The United States has no overarching statute or sui generis right for database protection. Instead, data and databases are protected through a patchwork of federal and state intellectual property laws, contract law, and consumer privacy statutes. At the federal level, databases are protected primarily as trade secrets under the Defend Trade Secrets Act and as compilations under the Copyright Act, while most states protect trade secrets under the Uniform Trade Secrets Act. Consumer privacy laws such as the California Consumer Privacy Act increasingly shape how personal data may be used and commercialized.
Copyright protection is deliberately narrow. In Feist Publications v. Rural Telephone Service (1991), the Supreme Court rejected the 'sweat of the brow' doctrine, holding that compilations must display a minimal degree of creativity in selection or arrangement; raw facts remain unprotected, and courts often require 'virtual identity' to find infringement of thin factual compilations. Trade secret law is correspondingly the strongest tool: the DTSA expressly covers compilations, and courts have upheld non-public customer databases as trade secrets where owners take reasonable measures to maintain secrecy.
Contract law fills many statutory gaps. Shrink-wrap licenses are enforceable even for non-copyrightable databases (ProCD v. Zeidenberg), and courts have extended the same reasoning to click-through terms, and 2022 amendments adding Article 12 to the Uniform Commercial Code signal growing recognition of digital assets as commercial property. On the AI front, Thaler v. Perlmutter reaffirmed that purely AI-generated works are not copyrightable absent human authorship, and litigation over the use of scraped or copyrighted data to train generative AI models remains unresolved.
Key takeaways
- Trade secrecy under the DTSA is the most robust U.S. protection for databases, but it requires documented, reasonable measures to maintain secrecy.
- Copyright covers only original selection or arrangement of data, so raw or machine-generated datasets generally fall outside its scope.
- Contracts, including shrink-wrap and click-through licenses, are enforceable and routinely used to allocate data rights where statutory IP protection is thin.
- Purely AI-generated outputs are not copyrightable under current U.S. doctrine, and disputes over AI training data remain unresolved in the courts.
- State privacy laws such as the CCPA constrain the use of personal data but exempt businesses from disclosing trade secrets in access requests.
Primary legal instruments
AI-assisted summary of the report, editorially reviewed before publication · AI transparency
Protection mechanisms
Report-derived analysis per mechanism. The report text is fixed; committee members with contributor access can revise the rating (with an audit trail) and add notes below each block.
Recent Developments
Live updates contributed by committee members and the AI research bot — separate from the fixed report content above.
FTC Finalizes Orders on Deceptive AI-Powered Marketing Practices Involving Consumer Data
The Federal Trade Commission has finalized orders against Cox Media Group and two other companies, imposing over $900,000 in penalties. These firms were accused of misleading consumers by falsely claiming to use an AI-powered service for targeted advertising based on 'active listening' of smart device conversations, and that consumers had opted into such data collection. This action underscores the FTC's focus on transparency and truthfulness in AI-driven data acquisition and marketing.
FTC Seeks Public Comment on Policy Statement Addressing Personalized Pricing Practices
The Federal Trade Commission has opened a public consultation on a proposed enforcement policy statement concerning personalized pricing. This initiative aims to address legal concerns arising from companies using personal data to tailor prices for individual consumers. The policy statement will outline the FTC's approach to practices that may constitute unfair competition or deceptive acts under existing law.
Copyright Office Amends Group Registration for News Website Updates to Ease Process
The U.S. Copyright Office has issued a final rule amending the group registration option for updates to news websites. This amendment clarifies the definition of a "news website" to include sites primarily designed as sources of written information on current events, updated frequently, and reporting on various subjects. The change aims to improve the administrability of the Group Registration of Updates to a News Website (GRNW) option and simplify the registration process for rightsholders.
FTC Clarifies Policy on Disparate Impact and Unfair Discrimination Enforcement
The Federal Trade Commission issued a policy statement indicating it will no longer pursue claims based on "disparate impact" or "unfair discrimination" theories. This clarification outlines the agency's enforcement approach, particularly relevant for data-driven systems and AI. The policy aims to provide clear guidance on how the FTC will address potential discriminatory practices.
Third Circuit hears first appellate argument on AI training fair use in Thomson Reuters v. Ross Intelligence
On June 11, 2026 the U.S. Court of Appeals for the Third Circuit heard oral argument in Thomson Reuters v. Ross Intelligence (No. 25-2153), the first federal appellate review of whether copying a proprietary legal database to train an AI research tool is fair use. The appeal challenges the February 2025 district court ruling that Ross infringed Westlaw's copyrighted headnotes and Key Number System and could not rely on fair use. The forthcoming decision will be the first binding circuit precedent on AI training with protected database content.
Bartz v. Anthropic: $1.5 billion AI training-data settlement reaches final approval stage
The $1.5 billion class settlement over Anthropic's use of pirated books to train its language models moved to its final-approval fairness hearing before Judge Alsup on May 14, 2026, after a March 30, 2026 claims deadline covering roughly 500,000 works at about $3,000 each. The judge took final approval under submission pending further briefing on objections and opt-outs, and the deal requires destruction of the pirated libraries. It remains the largest copyright recovery tied to AI training data.
Supreme Court denies certiorari in Thaler v. Perlmutter, leaving human-authorship rule for AI works intact
On March 2, 2026 the U.S. Supreme Court declined to review Thaler v. Perlmutter (No. 25-449), in which Dr. Stephen Thaler sought copyright registration for an image generated autonomously by his AI system. The denial leaves standing the D.C. Circuit's holding that the Copyright Act requires a human author, confirming that purely machine-generated outputs are not copyrightable in the United States. Owners of AI-generated data and content must therefore rely on other mechanisms such as contracts or trade secrets.