Data Made Manifestly Public by the Data Subject
This is one of the specific conditions that can allow an organisation to process sensitive personal data, applying where the individual has themselves clearly and deliberately made that information public. For example, it may be relevant where a person has openly shared special category details about themselves. Whether this condition applies depends on the facts, and it is generally interpreted narrowly, so it should be assessed carefully rather than assumed.
Under Article 9(2)(e) of the (UK) GDPR, the general prohibition on processing special category data may be lifted where the processing relates to personal data that the data subject has manifestly made public. The word "manifestly" indicates a high threshold: it is typically read as requiring a clear, deliberate act by the data subject to make their own special category data public, rather than data being publicly available through third parties or through inference. Practitioners should note that this is an Article 9 condition permitting the processing of special category data and does not, on its own, provide an Article 6 lawful basis, which must be established separately. The condition is generally construed narrowly and its application is fact-specific; the fact that data is publicly accessible does not automatically mean it was manifestly made public by the data subject, and it must be assessed whether it was made public by the individual concerned or by another party. Interpretation may be informed by regulator guidance and can be subject to divergence, so the current official text and applicable guidance should be verified.
Why it matters
Special category data, such as information revealing health, ethnicity, political opinions, or sexual orientation, is subject to a general prohibition on processing under the GDPR, which can only be lifted where a specific Article 9 condition applies. The "manifestly made public" condition under Article 9(2)(e) is one such gateway, and it is frequently misunderstood. Organisations sometimes assume that because sensitive information is visible online or otherwise publicly accessible, they are free to process it. That assumption is risky: the condition is generally construed narrowly and turns on whether the data subject themselves clearly and deliberately made the information public, not merely on whether the data happens to be available.
The practical stakes are significant because getting this wrong can mean processing special category data without a valid condition, leaving the activity unlawful even where the underlying data is easy to find. As regulator and guidance sources note, it must be assessed whether the data was made public by the individual concerned or by a third party, and data that is publicly accessible is not automatically data that was manifestly made public by the data subject. This distinction matters for activities such as open-source intelligence gathering, social media monitoring, and dataset compilation, where the source and manner of publication are often unclear.
Even where Article 9(2)(e) may apply, it addresses only the special category prohibition and does not supply an Article 6 lawful basis, which must be established separately. Treating the condition as a complete authorisation to process is a common error that can undermine an organisation's overall compliance position. Because interpretation may be informed by regulator guidance and can be subject to divergence, organisations should document their assessment carefully rather than relying on the mere public availability of the data.
Who it's relevant to
Inside Data Made Manifestly Public by the Data Subject
Common questions
Answers to the questions practitioners most commonly ask about Data Made Manifestly Public by the Data Subject.