Skip to main content
Category: Special Category Data

Data Made Manifestly Public by the Data Subject

Also known as: Manifestly Made Public, Made Public by the Data Subject, Article 9(2)(e) condition
Simply put

This is one of the specific conditions that can allow an organisation to process sensitive personal data, applying where the individual has themselves clearly and deliberately made that information public. For example, it may be relevant where a person has openly shared special category details about themselves. Whether this condition applies depends on the facts, and it is generally interpreted narrowly, so it should be assessed carefully rather than assumed.

Formal definition

Under Article 9(2)(e) of the (UK) GDPR, the general prohibition on processing special category data may be lifted where the processing relates to personal data that the data subject has manifestly made public. The word "manifestly" indicates a high threshold: it is typically read as requiring a clear, deliberate act by the data subject to make their own special category data public, rather than data being publicly available through third parties or through inference. Practitioners should note that this is an Article 9 condition permitting the processing of special category data and does not, on its own, provide an Article 6 lawful basis, which must be established separately. The condition is generally construed narrowly and its application is fact-specific; the fact that data is publicly accessible does not automatically mean it was manifestly made public by the data subject, and it must be assessed whether it was made public by the individual concerned or by another party. Interpretation may be informed by regulator guidance and can be subject to divergence, so the current official text and applicable guidance should be verified.

Why it matters

Special category data, such as information revealing health, ethnicity, political opinions, or sexual orientation, is subject to a general prohibition on processing under the GDPR, which can only be lifted where a specific Article 9 condition applies. The "manifestly made public" condition under Article 9(2)(e) is one such gateway, and it is frequently misunderstood. Organisations sometimes assume that because sensitive information is visible online or otherwise publicly accessible, they are free to process it. That assumption is risky: the condition is generally construed narrowly and turns on whether the data subject themselves clearly and deliberately made the information public, not merely on whether the data happens to be available.

The practical stakes are significant because getting this wrong can mean processing special category data without a valid condition, leaving the activity unlawful even where the underlying data is easy to find. As regulator and guidance sources note, it must be assessed whether the data was made public by the individual concerned or by a third party, and data that is publicly accessible is not automatically data that was manifestly made public by the data subject. This distinction matters for activities such as open-source intelligence gathering, social media monitoring, and dataset compilation, where the source and manner of publication are often unclear.

Even where Article 9(2)(e) may apply, it addresses only the special category prohibition and does not supply an Article 6 lawful basis, which must be established separately. Treating the condition as a complete authorisation to process is a common error that can undermine an organisation's overall compliance position. Because interpretation may be informed by regulator guidance and can be subject to divergence, organisations should document their assessment carefully rather than relying on the mere public availability of the data.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to scrutinise any reliance on Article 9(2)(e), particularly where teams are tempted to treat publicly accessible sensitive data as free to use. They should ensure the narrow "manifestly made public" threshold is genuinely met, that the assessment distinguishes publication by the data subject from publication by third parties, and that a separate Article 6 basis is also documented.
Privacy and Data Protection Lawyers
Legal advisers assessing processing of special category data should treat this as a fact-specific condition that is generally interpreted narrowly. They should flag that public accessibility does not equate to the data subject having manifestly made the data public, note the separation between Article 9 conditions and Article 6 bases, and advise that interpretation may vary and should be verified against current guidance.
Engineers and Teams Building Data Collection or OSINT Tools
Those designing systems that scrape, aggregate, or monitor publicly available content, including social media data, should not assume that visibility implies lawful processing. Where such data reveals special category information, the source and manner of publication matter, and teams should build in the ability to assess and record whether the data subject themselves deliberately made the information public.
Teams Handling Legal Proceedings and Claims
As guidance notes, processing of sensitive data can arise in the context of legal proceedings, where a separate condition covering legal claims may be relevant. Teams should be careful not to conflate the "manifestly made public" condition with the legal claims condition, and should identify the correct Article 9 condition for each processing activity.

Inside Data Made Manifestly Public by the Data Subject

Article 9(2)(e) condition
This concept derives from the exception in Article 9(2)(e) GDPR, which lifts the general prohibition on processing special category data where the data subject has manifestly made that data public. It functions as one of the additional Article 9 conditions and does not itself provide an Article 6 lawful basis, which must still be identified separately.
Special category data scope
The condition applies specifically to the special categories of personal data listed in Article 9(1), such as data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and data concerning health, sex life, or sexual orientation, along with genetic and biometric data used for identification. It is generally not the relevant condition for ordinary personal data.
"Manifestly" threshold
The word manifestly signals a high and deliberate threshold. In most interpretations the data subject must have taken a clear, affirmative step to make the data public, rather than the data becoming public through inadvertence, a default setting, or the actions of a third party. The precise threshold is subject to assessment and can be informed by regulator guidance and case law rather than being fully defined in the Regulation text.
Act of the data subject
The public disclosure must generally originate from the data subject themselves. Data made public by another person, by a controller, or through a data breach would typically not satisfy this condition.
Interaction with Article 6
Even where this Article 9 condition is met, a controller still needs a separate lawful basis under Article 6, such as legitimate interests, and must satisfy the wider principles including fairness, purpose limitation, and transparency.

Common questions

Answers to the questions practitioners most commonly ask about Data Made Manifestly Public by the Data Subject.

If someone posts personal information publicly, does that mean I can process it freely for any purpose?
No. The fact that a data subject has manifestly made special category data public (a condition under Article 9(2)(e) that lifts the Article 9(1) prohibition on processing such data) does not remove your other obligations. You still need a valid Article 6 legal basis, and the general principles in Article 5 continue to apply, including purpose limitation, data minimisation, fairness, and transparency. In most cases the condition only addresses the special category barrier for the specific data the individual actually made public, not a general licence to reuse it for unrelated purposes. The scope and interpretation of this condition can be subject to regulatory guidance and assessment, so you should verify the position against current official sources.
Does relying on data being manifestly public mean I no longer need consent?
Not in the way this is sometimes assumed. Consent (Article 6(1)(a), and the separate explicit consent condition in Article 9(2)(a)) is only one route. Where special category data has been manifestly made public by the data subject, Article 9(2)(e) can provide the additional condition needed for processing that category of data, which is distinct from the Article 6 legal basis you still require. This does not make consent a universal requirement that is simply being replaced, nor does it convert 'public' data into unrestricted data. It is one of several distinct conditions, and whether it applies depends on the facts and, potentially, on regulator interpretation.
How do I assess whether data was 'manifestly' made public by the data subject?
The word 'manifestly' generally signals a high threshold: the assessment typically focuses on whether the individual took a clear, deliberate action that unambiguously made the specific data public. Relevant factors can include the platform's privacy settings, whether the data subject themselves (rather than a third party) published it, the audience the individual chose, and whether the disclosure was evidently intentional. This is a fact-specific evaluation, and interpretation may differ between supervisory authorities, so document your reasoning and treat borderline cases with caution. You should verify current guidance rather than assume a fixed standard.
What should I document when relying on this condition?
As a matter of accountability under Article 5(2), it is generally advisable to record the specific data items relied upon, the source and evidence that the data subject themselves made them public, the platform and its access settings at the time, the date of assessment, and your reasoning for concluding the disclosure was manifest and deliberate. You should also record the separate Article 6 legal basis relied upon and how the purpose aligns with the original disclosure. Retaining this evidence helps demonstrate the condition applied at the point of processing, though the exact documentation expectations can be shaped by regulator guidance.
Do data subject rights still apply to data I process under this condition?
Yes. Reliance on this condition does not switch off individual rights. Data subjects can still, subject to the applicable rules and any exemptions, exercise rights such as access, rectification, erasure, restriction, and objection, and transparency obligations under Articles 13 and 14 continue to apply. The availability and limits of specific rights can depend on the Article 6 basis you rely on and on any applicable member state derogations, so these should be assessed case by case.
Can I keep relying on this condition if the individual later removes or restricts the data?
This should be treated with caution and is subject to assessment. The condition generally speaks to whether data was manifestly made public by the data subject, but ongoing reliance where the individual has taken steps to make the data private again may be difficult to sustain, and could interact with the principles in Article 5 and with the data subject's rights. Regulatory interpretation on the durability of this condition can vary, so you should reassess your position if circumstances change and verify against current official guidance rather than assume the condition persists indefinitely.

Common misconceptions

If special category data is publicly accessible online, anyone may freely process it.
Public accessibility alone does not satisfy this condition. The data must have been made manifestly public by the data subject through a deliberate act, and the controller must still identify an Article 6 basis and comply with the other GDPR principles. Public availability created by a third party or a breach generally does not qualify.
Relying on Article 9(2)(e) removes the need for any other lawful basis.
Article 9(2)(e) only addresses the Article 9 prohibition on special category data. A separate Article 6 lawful basis is still required, and consent is not automatically implied by the data having been made public.
Data on a profile with default-open settings counts as manifestly made public.
The manifestly threshold is high and typically requires a clear, intentional step by the data subject. Reliance on default settings or ambiguous disclosure is uncertain and subject to assessment, with possible divergence between regulators.

Best practices

Confirm that the disclosure was made by the data subject themselves through a clear, affirmative act before relying on this condition, and document the evidence supporting that conclusion.
Treat the manifestly threshold as high; do not rely on default privacy settings, third-party republication, or accidental exposure as satisfying the condition.
Identify and record a separate Article 6 lawful basis for the processing, since this Article 9 condition alone is not sufficient.
Continue to apply the wider GDPR principles, including transparency, fairness, purpose limitation, and data minimisation, even where the data appears public.
Check current regulator guidance and relevant case law for your jurisdiction, and note any divergence between EU GDPR, UK GDPR, and national implementing law, as interpretation of this condition can vary.
Reassess reliance on this condition over time, as the data subject may withdraw or alter the public status of the data and their rights, such as objection or erasure, may still apply.