Public Data
Public data is information that is openly available and can generally be used, reused, and redistributed without needing special authorization. It typically does not require the protective controls applied to confidential or restricted information. Whether a specific dataset qualifies as public depends on its source and on any legal restrictions that may still apply.
Public data is a data-classification designation for information that is openly accessible and can generally be used, reused, or redistributed without contractual or authorization-based restriction. It is commonly positioned as the lowest-sensitivity tier in a governance classification scheme, contrasted with private, confidential, or restricted categories, and its handling requirements typically focus on integrity and availability rather than confidentiality. This designation concerns accessibility and reuse, not privacy status: data that is publicly accessible may still constitute personal data or special category data under regimes such as the EU GDPR or UK GDPR, and public availability does not by itself remove data from regulatory scope. Under the CCPA/CPRA, a distinct statutory notion of 'publicly available information' applies as a definitional exclusion from personal information, which is scoped to those statutes and should not be conflated with an organization's internal 'public' classification tier. Some categories of records that are informally described as public may in fact be subject to specific access restrictions under applicable law; classification decisions should be validated against the governing legal framework rather than assumed from general availability. This entry defines the classification concept only and does not address cross-border transfer mechanics, retention obligations, lawful bases for processing, or jurisdiction-specific enforcement.
Why it matters
Public data classification matters because it determines the level of protective control an organization applies to information, and misclassification carries risk in both directions. Treating genuinely sensitive information as public can expose an organization to regulatory and reputational harm, while over-restricting openly available information wastes resources and can impede legitimate use, reuse, and redistribution. Because public data sits at the lowest-sensitivity tier in most governance schemes, its handling requirements typically emphasize integrity and availability rather than confidentiality, which shifts the control focus but does not eliminate the need for governance oversight.
A critical and frequently misunderstood point is that public accessibility is not the same as being outside regulatory scope. Data that is openly accessible may still constitute personal data or special category data under the EU GDPR or UK GDPR, and public availability does not by itself remove that data from regulatory obligations. Separately, the CCPA and CPRA contain a distinct statutory notion of 'publicly available information' that operates as a definitional exclusion from personal information; this is scoped to those statutes and should not be conflated with an organization's internal 'public' classification tier. Conflating the two can lead teams to assume regulatory relief that does not exist under the applicable framework.
Organizations should also recognize that records informally described as public may in fact be subject to specific access restrictions under applicable law. General availability is not a substitute for a legal determination. Classification decisions should be validated against the governing legal framework rather than inferred from the fact that information appears accessible, and accountability under governance frameworks generally requires demonstrable evidence of that validation rather than a stated assumption.
Who it's relevant to
Inside Public Data
Common questions
Answers to the questions practitioners most commonly ask about Public Data.