You Have the Data. But Can You Use It for That? │ CLICBrain Weekly Briefing – Issue #12

Compliance Intelligence for Online Businesses.

What Changed. Why It Matters. What to Do Next.

 

You Have the Data. But Can You Use It for That?

Operational Compliance Intelligence for Internet Businesses.

Welcome to the CLICBrain Weekly Briefing – operational compliance intelligence for internet businesses from CLIClaw.com.
Each week, we identify significant privacy, AI, advertising, data governance, email marketing, and regulatory developments and focus on what they mean operationally: what systems, workflows, governance controls, and evidence organizations should examine in response.
Following the FTC’s May 4 announcement of a proposed settlement with data broker Kochava and its subsidiary, Collective Data Solutions, the agency’s case docket lists a stipulated order dated June 26, 2026. The matter concerns alleged privacy harms involving precise location data that could reveal visits to medical facilities, places of worship, and other sensitive locations.
The settlement’s restrictions are more specific than a general requirement to obtain consent. The FTC describes a prohibition on selling, licensing, transferring, sharing, or disclosing sensitive location data unless the companies obtain the consumer’s affirmative express consent and the information is used to provide a service directly requested by that consumer.
These are company-specific settlement obligations, not a rule imposing identical requirements on every business or dataset.
But the matter provides a useful operational prompt for data-driven businesses: When your organization obtains personal information, what determines whether it may be used for the next proposed activity? Collection is only the beginning of the data lifecycle.
✔ CLIClaw Compliance Tip: Possessing data and having a defensible basis for a particular use are not necessarily the same thing.

 

 

 

 

 

Data Needs a Purpose – Not Just a Destination.

A business collects or obtains information for one reason.
Then another opportunity appears. Marketing wants better targeting. Analytics wants to combine datasets. Product wants personalization. Sales wants enriched profiles. An AI service can analyze the information. A vendor proposes another use. The data already exists.
So the new activity can feel like a technical decision: “Can the system do it?”
Compliance asks a different question: “Is this use permitted, and under what conditions?”
That requires understanding:
  • Why the information was obtained.
  • What consumers were told.
  • What permissions and restrictions apply.
  • Which choices consumers have exercised.
  • Whether contracts limit the activity.
  • Whether the use creates new disclosures, sensitive inferences, or other risks.
The governing principle is purpose: Evaluate the activity, not merely the availability of the information.
Purpose review is not solely a voluntary governance practice. For businesses subject to the CCPA, collection, use, retention, and sharing must be reasonably necessary and proportionate to the applicable purpose. California also addresses compatibility with the collection context and qualifying consent for processing outside permitted purposes. Other laws may use different standards.
A secondary use is not automatically impermissible. But it should not become routine merely because the data is accessible.

 

 

 

 

 

Pick One Dataset Your Business Uses in More Than One Way.

Choose one category of personal information:
  • Location data.
  • Purchase history.
  • Email addresses.
  • Website activity.
  • Lead data.
  • Customer-service interactions.
  • Account information.
First, ask: “Why did we originally collect or obtain it?”
Then ask: “How are we using it today?”
If the answers differ, investigate:
  • Was the additional use identified and reviewed?
  • Which legal requirements apply?
  • Do relevant disclosures accurately describe it?
  • Does the use require consent or another authorization?
  • Do existing consumer choices restrict it?
  • Do contracts or vendor terms permit it?
  • Does the activity create additional risk?
The objective is not to reject every secondary use. It is to determine whether that use is allowed and whether any necessary notice, consent, assessment, contract change, or technical control occurred before the activity began.
If no one can identify that decision, the use may have expanded without a review point.

 

The Kochava Matter Puts Data Use and Permissions in the Spotlight.
The FTC announced its proposed settlement with Kochava and Collective Data Solutions, or CDS, on May 4, 2026. CDS had taken over Kochava’s data broker business. The FTC’s case docket subsequently lists a stipulated order dated June 26.
The FTC alleged that precise location information associated with hundreds of millions of mobile devices could reveal consumers’ visits to sensitive locations and expose highly personal aspects of their lives. These are allegations underlying the settlement, not independent findings that every alleged practice occurred.
The FTC describes restrictions on selling, licensing, transferring, sharing, or disclosing sensitive location data unless both conditions are satisfied:
  1. The consumer provides affirmative express consent.
  2. The information is used to provide a service directly requested by that consumer.
The settlement’s operational requirements extend beyond that restriction. The FTC also describes:
  • Controls for identifying sensitive locations.
  • Supplier assessments concerning consent for collection and use.
  • Incident reporting for certain third-party contractual violations.
  • A process for consumers to request the names of known purchasers of their precise location data.
  • An easy mechanism to withdraw consent for the sale of their device’s precise location data.
  • An established retention and deletion schedule.
The applicability of particular provisions depends on the entity and its activities. These settlement requirements should not be presented as a universal checklist for every organization.
CLICBrain’s operational interpretation: Before expanding a data use, review the purpose, permissions, restrictions, consumer-facing representations, and risks, not merely whether the information is technically available.
The important question is not only: “Do we have this data?”
It is: “What activity are we proposing, and what permits us to do it?”

 

 

 

 

 

1. Data Can Reveal More Than Its Original Label Suggests. A location record, purchase, or browsing event may appear ordinary in isolation. Analysis or combination may reveal health-related activity, religious interests, or other highly personal information. The Kochava allegations illustrate the practical concern: Precise location information could reveal visits to medical facilities, places of worship, and other sensitive locations.
Review both:
  • What the information reveals in the proposed activity.
  • Whether the underlying data or resulting inference falls within a legally defined sensitive-data category.
Definitions and resulting obligations vary by law. A heightened privacy risk does not automatically mean every statute classifies the information in the same way.
✔ CLIClaw Compliance Tip: Reassess sensitivity when data is combined, analyzed, or used to draw conclusions, not only when it first enters the organization.

 

2. Third-Party Data Still Needs a Use Review. Buying information from a vendor does not, by itself, establish permission for every downstream activity. Before using third-party information for targeting, enrichment, analytics, personalization, AI, or lead generation, ask:
  • Where did the information come from?
  • Why was it originally collected?
  • What evidence supports the claimed permission?
  • Does that permission cover our proposed use and any disclosure?
  • What contractual restrictions apply?
  • How are withdrawal, opt-out, or deletion instructions communicated?
  • What happens if the source cannot substantiate permission?
  • Who approves or blocks activation?
The Kochava settlement’s supplier-assessment requirements reinforce the importance of examining consent practices rather than relying only on a vendor’s general assurances.
Provenance identifies the source. Purpose identifies the activity. Permissions and restrictions determine whether the activity is allowed.

 

3. Connecting Existing Data to AI Can Create a New Processing Activity. An organization may approve an AI tool without collecting any new information. But connecting existing information to that tool can still require a use review.
Determine the proposed activity:
  • Sending CRM information to an AI service.
  • Using customer-service conversations for model training or fine-tuning.
  • Adding documents to a retrieval system.
  • Using employee information in a scoring process.
  • Connecting historical customer information to a prediction model.
Also distinguish what the service does with the information.
Is it used only to generate a response? Retained in logs? Added to retrieval sources? Used for fine-tuning? Available for model training?
Do not assume those activities are equivalent, or that every AI service uses submitted information for training.
✔ CLIClaw Compliance Tip: Review the specific AI data flow, provider terms, settings, and intended activity before connecting an existing dataset.

 

The Operational Problem: Data Use Creep.
Many organizations have review points for collecting new information:
  • A new form is reviewed.
  • A tracking technology is assessed.
  • A vendor goes through onboarding.
  • A database is documented.
But existing data can acquire new purposes without the same scrutiny. The progression can sound harmless:
  • “We already collect it.”
  • “We already store it.”
  • “Marketing could use it.”
  • “Our vendor can enrich it.”
  • “Our AI platform can analyze it.”
  • “We have always used it this way.”
No single step appears significant. Over time, however, the current activity may differ substantially from the purpose, disclosures, or restrictions under which the information entered the organization. That is data use creep.
✔ CLIClaw Compliance Tip: A practical control is a review point for materially new or expanded uses, before they become routine.

 

 

 

 

 

“We Already Have the Data.”

That answers a possession question. It does not necessarily answer a permission question.
Before using existing personal information for a materially different purpose, review:
  • The original purpose and collection context.
  • Current consumer-facing disclosures.
  • Applicable consent or authorization.
  • Consumer choices and restrictions.
  • Contractual limits.
  • Sensitive-data requirements.
  • Vendor terms.
  • Applicable privacy, sector-specific, and consumer-protection requirements.
A broad notice, an accessible database, or a vendor assurance should not substitute for that analysis.
✔ CLIClaw Compliance Tip: Existing data should not automatically become approved data for a new purpose. Record the decision before the expanded use becomes routine.

 

 

 

 

 

Review One Secondary Use, and Record the Decision.

Do not inventory every data use this week. Choose one dataset your organization already has. Complete these sentences: “We originally obtained this data to .” “Today, we also use, or propose to use, this data to .”
Then document:
  1. ORIGINAL PURPOSE. Why was the information obtained, and what was the collection context?
  2. SECONDARY USE. What additional activity occurs or is proposed?
  3. SCOPE. Which individuals, jurisdictions, and data categories are involved?
  4. PERMISSIONS AND RESTRICTIONS. What notices, consent records, contracts, consumer choices, and legal limits apply?
  5. RISK. Does the activity introduce sensitive inferences, new disclosures, or decisions affecting individuals?
  6. REQUIRED ACTION. Is notice, consent, an assessment, a contract change, a technical restriction, or another control needed?
  7. DECISION. Approve, approve with conditions, pause pending evidence, or prohibit.
  8. EVIDENCE. Who decided, when, and on what basis?
These are practical review fields, not a claim that a single statute mandates this exact format.
If a current use lacks sufficient support, assign an owner to assess whether it should be paused, restricted, or changed while the issue is resolved.
You are testing whether one secondary use was identified, evaluated, and permitted, not merely whether it was intentional.

 

 

 

 

 

Q: If our privacy policy says we may use information for “business purposes,” doesn’t that cover new uses?

CLICBrain: Not necessarily.
A broad phrase in a privacy notice does not create permission for every future activity. The notice must accurately describe relevant practices, and the processing must independently satisfy the requirements that apply.
For businesses subject to the CCPA, purpose limitation, compatibility, proportionality, and qualifying consent can be relevant to that analysis. Other requirements may arise from sensitive-data rules, sector-specific laws, consumer choices, or contracts.
Updating a notice alone may not be sufficient if the activity requires consent, conflicts with applicable purpose restrictions, or is prohibited by another requirement. Operationally, create a review point for materially new uses.
Ask:
  • What information is involved?
  • Why was it obtained?
  • What is the proposed activity?
  • What permissions and restrictions apply?
  • Does the activity change the risk?
  • What must happen before it begins?
  • Who authorizes the decision?
The goal is not a longer privacy policy. It is a supported decision about what the organization may do with the information.
Have another compliance question? Ask CLICBrain on CLIClaw.com.

 

Related CLIClaw Solutions.

This week’s CLICBrain Takeaway highlights two connected needs: understanding how personal information moves through the organization and reviewing new or expanded uses before they become routine.
CLIClaw‘s compliance resources can help organizations evaluate related advertising, affiliate marketing, lead-generation, AI governance, vendor-management, privacy, and operational compliance requirements and identify where additional controls, documentation, or review may be appropriate.
Explore the:
  • Multi-State Privacy Compliance Program. Use it to evaluate data-processing purposes, sensitive-data requirements, consumer rights, assessments, disclosures, and jurisdiction-specific privacy obligations.
  • CLIClaw Compliance Library to find practical guidance, compliance programs, SOPs, checklists, assessments, FAQs, and other resources for building and maintaining an operational compliance program.

 

One Question to Take With You.

What personal information does your organization use today for something it was not originally obtained to do?
Identify one example. Then find the decision, and the supporting basis, that permits the additional use. If you can identify the data but not that decision, you have found this week’s review.

 

CLICBrain Weekly Briefings provide operational compliance intelligence and commentary for internet businesses. Regulatory developments, enforcement activity, and legal requirements discussed herein should be evaluated in the context of your organization’s specific operations, systems, data practices, jurisdictions, and risk profile. This briefing is for informational and educational purposes only and does not constitute legal advice.