Skip to main content
Category: Data Classification & Identifiers

Publicly Available Data

Also known as: Public Data, Publicly Available Information
Simply put

Publicly available data is information that can be legally accessed by the general public, such as records held in government registers, open government datasets, or other sources made freely available. A common misconception is that data loses its privacy protections simply because it is public; however, where such data relates to an identified or identifiable individual, it generally remains personal data and continues to fall within data protection rules. The fact that information is publicly accessible does not, on its own, remove the obligations that apply to its further use.

Formal definition

Publicly available data refers to information that is legally accessible to the general public, including sources such as government records, open data portals, and de-identified public-use datasets. Under the GDPR framework, the public availability of information does not change its classification: where the data 'relates to an identified or identifiable natural person' it constitutes personal data and remains within the material scope of the Regulation, so a lawful basis under Article 6 (and, for special category data, an additional condition under Article 9) is still generally required for its processing. This is sometimes described as the 'paradox' of publicly available data, because accessibility is frequently but incorrectly treated as equivalent to a right to reuse. Practitioners should note that scope varies: genuinely anonymized or de-identified datasets may fall outside the definition of personal data, but the threshold for anonymization is context-dependent and subject to assessment. This entry does not address specific member state derogations that may apply to certain public registers, or the distinct treatment of publicly available data under Article 9 special category conditions, which should be verified against the current official text and applicable regulatory guidance.

Why it matters

Publicly available data is frequently misunderstood as falling outside data protection rules, but this assumption creates significant compliance risk. Under the GDPR framework, personal data is defined as any information relating to an identified or identifiable natural person, and this classification does not change simply because the information is legally accessible to the general public. Where publicly accessible information relates to an identifiable individual, it generally remains personal data, and its further use continues to require a lawful basis under Article 6 (and, for special category data, an additional condition under Article 9).

This creates what is sometimes described as the 'paradox' of publicly available data: accessibility is often, but incorrectly, treated as equivalent to a right to reuse. Organizations that scrape, aggregate, or repurpose data from government registers, open data portals, or other public sources may assume they are free of obligations, when in fact processing such data typically still triggers transparency, purpose limitation, and lawful basis requirements. The gap between accessibility and permitted reuse is where many compliance failures originate.

The practical stakes are heightened because scope varies with context. Genuinely anonymized or de-identified datasets may fall outside the definition of personal data, but the threshold for anonymization is context-dependent and subject to assessment; a dataset treated as de-identified may still permit re-identification when combined with other information. Practitioners should treat public availability as a factor to weigh, not a conclusion, and verify the position against the current official text and applicable regulatory guidance.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads must ensure their organizations do not treat public accessibility as a lawful basis for reuse. Where publicly available data relates to identifiable individuals, a lawful basis under Article 6 is generally still required, and transparency and purpose limitation obligations continue to apply. Compliance programs should include a documented assessment of whether public data used within the organization qualifies as personal data or has been genuinely anonymized.
Privacy and Data Protection Lawyers
Legal advisors should be prepared to counsel clients through the 'paradox' that accessibility is not equivalent to a right to reuse. Advice should account for the context-dependent threshold for anonymization, potential member state derogations applicable to certain public registers, and the additional conditions required under Article 9 for special category data. Given that these areas can vary and evolve, positions should be verified against current official text and regulatory guidance rather than treated as settled.
Engineers and Data Scientists
Teams that scrape, aggregate, or build datasets from open data portals, government records, or public-use datasets should recognize that de-identified datasets may not be genuinely anonymous once combined with other information. Because re-identification risk is assessed in context, technical teams should work with privacy stakeholders to evaluate whether a dataset remains personal data before assuming it falls outside data protection obligations.

Inside Publicly Available Data

Publicly accessible personal data
Personal data that has been made available to the public, for example through public registers, published court records, official gazettes, or information that a data subject or a third party has deliberately placed in the public domain. The mere fact that data is accessible does not remove it from the scope of data protection law where it still relates to an identified or identifiable individual.
Continued application of the GDPR
Personal data does not lose the protection of the GDPR simply because it is publicly available. Processing such data generally remains subject to the Regulation, including the requirement for a lawful basis under Article 6 and, where relevant, an additional condition under Article 9 for special category data.
Legal basis for reuse
A controller reusing publicly available personal data must still identify an appropriate Article 6 legal basis. Legitimate interests is often relied upon in this context, but its availability is subject to a balancing assessment against the interests, rights, and freedoms of the data subject, and consent is not automatically satisfied by the data being public.
Special category and public disclosure
Article 9 recognizes a condition where personal data has been manifestly made public by the data subject, which may permit processing of certain special category data. This condition is narrow and typically requires a deliberate act by the data subject making the data public, rather than data being public through another party or by inference.
Boundary with anonymous data
Data that is truly anonymous, such that no individual can be identified directly or indirectly, falls outside the GDPR. The distinction between publicly available personal data and anonymous data is important, as only the former attracts the Regulation's obligations.

Common questions

Answers to the questions practitioners most commonly ask about Publicly Available Data.

Does data being publicly available mean it is exempt from the GDPR?
No. Personal data does not lose its status as personal data simply because it has been made public or is accessible from a public source. In most cases the GDPR continues to apply to the collection, further use, and other processing of publicly available personal data, and a controller still needs an appropriate legal basis under Article 6 and, where relevant, a condition under Article 9. The public nature of the data may be relevant to certain assessments, but it is not a general exemption. Verify the position against the current text and applicable regulator guidance.
Can I rely on consent as the legal basis just because someone published their own information publicly?
Generally no. The act of an individual publishing information themselves does not, on its own, constitute valid consent to your processing of that data, since consent under the GDPR must typically be a specific, informed, freely given, and unambiguous indication directed at your processing. Publication by the data subject may be a factor in some assessments, but you should identify which Article 6 basis actually applies to your intended processing rather than assuming consent exists. Consent is one of several distinct legal bases and is not a universal requirement.
How do I choose a legal basis for processing publicly available personal data?
Assess your specific purpose against the Article 6 bases and select the one that genuinely fits, documenting your reasoning. Legitimate interests is often considered for such processing, subject to a balancing test that weighs your interests against the rights, freedoms, and reasonable expectations of the data subject; the public availability of the data may inform that balancing but does not determine it. The appropriate basis is context and purpose dependent, so the analysis should be carried out and recorded for each processing activity.
What additional steps apply if the publicly available data includes special category data?
If the data falls within the special categories under Article 9, you generally need both an Article 6 legal basis and a separate Article 9 condition before processing. Some conditions may be relevant where data has manifestly been made public by the data subject, but reliance on any such condition should be assessed carefully against the facts and the current text, as the threshold and scope can be narrow. Do not assume public availability alone satisfies the Article 9 requirement; confirm the applicable condition and any member state derogations.
Do transparency and information obligations still apply when data is collected from public sources rather than the individual?
Typically yes. Where personal data is obtained from a source other than the data subject, information obligations generally continue to apply, subject to any recognized exceptions. You should consider how and when to provide the required information and whether any exemption may be relevant to your circumstances. Because the availability and interpretation of exceptions can vary, review the applicable provisions and current guidance rather than assuming the obligation is disapplied.
What should I document when building a process that uses publicly available personal data?
In most cases you should record the source of the data, the purpose and lawful basis for the processing, any legitimate interests balancing carried out, any Article 9 condition where special category data is involved, how transparency obligations are met, and how data subject rights will be handled. Where the processing is likely to result in high risk, consider whether a Data Protection Impact Assessment under Article 35 is required. Retain this documentation as part of your accountability records and revisit it as guidance and transfer or adequacy positions evolve.

Common misconceptions

If personal data is publicly available, it can be freely collected and reused without restriction.
Public availability does not exempt data from the GDPR. A controller generally still needs a lawful basis under Article 6, must observe transparency, purpose limitation, and other principles, and, for special category data, must meet an additional Article 9 condition. Reuse is context and risk dependent rather than automatically lawful.
Because a data subject made their data public, consent to any further processing is implied.
The fact that data is public does not equate to consent for all purposes. Where Article 9 applies, the relevant condition is that data was manifestly made public by the data subject, which is a distinct and narrowly interpreted concept and is not the same as a valid Article 6 consent basis. The applicable basis should be assessed for each purpose.
Publicly available data is effectively the same as anonymous data and outside data protection law.
Publicly available data often still relates to identifiable individuals and therefore remains personal data within scope. Only genuinely anonymous data, where identification is not possible, falls outside the GDPR.

Best practices

Identify and document an appropriate Article 6 legal basis before collecting or reusing publicly available personal data, and do not treat public availability as a substitute for a lawful basis.
Where relying on legitimate interests, conduct and record a balancing assessment that weighs the interests of the controller against the rights and reasonable expectations of the data subject.
For special category data, verify that a specific Article 9 condition applies, and interpret the manifestly made public condition narrowly, confirming a deliberate act by the data subject rather than assuming it from context.
Assess whether the data can be genuinely anonymized so that it falls outside scope, and distinguish clearly in your records between anonymous data and identifiable personal data.
Provide transparency to data subjects where required and observe purpose limitation, applying only the purposes for which a lawful basis has been established.
Verify the position under the applicable regime, noting possible divergence between the EU GDPR, the UK GDPR, national implementing laws, and regulator guidance, and check the current official text where any point is uncertain.