Open data licenses work by giving you explicit, legal permission to access, reuse and redistribute a dataset — usually on two conditions: credit the source, and publish any derivative dataset under the same license. Data that is merely downloadable is not open data until someone attaches one of those permissions in writing. That single distinction decides whether a city department’s spreadsheet can legally sit inside your app.
Most civic technology projects stumble on the same thing. Someone downloads a file, assumes public equals free to use, and builds six months of work on top of it. Later somebody points out that no license was ever granted, and the default legal position turns out to be all rights reserved.
This guide walks through what an open data license actually controls, how to read one, which of the common licenses fits which kind of project, and how to apply a license to your own dataset. It is general information about how licensing works, not legal advice for your specific situation.
Table of Contents
- What Is an Open Data License?
- The three levels of openness
- Why Do Cities and Publishers Attach Licenses to Data?
- How Open Data Licenses Work
- Step 1: Identify who holds the rights
- Step 2: Locate the license statement
- Step 3: Read the permissions and conditions
- Step 4: Check the exceptions
- Step 5: Document and comply
- What Do the Main License Terms Mean?
- Common Open Data License Options
- Creative Commons: CC0, CC BY, CC BY-SA
- Open Data Commons: PDDL, ODC-By, ODbL
- Government-specific licenses
- Licenses that are not open
- How to Choose the Right License for a Civic Technology Project
- How to Check and Apply a License to a Dataset
- If you are publishing a dataset
- If you are using a dataset
- Common License Mistakes in Open Data Projects
- Copying a dataset without its license
- Assuming public records mean public domain
- Failing to attribute properly
- Treating share-alike as viral
- Mixing incompatible sources
- Scraping a site with no stated terms
- Frequently Asked Questions
- Is open data the same as public domain data?
- Can I use open data for commercial apps?
- Do I have to attribute data if the license says attribution is required?
- Can I combine data released under different open licenses?
- What happens if a city changes its data license?
- Who is responsible for licensing third-party data in an app?
- Conclusion
What Is an Open Data License?

An open data license is a standard legal instrument that lets anyone access, copy, redistribute and build on a dataset, subject to a small number of conditions — typically attribution, and sometimes a requirement to license derivative databases the same way. Without an explicit license, the copyright in a published dataset stays with the publisher and reuse is legally risky by default.
So what does an open license actually grant you in practice? These are the permissions that matter:
- Republish the dataset, in whole or in part
- Create derivative datasets by combining, filtering or translating the source
- Use the data commercially, including inside a paid or freemium product
- Charge for access to your own version of the data
- Store and analyse the data locally with your own tooling
The Open Data Commons puts it plainly: data shared with a license becomes open data. Without that license attached, it is just a file.
The three levels of openness
Openness is not binary. Licenses fall into three practical tiers, and this mapping is the fastest way to understand any license you meet.
- Public domain. The reuser does nothing, at most a courtesy credit. Creative Commons equivalent: CC0 1.0. Open Data Commons equivalent: PDDL 1.0.
- Attribution. The reuser credits the source and links the license. Creative Commons equivalent: CC BY 4.0. Open Data Commons equivalent: ODC-By 1.0.
- Attribution plus share-alike. The reuser credits the source and licenses their derived database the same way. Creative Commons equivalent: CC BY-SA 4.0. Open Data Commons equivalent: ODbL 1.0.
Anything below those three tiers — non-commercial, no-derivatives — is technically a Creative Commons license but is not an open data license under the Open Knowledge Definition.
Why Do Cities and Publishers Attach Licenses to Data?
Because without one, nobody can safely reuse the data, and the default legal position is that all rights are reserved. Publishing a PDF onto a website is an act of distribution, not a grant of permission.
There are a handful of practical reasons publishers land on this:
- Legal clarity. A named license replaces an argument. Reusers know exactly what they may do without asking the publisher.
- Attribution and credit. Many city teams publish data expecting their work to be credited, and a license is the only reliable way to require it.
- Privacy and third-party constraints. A license lets the publisher promise reusers that personal data and contracted data have been stripped out or cleared.
- Preservation. A license that forbids redistribution lets a publisher share a searchable catalog publicly while keeping the underlying records closed.
- Accountability. If a license is attached, the publisher has created something reusable. Without one, they have not.
One distinction worth keeping straight: a permissive statement in a data portal’s terms of use is not the same as a license attached to the dataset itself. Terms of service usually cover the website. The license covers the data.
How Open Data Licenses Work

A license works by moving a specific set of rights from the rights holder to everyone else, under stated conditions. From your side as a builder, it takes five steps to go from a downloaded file to a defensible product.
Step 1: Identify who holds the rights
For government data in the UK, that question can be complicated by Crown copyright, which keeps copyright in government works rather than the individual civil servant who created them. In the US, federal works are generally in the public domain. Check the dataset page for a named publisher, because that is who granted the license.
Step 2: Locate the license statement
Look for a license named on the dataset page, in a footer, or in the metadata. Open data portals increasingly publish machine-readable metadata, where the license appears as a URI such as the CC BY 4.0 deed address rather than as prose. If no license appears anywhere, treat the data as all rights reserved.
Step 3: Read the permissions and conditions
Check what the license grants and what it demands. The two questions that trip people up are whether commercial use is permitted and whether a share-alike obligation applies to your output.
Step 4: Check the exceptions
Open licenses almost always carve something out. Trademarks, logos and the publisher’s brand are excluded, so you can reuse the data without implying the city endorses your product. Personal data and third-party contributions are excluded too, and those exclusions are what keep the promise honest.
Step 5: Document and comply
Write down what you used, under what license, and when you pulled it. Store the license text and a snapshot of the dataset version alongside your code. When a reuser asks you what you used six months later, you will want the answer to take ten seconds.
What Do the Main License Terms Mean?
License vocabulary is dense because it has to be precise. Here is what each clause does in practice, in plain words.
- Attribution
- Credit the original creator, include a link to the license, and indicate whether you made changes. Good attribution names the publisher, the dataset, the license, and the source URL.
- Commercial use
- Permission to make money from it, directly or indirectly, including a subscription product. This is the clause that separates open from merely free-to-view.
- Modification and adaptation
- Permission to build derivative works: filtered extracts, translated files, joined datasets, corrected versions. A no-derivatives clause blocks this entirely.
- Redistribution
- Permission to republish the data or a derived version yourself, not just to use it privately in your own system.
- Share-alike
- An obligation, not a permission. If you distribute a derived database, you must offer it under the same or a compatible license. Crucially, share-alike attaches to the database you distribute, not to your software, your brand, or your other unrelated data holdings.
- Licence compatibility
- Whether two licenses can legally be combined in one derived work. Sharing-alike terms cannot be waived, so a share-alike dataset cannot be folded into a proprietary database without passing the obligation on.
- Trademark carve-out
- Rights in names, logos and branding are never granted by a data license. Reuse the data without implying endorsement.
- Disclaimer of warranties
- The data is provided as-is. Nobody guarantees accuracy, and the publisher’s liability for your use of it is limited. Build quality checks into your pipeline.
- Database right
- A separate, shorter right that exists in the EU and Mexico to protect the investment in compiling a database, distinct from copyright in each individual record. This is why Open Data Commons licenses exist at all — Creative Commons licenses were designed for creative works, not datasets.
Common Open Data License Options
Two families cover almost all open data publishing: Creative Commons, designed for content, and Open Data Commons, designed for databases. Both are widely accepted. They differ in what they treat as the thing being licensed.
Creative Commons: CC0, CC BY, CC BY-SA
CC0 is a public domain dedication — the publisher waives rights as far as the law allows. CC BY 4.0 requires attribution. CC BY-SA 4.0 adds the share-alike obligation. The community has largely converged on CC BY 4.0 as the default for open data, with CC0 used when maximum reuse freedom matters.
Open Data Commons: PDDL, ODC-By, ODbL
PDDL 1.0 is a public domain dedication with fallback rights. ODC-By 1.0 requires attribution. ODbL 1.0 requires attribution and share-alike, written specifically for databases.
OpenStreetMap made that switch deliberately, moving its core map data from CC BY-SA to ODbL because Creative Commons licenses are aimed at content and do not cleanly express database obligations. That decision is the clearest real-world case for why both families exist.
Government-specific licenses
Many public bodies publish under their own terms rather than a standard license. The UK Open Government Licence is the best-known example, and national and regional variations exist across Europe and elsewhere. Read the actual text: some restrict use to a named authority, some require an attribution statement in a specified form, and some only permit use in published research.
Licenses that are not open
Several widely used licenses look open but fail the Open Knowledge Definition:
- CC BY-NC forbids commercial use, which rules out a paid app and much of the private sector
- CC BY-ND forbids derivatives, which rules out merging the data with anything else
- Source-available licenses such as BUSL-style terms, which grant use but reserve publication rights
- Custom government terms that restrict fields of use
There is a practical trap here. A team publishes a dataset under CC BY-NC, builds a community around it, and then discovers nobody in the private sector can legally build a product on it. Publishing under a restrictive license is easy to fix. Retiring one is not.
How to Choose the Right License for a Civic Technology Project
Pick the license that matches what you want to happen to the data, then check that it is compatible with what you already use. The order matters — checking compatibility first saves rework later.
- Do you want maximum adoption with no obligations? Use CC0 1.0. Nothing to comply with, nothing to get wrong, and the lowest barrier for a newsroom or student to use it.
- Do you want credit but full freedom otherwise? Use CC BY 4.0. This is the mainstream community default and the safe answer for a commercial app.
- Are you building a community data commons and want reciprocity? Consider ODbL 1.0. Anyone who redistributes must keep the commons open, which prevents a well-funded company from absorbing the work.
- Do you publish a catalogue or index rather than records? ODbL was written for this. CC BY 4.0 or a government license also works.
- Are you consuming data rather than publishing? Check your output. A share-alike source pushes an obligation onto any database you distribute; an attribution source does not.
Two audience questions settle most cases. If your audience is developers who will build commercial tools, choose CC BY 4.0. If your audience is a civic community contributing data back into a shared pool, share-alike is doing real work for you.
How to Check and Apply a License to a Dataset
Applying a license is a documentation exercise. The hard part happened earlier, when you cleared third-party material and personal data.
If you are publishing a dataset
- Confirm you hold the rights. Check contracts, contributor terms and any upstream sources you intend to republish.
- Strip what you cannot license. Personal data, licensed third-party records and anything under a conflicting license come out.
- Choose a standard license. Use CC BY 4.0 or ODbL 1.0 rather than writing your own. Bespoke terms are expensive to explain and hard to enforce.
- Write a human-readable statement. Plain language naming the publisher, the license with a link, and what attribution should say.
- Add machine-readable metadata. Publish the license as a URI in the dataset metadata so tools can pick it up automatically.
- Version the license. State which version applies and from when. A license change should never silently rewrite the terms for existing users.
- Document downstream use. Keep an attribution record and update your documentation whenever the terms change.
If you are using a dataset
- Save the license page and a copy of the dataset with a dated filename
- Keep a one-line attribution string ready, such as “Data: City Transport Department, licensed CC BY 4.0”
- Check whether your output is a distributed database, because that determines if share-alike attaches
- Confirm nothing in your pipeline pulls from an unlicensed source
Common License Mistakes in Open Data Projects
These are the failures that show up repeatedly in civic technology work, and every one of them is avoidable.
Copying a dataset without its license
A file with no license statement is copyrighted by default. OpenStreetMap contributors have argued this for years, and the UK government’s licensing work for Ordnance Survey data is a well-known case where unclear terms kept reusers blocked for a long time. If there is no license, ask before you build.
Assuming public records mean public domain
A dataset built from government records is usually a compilation, and the compilation carries its own rights even when the individual facts are free. That compilation is what the publisher is licensing.
Failing to attribute properly
Attribution is the single most common breach. On a mobile app, put a credits screen or an info panel in the settings rather than trying to squeeze credit into every view — that is how teams handle the limited screen space in practice. Name the publisher, the dataset, the license and the source.
Treating share-alike as viral
This fear comes up constantly and it is largely misplaced. Share-alike applies to the database you distribute. It does not reach your application code, your brand, or data you collected independently. What it does prevent is quietly folding a commons into a proprietary database.
Mixing incompatible sources
Attribution data combines freely with anything. Share-alike data cannot be combined into a proprietary output. And non-commercial terms block the combination almost entirely. Check every source before you join them.
Scraping a site with no stated terms
If a site publishes an API, the API terms govern. If it publishes nothing, there is no permission to rely on, whatever a law firm might later argue about scraping. Check for a robots.txt and a terms page, and treat the answer as binding either way.
Frequently Asked Questions
Is open data the same as public domain data?
No. Open data means a license grants permissions to access, reuse and redistribute. Public domain means the rights holder has waived those rights entirely, usually through a dedication like CC0 1.0 or PDDL 1.0. Open data under CC BY 4.0 still requires attribution, so reusing it without crediting the source breaches the license. Most open datasets in circulation are licensed rather than in the public domain.
Can I use open data for commercial apps?
Yes, with licenses like CC BY 4.0, ODbL 1.0 or the UK Open Government Licence. Commercial use means you can charge for your product, sell subscriptions, or offer a freemium tier. The obligations are still there: credit the source, and under share-alike licenses distribute any derived database under the same terms. Licenses marked NC forbid commercial use entirely, which rules them out for a paid product.
Do I have to attribute data if the license says attribution is required?
Yes. Attribution is a legal condition of the license, not a courtesy. A good attribution names the publisher, the dataset title, the license name with a link, and a link to the source, and it notes whether you made changes. In a mobile app, a credits or info screen in the settings usually satisfies this. Omitting it is the most common way projects breach an open license.
Can I combine data released under different open licenses?
It depends on the licenses. Attribution-only data such as CC BY 4.0 or ODC-By combines freely with other open data. Share-alike licenses like CC BY-SA and ODbL push the share-alike obligation onto the database you produce, so you cannot fold them into a proprietary dataset. Non-commercial licenses block commercial combination entirely. Keep an attribution record for every source in a mixed dataset.
What happens if a city changes its data license?
It depends on how and when it happens. A well-run publisher announces changes and gives existing users time, because silent license changes are legally fragile and destroy trust. In practice, publishers rarely revoke permissions already granted for earlier versions, but they do apply new terms going forward. Snapshot datasets and license text when you download them, so you can show what terms applied at the time you relied on them.
Who is responsible for licensing third-party data in an app?
You are, for everything your app serves. If you pull in a third-party dataset, you are the one making it available to your users and you need permission to do so. Each source must be clearly licensed and compatible with the rest of your data, and a reuser of your app should be able to find the licenses you applied. Where the terms are unclear, ask the publisher before you ship.
Conclusion
Start with the license statement on the dataset page. If there isn’t one, ask the publisher before you build rather than after you ship.
Then note the two conditions that matter: whether you must credit the source, and whether anything you distribute inherits a share-alike obligation. Choose CC BY 4.0 if you want freedom with credit, CC0 if you want nothing to keep track of, and ODbL only if you are deliberately building a commons.
Finally, snapshot the data and the license text together with a date, and write your attribution string once so it stays consistent across your app, your docs and your website. That is the whole job — the rest is habit.


