ODC-By-1.0 is attribution-only for databases. Share the data, keep the credit. No share-alike. Sibling of ODbL without copyleft.
On this page
What it does
Open Data Commons Attribution License 1.0 lets you use, share and adapt a database if you attribute. There is no share-alike on derivative databases. It sits next to ODbL (copyleft) and PDDL (public-domain style) in the ODC family. Use it for datasets where credit matters and reuse should stay easy.
Pros
- Easy to drop into a closed, paid product. Procurement has seen this family many times.
- No copyleft on your own files. You keep your source private.
Cons
- The notice duty is easy to miss in a desktop, mobile, or container build. A web page is not a substitute for notices inside the artifact.
- Transitive copies in the lockfile count. Listing only direct dependencies leaves notices out.
What it allows and requires
Choose a category to see the full grant in one scannable list. Permissions show what the license allows, limits show what it withholds, and obligations show the conditions your release process must satisfy.
Permissions
Commercial use
Commercial use is allowed. CC-BY and OFL do not ban selling a product that includes the work.
Modify
You may adapt the work, within the license's share-alike or non-commercial limits if those apply.
Distribute
You may share copies of the original and, where allowed, of your adaptations.
Limits
Hold liable
The authors disclaim warranty. Recipients cannot hold them liable for damages arising from the software, except where law forbids that disclaimer.
Use trademark
The license is not a trademark license. Names, logos and product marks stay with their owners unless a separate grant says otherwise.
Obligations
Give credit
Give the credit the license asks for, in a reasonable manner, without implying endorsement.
What ODC-By-1.0 requires when you ship
When a copy that includes ODC-By-1.0 code leaves your company, the grant is broad and the paperwork is easy to miss. Distribution here means an installer, a mobile binary, a container image, or an SDK another team embeds. Work this list against the artifact you actually hand over, not against a README. A hosted service that never gives out a copy still belongs on the record, but the notice duty does not fire until a copy exists.
You meet the notice condition when each ODC-By-1.0 component's copyright line and license text appear in the material the recipient actually gets.
You are done for a hosted service that never hands out a copy. Running the software for users over a network does not, by itself, trigger a notice duty.
You are covered for a desktop, mobile or on-premise build when the notices sit inside the artifact. An about screen or a bundled licenses file both work.
The duties named in ODC-By-1.0
The license text itself is short. These are the named conditions. They follow the code, including files you vendor into your own repository and transitive packages in the lockfile.
Give credit
Give the credit the license asks for, in a reasonable manner, without implying endorsement.
Things to be aware of
- Reading ODC-By-1.0 as no obligations at all and shipping a binary with no notices in it. Put the notices in the artifact you hand over.
- Deleting the license header when you copy one or two files into your own repository. The condition follows the code, not the package it came in.
What the Open Data Commons Attribution 1.0 does not do
Search results often flatten Open Data Commons Attribution 1.0 into a slogan. These are the usual misreads. ODC-By-1.0 is a grant with conditions, not a permission to skip the paperwork below.
- ODC-By-1.0 does not mean no obligations. The copyright line and the license text still have to travel with copies you distribute.
- ODC-By-1.0 does not force you to open your own source. There is no copyleft here unless a later clause in this text says otherwise.
How ODC-By-1.0 differs from nearby licenses
These licenses are often confused with ODC-By-1.0, but their release duties differ. Each row summarizes what the license requires when you ship. Open the linked page for the full checklist.
- ODC-By-1.0
- ODC-By-1.0 is attribution-only for databases. Share the data, keep the credit. No share-alike. Sibling of ODbL without copyleft.
- ODbL-1.0
- ODbL-1.0 is share-alike for databases, not code. OpenStreetMap uses it. Produced works have a notice duty; derivative databases stay under ODbL.
- PDDL-1.0
- PDDL-1.0 waives database rights to the public domain as far as the waiver can reach. Keep the SPDX id on the record anyway.
- CC-BY-4.0
- Credit the creator and you may use the work commercially. The credit may sit anywhere a user can reasonably find it.
Common questions about Open Data Commons Attribution 1.0
Answers to common questions about what Open Data Commons Attribution 1.0 requires, when its duties apply, and what evidence belongs with a release.
What is the Open Data Commons Attribution 1.0?
Open Data Commons Attribution License 1.0 lets you use, share and adapt a database if you attribute. There is no share-alike on derivative databases. It sits next to ODbL (copyleft) and PDDL (public-domain style) in the ODC family. Use it for datasets where credit matters and reuse should stay easy.
What does ODC-By-1.0 require when you ship a product?
You meet the notice condition when each ODC-By-1.0 component's copyright line and license text appear in the material the recipient actually gets. You are done for a hosted service that never hands out a copy. Running the software for users over a network does not, by itself, trigger a notice duty. You are covered for a desktop, mobile or on-premise build when the notices sit inside the artifact. An about screen or a bundled licenses file both work.
Does ODC-By-1.0 require me to open my own source?
ODC-By-1.0 does not force you to open your own source. There is no copyleft here unless a later clause in this text says otherwise.
How do I attribute ODC-By-1.0 in a product I ship?
Attribution for ODC-By-1.0 means the copyright line and the license text travel with every copy a recipient actually gets. That can be an about screen, a licenses file inside the installer, or a notice in the container image. A public page helps a buyer audit the inventory. It does not replace notices inside the artifact. If you copied files into your own repository, the header on those files still has to stay.
Is a website notice enough for ODC-By-1.0?
No. ODC-By-1.0 talks about copies. A public attestation page is the honest list for procurement. The condition is met when the notices sit in the material you hand over. Put them in the installer, the about screen, or a licenses file inside the binary, then keep the same texts on the page.
Do transitive ODC-By-1.0 dependencies count?
Yes. The condition follows the code, not the package you chose by name. If the lockfile pulled in ODC-By-1.0 transitively and you distribute that tree, those notices travel too. Listing only direct dependencies is how teams miss the duty.
How is ODC-By-1.0 different from Open Database License 1.0?
ODC-By-1.0 asks this: ODC-By-1.0 is attribution-only for databases. Share the data, keep the credit. No share-alike. Sibling of ODbL without copyleft. Open Database License 1.0 asks this: ODbL-1.0 is share-alike for databases, not code. OpenStreetMap uses it. Produced works have a notice duty; derivative databases stay under ODbL. Open the Open Database License 1.0 page for what that license requires when you ship. Do not treat the SPDX ids as interchangeable because the short names look similar.
Where do I record ODC-By-1.0 for a buyer?
ODC-By-1.0 is a notice license in the catalog, so a component under it needs license text attached before it counts as live on your published page. SourceTrust fetches the published artifact, extracts the license file, and compares that text against the declared SPDX id. A match fills the text in. Every other outcome waits for a person. The stored text is what your page and each export file carry.
Where do I record ODC-By-1.0 for a buyer?
ODC-By-1.0 is a notice license in the catalog, so a component under it needs license text attached before it counts as live on your published page. SourceTrust fetches the published artifact, extracts the license file, and compares that text against the declared SPDX id.
A match fills the text in. Every other outcome waits for a person.
The stored text is what your page and each export file carry. Read /docs/auto-fetch-license for how the fetch works.
See also
The hub is the pillar for this cluster. Sibling licenses are the other spokes. Product FAQ links explain how SourceTrust records the duty, not the license text itself.
Practical guidance for procurement review, not legal advice. Confirm high-stakes use with counsel.
