DPDP enforcement deadline: May 2027Rules notified Nov 2025Penalty exposure up to ₹250 Cr
⚡ DPDP Act enforcement begins May 2026 — Check your readiness score

Quick Answer

Under Section 3(c) of the DPDP Act 2023, the Act does not apply to personal data that a Data Principal has made publicly available themselves, or that someone else has made public under a legal obligation. The exemption is narrow: it turns on who made the data public and why, not on whether the data happens to be visible online. Data scraped from a profile, published by a third party without the individual's choice, or made public by you rather than by the Data Principal, generally does not qualify. This checker helps you decide whether the Section 3(c) exemption genuinely applies to your specific data.

Does the Publicly-Available-Data Exemption Apply? (DPDP S.3(c))

The publicly-available-data exemption is far narrower than most people assume. Check whether Section 3(c) genuinely applies to your data before you rely on it.

Check whether Section 3(c) applies

Applying the Section 3(c) publicly-available-data exemption correctly

What does Section 3(c) actually exempt — and what it does not

Section 3(c) of the DPDP Act 2023 provides that the Act does not apply to personal data that is made publicly available by the Data Principal to whom it relates, or by any other person who is under a legal obligation to make it public. The precise wording matters. The exemption is anchored to the individual's own choice to make their data public, or to a legal duty on someone to publish it — for instance a statutory public register. It is not a general carve-out for any personal data that happens to be accessible on the internet.

This is where most organisations go wrong. Data scraped from social profiles, contact details compiled by a third-party data broker, leaked information, or data that a company itself exposed does not become exempt simply because it is visible. In each of those cases the data was not made public by the Data Principal themselves, nor under a legal obligation, so the DPDP Act continues to apply in full — a lawful basis, notice and Data Principal rights all remain live obligations.

Why relying on the public-data exemption is riskier than it looks

Because the exemption is narrow and fact-specific, building a business process on the assumption that it applies is a fragile strategy. The moment the circumstances of publication are questioned — did the individual really make this data public, or was it a third party; was it openly public or shared within a limited audience — the exemption can fall away and expose the entire downstream use. This is particularly dangerous for lead-enrichment, profiling and marketing use cases built on data collected from the open web.

The safer posture for most Indian companies is to assume the DPDP Act applies and to secure a proper lawful basis, rather than to lean on Section 3(c). Where the exemption genuinely does apply, it should be documented with evidence of who made the data public and how that was established. Niti Bharat helps companies assess exactly where the public-data exemption holds and where it does not, and build compliant data-sourcing practices that do not depend on a narrow exemption surviving scrutiny — well before enforcement is expected around May 2027.

Get the Section 3(c) exemption decision guide (free)

A PDF explainer of the publicly-available-data exemption with worked examples of what qualifies and what does not, and a documentation template for when you do rely on it.

Frequently Asked Questions

Does the DPDP Act apply to data I find on the public internet?+
Generally yes. Section 3(c) only exempts data made publicly available by the Data Principal themselves or by someone under a legal obligation to make it public. Data being visible online — scraped, brokered or third-party-published — does not by itself qualify, so the Act continues to apply and you still need a lawful basis to process it.
If someone posted their phone number publicly, can I use it for marketing?+
Not automatically. Even if the person made the data public, using it for a new and unrelated purpose such as marketing carries risk, and the exemption is fact-specific. It is safer to obtain consent for the intended use rather than to assume the exemption covers repurposing that the individual did not anticipate.
Does a statutory public register fall under Section 3(c)?+
Data that a person is under a legal obligation to make public — such as certain entries in a statutory public register — can fall within the exemption, because it was made public under a legal obligation. Even so, you should confirm the specific data and use, and document your basis, because the exemption is narrow.
Is scraped data exempt from the DPDP Act?+
Scraping data from profiles or websites does not make it exempt. Unless the Data Principal themselves made that specific data publicly available, or it was published under a legal obligation, Section 3(c) does not apply and the DPDP Act governs your use of the data in full.

Related Tools

Every Sunday

The Sunday DPDP Brief

One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.

No spam. Unsubscribe with one click, anytime.

Related tools & reading
DPA Checklist CheckerDPB Complaint Response SimulatorDPDP Applicability CheckerComplete DPDP Policy BundleSee all Calculators tools →📝 DPDP Compliance Cost India📝 DPDP Compliance Pricing India