Publicly Available Data

Publicly available data is information anyone can access without special permission, such as a company website, press coverage or a public register. When it relates to an identifiable person it usually remains personal data under GDPR, even though it is public.

Compliance & PrivacyUpdated September 30, 2026

In short

Public does not mean free to use: under GDPR, personal data you find in public still needs a lawful basis, transparency and respect for individual rights.

Key points

  1. The GDPR has no general exemption for public information; if it relates to an identifiable person, it is Personal Data [1][2].
  2. Article 14 requires you to tell people when you collect their data from somewhere other than them, including where it came from, at the latest at first contact [3].
  3. Using public data still needs a lawful basis, most often Legitimate Interest, and a balancing test that considers the person's reasonable expectations [4].
  4. California's CCPA / CPRA excludes some publicly available information from its definition of personal information, such as lawfully available government records [5].
  5. Company-level facts, such as Firmographics and Technographics, are not personal data, so they carry far less legal risk than contact details [2].
  6. Terms of use, copyright and computer misuse laws can restrict how public web content is collected, separately from privacy law; see Web Scraping.

Why public data is still regulated

A common assumption in sales is that anything visible online is fair game. Privacy law does not agree. Under the GDPR, the definition of Personal Data turns on whether information relates to an identifiable person, not on whether it is secret [1]. A name and job title on a company team page, or a quote in a trade article, are personal data. The European Commission gives business email addresses as a standard example [2]. The practical effect is that the usual obligations apply: a lawful basis, Data Minimization, accuracy, and the rights to object and to the Right to Erasure. Article 9 even notes that special category data is treated differently only when the person has manifestly made it public themselves, which shows how narrow the public-data allowances are.

Transparency when data is not collected from the person

Article 14 is the rule most outbound teams overlook [3]. When you obtain personal data from any source other than the person, you must provide a privacy notice covering who you are, why you are processing the data, your lawful basis, the categories of data, the source it came from, how long you keep it and the person's rights. You must do this within a reasonable period and no later than one month, or at the latest when you first communicate with the person if you use the data to contact them [3]. For a Cold Email, a short line identifying you and linking to a privacy notice is a common way to meet this. There is a narrow exception for disproportionate effort, but it rarely fits direct outreach to named individuals.

Balancing expectations and other laws

Where public data is used for Outbound Sales, the Legitimate Interest balancing test does much of the work [4]. A person who publishes a work email in a professional context may reasonably expect relevant business contact; the same person would not expect their details to be combined into a detailed profile or sold on. The EDPB's guidelines stress reasonable expectations and the context in which data was made available [4]. In California, the CCPA / CPRA carve-out for publicly available information is limited to specific categories: lawfully available government records, information the consumer or widely distributed media made available to the general public, and information shared by someone the consumer did not restrict to a specific audience. It never covers biometric data collected without the consumer's knowledge [5]. Other rules, such as website terms and CASL conditions on conspicuous publication, can also apply. This is general information, not legal advice.

Sources
  1. Art. 4 GDPR — Definitions — gdpr-info.eu
  2. Data protection explained — European Commission
  3. Art. 14 GDPR — Information to be provided where personal data have not been obtained from the data subject — gdpr-info.eu
  4. Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR — European Data Protection Board
  5. California Civil Code 1798.140 — Definitions — California Legislative Information
External sources open in a new tab.

Related terms

Mentioned in

Outreach without the busywork.

PineLead finds new B2B prospects every day, qualifies them against your criteria and writes the first email in your voice. You approve — PineLead sends.

Start free with 100 credits →