Quick Answer: Compliant real estate data is MLS listing data used under a current agreement, for a use the granted access type actually covers, by parties the agreement names, within permitted retention and processing limits. MLS data is licensed, not public. Most non-compliance is drift rather than intent: the data arrived legitimately and the use changed. Consequences run from feed termination in a market, through liability flowing back to the sponsoring brokerage, to failed diligence when an acquirer finds the core data asset was never properly licensed.
This article is general information for product, engineering and commercial teams. It is not legal advice. MLS rules are set and enforced locally and vary by market, and several national policies referenced here changed in the 2026 Handbook. Confirm specifics with counsel and with the MLS in each market you operate in.
Most conversations about MLS data compliance start with a narrow question, usually some version of “can we scrape this,” and miss the structural point that makes the subject coherent.
MLS listing data is licensed content, not public information. It is visible publicly, which causes the confusion, but visibility and availability are different things. A listing appears on a public website under a licensing chain running from the seller, through the listing broker, to the MLS, and out to whoever is authorized to display it. Every link carries terms.
This guide covers that chain as of 2026, a year in which the national framework changed substantially. It sets out what compliance means here, who holds which rights, the six conditions that make a dataset compliant, where compliant and non-compliant data come from, what non-compliance puts at risk, and how to verify what you are actually using.
What This Guide Covers
• Why compliance here is mostly contractual, where statute does bite, and what changed in the 2026 Handbook
• How rights flow from seller to broker to MLS to you, and the two designee provisions proptech companies rely on
• The six conditions that define compliant data, and where the delivery layer enforces them
• Five legitimate routes to MLS data, and which suits which kind of company
• Seven sources of non-compliant data, and why five of them are drift rather than decision
• Four questions worth raising with your MLS
• What non-compliance puts at risk, from feed termination to failed diligence
• How to verify what you are using, why the audit must be scoped through counsel, and what to do if you find a problem
Real Estate Data Compliance Is Mostly Contractual, But Not Only Contractual
The Contractual Layer Is Where Most of the Risk Sits
When a software team hears compliance, the reflex is statute: GDPR, CCPA, HIPAA. Frameworks written by legislators, enforced by regulators, carrying defined penalties.
MLS data compliance is mostly a different animal. There is no federal listing data statute and no regulator issuing fines for misusing a feed. What exists is a network of private agreements, association policies, and local rules, enforced by the MLS itself.
Enforcement Became More Local in 2026, Not Less
In November 2025, following its first comprehensive antitrust risk assessment of MLS policy, NAR approved 18 changes to the MLS Handbook. Real Estate News described them as the most extensive revisions in twenty years, and they took effect on 1 January 2026. The NAR Summary of 2025 MLS Changes sets the local adoption deadline at 1 March 2026 and gives the compliance classification of each policy.
Two of those changes matter directly here. NAR repealed Policy Statement 7.89, which had authorized financial penalties up to $15,000, and repealed Section 5 of the MLS Disciplinary Guidelines in its entirety. As HousingWire reported, the effect is that each MLS now independently determines its own fine amounts and disciplinary practices. The national ceiling is gone.
For a brokerage or proptech company operating across markets, this is a meaningful shift and it runs against the intuitive direction. Enforcement did not become more uniform. It became less. Penalty exposure is now whatever each individual MLS decides it is, set locally, with no national cap and no common disciplinary schedule to reason from.
A third repeal in the same cycle is worth flagging for anyone building on aggregated data. Policy Statement 7.87, which addressed whether MLSs must transmit listings to third-party aggregators or display them on public websites, was also repealed, making those decisions entirely local. NAR’s MLS Policy Risk Assessment PAG Recommendations set out all eighteen in full, and the Summary of 2025 MLS Changes carries the same list on a permanent page.
This compounds a point NAR made separately in 2026 guidance on office exclusives: individual MLSs enforce their own rules, evaluate violations, and determine sanctions. There is no central enforcement body and no single appeals process. After the 2026 changes, there is no national penalty ceiling either.
Consequences also arrive faster than statutory ones. A regulator investigates for months. An MLS can begin termination proceedings in weeks, and your product stops working in that market.
Access Prerequisites Also Moved to Local Discretion
Enforcement was only half of what changed, and for proptech companies the other half matters more.
Six of the eighteen recommendations repealed policies governing non-member access to the MLS. NAR repealed Policy Statement 7.7, which had made association membership a prerequisite to MLS participation, along with 7.25 (procedures for requesting access without association membership), 7.55 (nonmember broker and appraiser access), 7.38 (indoctrination requirements for those entitled to participate without membership), 7.92 (orientation and training requirements), and the Note under 7.26 covering commercial and industrial MLSs. The combined effect, in NAR framing quoted in the Summary of 2025 MLS Changes, is that prerequisites to MLS access are now a matter of local discretion.
A seventh change in the same group amended Policy Statement 7.58 to remove the optional local provision that had allowed an MLS to limit IDX display rights to REALTORS only. If you were previously excluded from IDX display in a market on membership grounds, that specific basis for exclusion is gone.
Read carefully, none of this dissolves the eligibility gate described in the next section. The Participant definition, and its broker license requirement, sits in the qualification policy and still stands. What moved is the layer of national prerequisites around that definition, including whether association membership is required at all.
The practical consequence is that the answer to “can we get access here” is now more local, and more variable, than it was in 2025. Ask each MLS directly rather than reasoning from a national position, and re-ask in markets where you were previously told no.
Where Statute Does Bite
It would be convenient to say this is purely contractual. It is not, and a team relying on that framing underestimates its exposure in three places.
Copyright. MLS compilations can attract copyright protection as compilations, and infringement is a statutory claim carrying statutory damages entirely separate from any contract. In MRIS v. American Home Realty Network (722 F.3d 591, 4th Cir. 2013), the Fourth Circuit upheld a preliminary injunction protecting an MLS’s copyright in its compilation and in photographs, against a company aggregating listings into a competing search product.
Unauthorized access. Collecting data in circumvention of technical controls can implicate the Computer Fraud and Abuse Act, state computer-crime statutes, and common-law claims such as trespass to chattels. The picture here is more contested than it once was: following hiQ Labs v. LinkedIn, CFAA theories against collection of genuinely public pages are considerably weaker than they were a decade ago. That narrows one avenue without closing the others, and it does nothing to address the copyright exposure above.
Privacy statute. VOW registration records, agent roster information, and consumer data collected alongside listing data are personal information. CCPA and CPRA apply in California, with comparable regimes in other states, and Canadian operations engage PIPEDA and Quebec Law 25.
The honest framing is layered. Most day-to-day failures are contractual and resolve commercially. A subset carry statutory exposure on top. Condition 6 below, covering processing locations and subprocessors, exists precisely because the statutory layer is real.
A working distinction: statutory failures usually end in a fine or a claim. Contractual failures usually end in your data being switched off, which for a data-dependent product is often the more immediate problem.
Why Visibility Is Not Availability
The most common misconception here is that publicly displayed listing data is therefore public data.
The parallel is a newspaper article. It is visible to anyone who visits the site. That visibility transfers no right to republish it, build a product on it, or resell it. MLS data works the same way. What you can see, you can see because someone was authorized to display it to you, under terms governing what happens next.
Genuinely public real estate records do exist and matter. County assessor records, recorded deeds, mortgage filings, and permit records are government records with terms set by the county. Much of the confusion comes from the two categories sitting side by side in the same products. We cover the distinction in our plain-English guide to real estate data types.
The Three Questions That Define Compliance
Strip away detail and compliance reduces to three questions. Do you have the right to receive this data? Does what you are doing with it match what you were granted? Is the data staying where it should, for as long as it should?
A dataset is compliant when all three answers are yes, continuously. Most non-compliance is a yes on the first and a no on one of the others, which is why it goes unnoticed. The data arrived legitimately. What happened next drifted.
How Rights Flow: Seller to Broker to MLS to You
Obligations attach at every link. Skip one and you inherit an obligation you did not know you had.
The Seller and the Listing Broker
The chain starts with the property owner, who signs a listing agreement authorizing a brokerage to market the property, which includes submitting it to the MLS so other brokers can cooperate.
The listing broker is the origin point of the data rights, and Policy Statement 7.85, Ownership of Listing and Listing Content, is explicit about it: the listing broker owns the listing agreement, and should own or hold a license to all listing content before submitting it. It also provides that MLSs cannot require participants to transfer intellectual property rights as a condition of participation, and that MLS use of listings beyond the defined purposes of the MLS requires participants’ consent.
That last clause is worth sitting with. The MLS controls access to the aggregated database, but it does not own the underlying content, and its own use of that content is bounded. Rights flow through the MLS rather than originating there.
Seller elections are a separate mechanism, governed by the IDX policy at 7.58 and the VOW policy. Where a seller has directed that a particular feature be disabled on IDX displays, or has opted their listing out of specific treatments, those elections travel with the record and bind everyone displaying it, not only the listing brokerage.
The MLS
The MLS aggregates listings from participating brokerages and makes them available under rules it sets and enforces. It controls access to the aggregated database and sets terms for every feed.
MLSs vary enormously, from large regional systems carrying millions of listings to organizations covering a single county. Each sets rules within the NAR framework, and local supplements are frequently more restrictive than the national baseline. After the 2026 changes, the space in which local variation operates is wider than it was.
The framework has been shaped by antitrust litigation. The VOW policy in its current form emerged from a 2008 settlement between NAR and the US Department of Justice, which required that brokers not be excluded from MLS participation on the basis of their business model. That history matters to proptech founders, because it is why internet-based access exists as a defined category at all, and the 2025 antitrust risk assessment that produced the 2026 changes is a continuation of the same pressure.
Participants and Subscribers
Access is granted through defined roles. Under NAR qualification policy, a Participant must hold a current, valid real estate broker license and be a principal, partner, corporate officer, or branch office manager acting on behalf of a principal. Subscribers are non-principal brokers, sales licensees, and others affiliated with a Participant.
This is the eligibility gate and, for proptech companies, the first hard constraint. A software company with no licensed broker is not a Participant and cannot hold participation rights in its own name. It is the reason so many proptech products are built on a relationship rather than a direct license.
The Designee Provisions, and Why Proptech Companies Should Read Them Carefully
There is a mechanism allowing a technology company to receive MLS data legitimately without holding a broker license. It is frequently described loosely, and the detail defines the boundary of an entire business model.
There are two distinct provisions, and conflating them is a common error.
Policy Statement 8.6, One Data Source, requires that at the request of a Participant, the MLS provide a single data feed for that Participant’s licensed uses to that Participant’s designee. The designee may use that feed only to facilitate the Participant’s licensed uses, on behalf of that Participant.
Policy Statement 8.7, Brokerage Back Office Feed, is narrower and specific to BBO. BBO Use may only be made by the Participant and affiliated Subscribers, except that at the request of a Participant the MLS must provide BBO Data to that Participant’s designee, who may use it only to facilitate the BBO Use on behalf of that Participant and its affiliated Subscribers. The same statement confirms MLSs may require the designee to sign the same or a separate and different license agreement from the Participant’s.
In both cases the operative constraint is identical. A designee is not licensed in its own right. It acts on behalf of a specific Participant, for that Participant’s permitted purposes. It acquires no independent right to use the data for its own purposes, serve other customers from the same feed, or build products unrelated to that Participant’s licensed uses.
A great deal of well-intentioned non-compliance lives in the gap between what a designee may do and what a growing software business wants to do next. A feed that legitimately powers one brokerage’s tools does not legitimately power a multi-tenant product serving forty other brokerages unless each relationship is separately established.
Six Conditions Define Compliant Real Estate Data
Compliance can be stated as six conditions. All six must hold simultaneously and continuously. It is a state, not an event.
| Condition | The question it answers | Where teams commonly fail |
| 1. Valid agreement | Is there a current, executed agreement covering this data? | Agreement lapsed but the feed kept delivering |
| 2. Correct access type | Does the granted access type cover this use? | IDX feed powering analytics or model training |
| 3. Permitted use | Is the specific application within scope? | A feature the agreement never contemplated |
| 4. Permitted parties | Is only an authorized entity touching the data? | Affiliates, franchise parents, vendors receiving data |
| 5. Permitted retention | Is the data held only as long as allowed? | Multi-year archives in shorter-window markets |
| 6. Disclosed processing | Is processing happening where it was declared? | Offshore teams, AI services, undisclosed subprocessors |
Condition 1: A Valid, Current Agreement
An executed agreement must be in force, covering the specific data received, between parties each with authority to enter it. Agreements expire, get superseded, and are sometimes signed by a counterparty who never had the right to grant what they granted.
Renewal deserves attention. MLS agreements are typically annual and frequently auto-renew, but not always and not in every market. A feed continuing to deliver after an agreement lapsed is delivering unlicensed data, and continued delivery is not evidence of permission.
Condition 2: The Correct Access Type
Access is granted in categories narrower than most teams assume. We cover all three in detail in Real Estate Data Compliance 101, so this is a summary.
IDX (Internet Data Exchange): public display of active listings in consumer-facing search applications operated by licensed Participants.
VOW (Virtual Office Website): access for registered users where a lawful broker-consumer relationship has been established first.
BBO (Broker Back-Office): non-display uses including brokerage management systems, CRM and transaction management tools, and agent and brokerage productivity and ranking tools and reports.
The word doing the work in IDX is display, and this is not a matter of interpretation.
The NAR IDX policy at Policy Statement 7.58 establishes that MLS participants may not use IDX-provided listings for any purpose other than IDX display. That principle is carried into the model IDX rules individual MLSs adopt locally, typically numbered around Section 18.2.2. The Pikes Peak MLS IDX and VOW rules are a representative example: IDX users may not use IDX-provided listings for any purpose other than display as provided for in those rules.
One carve-out matters for anyone building a web product. The rule as commonly adopted does not require IDX users to prevent indexing of IDX listings by recognized search engines, so search engine indexing of an otherwise compliant IDX display is contemplated. The IDX policy carries a number of local options an MLS may or may not adopt, so confirm the position with each MLS rather than assuming the default applies everywhere.
The 2026 amendment to 7.58, covered earlier, removed the optional local provision allowing an MLS to limit IDX display rights to REALTORS only. That is a narrowing of local discretion rather than a widening of it, and it runs against the general direction of the cycle.
Everything else in the non-display category remains outside IDX. Analytics is not display. Model training is not display. Generating an internal market report is not display. Each requires BBO access, in each market where it happens.
Condition 3: The Specific Use Is Within Scope
Holding the right access type is necessary but not sufficient. BBO in particular is narrower than the phrase “back office” suggests.
Under Policy Statement 8.7, BBO Use covers brokerage management systems exposing data only to the Participant and affiliated Subscribers, CRM and transaction management tools exposing data to the Participant, Subscribers, and their bona fide clients as established under state law, and agent and brokerage productivity and ranking tools and reports. It also covers marketplace statistical analysis and reports, but only in conformance with Policy Statement 7.80.
That cross-reference is the one most often missed.
Policy Statement 7.80 governs use of MLS information in advertising and other public representations. It permits information from MLS compilations, statistical reports, and sold or comparable reports to be used as the basis for aggregated demonstrations of market share, or comparisons of firms, in public mass-media advertising and other public representations. It attaches a requirement that is easy to overlook: any advertising or public representation based in whole or part on MLS information must clearly disclose the source of the information and the period of time over which the claims are based.
Read carefully, 7.80 is narrower than a general permission to publish market statistics. It is framed around market share demonstrations and firm comparisons. A product publishing neighborhood-level median days on market as a general market intelligence feature is not squarely within that framing, and should be assessed against the specific MLS agreement rather than assumed to be covered.
Condition 4: Only Permitted Parties Receive the Data
Agreements name the parties who may receive data. Everyone else is a third party, including entities that feel internal.
An affiliated mortgage company under common ownership is a separate legal entity. A franchise parent aggregating from franchisees is separate from each franchisee. A technology vendor processing on your behalf is a third party whose use you remain responsible for. None of these permit data flow by default, and the corporate structure that feels like one business is several parties in contract terms.
Condition 5: Retention Stays Within Permitted Windows
Sold and expired listing retention terms vary considerably between markets. Some permit indefinite retention for internal analysis. Others require deletion within a defined window after closing.
One concrete anchor shows why uniform policies fail. The NAR VOW policy establishes that sale prices can only be categorized as confidential in states where actual sale prices of completed transactions are not accessible from public records. Those non-disclosure states are Alaska, Idaho, Kansas, Louisiana, Mississippi, Montana, New Mexico, North Dakota, Texas, Utah and Wyoming, with Missouri a partial case where St. Louis City, St. Louis County and Jackson County mandate disclosure and other counties do not.
Missouri is the most instructive of these, because it shows the problem is not even reliably solvable at state level. A product displaying sold prices operates under different constraints in Jackson County than in the county next to it.
For a multi-market product, a single retention and display policy applied uniformly is almost certainly wrong somewhere. Either the policy follows the most restrictive market, accepting reduced capability everywhere, or the system applies per-market logic. Most teams discover this late.
Condition 6: Processing Happens Where It Was Declared
The newest condition in practical terms, and the one most likely to catch teams that were compliant a year ago.
Where agreements require disclosure of processing locations or restrict subprocessors, arrangements must match what was declared. MLSs may impose security requirements as part of licensing, and the VOW policy contemplates MLSs requiring participants to maintain audit trails and produce registrant records where a breach or rules violation is suspected.
An offshore engineering team with production access, a cloud region outside the declared territory, or a third-party AI service processing listing content can each put an otherwise compliant operation offside. The AI point is live: routing MLS data through an external model service is a disclosure question most agreements did not anticipate and most teams have not revisited.
Where the Delivery Layer Binds
Compliance obligations do not only live in contracts. They are frequently enforced at the point of delivery, which is why the transport standard matters, and there is a mandatory policy on point. Policy Statement 7.90 requires MLSs owned and operated by associations of REALTORS to implement the RESO Standards, including the RESO Data Dictionary and the RESO Web API, and to keep current within one year of each new release. It adds a floor that is easy to miss: Web API access provided to participants and subscribers must carry no less than the same data available through older methods such as RETS or FTP, and fields that exist in the Data Dictionary must be delivered in conformance with the standard.
Note the scope. 7.90 binds MLSs owned and operated by associations of REALTORS. Broker-owned and independent MLSs exist and are not covered by it, so a team working with one may find no RESO obligation at all and should confirm rather than assume.
Where it does apply, access type is commonly implemented as a distinct feed or a field-level entitlement rather than as an honor-system contract term.
The practical consequence is that an IDX feed and a BBO feed for the same market can differ in the fields they carry, the record counts they return, and the rate limits they impose. A team that finds a field missing from its feed has usually found a licensing boundary rather than a bug. Retention constraints frequently bind here too, expressed as limits on how much history a feed will serve rather than as a clause anyone reads.
We cover the standard itself in What Is RESO and Why Does It Matter for Real Estate Data Products.
Five Legitimate Routes to MLS Listing Data
Each route carries different requirements, costs, and constraints. The right choice depends on scale, footprint, and whether the organization holds a broker license.
Route 1: Direct Participation
An organization holding a real estate broker license, whose principal qualifies as a Participant, can apply directly with each MLS covering its markets. The most complete form of access and the most demanding to operate.
Each market means a separate application, agreement, compliance obligation, and ongoing relationship. For a brokerage in its own markets this is simply how business is done. For a technology company it means maintaining a licensed brokerage entity and administering a growing portfolio of agreements as the footprint expands.
Route 2: Designee Access Through a Participant
The route most proptech companies actually use. A Participant requests that its designee receive a feed, under Policy Statement 8.6 for the Participant’s licensed uses generally, or Policy Statement 8.7 for BBO Data specifically.
The constraint bears repeating: the designee’s rights are derivative. They exist to serve that Participant’s permitted purposes. Scaling to many brokerages means establishing this relationship many times, not extending one relationship to cover everyone. The MLS may also require the designee to sign its own license agreement, separate from the Participant’s.
Route 3: A Licensed Aggregator
An aggregator holds its own agreements across many markets and delivers normalized data under terms flowing from those agreements. For any company needing more than a handful of markets, usually the only practical option.
The critical diligence question is whether the aggregator holds direct agreements or is itself downstream of another provider. A company reselling data it licensed from someone else may hold no redistribution right, and a customer buying from that reseller can hold a signed contract while having no valid license, because the counterparty never had one to convey. Our guide to evaluating a real estate data provider covers the questions that surface this.
Route 4: MLS-Operated and MLS-Owned Data Programs
Some MLSs and MLS-owned consortia operate their own data distribution programs, offering standardized access across a group of participating MLSs under a single agreement. Where one covers your markets, it can be the cleanest route available, since the counterparty and the rights holder are closely aligned.
The constraint is coverage, and the 2026 changes made it less predictable. Policy Statement 7.87, which addressed whether MLSs must transmit listing data to third-party aggregators or display listings on public websites, was repealed, leaving those decisions entirely local. As HousingWire noted in reporting the wider decentralization, the direction is toward more local variation rather than less. Whether a given program exists, what it covers, and what terms it carries is now more market-specific than it was.
Route 5: County Public Records
County assessor records, recorded deeds, mortgage filings, and permit records are government records. Access terms are set by each county and vary, but these differ fundamentally from MLS data in availability and attached obligations.
Two cautions. Public availability does not mean unrestricted commercial use in every jurisdiction, and bulk access agreements often carry their own terms. And public records answer different questions than MLS data: they tell you who owns a property and what they paid, not what is on the market today. Products frequently need both, which means managing two compliance regimes in one system.
| Route | Requires broker license | Practical ceiling | Best suited to |
| Direct participation | Yes | A few markets | Brokerages in their own footprint |
| Designee access | No (the Participant does) | Per-Participant scope | Products built for specific brokerages |
| Licensed aggregator | No | National | Multi-market proptech and enterprise |
| MLS-operated program | Varies by program | Program footprint | Teams whose markets one program covers |
| Public records | No | National, per-county terms | Ownership and characteristics data |
Seven Sources of Non-Compliant MLS Data
Seven sources account for most non-compliant MLS data in circulation. Two involve a deliberate decision, and in the second of those the decision is made by someone other than the company holding the data. The remaining five are things capable, well-run companies do without realizing, which is why they persist.
1. Data Collected From Public Portals Rather Than Licensed at Source
Listings displayed on a public website are licensed content, and public visibility conveys no right to collect, store, or build on them. A dataset assembled this way creates two distinct problems.
The first is direct exposure, and it is broader than contract. Beyond the terms of service of the site it came from, unauthorized collection can implicate copyright in the MLS compilation, which MRIS v. American Home Realty Network shows courts will enforce. That decision is Fourth Circuit and affirmed a preliminary injunction rather than deciding the merits, and the defendant sourced data from several places rather than purely by collecting from portals, so it is persuasive rather than dispositive. Computer-crime and common-law theories may also apply.
The second is provenance, and it is more consequential over time. There is no agreement to produce, no chain to document, and no answer when a partner, enterprise customer, or acquirer asks where the data came from. A dataset that cannot be explained is a liability that surfaces at the least convenient moment.
2. Feeds Resold by a Party Without Redistribution Rights
A vendor holding valid access for its own use does not automatically hold the right to resell. Redistribution is a separate right that must be granted explicitly.
This is the case where intent sits upstream and consequence lands downstream. The reseller made a decision. The buyer, acting in complete good faith, inherits the defect. A company can hold a properly executed contract, pay invoices on time, and still have no valid license, because the counterparty never had one to convey.
Good faith does not cure the underlying gap, and the buyer is the one whose product stops working when it surfaces. This is the strongest argument for asking a prospective provider directly whether they hold their own agreements, in a form requiring a documented answer.
3. Data Still Flowing After an Agreement Lapsed
Feeds frequently continue delivering past the expiry or termination of the agreement authorizing them. Credentials remain valid, the pipeline runs, nothing visibly changes.
Continued use after expiry is unlicensed use. The failure is administrative rather than technical, which is why it goes undetected: nobody monitors for the absence of an event. Engineering sees a healthy feed. Legal assumes renewal happened. Neither checks the other.
4. Data Used Outside the Access Type It Was Licensed Under
The most common source of non-compliance, and almost always unintentional.
The pattern is consistent. A company obtains IDX access for a consumer search product. Six months later the team builds an internal dashboard showing market trends, trains a recommendation model on accumulated listing data, or produces a neighborhood market report for prospects. Each is a reasonable product decision. Each is a non-display use IDX does not authorize.
Nobody decided to breach anything. The team extended a product using data it already had, and the licensing boundary was not part of the product conversation because it had been settled months earlier. This is why the access-type question belongs in feature planning, not only in procurement.
5. Data Shared With Entities Not Named in the Agreement
Where corporate structure and contract structure diverge.
Data flowing to an affiliated mortgage or title business, aggregating from franchisees to a brand-level analytics environment, or passing to a technology vendor for processing all involve parties legally distinct from the entity that signed. Each requires its own authorization. The intuition that these are all “us” is organizationally true and contractually irrelevant.
6. Data Retained Beyond Permitted Windows
A market intelligence feature built on a five-year archive of sold listings is a straightforward product decision and an exposure in every market whose retention window is shorter than five years.
The difficulty is that this failure is invisible in normal operation. Nothing breaks. The feature works. The exposure exists only in the gap between what the system retains and what each market permits, and surfaces in an audit or when someone finally reads the terms market by market.
7. Processing by Undisclosed Locations or Subprocessors
The category most likely to have changed underneath a team that was compliant when it last checked.
Adding an offshore development team, migrating to a new cloud region, or introducing a third-party AI service are ordinary engineering decisions taken for ordinary engineering reasons. Where agreements require disclosure or restrict subprocessors, each can put an otherwise compliant operation offside without anyone in the decision having considered the data agreement at all.
The Pattern Across All Seven
Only the first two involve a deliberate decision, and in the second that decision belongs to the reseller rather than to the company that ends up holding defective data. Numbers three through seven are drift: the data arrived legitimately and the use changed around it.
This is why compliance has to be reviewed periodically rather than established once. Nothing in the drift categories announces itself. The feed keeps working, the feature ships, and the gap widens quietly.
Four Questions to Raise With Your MLS
Some questions sit between clearly compliant and clearly non-compliant, usually because the technology arrived after the agreement was written. These are worth raising directly with the MLS in each market rather than resolving internally on assumption, and a well-framed question is generally welcomed.
Aggregate Statistics Derived From MLS Data
If a product calculates median days on market across a neighborhood and publishes it, is the output still licensed data? The underlying records are. The derived statistic arguably is not. Policy Statement 7.80 permits aggregated demonstrations of market share and comparisons of firms in public advertising, with source and time period disclosed, but that is framed around firm comparison rather than general market intelligence. A statistic aggregated across thousands of listings sits more comfortably than one describing three properties in a small submarket, and neither is squarely addressed. This is a question for your specific agreement and worth confirming with the MLS.
Model Weights Trained on MLS Data
If a model trains on MLS data and the training data is later deleted, what is the status of the resulting weights? They are not the data. They encode information derived from it. Most agreements were written before this question existed.
The defensible position is that training is a non-display use requiring BBO access, and the resulting model inherits the scope limits of the data it was trained on. That is a conservative reading and your counsel may reach a different one. What is not defensible is treating the question as settled because the agreement is silent.
What Happens to Data After a Contract Ends
Termination provisions vary in how clearly they address data already received. Some require deletion or return. Some are silent. A team that has ingested three years of listing data into a warehouse needs to know which category its agreements fall into, and the time to establish that is at signature.
Cached and Derived Artifacts
Search indexes, denormalized tables, materialized views, and pre-computed aggregates all contain MLS data in transformed form. When a retention window requires deletion, does it reach these? The technically correct answer is usually yes. The practically common outcome is that teams delete primary records and forget the derivatives.
What Non-Compliance Puts at Risk
Four categories, roughly in order of how quickly they arrive.
Operational: Your Product Stops Working
The most immediate risk and the one teams underweight. An MLS that identifies a violation can suspend or terminate a feed.
Many MLS rules provide for notice and a cure period, and enforcement typically follows a defined process rather than arriving without warning. But cure windows are measured in days or weeks, and for a serious or repeated violation an MLS may move directly to suspension. Since the repeal of the national disciplinary guidelines, the process and the severity are set locally, so what applies in one market tells you little about the next.
For a product where MLS data is the core function, feed termination in a market is a full outage there: search returns nothing, alerts stop, the product is visibly broken for every customer in that market. Reinstatement, where available, takes weeks or months.
Contractual: Liability Flows Upstream and Downstream
Where access came through a Participant, the Participant is the party in contract with the MLS. A designee’s violation is the Participant’s problem first, which means a proptech company’s compliance failure lands on the brokerage that sponsored it.
That is a commercial relationship problem as much as a legal one. A brokerage whose access is jeopardized by a vendor rarely continues with that vendor, and word travels in an industry where the relevant decision-makers know each other.
Downstream, customer agreements typically contain warranties about the legitimacy of what is supplied. A company that cannot substantiate its own data rights may be in breach of every customer contract simultaneously.
Commercial: The Enterprise Sale Becomes Impossible
Enterprise buyers run vendor diligence, and data provenance is a standard question, increasingly a documented one.
A company that cannot produce a clean answer is rarely told it failed on compliance. It is told the timeline has moved, the requirement has changed, or the process is on hold. The deal does not close and the reason is never stated.
The Diligence Problem: Where This Gets Genuinely Expensive
The consequence with the largest financial magnitude, and the one least discussed.
In an acquisition or priced round, data rights are examined. For a company whose product is built on real estate data, the licensing position is not a diligence footnote, it is central to what is being valued. An acquirer asks what rights the company holds, in which markets, under which agreements, and whether those rights survive a change of control.
Three findings cause real damage. That agreements do not exist or were never valid, in which case the core asset is not owned. That agreements exist but use exceeds scope, creating unquantified liability. That agreements contain change-of-control provisions requiring consent, in which case the acquirer may be buying something that does not transfer.
Any of these can reduce a valuation, force substantial escrow, or end a process. Unlike the operational risks, this one arrives when the company has no leverage and no time to remediate.
Compliance is not only a cost of doing business in this industry. It is a component of enterprise value, assessed at exactly the moment it can no longer be fixed.
How to Verify What You Are Actually Using
Verification has two halves: what to ask a provider before signing, and what to audit internally on data you already hold. The second carries a sequencing risk that is worth understanding before you start.
Questions for a Prospective Provider
Written to require specific answers. Vague responses to specific questions are themselves informative.
• Do you hold your own agreements with MLSs, or do you license data from another provider who does?
• For each market on this list, which access type do you hold: IDX, VOW, or BBO?
• Can you provide that coverage in writing, by named market, before we sign?
• What are the retention and sold price display terms in each of these markets?
• What is required if we add a non-display use later, and what is the timeline?
• What happens to data we have received if this agreement terminates?
• Do your agreements permit us to share data with our affiliated entities, and which ones?
• Where is data processed, and what disclosure applies if we add a subprocessor?
The first is the most important. A provider holding direct agreements answers it immediately and specifically. A reseller typically reframes it, describes the depth of its partnerships, or answers a slightly different question.
Before You Audit: Scope It Through Counsel
This is the most important section in the article, and it comes before the checklist deliberately.
An internal audit that documents a compliance gap creates a written record that you knew about it. Conducted without legal privilege, that record is potentially discoverable, and a document proving knowledge of a violation is materially worse than the violation alone.
Before starting the inventory below, have counsel scope and direct it, so the work and its output are covered by attorney-client privilege or work product protection where available. This is not a reason to avoid auditing, which remains the only way to know where you stand. It is a reason to sequence it correctly, and the cost of involving counsel at the start is trivial against the cost of an unprivileged memo describing your own exposure.
Auditing Data You Already Hold
With scoping in place, the audit is an inventory exercise. Unglamorous, and the only way to know where you stand.
• List every system storing, processing, or displaying MLS data, including warehouses, caches, search indexes, and analytics environments.
• For each, record which market the data covers and which agreement authorizes it.
• For each use, record whether it is display or non-display, and which access type it requires.
• Compare required access type against held access type, market by market.
• List every third party receiving MLS data, including processors and analytics vendors, and confirm each is authorized.
• Compare actual retention against permitted retention for each market.
• Confirm every agreement is current, and identify who owns renewal.
Teams running this for the first time typically find something. Most often an access type mismatch on a feature added after the original agreement, or a vendor receiving data without explicit authorization.
What Documentation to Keep
Executed agreements with renewal dates and owners. Written access type confirmation by market. A data flow map showing where data moves and who touches it. Retention policy documented per market. A subprocessor list with disclosure status.
This is the package a diligence process asks for. Assembling it in advance takes days. Assembling it under deal pressure takes weeks and reveals gaps at the worst possible time.
What to Do If You Find a Problem
The instinct on discovering a gap is to say nothing and hope. That is usually the worst option, because exposure accumulates while remediation gets harder.
Establish scope before acting, since one market versus twenty determines everything that follows. Stop the non-compliant use rather than the whole product where the two can be separated. Take legal advice before initiating any contact, because how a disclosure is framed matters and privilege considerations apply to the disclosure itself as much as to the audit. Then approach the counterparty, whether the MLS directly or the sponsoring Participant, with a remediation plan rather than only a problem.
Voluntary disclosure with a plan is treated differently from discovery during an audit. Organizations enforcing these rules are generally more interested in compliant outcomes than punishment, and a company that identifies its own gap and arrives with a fix is in a fundamentally better position than one that waited to be caught.
The Practical Summary
MLS data is licensed, not public. Compliance is mostly contractual, which means consequences are faster and more operational than most regulatory regimes: not a fine months later, but a feed switched off. A statutory layer sits on top of it in copyright, unauthorized access, and privacy.
The 2026 Handbook changes moved enforcement further toward local control, repealing the national disciplinary guidelines and the $15,000 penalty ceiling. Practically, that means less predictability across a multi-market footprint and a stronger case for confirming terms market by market rather than reasoning from a national baseline.
Six conditions define compliant real estate data, and all six must hold continuously. Most non-compliance is drift rather than decision, which is why the access-type question belongs in feature planning and not only in procurement. Risks run from operational outage through contractual liability to the diligence problem, where financial magnitude is largest and the ability to remediate is smallest.
Verification is straightforward and rarely done. Ask providers whether they hold their own agreements, get access type coverage in writing by market, and audit what you hold against what you are permitted to do with it, scoped through counsel first. For the wider infrastructure context, see our complete guide to real estate data for proptech companies.
About Constellation Data Labs
Constellation Data Labs provides MLS listing data, property records, and location intelligence to proptech companies, brokerages, mortgage lenders, and asset managers through one API and one relationship.
This article sets out eight questions to put to a prospective provider. Here are our answers to them.
Do you hold your own agreements? Yes. We hold our own agreements with MLSs nationwide rather than reselling another provider’s feed. Send us your market list and we will confirm, in writing and market by market, which agreements sit behind each one before you sign anything.
Can you confirm access type by named market, in writing? Yes. Send us your target market list and we will return IDX, VOW and BBO coverage market by market, in writing, before you sign anything.
Who manages per-market terms? We do. Retention windows, sold price display rules in non-disclosure states, and attribution requirements differ by market, and the 2026 policy changes widened that variation. We track them so your engineering team is not building per-market compliance logic.
What happens on termination? Defined in the agreement rather than left silent, so you know at signature what happens to data you have already received.
How is data delivered? RESO Web API with Data Dictionary normalization, so field-level entitlements and access type boundaries are explicit in the feed rather than left to interpretation.
Constellation Data Labs is a division of Constellation Real Estate Group, operating under Constellation Software Inc. (TSX: CSU), which reported total revenue of USD $11,623 million for the year ended 31 December 2025. To discuss your data architecture or request market-level coverage confirmation, visit cdatalabs.com/contact-us.
Frequently Asked Questions
Q: Is MLS data public information?
No. MLS listing data is licensed content, not public information. The confusion arises because listings are displayed publicly on brokerage and portal websites, but visibility and availability are different things. A listing appears publicly because someone in the licensing chain was authorized to display it, under terms governing what happens next. Genuinely public real estate records do exist, including county assessor records, recorded deeds, mortgage filings, and permit records, and these are government records with terms set by each county. MLS listing data is not in that category.
Q: What makes real estate data compliant?
Six conditions, all of which must hold simultaneously and continuously. A valid, current agreement covering the data. An access type that covers the intended use. A specific application within the scope the agreement contemplates. Only parties named in the agreement receiving the data. Retention within permitted windows, which vary by market. And processing in locations and through subprocessors that were disclosed where disclosure is required. Most non-compliance is a failure of conditions three through six on data legitimately obtained under conditions one and two.
Q: What changed in MLS policy in 2026?
In November 2025, following its first comprehensive antitrust risk assessment of MLS policy, NAR approved 18 changes to the MLS Handbook, effective 1 January 2026 with local adoption required by 1 March 2026. The consistent theme is decentralization. Among the changes most relevant to data compliance: Policy Statement 7.89, which authorized financial penalties up to $15,000, was repealed, as was Section 5 of the MLS Disciplinary Guidelines in its entirety, so each MLS now sets its own fine amounts and disciplinary practices with no national ceiling. Policy Statement 7.87, addressing whether MLSs must transmit listing data to third-party aggregators or display listings on public websites, was also repealed, making those decisions entirely local. Separately, six repeals concerned non-member access: Policy Statement 7.7, which had made association membership a prerequisite to MLS participation, along with 7.25, 7.38, 7.55, 7.92 and the Note under 7.26, so prerequisites to MLS access are now a matter of local discretion. A seventh change in the same group amended Policy Statement 7.58 to remove the optional local provision allowing an MLS to limit IDX display rights to REALTORS only, so if you were previously excluded from IDX display in a market on membership grounds, that specific basis is gone. For teams operating across markets, the practical effect is less national uniformity to reason from and a stronger need to confirm terms market by market.
Q: Can a proptech company get MLS data without a real estate broker license?
Yes, through two routes. The first is the designee provisions. Policy Statement 8.6, One Data Source, requires that at the request of a Participant, the MLS provide a single data feed for that Participant’s licensed uses to that Participant’s designee. Policy Statement 8.7 provides the equivalent for BBO Data specifically. In both cases the designee may use the feed only to facilitate that Participant’s licensed uses, on behalf of that Participant, so the rights are derivative rather than independent, and the MLS may require the designee to sign the same or a separate license agreement. The second route is working with a licensed aggregator holding its own agreements across markets. Direct participation requires a broker license, since a Participant must hold a current, valid real estate broker license and be a principal, partner, corporate officer, or branch office manager.
Q: What is the difference between IDX, VOW, and BBO access?
IDX authorizes public display of active listings in consumer-facing search applications operated by licensed Participants. VOW extends access to registered users where a lawful broker-consumer relationship has been established first. BBO covers non-display uses including brokerage management systems, CRM and transaction management tools, and agent and brokerage productivity and ranking tools and reports. The operative word in IDX is display. NAR Policy Statement 7.58 establishes that participants may not use IDX-provided listings for any purpose other than IDX display, and model IDX rules adopted locally carry the same restriction. Analytics, model training, and internal market reporting are non-display uses requiring BBO access in each market where they occur.
Q: What are the risks of using non-compliant MLS data?
Four categories. Operationally, an MLS can suspend or terminate a feed for a violation. Many rules provide notice and a cure period, but cure windows are short and serious violations can move directly to suspension, which for a listing-dependent product means a full outage in that market. Since the 2026 repeal of the national disciplinary guidelines, the process and severity are set locally. Contractually, where access came through a Participant, the violation is the Participant’s problem first, so a vendor’s failure lands on the sponsoring brokerage, while customer agreements containing data legitimacy warranties may be breached simultaneously. Commercially, enterprise diligence asks about provenance and deals quietly stall when the answer is unclear. And in acquisition or funding diligence, findings that agreements do not exist, that use exceeds scope, or that change-of-control consent is required can reduce valuation, force escrow, or end a process.
Q: Where does non-compliant MLS data usually come from?
Seven sources. Data collected from public portals rather than licensed at source. Feeds resold by a party without redistribution rights, where the defect is inherited by a buyer who may hold a valid-looking contract. Data still flowing after an agreement lapsed. Data used outside the access type it was licensed under, which is the most common source and almost always unintentional. Data shared with entities not named in the agreement, including affiliates and technology vendors. Data retained beyond permitted windows. And processing by undisclosed locations or subprocessors, including offshore teams and third-party AI services. Only the first two involve a deliberate decision, and in the second that decision belongs to the reseller rather than to the company holding the data.
Q: Does using MLS data to train an AI model require BBO access?
The defensible position is yes. NAR IDX policy restricts IDX-provided listings to display purposes, and training a model is not display. It is a non-display analytical use, the category BBO covers. There is genuine ambiguity about the status of the resulting model weights once training data is deleted, since most agreements predate the question. The conservative reading is that a model inherits the scope limits of the data it was trained on. What is not defensible is treating the question as settled because the agreement is silent on it. This is a question to put to your counsel and, where the answer matters commercially, to the MLS.
Q: How long can we keep sold MLS listing data?
It depends on the market, and the variance is significant. Some MLSs permit indefinite retention for internal analysis. Others require deletion within a defined window after closing. Display terms for sold prices are frequently more restrictive than retention terms for internal use. NAR VOW policy establishes that sale prices can only be treated as confidential in states where actual sale prices are not accessible from public records. Those non-disclosure states are Alaska, Idaho, Kansas, Louisiana, Mississippi, Montana, New Mexico, North Dakota, Texas, Utah and Wyoming, with Missouri a partial case where St. Louis City, St. Louis County and Jackson County mandate disclosure and other counties do not. For a multi-market product, a single uniform retention policy is almost certainly wrong somewhere.
Q: Should we audit our own MLS data compliance internally?
Yes, but scope it through counsel first. An internal audit that documents a compliance gap creates a written record that you knew about it, and conducted without legal privilege that record is potentially discoverable. A document proving knowledge of a violation is materially worse than the violation alone. Have counsel scope and direct the audit so the work and its output are covered by attorney-client privilege or work product protection where available. This is not a reason to avoid auditing, which remains the only way to know where you stand. It is a reason to sequence it correctly, and the cost of involving counsel at the start is trivial against the cost of an unprivileged memo describing your own exposure.
Q: How do I check whether a data provider actually holds their own MLS agreements?
Ask directly and require a documented answer: do you hold your own agreements with MLSs, or do you license data from another provider? Then ask for access type coverage in writing, by named market, before signing. A provider holding direct agreements answers both immediately and specifically. A reseller typically reframes the question, describes the depth of its partnerships, or answers a slightly different question. This matters because redistribution is a separate right that must be granted explicitly, and a customer buying from a reseller without that right can hold a properly executed contract while having no valid license, because the counterparty never had one to convey.
Q: Which real estate data providers should I evaluate?
The market includes national aggregators holding direct MLS agreements, regional providers with deep coverage in specific geographies, MLS-operated and MLS-owned data programs, and resellers operating downstream of other providers. Which is right depends on your market footprint, whether you need non-display access, and whether you have a broker license or a Participant relationship. Rather than name a shortlist that will date quickly, run every candidate, including Constellation Data Labs, through the eight questions in the verification section above. The answers separate the categories faster than any vendor comparison, and the first question about direct agreements is usually decisive on its own.