on one definition, and on what you did to the data before anyone else saw it.
WritingBy Landon LittleSeptember 28, 20267 min read
The honest answer
Usually yes, but not in the form it is sitting in right now. There is no single federal statute that says a business may not license data it holds. What there is instead is a layer of state privacy law, a layer of sector-specific rules, and a layer of promises you have already made in your own documents. All three have to clear.
That is a more useful answer than a flat yes or no, because it tells you where the work is. Almost all of it happens before the data leaves your systems, and almost none of it is about the transaction itself.
What counts as a sale, and why the definition is so wide
California's Consumer Privacy Act is the most commonly cited reference point, and its definition of a sale is deliberately broad. Under Civil Code section 1798.140, subdivision (ad)(1), sell, selling, sale, or sold means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating a consumer's personal information by the business to a third party for monetary or other valuable consideration.
Two things in that sentence do more work than people expect. Making available is in the list, so you do not have to hand anything over for it to count. And monetary or other valuable consideration means a barter, a discount, or a credit lands in the same place as a cheque.
Where a transfer is a sale of personal information, consumers have a right to opt out of it under section 1798.120. That is not a fatal problem, but it is an operational one: you would be taking on an ongoing obligation to honor opt-outs against data you have already licensed to somebody else.
The mechanism the statute itself provides
The same statute supplies the way through. Section 1798.140, subdivision (v)(3) states plainly that personal information does not include consumer information that is deidentified or aggregate consumer information.
If the information is not personal information, the sale rules built on top of personal information do not reach it. That is the whole architecture, and it is why every serious data licensing arrangement is built around deidentification rather than around consent.
The catch is that deidentified is a defined term with three conditions, not a description of effort. Under subdivision (m), it means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, provided that the business possessing it does all of the following.
- Takes reasonable measures to ensure that the information cannot be associated with a consumer or household.
- Publicly commits to maintain and use the information in deidentified form and not to attempt to reidentify it, except to test whether its own deidentification process works.
- Contractually obligates any recipients of the information to comply with all of the same provisions.
Health data is a separate regime, not a harder one
If what you hold is protected health information, none of the above is the governing test. HIPAA has its own deidentification standard at 45 CFR 164.514(b), and it offers two routes.
- Safe Harbor, at 164.514(b)(2): remove eighteen enumerated identifiers, including names, most geographic subdivisions, dates, phone and fax numbers, email addresses, URLs, IP addresses, Social Security numbers, medical record numbers, device identifiers and serial numbers, vehicle identifiers, and biometric identifiers, and have no actual knowledge that what remains could identify a person.
- Expert Determination, at 164.514(b)(1): a person with appropriate statistical and scientific expertise determines that the risk of reidentification is very small, and documents the analysis supporting that conclusion.
Safe Harbor is used more often simply because it is precisely specified and therefore easier to demonstrate. Neither route is something to attempt from a blog post. If you are in this category, the first call is to counsel, not to a broker.
Your own documents can be stricter than the law
This is the constraint that catches people, because it does not appear in any statute. Your privacy policy is a public promise. Your customer agreements are private ones. Your vendor contracts may restrict what you can do with data that passed through their systems.
A statute sets a floor. A promise you published sits above it, and nothing about a licensing deal erases it. If your privacy policy says you never share customer information with third parties, that sentence governs you regardless of how thoroughly you deidentified anything.
The practical sequence is therefore backwards from what most people expect. Read your own documents first. Then look at the statute. Then think about a transaction.
What a defensible version looks like
- The copy that leaves is deidentified to a defined standard, not simply stripped of obvious names.
- You have published the commitment the definition requires, not just made it internally.
- Every recipient is contractually bound to the same conditions, including not attempting reidentification.
- The license is non-exclusive and scoped, so you have not signed away the ability to use your own records.
- You keep every original, in your own systems, unchanged.
- Anything touching health, legal privilege, or children gets sector-specific advice before anything moves.
None of that is exotic, and none of it is fast. It is the difference between a transaction you can explain to a regulator, a customer, or an acquirer, and one you cannot. Again: this is general information about published rules, not legal advice. Before anything leaves your systems, have a lawyer look at your situation specifically.
Sources
- California Consumer Privacy Act, Cal. Civ. Code 1798.140(ad)(1), definition of sell, selling, sale, or sold.
- Cal. Civ. Code 1798.140(m), definition of deidentified and its three conditions.
- Cal. Civ. Code 1798.140(v)(3), personal information does not include deidentified or aggregate consumer information.
- Cal. Civ. Code 1798.120, the consumer right to opt out of sale or sharing.
- HIPAA Privacy Rule, 45 CFR 164.514(b)(1) Expert Determination and 164.514(b)(2) Safe Harbor, with guidance published by the US Department of Health and Human Services.
Questions this post answers
- Is it legal to sell customer data?
- Selling identifiable customer data is legal in many US contexts but heavily regulated, and under the CCPA it counts as a sale that consumers can opt out of. Licensing properly deidentified data is a different question, because the CCPA states that personal information does not include consumer information that is deidentified or aggregate consumer information. The work is in meeting the statutory definition of deidentified, not in the sale itself.
- What counts as a sale under the CCPA?
- The statute defines it broadly. Selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating a consumer's personal information to a third party for monetary or other valuable consideration. Note the last five words: you do not need to be paid in cash for it to count.
- Does deidentifying the data actually solve it?
- It is the mechanism the statute itself provides, but it is a three-part test, not a single step. California requires reasonable measures so the information cannot be associated with a consumer or household, a public commitment to keep it deidentified and not attempt reidentification, and a contractual obligation on any recipient to comply with the same rules. Strip names and stop there and you have not met it.
- What if my business holds health records?
- Then a different and stricter regime applies. HIPAA sets out two methods for deidentifying protected health information: removing eighteen enumerated identifiers under the Safe Harbor method, or an Expert Determination that the reidentification risk is very small, documented by a qualified person. Health data is not a harder version of the same problem, it is a separate one, and it needs sector-specific advice.
- Can my own contracts stop me even if the law allows it?
- Yes, and this is the trap people miss. Your published privacy policy, your customer terms, and your vendor agreements may each promise things about how data is used. A statute setting a floor does not override a promise you made above it. Read your own documents before you read anyone else's.
- Is this legal advice?
- No. It is general information about publicly available statutory text, written for owners deciding whether the idea is worth exploring at all. Your state, your sector, and the specific data you hold all change the answer. Get advice from a lawyer before acting on any of it.
Wondering what your own data is worth?
We broker the deal on your behalf: you approve the buyer and the price, you keep every original, and nothing is owed unless a deal closes.