# iSHARE Licenses

{% hint style="info" %}
**This documentation is part of the formal iSHARE Framework specification**

This documentation must be considered part of the formal iSHARE Framework Specification.
{% endhint %}

This site contains all the licenses that are maintained under the [iSHARE Framework](https://framework.ishare.eu/) governance. More information about licenses is available in [the page about licenses in the iSHARE Framework](https://framework.ishare.eu/detailed-descriptions/functional/licenses).

This page contains all the latest versions of the licenses. The latest versions and all previous versions of licenses are available as subpages.

## Machine-readable catalogue

All licenses are also published as a single machine-readable JSON file that participants can fetch and parse directly: <https://ishare-licenses-df1e38.gitlab.io/index.json>.

## License versioning

Every iSHARE license identifier ends with a version suffix (e.g. `/1.0`). Versions follow **SemVer with MAJOR.MINOR only** (no PATCH).

* **MAJOR** (`1.0` → `2.0`) — Breaking change. The meaning, scope, or constraints of the license have changed in a way that affects whether existing delegations remain valid.
* **MINOR** (`1.0` → `1.1`) — Editorial clarification. Wording is refined for readability or to resolve ambiguity, but the legal and operational meaning is unchanged.

When a MAJOR version is published, it becomes the only version that issuers MAY include in newly-created delegation evidence after the publication date. The previous MAJOR remains valid for evaluation of evidence issued before that date, until its explicit sunset date. Each MAJOR version page declares its `status` (`current`, `superseded`, or `sunset`) and, where applicable, a sunset date.

A MINOR version supersedes the prior MINOR within the same MAJOR. The latest MINOR within a MAJOR is the authoritative wording.

## General licenses

### Use and process without restrictions

**Identifier**: [https://licenses.ishare.eu/general-unrestricted/1.0](/general-unrestricted/1.0)\
Previous identifier: 0000

* Data labeled with this License may be used and (re-)shared without further limitations and/or conditions imposed pursuant to the iSHARE Framework.
* The above applies without prejudice to any applicable laws and/or rights of third parties.

### Reshare with Adhering Parties

**Identifier**: [https://licenses.ishare.eu/general-resharing-with-adhering-parties/1.0](/general-resharing-with-adhering-parties/1.0)\
Previous identifier: 0001

* Data labeled with this License may exclusively be (re-)shared with and used by Adhering Parties in accordance with the rules of the iSHARE Framework.

### Use and process for internal purposes only

**Identifier**: [https://licenses.ishare.eu/general-internal-use/1.0](/general-internal-use/1.0)\
Previous identifier: 0002

* Data labeled with this License is intended for internal use only and may not be shared with or used by any other party
* The above limitation applies to the Data or Dataset itself, and does not extend to any products and/or services developed or generated by such internal use of the Data. Such products or services may be put to commercial use.

### Use and process for internal purposes — generated insights/know how

**Identifier**: [https://licenses.ishare.eu/general-internal-use-insights/1.0](/general-internal-use-insights/1.0)

* Data labeled with this License is intended for internal use only and may not be shared with or used by any other party.
* The above limitation applies to the Data or Dataset itself, and does not extend to any products and/or, services, insights/know-how or similar developed or generated by such internal use of the Data. Such insights/know-how or similar may be put to commercial use.

### Use and process for non-commercial purposes

**Identifier**: [https://licenses.ishare.eu/general-non-commercial-use/1.0](/general-non-commercial-use/1.0)\
Previous identifier: 0003

* Data labeled with this License may be used and (re-)shared freely, provided that such use or sharing occurs for strictly non-commercial purposes.
* Any commercial use of or (end-)purpose for the Data is strictly prohibited. This includes without limitation:
  * any use and/or (re-)sharing of the Data for the purpose of receiving compensation or generating revenue; and
  * use and/or (re-)sharing of the Data for the purpose of developing products, services or similar for commercial use.

### Enrich with own data

**Identifier**: [https://licenses.ishare.eu/general-enrich-with-own-data/1.0](/general-enrich-with-own-data/1.0)\
Previous identifier: 0004

* Data labeled with this License may be enriched, but only with data generated by the direct recipient of the Data.
* Enrichment using data provided by third parties is strictly prohibited unless such is allowed under another applicable License.

### Enrich with data generated directly by third parties

**Identifier**: [https://licenses.ishare.eu/general-enrich-with-third-party-generated-data/1.0](/general-enrich-with-third-party-generated-data/1.0)

* Data labeled with this License may be enriched, but only with data generated by the discloser and/or the direct provider of the Data.
* Data provided by third parties may be used for enrichment but only if the data was generated by such third parties directly.
* Enrichment using data provided by third parties that was not generated by such third parties is strictly prohibited unless such is allowed under another applicable License.

### Enrich with data provided by third parties

**Identifier**: [https://licenses.ishare.eu/general-enrich-with-others-data/1.0](/general-enrich-with-others-data/1.0)\
Previous identifier: 0005

* Data labeled with this License may be enriched, but only with data generated by third parties.
* Enrichment using data generated by the direct recipient of the Data is strictly prohibited, unless such is allowed under another applicable License.

### Use and process to service an Entitled Party

**Identifier**: [https://licenses.ishare.eu/general-use-to-service-entitled-party/1.0](/general-use-to-service-entitled-party/1.0)\
Previous identifier: 0008

* Data labeled with this License may only be used and processed insofar this is strictly necessary for the provision of the specific service(s) to an Entitled Party under an agreement in the context of which the Data is shared.

### Use and process as determined between Parties

**Identifier**: [https://licenses.ishare.eu/general-determined-between-parties/1.0](/general-determined-between-parties/1.0)\
Previous identifier: 9999

* Data labeled with this License is shared under specific conditions and under the applicability of specific provisions agreed to between the exchanging parties in a separate agreement. Care must be taken at all times to reference the relevant agreement and act in full compliance with the relevant agreement.

## Country licenses

### Use and process within country

**Identifier**: [https://licenses.ishare.eu/country-{XX}/1.0](/country-xx/1.0)

* Data labeled with this License may only be used and processed within the country/countries corresponding to the specified [ISO 3166-1 alpha-2](https://www.iso.org/iso-3166-country-codes.html) two-letter country code (e.g. NL, BE).

## Industry licenses

### Use and process within industry

**Identifier**: [https://licenses.ishare.eu/industry-{NNNN}/1.0](/industry-nnnn/1.0)

* Data labeled with this License may only be used and processed within the industry corresponding to the specified [ISIC industry code](https://unstats.un.org/unsd/classifications/Econ/ISIC).

## Certification licenses

The licenses below apply only to use and processing by organisations that maintain such certification.

### Use and process in full compliance with ISO 27001

**Identifier**: [https://licenses.ishare.eu/certification-iso-27001/1.0](/certification-iso-27001/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 27001 - Information Security Management’ certification standard.

### Use and process in full compliance with ISO 9001

**Identifier**: [https://licenses.ishare.eu/certification-iso-9001/1.0](/certification-iso-9001/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 9001 - Quality Management’ certification standard.

### Use and process in full compliance with ISO 14001

**Identifier**: [https://licenses.ishare.eu/certification-iso-14001/1.0](/certification-iso-14001/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 14001 - Environmental Management’ certification standard.

### Use and process in full compliance with ISO 45001

**Identifier**: [https://licenses.ishare.eu/certification-iso-45001/1.0](/certification-iso-45001/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 45001 - Occupational Health and Safety’ certification standard.

### Use and process in full compliance with ISO 22000

**Identifier**: [https://licenses.ishare.eu/certification-iso-22000/1.0](/certification-iso-22000/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 22000 - Food Safety Management’ certification standard.

### Use and process in full compliance with GDPR

**Identifier**: [https://licenses.ishare.eu/certification-gdpr-regulated/1.0](/certification-gdpr-regulated/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘GDPR Certification’ standard as meant in article 42 of the European General Data Protection Regulation.

### Use and process in full compliance with HIPAA

**Identifier**: [https://licenses.ishare.eu/certification-hipaa-regulated/1.0](/certification-hipaa-regulated/1.0)

* Data labeled with this License may only be used and processed in full compliance with the Health Insurance Portability and Accountability Act (HIPAA).

### Use and process in full compliance with SOC 2

**Identifier**: [https://licenses.ishare.eu/certification-soc-2/1.0](/certification-soc-2/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘SOC 2 - Service Organization Control Type 2’ certification.

### Use and process in full compliance with PCI DSS

**Identifier**: [https://licenses.ishare.eu/certification-pci-dss/1.0](/certification-pci-dss/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘PCI DSS - Payment Card Industry Data Security Standard’ certification.

### Use and process in full compliance with CSA STAR

**Identifier**: [https://licenses.ishare.eu/certification-csa-star/1.0](/certification-csa-star/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘CSA STAR - Cloud Security Alliance Security Trust Assurance and Risk’ certification.


# Legacy Identifier Mapping

Earlier iSHARE Framework versions used short numeric identifiers (`0000`, `0001`, …) to reference licenses in delegation evidence. From Framework v3.0 onwards, the canonical license identifier is a fully-qualified URL (e.g. `https://licenses.ishare.eu/general-unrestricted/1.0`).

This page defines the canonical mapping from every recognised legacy identifier — in both bare and namespaced form — to its v3.0 canonical URL, and the timeline for the transition.

## Mapping table

Both the bare form (`0001`) and the namespaced form (`ISHARE.0001`) MUST be treated as equivalent and MUST map to the same canonical URL.

| Legacy identifier (bare) | Legacy identifier (namespaced) | Canonical URL                                                            |
| ------------------------ | ------------------------------ | ------------------------------------------------------------------------ |
| `0000`                   | `ISHARE.0000`                  | `https://licenses.ishare.eu/general-unrestricted/1.0`                    |
| `0001`                   | `ISHARE.0001`                  | `https://licenses.ishare.eu/general-resharing-with-adhering-parties/1.0` |
| `0002`                   | `ISHARE.0002`                  | `https://licenses.ishare.eu/general-internal-use/1.0`                    |
| `0003`                   | `ISHARE.0003`                  | `https://licenses.ishare.eu/general-non-commercial-use/1.0`              |
| `0004`                   | `ISHARE.0004`                  | `https://licenses.ishare.eu/general-enrich-with-own-data/1.0`            |
| `0005`                   | `ISHARE.0005`                  | `https://licenses.ishare.eu/general-enrich-with-others-data/1.0`         |
| `0008`                   | `ISHARE.0008`                  | `https://licenses.ishare.eu/general-use-to-service-entitled-party/1.0`   |
| `9999`                   | `ISHARE.9999`                  | `https://licenses.ishare.eu/general-determined-between-parties/1.0`      |

### Gaps and licenses without a legacy form

* **`0006` and `0007`** were never assigned in the legacy scheme.
* **`general-internal-use-insights`** and **`general-enrich-with-third-party-generated-data`** are v3.0 additions and have no legacy numeric form. They MUST be referenced by canonical URL only.
* **All certification, country, and industry licenses** have no legacy numeric form. They MUST be referenced by canonical URL only.


# general/unrestricted

Available versions:

* [1.0](/general-unrestricted/1.0)


# 1.0

## Use and process without restrictions

**Identifier**: [https://licenses.ishare.eu/general-unrestricted/1.0](/general-unrestricted/1.0)\
Previous identifier: 0000

* Data labeled with this License may be used and (re-)shared without further limitations and/or conditions imposed pursuant to the iSHARE Framework.
* The above applies without prejudice to any applicable laws and/or rights of third parties.


# general/resharing-with-adhering-parties

Available versions:

* [1.0](/general-resharing-with-adhering-parties/1.0)


# 1.0

## Reshare with Adhering Parties

**Identifier**: [https://licenses.ishare.eu/general-resharing-with-adhering-parties/1.0](/general-resharing-with-adhering-parties/1.0)\
Previous identifier: 0001

* Data labeled with this License may exclusively be (re-)shared with and used by Adhering Parties in accordance with the rules of the iSHARE Framework.


# general/internal-use

Available versions:

* [1.0](/general-internal-use/1.0)


# 1.0

## Use and process for internal purposes only

**Identifier**: [https://licenses.ishare.eu/general-internal-use/1.0](/general-internal-use/1.0)\
Previous identifier: 0002

* Data labeled with this License is intended for internal use only and may not be shared with or used by any other party
* The above limitation applies to the Data or Dataset itself, and does not extend to any products and/or services developed or generated by such internal use of the Data. Such products or services may be put to commercial use.


# general/internal-use-insights

Available versions:

* [1.0](/general-internal-use-insights/1.0)


# 1.0

## Use and process for internal purposes — generated insights/know how

**Identifier**: [https://licenses.ishare.eu/general-internal-use-insights/1.0](/general-internal-use-insights/1.0)

* Data labeled with this License is intended for internal use only and may not be shared with or used by any other party.
* The above limitation applies to the Data or Dataset itself, and does not extend to any products and/or, services, insights/know-how or similar developed or generated by such internal use of the Data. Such insights/know-how or similar may be put to commercial use.


# general/non-commercial-use

Available versions:

* [1.0](/general-non-commercial-use/1.0)


# 1.0

## Use and process for non-commercial purposes

**Identifier**: [https://licenses.ishare.eu/general-non-commercial-use/1.0](/general-non-commercial-use/1.0)\
Previous identifier: 0003

* Data labeled with this License may be used and (re-)shared freely, provided that such use or sharing occurs for strictly non-commercial purposes.
* Any commercial use of or (end-)purpose for the Data is strictly prohibited. This includes without limitation:
  * any use and/or (re-)sharing of the Data for the purpose of receiving compensation or generating revenue; and
  * use and/or (re-)sharing of the Data for the purpose of developing products, services or similar for commercial use.


# general/enrich-with-own-data

Available versions:

* [1.0](/general-enrich-with-own-data/1.0)


# 1.0

## Enrich with own data

**Identifier**: [https://licenses.ishare.eu/general-enrich-with-own-data/1.0](/general-enrich-with-own-data/1.0)\
Previous identifier: 0004

May enrich with own data or available data generated by third parties

* Data labeled with this License may be enriched, but only with data generated by the direct recipient of the Data.
* Enrichment using data provided by third parties is strictly prohibited unless such is allowed under another applicable License.


# general/enrich-with-third-party-generated-data

Available versions:

* [1.0](/general-enrich-with-third-party-generated-data/1.0)


# 1.0

## Enrich with data generated directly by third parties

**Identifier**: [https://licenses.ishare.eu/general-enrich-with-third-party-generated-data/1.0](/general-enrich-with-third-party-generated-data/1.0)

* Data labeled with this License may be enriched, but only with data generated by the discloser and/or the direct provider of the Data.
* Data provided by third parties may be used for enrichment but only if the data was generated by such third parties directly.
* Enrichment using data provided by third parties that was not generated by such third parties is strictly prohibited unless such is allowed under another applicable License.


# general/enrich-with-others-data

Available versions:

* [1.0](/general-enrich-with-others-data/1.0)


# 1.0

## Enrich with data provided by third parties

**Identifier**: [https://licenses.ishare.eu/general-enrich-with-others-data/1.0](/general-enrich-with-others-data/1.0)\
Previous identifier: 0005

* Data labeled with this License may be enriched, but only with data generated by third parties.
* Enrichment using data generated by the direct recipient of the Data is strictly prohibited, unless such is allowed under another applicable License.


# general/use-to-service-entitled-party

Available versions:

* [1.0](/general-use-to-service-entitled-party/1.0)


# 1.0

## Use and process to service an Entitled Party

**Identifier**: [https://licenses.ishare.eu/general-use-to-service-entitled-party/1.0](/general-use-to-service-entitled-party/1.0)\
Previous identifier: 0008

Licensee may only use and process received data for an explicit service to the data rights holder / entitled party

* Data labeled with this License may only be used and processed insofar this is strictly necessary for the provision of the specific service(s) to an Entitled Party under an agreement in the context of which the Data is shared.


# general/determined-between-parties

Available versions:

* [1.0](/general-determined-between-parties/1.0)


# 1.0

## Use and process as determined between Parties

**Identifier**: [https://licenses.ishare.eu/general-determined-between-parties/1.0](/general-determined-between-parties/1.0)\
Previous identifier: 9999

As determined between Parties

* Data labeled with this License is shared under specific conditions and under the applicability of specific provisions agreed to between the exchanging parties in a separate agreement. Care must be taken at all times to reference the relevant agreement and act in full compliance with the relevant agreement.


# country/{XX}

Available versions:

* [1.0](/country-xx/1.0)


# 1.0

## Use and process within country

**Identifier**: [https://licenses.ishare.eu/country-{XX}/1.0](/country-xx/1.0)

* Data labeled with this License may only be used and processed within the country/countries corresponding to the specified ISO 3166-1 alpha-2 two-letter country code (e.g. NL, BE).

## `{XX}` — Country code

* **Source standard**: [ISO 3166-1 alpha-2](https://www.iso.org/iso-3166-country-codes.html)
* **Case**: lower case (e.g. `nl`, `de`, `fr`)
* **Length**: exactly 2 characters

### Examples

| Country     | Identifier                                  |
| ----------- | ------------------------------------------- |
| Netherlands | `https://licenses.ishare.eu/country-nl/1.0` |
| Germany     | `https://licenses.ishare.eu/country-de/1.0` |
| France      | `https://licenses.ishare.eu/country-fr/1.0` |

## Multiple values

If a delegation applies to more than one country, the evidence MUST express the values using an `anyOf` structure. Inline concatenation (e.g. `country-nl-de`) is invalid.

**Correct**

```json
"licenses": [
  {
    "anyOf": [
      "https://licenses.ishare.eu/country-nl/1.0",
      "https://licenses.ishare.eu/country-de/1.0"
    ]
  }
]
```

**Invalid**

```json
"licenses": ["https://licenses.ishare.eu/country-nl-de/1.0"]
```


# industry/{NNNN}

Available versions:

* [1.0](/industry-nnnn/1.0)


# 1.0

## Use and process within industry

**Identifier**: [https://licenses.ishare.eu/industry-{NNNN}/1.0](/industry-nnnn/1.0)

* Data labeled with this License may only be used and processed within the industry corresponding to the specified [ISIC industry code](https://unstats.un.org/unsd/classifications/Econ/ISIC).

## `{NNNN}` — Industry code

* **Source standard**: [ISIC Rev.4](https://unstats.un.org/unsd/classifications/Econ/ISIC)
* **Format**: zero-padded to exactly 4 digits

### Examples

| Industry                                | ISIC code | Identifier                                     |
| --------------------------------------- | --------- | ---------------------------------------------- |
| Freight transport by road               | 4923      | `https://licenses.ishare.eu/industry-4923/1.0` |
| Warehousing and storage                 | 5210      | `https://licenses.ishare.eu/industry-5210/1.0` |
| Sea and coastal freight water transport | 0501      | `https://licenses.ishare.eu/industry-0501/1.0` |

## Multiple values

If a delegation applies to more than one industry, the evidence MUST express the values using an `anyOf` structure. Inline concatenation (e.g. `country-nl-de`) is invalid.

**Correct**

```json
"licenses": [
  {
    "anyOf": [
      "https://licenses.ishare.eu/industry-5210/1.0",
      "https://licenses.ishare.eu/industry-0501/1.0"
    ]
  }
]
```

**Invalid**

```json
"licenses": ["https://licenses.ishare.eu/industry-5210-0501/1.0"]
```


# certification/iso-27001

Available versions:

* [1.0](/certification-iso-27001/1.0)


# 1.0

## Use and process in full compliance with ISO 27001

**Identifier**: [https://licenses.ishare.eu/certification-iso-27001/1.0](/certification-iso-27001/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 27001 - Information Security Management’ certification standard.


# certification/iso-9001

Available versions:

* [1.0](/certification-iso-9001/1.0)


# 1.0

## Use and process in full compliance with ISO 9001

**Identifier**: [https://licenses.ishare.eu/certification-iso-9001/1.0](/certification-iso-9001/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 9001 - Quality Management’ certification standard.


# certification/iso-14001

Available versions:

* [1.0](/certification-iso-14001/1.0)


# 1.0

## Use and process in full compliance with ISO 14001

**Identifier**: [https://licenses.ishare.eu/certification-iso-14001/1.0](/certification-iso-14001/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 14001 - Environmental Management’ certification standard.


# certification/iso-45001

Available versions:

* [1.0](/certification-iso-45001/1.0)


# 1.0

## Use and process in full compliance with ISO 45001

**Identifier**: [https://licenses.ishare.eu/certification-iso-45001/1.0](/certification-iso-45001/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 45001 - Occupational Health and Safety’ certification standard.


# certification/iso-22000

Available versions:

* [1.0](/certification-iso-22000/1.0)


# 1.0

## Use and process in full compliance with ISO 22000

**Identifier**: [https://licenses.ishare.eu/certification-iso-22000/1.0](/certification-iso-22000/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘ISO 22000 - Food Safety Management’ certification standard.


# certification/gdpr-regulated

Available versions:

* [1.0](/certification-gdpr-regulated/1.0)


# 1.0

## Use and process in full compliance with GDPR

**Identifier**: [https://licenses.ishare.eu/certification-gdpr-regulated/1.0](/certification-gdpr-regulated/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘GDPR Certification’ standard as meant in article 42 of the European General Data Protection Regulation.


# certification/hipaa-regulated

Available versions:

* [1.0](/certification-hipaa-regulated/1.0)


# 1.0

## Use and process in full compliance with HIPAA

**Identifier**: [https://licenses.ishare.eu/certification-hipaa-regulated/1.0](/certification-hipaa-regulated/1.0)

* Data labeled with this License may only be used and processed in full compliance with the Health Insurance Portability and Accountability Act (HIPAA).


# certification/soc-2

Available versions:

* [1.0](/certification-soc-2/1.0)


# 1.0

## Use and process in full compliance with SOC 2

**Identifier**: [https://licenses.ishare.eu/certification-soc-2/1.0](/certification-soc-2/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘SOC 2 - Service Organization Control Type 2’ certification.


# certification/pci-dss

Available versions:

* [1.0](/certification-pci-dss/1.0)


# 1.0

## Use and process in full compliance with PCI DSS

**Identifier**: [https://licenses.ishare.eu/certification-pci-dss/1.0](/certification-pci-dss/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘PCI DSS - Payment Card Industry Data Security Standard’ certification.


# certification/csa-star

Available versions:

* [1.0](/certification-csa-star/1.0)


# 1.0

## Use and process in full compliance with CSA STAR

**Identifier**: [https://licenses.ishare.eu/certification-csa-star/1.0](/certification-csa-star/1.0)

* Data labeled with this License may only be used and processed in full compliance with the ‘CSA STAR - Cloud Security Alliance Security Trust Assurance and Risk’ certification.


