Key takeaway

Open access does not mean unrestricted downstream licensing. Keep the incoming license and the rights in individual contents visible before promising exclusivity, confidentiality or reuse controls.

Keep the upstream component identifiable

An owner can add substantial engineering work to an open database without removing its incoming conditions. Preserve the source URL, downloaded version, license text, notices and transformation history. Record which fields or rows came from that source and which were independently created. The resulting provenance file should explain the proposed product, rather than merely list a public website in a footnote.

ODbL 1.0 grants database permissions subject to conditions. It distinguishes database rights from rights in individual contents, and distinguishes a Derivative Database, a Collective Database and a Produced Work. Open Data Commons explains why the contents may need separate treatment and why substantiality is not a fixed row-percentage test. Classification is a fact-sensitive review, not a label chosen to fit the commercial offer.

Ask what will be used publicly under the license’s definition. That question is broader than whether a file is posted on the open internet. A delivery to someone outside the organization can require review of the public-use conditions. Internal access controls and an NDA do not by themselves tell you which license conditions follow the proposed transaction.

A completed incoming-license trace

Hypothetical example: an owner copies a substantial ODbL database of public facility locations, corrects coordinates and adds independently collected opening hours. For this example, assume the modified location database is a Derivative Database; that assumption must be tested for a real product. The proposed customer would receive that database and a map generated from it under an exclusive, no-redistribution agreement.

The trace below exposes the conflict before a customer receives an offer. It does not decide whether every join, enrichment or map is derivative. Keeping the source component, added fields and outputs separate gives a qualified reviewer enough detail to examine the actual classification and the terms the owner can reasonably propose.

Component or promiseIllustrative treatmentOffer consequence
Copied and corrected facility databaseAssumed substantial Derivative Database for this exampleReview share-alike and access-offer conditions before public use.
Added opening hoursIndependently gathered, but included in the assumed derivativeReview what must accompany an access offer; preserve separate origin evidence.
Customer mapProduced Work from the assumed derivativeReview notice and underlying-database access obligations.
Exclusive database rightsIncoming ODbL rights remain relevantDo not promise sole rights to the upstream component.
No redistributionProposed restriction may conflict with incoming conditionsRewrite only after assessing the license and the exact deliverable.
Photographs of facilitiesNot included in the database-rights conclusionCheck image, privacy and other content rights independently.
DecisionCurrent offer conflicts with the assumed license treatmentHold the offer; redesign deliverables and review downstream wording.

Put the obligation on the right deliverable

ODbL’s public-use conditions address notices, share-alike for qualifying derivative databases, access to a qualifying underlying database or alterations, and restrictions on granted rights. A Produced Work is not simply licensed as if it were the database, but its origin can bring notice and database-offer conditions into the review. Read the actual pathway for the proposed output instead of assuming that either every output must be open or every output escapes upstream conditions.

Separate three files in the review package: provenance and license terms; transformation and component classification; and the proposed delivery agreement. For each promise in the agreement, identify the component it covers. A customer may pay for service, independent material or another permitted offering, but that commercial structure does not erase upstream rights. Ask whether a separately maintained collective arrangement is actually feasible, rather than changing the label on the same merged database.

Record the reviewer’s decision and the release version. If an engineer later replaces a small component with a substantial upstream extract, reopen the classification. If a sales team adds exclusivity or a redistribution ban, reopen the terms review. The inventory tool can track source components; rights review can hold the incoming-license evidence. This guide is limited to ODbL 1.0 as read on 10 October 2026. Other open licenses differ, and the real classification, individual-content rights, privacy obligations and contract enforceability require their own assessment.

Tools for this decision

Data inventory builder →Rights & privacy review →