Key takeaway
Open access does not mean unrestricted downstream licensing. Keep the incoming license and the rights in individual contents visible before promising exclusivity, confidentiality or reuse controls.
Keep the upstream component identifiable
An owner can add substantial engineering work to an open database without removing its incoming conditions. Preserve the source URL, downloaded version, license text, notices and transformation history. Record which fields or rows came from that source and which were independently created. The resulting provenance file should explain the proposed product, rather than merely list a public website in a footnote.
ODbL 1.0 grants database permissions subject to conditions. It distinguishes database rights from rights in individual contents, and distinguishes a Derivative Database, a Collective Database and a Produced Work. Open Data Commons explains why the contents may need separate treatment and why substantiality is not a fixed row-percentage test. Classification is a fact-sensitive review, not a label chosen to fit the commercial offer.
Ask what will be used publicly under the license’s definition. That question is broader than whether a file is posted on the open internet. A delivery to someone outside the organization can require review of the public-use conditions. Internal access controls and an NDA do not by themselves tell you which license conditions follow the proposed transaction.
A completed incoming-license trace
Hypothetical example: an owner copies a substantial ODbL database of public facility locations, corrects coordinates and adds independently collected opening hours. For this example, assume the modified location database is a Derivative Database; that assumption must be tested for a real product. The proposed customer would receive that database and a map generated from it under an exclusive, no-redistribution agreement.
The trace below exposes the conflict before a customer receives an offer. It does not decide whether every join, enrichment or map is derivative. Keeping the source component, added fields and outputs separate gives a qualified reviewer enough detail to examine the actual classification and the terms the owner can reasonably propose.
| Component or promise | Illustrative treatment | Offer consequence |
|---|---|---|
| Copied and corrected facility database | Assumed substantial Derivative Database for this example | Review share-alike and access-offer conditions before public use. |
| Added opening hours | Independently gathered, but included in the assumed derivative | Review what must accompany an access offer; preserve separate origin evidence. |
| Customer map | Produced Work from the assumed derivative | Review notice and underlying-database access obligations. |
| Exclusive database rights | Incoming ODbL rights remain relevant | Do not promise sole rights to the upstream component. |
| No redistribution | Proposed restriction may conflict with incoming conditions | Rewrite only after assessing the license and the exact deliverable. |
| Photographs of facilities | Not included in the database-rights conclusion | Check image, privacy and other content rights independently. |
| Decision | Current offer conflicts with the assumed license treatment | Hold the offer; redesign deliverables and review downstream wording. |
Put the obligation on the right deliverable
ODbL’s public-use conditions address notices, share-alike for qualifying derivative databases, access to a qualifying underlying database or alterations, and restrictions on granted rights. A Produced Work is not simply licensed as if it were the database, but its origin can bring notice and database-offer conditions into the review. Read the actual pathway for the proposed output instead of assuming that either every output must be open or every output escapes upstream conditions.
Separate three files in the review package: provenance and license terms; transformation and component classification; and the proposed delivery agreement. For each promise in the agreement, identify the component it covers. A customer may pay for service, independent material or another permitted offering, but that commercial structure does not erase upstream rights. Ask whether a separately maintained collective arrangement is actually feasible, rather than changing the label on the same merged database.
Record the reviewer’s decision and the release version. If an engineer later replaces a small component with a substantial upstream extract, reopen the classification. If a sales team adds exclusivity or a redistribution ban, reopen the terms review. The inventory tool can track source components; rights review can hold the incoming-license evidence. This guide is limited to ODbL 1.0 as read on 10 October 2026. Other open licenses differ, and the real classification, individual-content rights, privacy obligations and contract enforceability require their own assessment.
Use this review agenda with your legal and privacy advisers. Requirements depend on the records, jurisdictions and intended use.