Companies increasingly use publicly available personal data from websites, professional profiles, social media, public records, and other sources for market research, lead generation, recruitment, analytics, data enrichment, and artificial intelligence (AI).

India’s Digital Personal Data Protection Act, 2023 (DPDP Act), contains a specific exclusion for certain personal data made publicly available. Section 3(c)(ii) provides that the Act does not apply to personal data made or caused to be made publicly available by the Data Principal to whom it relates, or by another person who is under a legal obligation to make it publicly available.

For companies, the first compliance question is therefore whether the relevant personal data falls within this statutory exclusion. 

Strengthen DPDP Readiness

Firms using personal data in India should know how the DPDP Act applies to their operations. Our advisors can assess your data practices.
Book a free consultation

Understanding Section 3(c)(ii) exclusion

Section 3(c)(ii) of Chapter 1 of the DPDP Act is concerned with the circumstances in which personal data was made publicly available.

The provision covers two situations:

  1. The Data Principal made or caused the personal data to be made publicly available
  2. Another person was legally required under Indian law to make the personal data publicly available.

The Act provides an illustration involving an individual who publicly makes personal data available on social media. In that situation, the Act does not apply to that personal data.

This statutory test is narrower and more precise than simply asking whether information can be found online. Companies should establish how the relevant information entered the public domain and whether the circumstances fall within Section 3(c)(ii).

For example, an individual may voluntarily publish professional information on a public profile. Personal information may also appear in corporate filings, court records, or regulatory disclosures where applicable law requires its publication.

By contrast, information obtained through unauthorised access or by circumventing technical or contractual restrictions raises separate legal questions.

Web scraping and corporate data collection

Web scraping enables companies to automatically collect information from websites and other online sources. Businesses may use scraping for search services, market research, price monitoring, competitive intelligence, recruitment, and lead generation.

For companies, the relevant compliance assessment should begin with the status and source of the data. If the personal data falls within Section 3(c)(ii), the DPDP Act does not apply to that data by virtue of the statutory exclusion.

That does not, however, resolve every legal issue associated with the collection activity.

Companies should separately assess whether their methods of collection comply with the following:

  • Website terms and contractual restrictions
  • Applicable intellectual property rights
  • Confidentiality obligations
  • Laws governing unauthorised access or interference with computer resources
  • Sector-specific regulatory requirements

The distinction is particularly relevant where a company uses automated tools to collect information at massive scale or incorporates the resulting dataset into a commercial product.

Aggregation and data enrichment

Companies may combine information obtained from multiple sources to create business intelligence, customer profiles, recruitment databases, market datasets, or analytical products.

Aggregation can increase the commercial value of information by allowing a company to identify relationships between otherwise separate data points. Data enrichment may involve adding information from third-party databases or generating additional attributes through analytical tools.

The DPDP Act does not expressly state that aggregation, enrichment, profiling, inference, or commercialisation automatically removes personal data from the Section 3(c)(ii) exclusion. Companies should therefore avoid treating these activities as an automatic trigger for DPDP coverage.

At the same time, organisations should establish the provenance of the underlying information and document the legal basis on which they are relying on the exclusion. They should also consider whether the resulting product or processing activity is subject to other legal or contractual restrictions.

AI and large-scale data processing

AI development has increased the volume of information that companies may collect and process. Organisations may use information obtained from websites, public databases, social media, and other sources for model development, testing, retrieval, evaluation, or other AI-related applications.

Where personal data is included in these datasets, companies should first determine whether the data falls within an applicable exclusion under the DPDP Act.

Section 3(c)(ii) does not establish a separate rule specifically addressing AI training datasets. Nor does the DPDP Act expressly provide that using excluded publicly available personal data for AI development automatically brings that data within the Act.

Companies should therefore avoid making assumptions based solely on the fact that information is used for AI.

Instead, AI developers and businesses deploying AI systems should document the following:

  1. The sources used to create training or input datasets
  2. The categories of personal data contained in those datasets
  3. Whether the information falls within a statutory exclusion
  4. Whether third-party datasets or data providers are involved
  5. The contractual terms governing those datasets
  6. How the information is retained and secured
  7. Whether the company’s use creates obligations under other applicable laws

This approach is particularly relevant for companies developing proprietary AI systems or incorporating third-party AI models and datasets into commercial products.

DPDP readiness for companies

The DPDP Act commencement notification was issued on 13 November 2025, along with the DPDP Rules 2025 notification on the same day. Both frameworks provide for phased implementation. The next phase is scheduled for 13 November 2026, when Section 6(9), Section 27(1)(d), and Rule 4 of DPDP will come into force. The principal substantive provisions of the Act and Rules are scheduled to take effect on 13 May 2027.

Know the complete timeline: When Does India’s DPDP Law Begin Full Enforcement? 2026-2027 Timeline

Companies should therefore use the intervening period to assess their data-processing practices and prepare for the applicable compliance requirements.

Map data sources

Identify websites, platforms, databases, public records, and third-party datasets from which publicly available personal data is obtained for DPDP clearance.

Establish data provenance

Record how the information became publicly available and whether the circumstances fall within Section 3(c)(ii).

Classify excluded data

Where the company relies on the Section 3(c)(ii) exclusion, document the basis for that determination rather than assuming that all online information qualifies.

Review collection methods

Assess whether scraping or automated collection complies with applicable website terms, contracts, intellectual property requirements, confidentiality obligations, and other laws.

Govern third-party data

Where a company purchases or licenses datasets from data providers, conduct appropriate due diligence on the source, provenance, permitted use, and contractual restrictions attached to the data.

Review aggregation and enrichment

Document how datasets are combined, enriched, analysed, or incorporated into commercial products. While these activities do not automatically remove the Section 3(c)(ii) exclusion, they may create additional legal, contractual, or governance considerations.

Assess use of AI

Companies using publicly available personal data in AI training, testing, retrieval, or other applications should identify the data sources and determine whether the relevant information is covered by the DPDP Act or an applicable exclusion.

Maintain appropriate governance controls

Companies should establish appropriate policies and controls for data access, security, retention, vendor management, and onwards disclosure, taking into account the provisions of the DPDP framework as they come into force.

CLICK HERE: India DPDP Act Compliance 2027: Timeline, GDPR Comparison, and Business Checklist