Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Is Your Data Inventory Treating Internet Data as Public? Here's the Classification Template You NeedLaws and Regulations
6 min readFor Legal Counsel

Is Your Data Inventory Treating Internet Data as Public? Here's the Classification Template You Need

If you're treating internet-accessible information as "publicly available" under state privacy laws, you might be misclassifying personal information and exposing your organization to compliance risk. Most data privacy statutes don't classify all internet-accessible information as "publicly available."

This template provides a structured approach to classifying information sources across California, Virginia, Colorado, Utah, and Connecticut privacy laws.

Purpose of the Template

This classification matrix helps your legal and privacy teams:

  • Evaluate whether information sources qualify as "publicly available" under each state law
  • Document the legal basis for excluding certain data from privacy rights obligations
  • Identify data sets that require state-specific handling
  • Support defensible positions during regulatory inquiries

Use this when building data inventories, responding to access requests, or determining which processing activities fall outside statutory scope.

Prerequisites

Before using this template, ensure you have:

  1. A complete data inventory showing information sources (government records, media archives, vendor-provided datasets, web-scraped content)
  2. State applicability analysis confirming which laws apply to your processing activities
  3. Access to statutory text for Cal. Civ. Code § 1798.140, Va. Code § 59.1-571, C.R.S. § 6-1-1303, Utah Code Ann. § 13-61-101, and Conn. Sub. Bill No. 6, § 1
  4. Legal review capacity to interpret edge cases where definitions diverge

This isn't a self-service tool. You're creating a legal record that may be scrutinized by regulators.

The Classification Matrix

Copy this table structure into your data governance documentation:

DATA SOURCE CLASSIFICATION MATRIX

Data Source: [Description of information source]
Collection Method: [How you obtained it]
Date Classified: [YYYY-MM-DD]
Reviewer: [Name, Title]

┌─────────────────────────────────────────────────────────────────┐
│ CALIFORNIA (CPRA)                                               │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test:                                        │
│ □ Available from federal/state/local government records         │
│ □ Consumer made available from those records                    │
│ □ Business has reasonable basis to believe lawfully made public │
│                                                                  │
│ Widely Distributed Media Test:                                  │
│ □ Available from widely distributed media                       │
│ □ Consumer has not restricted to specific audience              │
│                                                                  │
│ Classification: □ Publicly Available  □ Personal Information    │
│ Notes: [Specific statutory basis]                               │
└─────────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────────┐
│ VIRGINIA (CDPA)                                                 │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test:                                        │
│ □ Lawfully made available from federal/state/local records      │
│                                                                  │
│ Widely Distributed Media Test:                                  │
│ □ Lawfully made available through widely distributed media      │
│                                                                  │
│ Classification: □ Publicly Available  □ Personal Data           │
│ Notes: [Specific statutory basis]                               │
└─────────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────────┐
│ COLORADO (CPA)                                                  │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test:                                        │
│ □ Lawfully made available through federal/state/local records   │
│                                                                  │
│ Mass Media Exception (for sales classification):                │
│ □ Consumer intentionally made available via mass media channel  │
│ □ To general public (not restricted audience)                   │
│                                                                  │
│ Classification: □ Publicly Available  □ Personal Data           │
│ Notes: [CPA does NOT treat widely distributed media as publicly │
│         available for most purposes]                            │
└─────────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────────┐
│ UTAH (UCPA)                                                     │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test:                                        │
│ □ Lawfully made available from federal/state/local records      │
│                                                                  │
│ Widely Distributed Media Test:                                  │
│ □ Lawfully made available from widely distributed media         │
│                                                                  │
│ Consumer Intent Test:                                           │
│ □ Consumer has not restricted information to specific audience  │
│                                                                  │
│ Classification: □ Publicly Available  □ Personal Data           │
│ Notes: [Utah adds consumer intent requirement]                  │
└─────────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────────┐
│ CONNECTICUT (CTDPA)                                             │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test:                                        │
│ □ Lawfully made available from federal/state/local records      │
│                                                                  │
│ Widely Distributed Media Test:                                  │
│ □ Lawfully made available from widely distributed media         │
│                                                                  │
│ Consumer Intent Test:                                           │
│ □ Consumer has not restricted information to specific audience  │
│                                                                  │
│ Classification: □ Publicly Available  □ Personal Data           │
│ Notes: [Connecticut mirrors Utah's approach]                    │
└─────────────────────────────────────────────────────────────────┘

CROSS-STATE SUMMARY:
Treated as publicly available in: [List states]
Treated as personal information in: [List states]
Requires state-specific handling: □ Yes  □ No

COMPLIANCE IMPACT:
□ Subject to access requests in: [States]
□ Subject to deletion requests in: [States]
□ Subject to sale/sharing opt-out in: [States]
□ Requires [purpose disclosure](/glossary/purpose-disclosure) in: [States]

NEXT REVIEW DATE: [YYYY-MM-DD]

How to Customize It

For each data source:

Start with the most restrictive test. If information fails Colorado's government-records-only standard, it's personal data under CPA regardless of how other states classify it.

Government records analysis:

Don't assume federal databases qualify automatically. You need a reasonable basis to believe the consumer lawfully made the information public from those records (California standard). Document which specific government database you're relying on and when you verified its public status.

Widely distributed media:

This doesn't mean "findable via Google." The information must come from media sources with broad public distribution. A personal blog with 50 readers doesn't qualify. A LinkedIn profile might, but only if the consumer hasn't restricted viewing to connections (Utah and Connecticut add this intent requirement).

Colorado's mass media exception:

Note that Colorado includes an exception for information "intentionally made available by a consumer to the general public via a channel of mass media," but this applies to specific compliance obligations like classifying data transfers as sales. It doesn't make the information "publicly available" for purposes of the statutory definition. Document this separately if you're relying on it.

State-specific divergence:

When information qualifies in some states but not others, your data inventory must flag this. You can't apply a single classification across your entire processing environment. Consider a scenario where you've collected professional email addresses from a business directory: if that directory is a widely distributed media source, it may be publicly available in California, Virginia, Utah, and Connecticut but still personal data in Colorado.

Edge cases requiring legal review:

  • Information from paywalled databases
  • Social media profiles with privacy settings
  • Professional directories with opt-out mechanisms
  • Archived web content that was later removed
  • Information "lawfully obtained" from the internet that California separately exempts as "truthful information that is a matter of public concern" (this is a different exemption than publicly available information)

Validation Steps

1. Cross-reference with your DSAR workflow

Pull your last 20 access requests. For each instance where you excluded information as "publicly available," verify it passes the classification test in every applicable state. If you can't document the basis, reclassify it.

2. Audit vendor contracts

If you're purchasing data that vendors label as "public," require them to specify which state definitions they're using. Their classification may not match yours.

3. Test with regulatory guidance

When state attorneys general publish enforcement priorities or FAQs, check whether your classifications align with their interpretation. If there's ambiguity, document your reasoning.

4. Review quarterly

Information status changes. A government database that was public may become restricted. A media source may remove content. Set a recurring review for high-risk data sources.

5. Document non-compliance risk

If you're treating information as publicly available in one state but not another, calculate your exposure. How many consumer requests would you need to honor? What's the cost of segmenting your data handling by state? Sometimes it's cheaper to treat everything as personal data than to maintain state-specific classifications.

The risk of misclassifying data as publicly available isn't theoretical. If you exclude information from a consumer access request because you believe it's public, and a regulator disagrees, you've violated the statute. Your classification matrix is your defense. Make it defensible.

California Consumer Privacy Act (CCPA)

Promotional banner for the Penetration Report Template Kit

You Might Also Like