Skip to main content
Category: Data Classification

Public Data

Also known as: Publicly Available Data, Open Data
Simply put

Public data is information that is openly available and can generally be used, reused, and redistributed without needing special authorization. It typically does not require the protective controls applied to confidential or restricted information. Whether a specific dataset qualifies as public depends on its source and on any legal restrictions that may still apply.

Formal definition

Public data is a data-classification designation for information that is openly accessible and can generally be used, reused, or redistributed without contractual or authorization-based restriction. It is commonly positioned as the lowest-sensitivity tier in a governance classification scheme, contrasted with private, confidential, or restricted categories, and its handling requirements typically focus on integrity and availability rather than confidentiality. This designation concerns accessibility and reuse, not privacy status: data that is publicly accessible may still constitute personal data or special category data under regimes such as the EU GDPR or UK GDPR, and public availability does not by itself remove data from regulatory scope. Under the CCPA/CPRA, a distinct statutory notion of 'publicly available information' applies as a definitional exclusion from personal information, which is scoped to those statutes and should not be conflated with an organization's internal 'public' classification tier. Some categories of records that are informally described as public may in fact be subject to specific access restrictions under applicable law; classification decisions should be validated against the governing legal framework rather than assumed from general availability. This entry defines the classification concept only and does not address cross-border transfer mechanics, retention obligations, lawful bases for processing, or jurisdiction-specific enforcement.

Why it matters

Public data classification matters because it determines the level of protective control an organization applies to information, and misclassification carries risk in both directions. Treating genuinely sensitive information as public can expose an organization to regulatory and reputational harm, while over-restricting openly available information wastes resources and can impede legitimate use, reuse, and redistribution. Because public data sits at the lowest-sensitivity tier in most governance schemes, its handling requirements typically emphasize integrity and availability rather than confidentiality, which shifts the control focus but does not eliminate the need for governance oversight.

A critical and frequently misunderstood point is that public accessibility is not the same as being outside regulatory scope. Data that is openly accessible may still constitute personal data or special category data under the EU GDPR or UK GDPR, and public availability does not by itself remove that data from regulatory obligations. Separately, the CCPA and CPRA contain a distinct statutory notion of 'publicly available information' that operates as a definitional exclusion from personal information; this is scoped to those statutes and should not be conflated with an organization's internal 'public' classification tier. Conflating the two can lead teams to assume regulatory relief that does not exist under the applicable framework.

Organizations should also recognize that records informally described as public may in fact be subject to specific access restrictions under applicable law. General availability is not a substitute for a legal determination. Classification decisions should be validated against the governing legal framework rather than inferred from the fact that information appears accessible, and accountability under governance frameworks generally requires demonstrable evidence of that validation rather than a stated assumption.

Who it's relevant to

Information Governance Leads
Governance leads own the classification scheme in which the public tier sits. They are responsible for ensuring the criteria for the public designation are defined, that classification decisions are validated against the governing legal framework rather than assumed from general availability, and that the accountability evidence supporting those decisions is demonstrable rather than merely stated.
Data Protection Officers and Privacy Professionals
DPOs and privacy professionals need to guard against the common assumption that publicly accessible data is outside regulatory scope. Under the EU GDPR or UK GDPR, publicly available information may still be personal data or special category data, and the CCPA/CPRA statutory notion of 'publicly available information' is scoped to those statutes and distinct from an internal public classification tier. This entry does not address lawful bases, retention, or transfer, which require separate analysis.
Privacy Engineers and Data Stewards
Those implementing classification tiers translate the public designation into handling controls. For public data these typically emphasize integrity and availability rather than confidentiality controls. Stewards should flag records that are informally described as public but may be subject to specific legal access restrictions, so that classification is validated rather than inferred.
Legal and Compliance Teams
Legal and compliance functions confirm whether a specific dataset genuinely qualifies as public under applicable law and whether any residual legal restrictions apply. They also advise on the distinction between an internal classification label and statutory definitions such as the CCPA/CPRA exclusion, which should not be treated as interchangeable.

Inside Public Data

Data lawfully available from public sources
Information that is accessible to the general public without breach of confidentiality obligations, such as content in public registers, court filings open to the public, or information an individual has clearly made public. The specific categories treated as 'public' vary by jurisdiction and instrument, so the scope must always be checked against the applicable regime rather than assumed.
Publicly available information exemption (CCPA/CPRA)
Under the California Consumer Privacy Act as amended by the CPRA, certain publicly available information is excluded from the definition of personal information. The current statutory text defines this by reference to lawful availability from government records and information the business has a reasonable basis to believe was lawfully made available to the general public. This entry does not attempt to reproduce the full statutory definition.
Public data that remains personal data
The fact that data is publicly accessible does not, in most data protection regimes, remove it from the definition of personal data. Under the EU GDPR and UK GDPR there is no general carve-out equivalent to the CCPA/CPRA publicly available exemption, so information about an identifiable individual generally remains personal data even when sourced from public records.
Special category data that is public
Where an individual has manifestly made special category (sensitive) data public, some regimes permit processing on that footing, but the data does not cease to be special category data and other obligations continue to apply. The precise conditions differ across the EU GDPR, UK GDPR, and other frameworks.
Source and provenance
The lawful basis, permitted uses, and applicable restrictions of public data depend on where and how it was obtained. Some publicly accessible datasets are subject to sector-specific access-and-use restrictions that limit onward disclosure regardless of general public accessibility.

Common questions

Answers to the questions practitioners most commonly ask about Public Data.

If data is publicly available, does that mean it is no longer personal data and falls outside data protection law?
No. Under the EU GDPR and UK GDPR, information that is publicly accessible can still qualify as personal data if it relates to an identified or identifiable individual, and processing it generally remains subject to the regulation, including lawful basis and transparency obligations. Public availability may affect which lawful basis is appropriate or the individual's reasonable expectations, but it does not remove the data from scope. This answer does not address every jurisdiction's treatment, and specific exemptions differ by regime.
Does an exemption for publicly available information under the CCPA/CPRA come with a condition that you not use the data in a way inconsistent with why it was made public?
No. The current CCPA/CPRA definition of publicly available information does not include a purpose-compatibility condition of that kind. You should not assume that using such information for a new or different purpose automatically strips the exemption. Because the scope and boundaries of the publicly available carve-out are specific and have been amended over time, consult the current statutory text and qualified counsel rather than relying on prior framings. This entry does not cover the exemption's full boundaries or how other regimes treat the same data.
How should we determine whether a given dataset actually qualifies as public data under a specific regime?
Assess the classification against the precise definition in the governing instrument, since regimes scope the term differently and a source being accessible does not by itself make its contents fall within any statutory carve-out. Document the source, the basis for treating it as public, and the applicable definition. Where a US statute restricts release of particular records, accessibility of a source does not override that restriction. This does not cover cross-border transfer or retention rules for the resulting dataset.
If we ingest public data into our systems, what governance obligations apply?
Data governance obligations such as recording the source and lineage, assigning ownership and stewardship, applying data quality controls, and cataloging the dataset generally still apply, independent of whether privacy exemptions reduce certain regulatory duties. Governance accountability typically requires demonstrable evidence of these controls rather than stated intent. This answer addresses governance and does not resolve the separate question of which lawful basis or exemption applies to the processing.
Do we still need to provide transparency information to individuals when we process their publicly available personal data?
In most cases under the EU GDPR and UK GDPR, transparency obligations apply to personal data obtained from sources other than the individual, though the applicable regime provides specific conditions and possible exceptions that must be evaluated against the current text. Public accessibility does not automatically remove the obligation to inform individuals. Treatment varies across regimes, so confirm the requirement under the instrument that governs your processing. This does not detail the specific exception criteria.
Does combining public data with other datasets change how it should be treated?
Potentially yes. Combining or enriching public data can increase identifiability, alter the sensitivity of the resulting dataset, and change the reasonable expectations of the individuals concerned, which may affect the appropriate lawful basis and the applicability of any exemption. Governance and information security controls should be reassessed after such combination. This entry does not prescribe when a data protection impact assessment is required, which depends on the specific processing and jurisdiction.

Common misconceptions

All government-held records about individuals are public data that anyone may freely use.
Availability of government records varies by jurisdiction and by dataset, and specific categories of personal information held by public bodies are subject to statutory access-and-use restrictions. For example, in the United States, personal information in state motor vehicle records is generally restricted from public release under the Driver's Privacy Protection Act (18 U.S.C. § 2721), with only specified permitted uses.
If data is public, it is no longer personal data and data protection law does not apply.
Public accessibility does not generally strip data of its status as personal data. Under the EU GDPR and UK GDPR there is no general publicly available exemption, so such data typically remains within scope. The CCPA/CPRA publicly available exemption is regime-specific and does not carry over to other frameworks.
The CCPA/CPRA publicly available exemption can be lost if the data is later used for a purpose inconsistent with the purpose for which it was originally made public.
The current CCPA text as amended does not contain a compatibility or consistent-purpose condition on the publicly available information exemption; that clause was removed by amendment. The exemption is defined by reference to lawful public availability rather than to the compatibility of subsequent use.

Best practices

Do not assume that publicly accessible data falls outside data protection obligations; confirm the position under each applicable regime, recognizing that the EU GDPR and UK GDPR generally lack a broad publicly available carve-out while the CCPA/CPRA provides a regime-specific exemption.
Verify the statutory definition of the relevant public data exemption directly against the current text of the applicable instrument, since amendments have changed the scope over time and older phrasing may no longer apply.
Check for sector-specific access-and-use restrictions on public records before relying on public availability, including restrictions such as those on motor vehicle record data in the United States.
Document the source, provenance, and lawful basis for any public data you process, and retain that record as demonstrable accountability evidence rather than relying on stated intent.
Treat public special category or sensitive data as continuing to require the additional protections of its category, and confirm the specific conditions permitting processing under the applicable regime.
Scope this analysis to the definitional and status question only; separately address cross-border transfer mechanics, retention, and enforcement, which are outside the coverage of a public data definition.