Research across the library

Search laws, regulations, standards and guides

Suggested searches

Current priorities

2026-07-03Revised Internet Information Service Measures draft2026-06-18Network data risk assessment: draft versus final

The key distinction: access versus permitted use

The August Q&A connects reuse of publicly available personal information to reasonable scope, an individual's explicit refusal and significant effects on rights. It also identifies unrelated commercial messages as an audit concern. Public visibility is not, by itself, permission for every subsequent purpose.

Five questions before reusing a public dataset

An internal record should identify where the information came from and why it was published. Then compare that purpose with the proposed use, the people affected, the retention period and the likely consequences. A link to the original page alone is not a complete record of that reasoning.

CheckWorking evidence
Origin and purposeOriginal publication context, collection date and proposed use
Reasonable scopeWhy these fields, this population and this retention period are needed
Refusal and rightsAn accessible objection channel and a process for acting on requests
ConsequencesWhether profiling, ranking or disclosure changes the effect on individuals
SecurityNamed access roles, retention controls and leakage checks

Two illustrative uses of the same contact detail

A researcher uses a company's published contact address to ask about a statement on that company's website. A marketing operator instead gathers thousands of employee addresses and adds them to a promotional mailing list. Even where the collection method is identical, the purpose, scale and effect differ. Record those differences rather than treating both as 'public data'. Neither example is an automatic legal conclusion.

For recruitment, a professional profile may help identify a candidate, but that does not resolve every later use of their details. Distinguish a specific approach about a role from indefinite storage, enrichment with unrelated information or onward sharing. Record which later activities require a separate assessment.

Check the interface as well as the database

The Q&A highlights weak authentication, unprotected internet-accessible interfaces, exposed credentials and inadequate protection in storage or transmission. These are operational checks, not reasons to publish sensitive test results.

Use approved test data to compare an authenticated request with an unauthenticated one. Check that a user cannot retrieve another user's records, that exports require the expected permission and that credentials are absent from public assets. Keep evidence in restricted internal records. Do not test systems you do not own or lack permission to assess.

A reviewable outcome

Close the review with a purpose statement, a field-level justification, retention and access decisions, a rights-handling owner and the remaining questions. If the proposed use changes, reopen the decision. This record is more useful than a generic checkbox asserting that all data was publicly available.

Official sources & revisions

: Added original reuse scenarios and a working review matrix, with source notes distinguishing guidance from analysis.

Examples and working tables are original research aids, not official forms or legal advice.

Suggest a correction

Continue researching