DPDP Exemptions9 minutes

Section 3 Publicly Available Personal Data Exclusion Under DPDP Act

A definitive legal analysis of the Section 3(c)(ii) exclusion for publicly available personal data under the DPDP Act 2023, outlining applicability thresholds, scraping risks, extra-territorial limits, and defensibility for enterprise General Counsel.

Written byVipul Abhishek· Former Advocate, Supreme Court of India · ComplyDP Co-Founder

Last updated:

The Public Data Carve-Out Explained

Section 3 of the Digital Personal Data Protection (DPDP) Act, 2023 establishes a critical exclusion for publicly available personal data, creating a specific safe harbour that exempts qualifying datasets from the rigorous compliance requirements of the statute. Specifically, the Act does not apply to personal data that has been made publicly available by the Data Principal themselves, nor does it apply to data published by any other person who is under a strict legal obligation to make that information public. For enterprise legal teams, data brokers, and AI developers, this statutory carve-out is immensely valuable. When appropriately applied, it completely removes the obligations of issuing privacy notices, collecting affirmative consent, managing data fiduciaries' vendor agreements, and fulfilling data rights requests for these specific datasets.

Statutory Anchors and Territorial Scope

To properly leverage this exemption, organizations must first understand the fundamental applicability parameters set forth in Section 3 of the Act. Under Section 3(a), the DPDP Act applies to the processing of digital personal data within the territory of India where the personal data is collected in digital form, or collected in non-digital form and digitised subsequently. Section 3(b) establishes the extra-territorial scope, stating that the Act applies to processing outside India if such processing is in connection with any activity related to offering of goods or services to Data Principals within the territory of India. Against this broad jurisdictional backdrop, Section 3(c)(ii) provides the explicit statutory basis for the exclusion, rendering the Act entirely inapplicable to personal data that is made or caused to be made publicly available by the Data Principal, or by a person legally obligated to do so.

The First Condition: The Data Principal's Direct Action

The first limb of the exclusion heavily relies on establishing the exact source and the intent behind the publication. For this safe harbour to hold, the enterprise must prove the Data Principal willfully made the data public or caused it to be made public. A standard example is a professional willfully posting their own contact details, employment history, and public profile on an open networking platform or their personal blog. Because the Data Principal initiated the publication, any subsequent collection and processing of that specific data does not require compliance with the Act. However, if a third party unlawfully leaks the data, or if a data broker aggregates and republishes information without the Principal's direct, willful involvement, the statutory conditions are decisively not met, and the exclusion fails to apply.

The Second Condition: Legal Obligation to Publish

The second limb of the exclusion under Section 3(c)(ii)(B) covers personal data made publicly available by any other person who is under an obligation under any law to publish it. This covers statutory registries and government databases. For example, if Indian corporate law mandates the Ministry of Corporate Affairs to publish the names, directorships, and specific details of corporate directors on a public portal, the processing of that mandated public data falls outside the scope of the DPDP Act. General Counsel must note that this exclusion applies strictly to the data explicitly required by law to be published. If a government department inadvertently publishes extraneous personal data that was not legally required to be part of the public record, that excess data likely remains subject to the DPDP Act.

Risks For Web Scrapers and Aggregators

General Counsel must recognize that simply classifying data as "found on the internet" does not eliminate enterprise liability. Aggregators and web scrapers carry significant litigation and regulatory risk if they assume all online data was placed there willfully by the Data Principal. Furthermore, Section 4 dictates that a person may process the personal data of a Data Principal only in accordance with the provisions of the Act and for a "lawful purpose." Section 4(2) defines a lawful purpose as any purpose which is not expressly forbidden by law. If a web scraper employs methods that violate civil laws, breach website terms of service, or bypass security protocols (such as CAPTCHAs), the underlying processing could fail the lawful purpose test entirely, compounding the risk if the data scraped does not legitimately qualify for the Section 3 exclusion.

The Contamination Risk in Mixed Datasets

A critical operational hazard arises when organizations combine excluded public data with regulated personal data to build enriched customer profiles. Once publicly available data is merged with protected digital personal data, the resulting blended dataset falls squarely back under the jurisdiction of the Act. At that point, the entire dataset must be treated as regulated information. Additionally, the DPDP Rules, 2025 mandate rigorous vendor oversight. This means that enterprise contracts with data brokers who claim the Section 3 exclusion must include robust warranties and strong indemnities, ensuring that the vendor's data collection methods genuinely satisfy the rigorous criteria of the public data carve-out.

Section 16 Transfers and Public Data Misconceptions

The most dangerous myth regarding public data is that any information accessible via search engines is entirely unregulated. Another major misconception involves cross-border data transfers. For purely excluded public data, the Act does not apply, meaning there are no statutory transfer restrictions. However, for regulated personal data, Section 16(1) states that the Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified. This is a negative-list approach, meaning transfers are generally permitted unless the destination is officially restricted by the government. Legal teams must accurately classify data to determine if Section 16 restrictions apply to their international data pipelines.

Establishing Defensibility And Evidence

Defensibility before the Data Protection Board requires a pristine audit trail proving that the Section 3 exclusion legitimately applies to a given dataset. Legal teams must operationalize these evidence-gathering steps to protect the enterprise from compliance failures:

1. Maintain a centralized data provenance registry managed by the Chief Data Officer documenting exactly where external datasets were sourced, the date of collection, and the contextual evidence of their original publication.

2. Collect strict contractual warranties and limitation of liability clauses from third-party data providers explicitly stating the data was made public directly by the Data Principal or under a legal mandate.

3. Document the specific legal obligation for any government datasets utilized, citing the exact statute or regulation requiring publication, overseen by the legal department.

4. Implement automated segregation checks in data lakes to separate purely public data from proprietary personal data. Remember that consent is the primary basis for processing, except where Section 7 legitimate uses apply, making dataset segregation crucial for ensuring unregulated data does not contaminate regulated environments.

5. Conduct periodic audits of scraping algorithms to ensure they only target data fields willfully exposed by Data Principals, avoiding private or gated sections of digital platforms.

Related Statutory Provisions

Section 4 - Limits processing to lawful purposes (purposes not expressly forbidden by law), reinforcing that unauthorized scraping activities may fail the lawful purpose test even if the data appears publicly accessible.

Section 8 - Mandates overarching obligations for Data Fiduciaries, which attach instantly and retroactively if an enterprise fails to definitively prove the public data exclusion is valid.

Section 16 - Empowers the Central Government to restrict transfers to notified countries outside India, a critical consideration if datasets are reclassified from exempt to regulated.

Bridging The Compliance Gap

Exactly 261 days remain until the DPDP hard compliance deadline of 13 May 2027. General Counsel must immediately audit their external data supply chains to limit outside counsel spend and regulator engagement risks. Improper reliance on the Section 3 public data exclusion can expose the enterprise to crippling penalties of up to 250 crore rupees for failing to fulfill Data Fiduciary obligations. Assess your data provenance architecture, evaluate vendor contracts for indemnities, and verify your exemption defensibility by visiting freescan.complydp.com for an automated applicability gap check.

Sources

Frequently asked questions

Does the DPDP Act apply to web scraping of public profiles?

If the data was placed online directly and willfully by the Data Principal, Section 3(c)(ii) excludes it from the application of the Act. However, if the scraper collects data leaked by third parties, accesses gated information, or violates terms of service, the exclusion fails, creating substantial litigation and regulatory risk for the enterprise.

Can our vendors rely on the public data exclusion without contractual warranties?

General Counsel should never accept unverified claims of public availability from vendors or data brokers. You must secure strong limitation of liability clauses, warranties, and indemnities to ensure their data aggregation methods strictly meet the criteria of Section 3, thereby shifting the regulatory risk away from your organization.

What happens if publicly available data is mixed with our internal customer records?

Once excluded public data is merged with regulated digital personal data, the entire blended dataset becomes subject to the Act. You must apply standard Data Fiduciary obligations to this mixed data, including securing a valid lawful basis for processing, ensuring breach readiness, and complying with all reporting protocols under the DPDP Rules, 2025.

Do we need consent to process government directory data?

Consent is the primary basis for processing, except where Section 7 legitimate uses apply. However, Section 3 completely excludes data published by a person under a legal obligation, meaning you do not need consent for mandated government registries, provided you can thoroughly document the specific statutory mandate requiring the publication.

Are there limits on transferring publicly available data outside India?

For purely excluded public data, the Act does not apply, meaning no statutory transfer restrictions exist. For any regulated personal data, transfers are generally permitted unless the Central Government specifically restricts the transfer to notified countries or territories outside India under Section 16 of the Act.