Under Section 3(c) of the DPDP Act 2023, the Act does not apply to personal data that a Data Principal has made publicly available themselves, or that someone else has made public under a legal obligation. The exemption is narrow: it turns on who made the data public and why, not on whether the data happens to be visible online. Data scraped from a profile, published by a third party without the individual's choice, or made public by you rather than by the Data Principal, generally does not qualify. This checker helps you decide whether the Section 3(c) exemption genuinely applies to your specific data.
The publicly-available-data exemption is far narrower than most people assume. Check whether Section 3(c) genuinely applies to your data before you rely on it.
Section 3(c) of the DPDP Act 2023 provides that the Act does not apply to personal data that is made publicly available by the Data Principal to whom it relates, or by any other person who is under a legal obligation to make it public. The precise wording matters. The exemption is anchored to the individual's own choice to make their data public, or to a legal duty on someone to publish it — for instance a statutory public register. It is not a general carve-out for any personal data that happens to be accessible on the internet.
This is where most organisations go wrong. Data scraped from social profiles, contact details compiled by a third-party data broker, leaked information, or data that a company itself exposed does not become exempt simply because it is visible. In each of those cases the data was not made public by the Data Principal themselves, nor under a legal obligation, so the DPDP Act continues to apply in full — a lawful basis, notice and Data Principal rights all remain live obligations.
Because the exemption is narrow and fact-specific, building a business process on the assumption that it applies is a fragile strategy. The moment the circumstances of publication are questioned — did the individual really make this data public, or was it a third party; was it openly public or shared within a limited audience — the exemption can fall away and expose the entire downstream use. This is particularly dangerous for lead-enrichment, profiling and marketing use cases built on data collected from the open web.
The safer posture for most Indian companies is to assume the DPDP Act applies and to secure a proper lawful basis, rather than to lean on Section 3(c). Where the exemption genuinely does apply, it should be documented with evidence of who made the data public and how that was established. Niti Bharat helps companies assess exactly where the public-data exemption holds and where it does not, and build compliant data-sourcing practices that do not depend on a narrow exemption surviving scrutiny — well before enforcement is expected around May 2027.
A PDF explainer of the publicly-available-data exemption with worked examples of what qualifies and what does not, and a documentation template for when you do rely on it.
One real DPDP development explained in plain English, one practical how-to, one number from our own assessment data. Nothing else — no daily noise, no sales pitch.
No spam. Unsubscribe with one click, anytime.