Compliance · Data licensing

What de-identified actually means, and what it does not

It is the word every data licensing conversation turns on, and it is used loosely almost everywhere. In the two places it is defined precisely, it is a test with conditions rather than a description of effort.

WritingBy Landon LittleSeptember 28, 20266 min read

Why one word carries the whole deal

In a data licensing arrangement, de-identified is not marketing language. It is the hinge the entire structure hangs on, because the CCPA states that personal information does not include consumer information that is deidentified or aggregate consumer information. Clear the definition and the privacy obligations built on personal information do not reach the data. Miss it, and they all do.

Which makes it worth knowing that four words get used interchangeably in ordinary conversation, two of them are defined in the statute, and they do not mean the same thing.

De-identified: a three-part test

Under Civil Code section 1798.140, subdivision (m), deidentified means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, provided the business that possesses it does three things.

  • Takes reasonable measures to ensure the information cannot be associated with a consumer or household.
  • Publicly commits to maintain and use the information in deidentified form and not to attempt to reidentify it, except to test whether its own deidentification process works.
  • Contractually obligates any recipient to comply with all of the same provisions.

Pseudonymized: the key still exists

The CCPA defines pseudonymization separately, at subdivision (aa): processing personal information in a manner that renders it no longer attributable to a specific consumer without the use of additional information, provided that the additional information is kept separately and is subject to technical and organizational measures ensuring the personal information is not attributed to an identified or identifiable consumer.

Read that carefully and the difference is obvious. Pseudonymization assumes a key exists and is being kept somewhere safe. De-identification claims the link cannot reasonably be rebuilt at all. Swapping customer names for stable customer IDs is pseudonymization. It is a genuine safeguard, and it is not the same claim.

Aggregate: a different category, not a stronger one

Aggregate consumer information is defined at subdivision (b) as information relating to a group or category of consumers, from which individual consumer identities have been removed, that is not linked or reasonably linkable to any consumer or household, including via a device.

Then the definition adds a sentence that settles a very common misconception: aggregate consumer information does not mean one or more individual consumer records that have been deidentified.

So rolling records up into counts and averages is aggregation. De-identifying a million individual rows is not aggregation, however many rows there are. They are two separate categories with two separate tests, and only the statute's own words settle which one you are in.

HIPAA runs its own standard entirely

For protected health information none of the above applies. HIPAA sets its own de-identification standard at 45 CFR 164.514(b), with two routes.

The two HIPAA de-identification methods
MethodRuleWhere it is defined
Safe HarborRemove eighteen enumerated identifiers, and have no actual knowledge that the remaining information could identify a person45 CFR 164.514(b)(2)
Expert DeterminationA person with appropriate statistical and scientific expertise concludes the reidentification risk is very small, and documents the analysis45 CFR 164.514(b)(1)

The eighteen identifiers include names, most geographic subdivisions, dates, telephone and fax numbers, email addresses, URLs, IP addresses, Social Security numbers, medical record numbers, device identifiers and serial numbers, vehicle identifiers, and biometric identifiers. Safe Harbor is used more often than Expert Determination, mostly because it is specified precisely enough to demonstrate.

What to do with this in a real negotiation

  • Define the term in the agreement itself. Do not let anonymized do load-bearing work when it has no statutory definition.
  • Check that the public commitment actually exists and is published, not just agreed internally.
  • Check the recipient-obligation clause is present and binds downstream recipients too.
  • Be honest internally about whether you have de-identified or pseudonymized. If someone in the building holds a key, you have pseudonymized.
  • If any of it is health data, stop and use the HIPAA standard with proper advice.

This post describes published statutory text. It is general information, not legal advice, and it cannot account for your sector or the specific records you hold. Have a lawyer look at the actual data before you agree to a definition in a contract.

Sources

  • Cal. Civ. Code 1798.140(m), definition of deidentified.
  • Cal. Civ. Code 1798.140(aa), definition of pseudonymize and pseudonymization.
  • Cal. Civ. Code 1798.140(b), definition of aggregate consumer information.
  • Cal. Civ. Code 1798.140(v)(3), personal information does not include deidentified or aggregate consumer information.
  • HIPAA Privacy Rule, 45 CFR 164.514(b)(1) and 164.514(b)(2), with de-identification guidance published by the US Department of Health and Human Services.

Questions this post answers

What does de-identified data mean?
Under the CCPA it means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular consumer, provided the business takes reasonable measures to ensure it cannot be associated with a consumer or household, publicly commits to keep it that way and not attempt reidentification, and contractually obligates any recipient to do the same. It is a three-part test, not a description of how hard you tried.
Is de-identified the same as anonymized?
Not in US statutory terms. Anonymized is a common-usage word that appears in everyday conversation and in some non-US frameworks, but the CCPA does not define it. What the CCPA defines is deidentified, and that is the term that determines whether the privacy obligations apply. Using anonymized in a contract without defining it leaves the most important word in the deal undefined.
What is the difference between de-identified and pseudonymized?
Pseudonymization, defined separately in the CCPA, means processing personal information so it is no longer attributable to a specific consumer without the use of additional information, where that additional information is kept separately and protected. The link still exists. Someone holds the key. De-identification is the stronger claim that the link cannot reasonably be reconstructed at all.
Does aggregating the data count as de-identifying it?
No, and the statute is unusually direct about this. Aggregate consumer information means information about a group or category of consumers that is not linked or reasonably linkable to any consumer or household, and the definition ends by stating that it does not mean one or more individual consumer records that have been deidentified. They are separate categories with separate tests.
How does HIPAA define it differently?
HIPAA does not use the CCPA test at all. It provides two routes at 45 CFR 164.514(b): the Safe Harbor method, which requires removing eighteen enumerated identifiers and having no actual knowledge that what remains could identify someone, and the Expert Determination method, in which a qualified person concludes and documents that the reidentification risk is very small. If you hold health data, this is your standard, not the CCPA one.

Wondering what your own data is worth?

We broker the deal on your behalf: you approve the buyer and the price, you keep every original, and nothing is owed unless a deal closes.

Book a 20-minute call

Pick a time that works. Twenty minutes on video, no pitch. You leave knowing whether this is worth doing.