US contracts frequently point at the CCPA deidentification standard or, for health fields, HIPAA 45 C.F.R. § 164.514. In the August 2026 Spirit Airlines data sale to Google, a buyer-designated agent had to deidentify the assets while preserving referential integrity across tables — join keys stay, names are supposed to go. That is a legal and operational control, not a guarantee against stylometry or later re-identification from other datasets.