Public Data Use Checklist: Source and Licence Verification, Restriction Screening, Derived Work Analysis, Attribution Compliance, and Refresh Obligations

By ·

This checklist audits a product built on public data, and it is organised around the four ways such businesses actually fail: a feed stops, a share-alike condition surfaces during diligence, an accuracy claim becomes a liability, or privacy regulation catches up with the aggregation. None of the four is prevented by a copyright opinion. The checklist starts with the provenance register and the acquisition route, then covers government work verification, portal terms read as contracts, restriction screening, the derived rights position, attribution propagation, refresh and accuracy obligations, per-state privacy analysis, the difficult source categories, and source dependency. Gate items mark where work should stop.

IP and Technology > General IP | Checklist | Published 22 February 2024 - Updated 19 June 2026 | Casey Scott McKay - marksy.us

Summary. This checklist audits a product built on public data, organised around the four ways such businesses actually fail: a feed stops, a share-alike condition surfaces during diligence, an accuracy claim becomes a liability, or privacy regulation catches up with the aggregation. None is prevented by a copyright opinion. It starts with the provenance register and the acquisition route, then covers government work verification, portal terms read as contracts, restriction screening, derived rights, attribution propagation, refresh and accuracy, per-state privacy analysis, the difficult source categories, and source dependency. Gate items mark where work should stop.

Keywords: public data checklist · provenance register · acquisition route · government work verification · portal terms · share-alike screening · licence compatibility · derived rights · attribution mechanism · refresh and accuracy · per-state privacy analysis · geospatial licensing · court records · incorporated standards · source dependency


How to use this checklist

| Phase | What it produces | Who runs it | Gate | |---|---|---|---| | 1. Register | Every source with its acquisition route | Counsel and engineering | Built from the warehouse, not from memory | | 2. Status | A government work answer per dataset | Counsel | Contractor and third-party material identified | | 3. Terms | Portal terms read as contracts | Counsel | Formation established per source | | 4. Screening | Share-alike and non-commercial findings | Counsel | Screened before the architecture is fixed | | 5. Ownership | An honest statement of what is owned | Counsel | Enrichment protected as secret | | 6. Attribution | A mechanism, not a line of copy | Product and counsel | Text in the product | | 7. Refresh | An accuracy and correction policy | Product and counsel | Staleness surfaced per dataset | | 8. Privacy | A per-state answer and a deletion process | Privacy counsel | Process before the first request | | 9. Hard categories | Separate reviews where warranted | Counsel | Court, geospatial, standards, training | | 10. Dependency | A quantified and disclosed exposure | Counsel and management | In the diligence file |

The matter. A company assembles property records, permits, and licensing data from four hundred municipal sources into a subscription product. A Series A closes in four months. The engineering team has been scraping whatever it could reach for three years, nobody has read a licence, and the product presents records about identifiable people as current.


Phase 1. Build the provenance register


Phase 2. Verify government work status per dataset


Phase 3. Read the terms of use as contracts


Reading a public sector licence, clause by clause

Fifteen minutes per licence answers most of Phase 4, and the clauses are in a predictable order.


Phase 4. Screen for the conditions that can break the product


Records requests as an acquisition route


Screening a combined product

Where the product assembles many sources, the compatibility question is not answered source by source and needs its own pass.


Phase 5. State honestly what the business owns


Phase 6. Build the attribution mechanism


Phase 7. Write the refresh and accuracy policy


Phase 8. Run the privacy analysis per state


Phase 9. Give the hard categories their own review

Court records.

Geospatial data.

Standards incorporated by reference.

Training data.


Phase 10. Price and disclose the source dependency

Advising the supply side

Where the client publishes rather than reuses — an agency, a contractor delivering to one, a grantee, or a non-profit — the questions are the mirror image and the mistakes are different.


A note on order

The phases are ordered by dependency, and the ordering matters because the instinct is to start in the wrong place.

Clients arrive worried about privacy, because privacy is the topic that generates headlines, or about copyright, because copyright is what "intellectual property" means to a board. Both are real and neither can be assessed first: a privacy analysis requires knowing which sources contain personal data, and a copyright position requires knowing which datasets are government works. Both questions are answered by the register, which is why the register is Phase 1 and why it has a gate that stops everything else.

The register is also the phase that takes longest, is least interesting, and requires engineering time the business would rather spend elsewhere. Expect resistance and expect the resistance to be strongest from the people whose undocumented ingestion jobs the exercise will surface.

Government work status and terms follow because they are the inputs to screening. Screening precedes the ownership discussion because what the business owns depends on what it was permitted to build.

Attribution, refresh, and privacy are product changes with engineering cost, which is why they sit after the analysis and why they should be scheduled rather than requested.

The hard categories at Phase 9 are placed late because most products touch only one or two, and a business touching none can skip it — while a business touching court records or geospatial data should have started there.

Dependency is last because it is the phase that produces no compliance artefact and the greatest commercial insight, and it is the one most likely to be dropped when the diligence deadline approaches. It should not be: of the four ways these businesses fail, a source stopping is the one nothing else on this list addresses.



Outcome. A business that has run this checklist can tell a buyer where every field in its product came from, under what terms, obtained how and when; can show that it screened for the two conditions that would have required a rebuild and remediated what it found; can demonstrate an attribution mechanism and a correction pipeline; and can say what happens if its largest source stops. None of those is a copyright opinion, and all four of the ways these businesses fail are addressed by them.


Key Authorities at a Glance

| Authority | What it settles | Phase | |---|---|---| | 17 U.S.C. § 105 | No copyright in works of the United States Government | 2 | | 17 U.S.C. § 101 | Definition of a work of the United States Government | 2 | | Feist Publications, Inc. v. Rural Telephone Service Co. | Facts unprotectable; no sweat of the brow | 2, 5 | | Georgia v. Public.Resource.Org, Inc. | Government edicts doctrine extends to official annotations | 2, 9 | | 17 U.S.C. § 102 | Subject matter of copyright | 5 | | 17 U.S.C. § 103 | Compilations and derivative works | 5 | | 17 U.S.C. § 106 | Exclusive rights | 4 | | 17 U.S.C. § 107 | Fair use | 9 | | 17 U.S.C. § 411 | Registration as a precondition to suit | 5 | | 17 U.S.C. § 201 | Ownership and transfer | 2 | | 17 U.S.C. § 512 | Notice and takedown | 7 | | 5 U.S.C. § 552 | Federal records access, exemptions, and fees | 8 | | Van Buren v. United States | Narrow reading of exceeding authorized access | 3 | | 18 U.S.C. § 1839 | Reasonable measures element of trade secret status | 5 | | 15 U.S.C. § 1125 | False designation of origin and false advertising | 7 |


The five things people get wrong

One: assuming public means free. Federal government works are outside copyright and almost nothing else in the register is covered by that rule. Contractor deliverables, licensed-in third-party material, state and municipal datasets, foreign government works, and grantee output are all outside it, and the portal that published them will not say which is which. The verification is dataset by dataset and there is no shortcut.

Two: looking for the restrictions in copyright. They are in contract. A public domain dataset downloaded under terms prohibiting commercial redistribution is a dataset the business agreed not to redistribute, and no amount of analysis about the copyright position answers that. Most public sector licences also disclaim accuracy entirely and terminate automatically on breach, which means an attribution failure ends the licence rather than merely breaching it.

Three: never recording how the data was obtained. Manual download, registered access, bulk agreement, purchase from an aggregator, scraping, and records request are materially different positions and they look identical in the warehouse. The question is asked in the first diligence session, and the answer has to be reconstructed from ingestion code because nobody wrote it down.

Four: discovering a share-alike condition after the architecture is fixed. Screened early it is a source removal; discovered during a funding round it is an argument about whether the proprietary product must be released, and the argument does not have to be right to end the transaction. The same screening costs a fortnight before the product and a quarter afterwards.

Five: treating accuracy as somebody else's problem. The product presents records about identifiable people, the source corrects one, the product does not, and the business is now publishing something it knows to be wrong about a named individual. That is the exposure most likely to produce an actual claim in this sector, it is entirely preventable with a correction pipeline, and it appears nowhere in a copyright opinion.


Related Documents

Articles

Guides

Checklists

Toolkits


This checklist is general information about intellectual property practice, not legal advice, and it does not create a lawyer-client relationship. Marksy is not a law firm. Public data reuse engages copyright, contract, access statutes, privacy law, and the terms of individual providers, and the correct answer depends on the specific sources, the jurisdictions involved, and how the data was obtained. Consult qualified counsel before acting.

Read this article on Marksy