Companies increasingly use publicly available personal data from websites, professional profiles, social media, public records, and other sources for market research, lead generation, recruitment, analytics, data enrichment, and artificial intelligence (AI).
India’s Digital Personal Data Protection Act, 2023 (DPDP Act), contains a specific exclusion for certain personal data made publicly available. Section 3(c)(ii) provides that the Act does not apply to personal data made or caused to be made publicly available by the Data Principal to whom it relates, or by another person who is under a legal obligation to make it publicly available.
For companies, the first compliance question is therefore whether the relevant personal data falls within this statutory exclusion.
Strengthen DPDP Readiness
Firms using personal data in India should know how the DPDP Act applies to their operations. Our advisors can assess your data practices.Understanding Section 3(c)(ii) exclusion
Section 3(c)(ii) of Chapter 1 of the DPDP Act is concerned with the circumstances in which personal data was made publicly available.
The provision covers two situations:
- The Data Principal made or caused the personal data to be made publicly available
- Another person was legally required under Indian law to make the personal data publicly available.
The Act provides an illustration involving an individual who publicly makes personal data available on social media. In that situation, the Act does not apply to that personal data.
This statutory test is narrower and more precise than simply asking whether information can be found online. Companies should establish how the relevant information entered the public domain and whether the circumstances fall within Section 3(c)(ii).
For example, an individual may voluntarily publish professional information on a public profile. Personal information may also appear in corporate filings, court records, or regulatory disclosures where applicable law requires its publication.
By contrast, information obtained through unauthorised access or by circumventing technical or contractual restrictions raises separate legal questions.
Web scraping and corporate data collection
Web scraping enables companies to automatically collect information from websites and other online sources. Businesses may use scraping for search services, market research, price monitoring, competitive intelligence, recruitment, and lead generation.
For companies, the relevant compliance assessment should begin with the status and source of the data. If the personal data falls within Section 3(c)(ii), the DPDP Act does not apply to that data by virtue of the statutory exclusion.
That does not, however, resolve every legal issue associated with the collection activity.
Companies should separately assess whether their methods of collection comply with the following:
- Website terms and contractual restrictions
- Applicable intellectual property rights
- Confidentiality obligations
- Laws governing unauthorised access or interference with computer resources
- Sector-specific regulatory requirements
The distinction is particularly relevant where a company uses automated tools to collect information at massive scale or incorporates the resulting dataset into a commercial product.
Aggregation and data enrichment
Companies may combine information obtained from multiple sources to create business intelligence, customer profiles, recruitment databases, market datasets, or analytical products.
Aggregation can increase the commercial value of information by allowing a company to identify relationships between otherwise separate data points. Data enrichment may involve adding information from third-party databases or generating additional attributes through analytical tools.
The DPDP Act does not expressly state that aggregation, enrichment, profiling, inference, or commercialisation automatically removes personal data from the Section 3(c)(ii) exclusion. Companies should therefore avoid treating these activities as an automatic trigger for DPDP coverage.
At the same time, organisations should establish the provenance of the underlying information and document the legal basis on which they are relying on the exclusion. They should also consider whether the resulting product or processing activity is subject to other legal or contractual restrictions.
AI and large-scale data processing
AI development has increased the volume of information that companies may collect and process. Organisations may use information obtained from websites, public databases, social media, and other sources for model development, testing, retrieval, evaluation, or other AI-related applications.
Where personal data is included in these datasets, companies should first determine whether the data falls within an applicable exclusion under the DPDP Act.
Section 3(c)(ii) does not establish a separate rule specifically addressing AI training datasets. Nor does the DPDP Act expressly provide that using excluded publicly available personal data for AI development automatically brings that data within the Act.
Companies should therefore avoid making assumptions based solely on the fact that information is used for AI.
Instead, AI developers and businesses deploying AI systems should document the following:
- The sources used to create training or input datasets
- The categories of personal data contained in those datasets
- Whether the information falls within a statutory exclusion
- Whether third-party datasets or data providers are involved
- The contractual terms governing those datasets
- How the information is retained and secured
- Whether the company’s use creates obligations under other applicable laws
This approach is particularly relevant for companies developing proprietary AI systems or incorporating third-party AI models and datasets into commercial products.
DPDP readiness for companies
The DPDP Act commencement notification was issued on 13 November 2025, along with the DPDP Rules 2025 notification on the same day. Both frameworks provide for phased implementation. The next phase is scheduled for 13 November 2026, when Section 6(9), Section 27(1)(d), and Rule 4 of DPDP will come into force. The principal substantive provisions of the Act and Rules are scheduled to take effect on 13 May 2027.
Know the complete timeline: When Does India’s DPDP Law Begin Full Enforcement? 2026-2027 Timeline
Companies should therefore use the intervening period to assess their data-processing practices and prepare for the applicable compliance requirements.
Map data sources
Identify websites, platforms, databases, public records, and third-party datasets from which publicly available personal data is obtained for DPDP clearance.
Establish data provenance
Record how the information became publicly available and whether the circumstances fall within Section 3(c)(ii).
Classify excluded data
Where the company relies on the Section 3(c)(ii) exclusion, document the basis for that determination rather than assuming that all online information qualifies.
Review collection methods
Assess whether scraping or automated collection complies with applicable website terms, contracts, intellectual property requirements, confidentiality obligations, and other laws.
Govern third-party data
Where a company purchases or licenses datasets from data providers, conduct appropriate due diligence on the source, provenance, permitted use, and contractual restrictions attached to the data.
Review aggregation and enrichment
Document how datasets are combined, enriched, analysed, or incorporated into commercial products. While these activities do not automatically remove the Section 3(c)(ii) exclusion, they may create additional legal, contractual, or governance considerations.
Assess use of AI
Companies using publicly available personal data in AI training, testing, retrieval, or other applications should identify the data sources and determine whether the relevant information is covered by the DPDP Act or an applicable exclusion.
Maintain appropriate governance controls
Companies should establish appropriate policies and controls for data access, security, retention, vendor management, and onwards disclosure, taking into account the provisions of the DPDP framework as they come into force.
CLICK HERE: India DPDP Act Compliance 2027: Timeline, GDPR Comparison, and Business Checklist