Publicly Available Data
Publicly available data is information that can be legally accessed by the general public, such as records held in government registers, open government datasets, or other sources made freely available. A common misconception is that data loses its privacy protections simply because it is public; however, where such data relates to an identified or identifiable individual, it generally remains personal data and continues to fall within data protection rules. The fact that information is publicly accessible does not, on its own, remove the obligations that apply to its further use.
Publicly available data refers to information that is legally accessible to the general public, including sources such as government records, open data portals, and de-identified public-use datasets. Under the GDPR framework, the public availability of information does not change its classification: where the data 'relates to an identified or identifiable natural person' it constitutes personal data and remains within the material scope of the Regulation, so a lawful basis under Article 6 (and, for special category data, an additional condition under Article 9) is still generally required for its processing. This is sometimes described as the 'paradox' of publicly available data, because accessibility is frequently but incorrectly treated as equivalent to a right to reuse. Practitioners should note that scope varies: genuinely anonymized or de-identified datasets may fall outside the definition of personal data, but the threshold for anonymization is context-dependent and subject to assessment. This entry does not address specific member state derogations that may apply to certain public registers, or the distinct treatment of publicly available data under Article 9 special category conditions, which should be verified against the current official text and applicable regulatory guidance.
Why it matters
Publicly available data is frequently misunderstood as falling outside data protection rules, but this assumption creates significant compliance risk. Under the GDPR framework, personal data is defined as any information relating to an identified or identifiable natural person, and this classification does not change simply because the information is legally accessible to the general public. Where publicly accessible information relates to an identifiable individual, it generally remains personal data, and its further use continues to require a lawful basis under Article 6 (and, for special category data, an additional condition under Article 9).
This creates what is sometimes described as the 'paradox' of publicly available data: accessibility is often, but incorrectly, treated as equivalent to a right to reuse. Organizations that scrape, aggregate, or repurpose data from government registers, open data portals, or other public sources may assume they are free of obligations, when in fact processing such data typically still triggers transparency, purpose limitation, and lawful basis requirements. The gap between accessibility and permitted reuse is where many compliance failures originate.
The practical stakes are heightened because scope varies with context. Genuinely anonymized or de-identified datasets may fall outside the definition of personal data, but the threshold for anonymization is context-dependent and subject to assessment; a dataset treated as de-identified may still permit re-identification when combined with other information. Practitioners should treat public availability as a factor to weigh, not a conclusion, and verify the position against the current official text and applicable regulatory guidance.
Who it's relevant to
Inside Publicly Available Data
Common questions
Answers to the questions practitioners most commonly ask about Publicly Available Data.