Situations
Some of our data is regulated. Can we still license the rest?
On this page
- Which rules might cover our records?
- If one of these rules covers us, is everything we hold regulated?
- How do we carve regulated systems out of scope?
- Where does regulated data turn up in the systems we keep?
- Can we de-identify regulated records instead of leaving them out?
- What do I do next?
Often, yes. HIPAA, GLBA, FERPA, the FCRA, CJIS rules and PCI DSS each attach to particular records or roles, so the systems holding those records can stay out of scope while the rest is licensed. Where regulated records run through everything, less is left.
Which rules might cover our records?
The rules below attach to particular kinds of records that operating businesses hold, for themselves or for clients. Most reach a business either because it is the regulated business or because it works for one. Whether a rule covers a given record is a question for a lawyer who knows that rule.
| Rule | What it covers | Where owners meet it | More |
|---|---|---|---|
| HIPAA | Health information held by health plans, clearinghouses and providers that conduct standard transactions such as claims electronically, and by business associates that handle it for them under the written contract HHS requires (HHS) | A practice or clinic; an IT firm, biller or answering service working for one | Dental practices, IT managed services |
| GLBA | Consumers’ nonpublic personal information held by financial institutions, which may not pass it to an unaffiliated third party without notice and a chance to opt out, apart from listed exceptions (15 U.S.C. §6802). The FTC’s examples include “mortgage brokers”, finance companies, collection agencies and tax preparation firms | Insurance agencies, where state insurance law enforces the rules (§6805); lenders, collection firms, tax preparers | Insurance agencies, Accounting |
| FERPA | Education records at schools that receive US Department of Education funds (34 CFR 99.1). A party that receives them may not pass them on “without the prior consent of the parent or eligible student” (§99.33), apart from listed exceptions | Software, IT, tutoring, transport and other contractors to schools | See below |
| FCRA | Consumer reports: background checks, credit reports, tenant screening. A person “shall not use or obtain a consumer report for any purpose” unless the act authorizes it (§1681b(f)) | Hiring files, tenant and credit applications | Staffing agencies, Property management |
| CJIS | Criminal history records that police, courts or jails share with private contractors under a security addendum that must “limit the use of the information to the purposes for which it is provided” (28 CFR 20.33(a)(7)). The FBI’s CJIS Security Policy, version 6.1 as of October 2026, sets security rules for criminal justice information more broadly | IT firms, software vendors and other contractors serving police, courts or jails | IT managed services |
| PCI DSS | A security standard, not a law, for entities that “store, process, or transmit cardholder data”. Whether a business must comply is up to “organizations that manage compliance programs, such as a payment brand, acquirer, or other entity”, so for a merchant it typically arrives through the agreement with its card processor or acquirer | Card numbers taken by phone, written on tickets or kept in email | HVAC |
| State privacy laws | Personal data about residents of states with comprehensive consumer privacy laws, which the IAPP tracker lists (updated September 8, 2026); each sets its own size thresholds and rules on selling data | Any business with consumer customers | Is it legal? (Texas and California), UK and EU |
The industry pages cover other record-specific rules, such as those for tax-return information under IRC §7216 (accounting), drug and alcohol test results (trucking), driver records (insurance agencies) and consumer credit reports on guarantors (wholesale distribution).
If one of these rules covers us, is everything we hold regulated?
Not necessarily; each rule names the records it covers. HHS, for one, says the HIPAA Privacy Rule “does not protect your employment records, even if the information in those records is health-related”. The other rules in the table are limited to the records they name too, which cuts both ways.
- A regulated business keeps other systems too. A clinic’s supply orders and an insurance agency’s own books are usually records of running the business rather than patient or policyholder files, though regulated details can turn up in them (below).
- An unregulated business can hold regulated records. An IT firm serving a clinic, a bus contractor serving a school district or a software vendor serving a sheriff’s office holds those records under the client’s rule and contract, which set what may be done with them. The IT managed services page covers clients’ data in more detail.
School contractors should read the redisclosure limit above and FERPA’s rule for de-identified records (below) alongside their contract with the school or district.
How do we carve regulated systems out of scope?
By whole system where you can, named in the agreement. Frankfurt Kurnit’s October 1, 2026 commentary advises: “Exclude high-risk data entirely rather than relying on de-identification.” Systems built around regulated records include:
- practice-management, imaging and claims systems;
- agency management, loan origination and collection platforms;
- student information systems and anything a school gave you access to;
- background-check, credit and tenant-screening portals and the reports saved from them;
- payment gateways and card terminals;
- a client’s records system that your staff administer.
For wording that holds up, see how to leave out records. Several providers’ pages plan for regulated records, as of October 2026. Avelence’s profile form lists “Regulated records” among known restrictions. Corpus asks sellers to keep out “Patient health records or anything covered by HIPAA”, “Payment card data and bank credentials” and “Government-issued identification numbers”. micro1’s payout estimator asks “Does your data include regulated or sensitive information?”, and Miro Advisory says “Healthcare and other regulated industries can qualify, but require substantially greater privacy, consent and regulatory review.” SimpleClosure, which sells closing startups’ data, said in a September 3, 2026 release that “Sensitive employee and health records, as well as any information sellers designate as out of scope, are not sold.” Telegraph Lab (affiliated with Data Licensing Report) says “Regulated, privileged, or third-party information requires additional review and may need to be excluded.”
Where does regulated data turn up in the systems we keep?
In the general-purpose systems people use to talk about the regulated work. Check these before anything from them goes into a sample:
- Email attachments: background-check PDFs, explanation-of-benefits forms, loan applications, class rosters.
- Call recordings and call notes: card numbers read aloud; the HVAC page quotes the PCI Council’s guidance on recordings.
- Accounting memo fields: patient, borrower or student names on deposits and refunds.
- Shared drives and chat: HR folders and messages with medical notes; Is it legal? covers employees’ medical leave records.
Data Licensing Report’s sample tool replaces card numbers that pass the standard checksum, and Social Security numbers in the usual formats, in the sample it prepares from a mailbox, Slack export or CSV, and shows how many of each it replaced. A count above zero shows where to look; a zero covers only the sample and does not replace reading.
Can we de-identify regulated records instead of leaving them out?
Sometimes, by each rule’s own test, and not under every rule:
- HIPAA: HHS says “There are no restrictions on the use or disclosure of de-identified health information”, meaning information that meets HIPAA’s de-identification standard. The dental practices page explains its two methods and what they remove.
- FERPA: a school, or a party that received education records from one, may release them without consent “after the removal of all personally identifiable information”, provided a reasonable determination is made that a student’s identity is not personally identifiable (§99.31(b)(1)). Your contract with the school may say more.
- Tax-return information: anonymizing does not take it outside §7216; see accounting.
- Card data: the PCI Council’s telephone-payments guidance (November 2018) says sensitive authentication data, which includes the card verification code, “must not be stored after authorization, even if encrypted”.
As of October 2026, five providers name patient or clinical records, or clinics, and the dental practices page lists them. Of those, only License My Data names a HIPAA method, “Expert determination under HIPAA for US records”, and it adds “Consent must be documented, not asserted.” Who performs de-identification, and under which test, is a question for counsel before any regulated record moves.
What do I do next?
- List every system, and mark those built around regulated records.
- Note your role for each, whether you are the regulated business or a vendor under a client’s contract, and find that contract: the business associate agreement, the school or district contract, the CJIS addendum, the merchant agreement.
- Take the list to a lawyer who knows each rule that applies, whether healthcare, financial privacy, education or criminal justice.
- Check the systems you keep for regulated details, with the sample tool and by reading.
- Apply with the regulated systems named as out of scope. The application needs no files.
- Write the exclusions into the agreement before any sample or export leaves.
Providers named on this page
Get offers
Find the next step for your company’s data.
- No records or exports needed to apply
- Free for businesses
- Your company profile comes to our team for review