Skip to content

5 min read

Permissions and privacy before sharing data

Why access, ownership, and anonymity need separate checks.

Access is not the same as licensing permission

A team may be allowed to use a record in its daily work without being allowed to license it for another purpose. Review the proposed use against the rights and agreements that cover the source.

Consider customer agreements, employee information, third-party materials, confidentiality duties, and the rules that apply in the relevant countries.

Define what the buyer needs

Start with the learning task, then identify the minimum information required. Exclude material that does not support that task.

Private channels, credentials, payment details, sensitive personal information, and restricted material should be flagged before a sample is prepared.

Removing names is only one step

A record may still identify someone through unusual events, dates, locations, or combinations of details. Replacing a name with a code is often pseudonymisation: the data may still relate to an identifiable person.

Anonymisation requires a separate assessment of whether identification remains reasonably possible. The Information Commissioner’s Office explains this distinction in its anonymisation guidance.

Agree and record the controls

Define who can review a sample, where it will be held, how it will be transferred, how long it may be kept, and what happens if the scope changes.

Resolve legal and permission questions with the people qualified to decide them. An intake assessment does not approve a transfer or replace legal advice.

Source: Information Commissioner’s Office: anonymisation and pseudonymisation.

Put it into an inventory.

Describe the records your team holds. You can start without a raw export.

See if your data qualifies

Keep reading.