{"id":"CDLA-Permissive-2.0","title":"Community Data License Agreement Permissive 2.0","reviewed_on":"2026-09-15","reviewer":"Giray Havur","text_source":"https://spdx.org/licenses/CDLA-Permissive-2.0.html","text_retrieved":true,"verdict":"created","summary":"The permissive Community Data License Agreement, version 2.0: one page, one condition, the text of the agreement travels with the data. The record follows the CDLA-Permissive-1.0 record of this review group and differs from it where the text does: no attribution duty, no changed file notice, no database right, no termination, and no option to publish under a licence of your choice.","findings":[{"rubric":1,"severity":"minor","field":"spdx:licenseId","description":"The record carries the SPDX id CDLA-Permissive-2.0 and the SPDX name as dct:title. dalicc:variantKind is \"version\": this is the later version of the text the CDLA-Permissive-1.0 record of this review group holds.","action":"applied"},{"rubric":2,"severity":"major","field":"odrl:target","description":"dcmitype:Dataset and dalicc:CreativeWork, as on the 1.0 record, although version 2.0 shortens the definition to \"the material received by a Data Recipient under this agreement\" and no longer names images or text.","action":"applied"},{"rubric":3,"severity":"major","field":"odrl:permission","description":"\"A Data Recipient may use, modify, and share the Data made available by Data Provider(s) under this agreement if that Data Recipient follows the terms of this agreement.\" The record permits reproduce, distribute, display, present, modify, derive, commercial use, derivative works, modified works, the distribution fee and dalicc:sublicense, the last because sharing the data with the agreement attached is passing the same licence on. dalicc:useForModelTraining is permitted because the agreement says so expressly: Results are defined as \"any outcome obtained by computational analysis of Data, including for example machine learning models and models' insights\" and section 3.1 imposes no restriction or obligation on them. dalicc:suiGenerisDatabaseRights is not written: unlike version 1.0, this text names no database right.","action":"applied"},{"rubric":4,"severity":"major","field":"odrl:prohibition","description":"One prohibition, dalicc:ChangeLicense, because the single condition of section 2.1 is that \"the Data Recipient makes available the text of this agreement with the shared Data\": the agreement travels with the data, which is the shape the library reads as a bar on relicensing. This is a real difference from version 1.0, whose section 3.1(a) expressly allows a licence of your choice, and it is the only modelled difference between the two records apart from the duties.","action":"applied"},{"rubric":5,"severity":"major","field":"odrl:duty","description":"One duty, cc:Notice, on odrl:distribute, odrl:modify and odrl:derive. Version 2.0 drops the attribution condition of version 1.0 (3.1(c)) and the changed file notice (3.1(b)) entirely, so no cc:Attribution and no dalicc:modificationNotice is written. A reader comparing the two records sees exactly that.","action":"applied"},{"rubric":6,"severity":"minor","field":"dalicc:WarrantyDisclaimer","description":"The first paragraph of section 4.1 goes into dalicc:WarrantyDisclaimer and the second into dalicc:LiabilityLimitation. dalicc:additionalClauses carries sections 1, 2, 3 and the definitions of Data and Results, which is most of the agreement: it is two pages long.","action":"applied"},{"rubric":7,"severity":"minor","field":"cc:jurisdiction","description":"cc:jurisdiction stays dalicc:worldwide and dalicc:validityType dalicc:perpetual. Version 2.0 names no governing law, no territory, no term and, unlike version 1.0, no termination at all.","action":"applied"},{"rubric":8,"severity":"info","field":"dalicc:useForModelTraining","description":"This is the first record in the library to carry dalicc:useForModelTraining. The term was defined by the review of 2026-09-15 and applied to no record; it is applied here, and on the two data use agreements of this review group, because those three texts are the only ones that say in their own words what happens to a model trained on the data.","action":"applied"},{"rubric":9,"severity":"info","field":"record","description":"The consistency check of app.services.composer with the axioms of dg_default returned an empty conflict list.","action":"none"},{"rubric":10,"severity":"info","field":"record","description":"Family: version 2.0 is a rewrite, not an amendment. Against the CDLA-Permissive-1.0 record it drops attribution, the changed file notice, the database right, the moral rights waiver, the litigation termination and the steward clause, and it closes the licence of your choice option. The two records share only their permissive core and their warranty and liability wording.","action":"none"},{"rubric":3,"severity":"major","field":"odrl:permission","description":"Library convention 15: a licence that asks for no reciprocity and no source code asks only that the notice travels with the copy, which is a duty on the acts it governs and not a bar on putting the copy under other terms. dalicc:ChangeLicense is therefore a permission here, and the prohibition the earlier reading wrote is removed. The text reads: \"A Data Recipient may use, modify, and share the Data made available by Data Provider(s) under this agreement if that Data Recipient follows the terms of this agreement.\" The permission carries the dalicc:compliantLicense duty, as Apache-2.0 does, because the notice has to survive the relicensing.","action":"applied"}],"family":"Community Data License Agreement","port_of":null,"variant_kind":"version","notes":"Modelled from the SPDX plain text. cc:legalcode points at the agreement on the steward's own site, dct:source at the SPDX page. dct:publisher is left out: unlike version 1.0, this text names no steward. No long dash appears in the source text."}