If you're treating internet-accessible information as "publicly available" under state privacy laws, you might be misclassifying personal information and exposing your organization to compliance risk. Most data privacy statutes don't classify all internet-accessible information as "publicly available."
This template provides a structured approach to classifying information sources across California, Virginia, Colorado, Utah, and Connecticut privacy laws.
Purpose of the Template
This classification matrix helps your legal and privacy teams:
- Evaluate whether information sources qualify as "publicly available" under each state law
- Document the legal basis for excluding certain data from privacy rights obligations
- Identify data sets that require state-specific handling
- Support defensible positions during regulatory inquiries
Use this when building data inventories, responding to access requests, or determining which processing activities fall outside statutory scope.
Prerequisites
Before using this template, ensure you have:
- A complete data inventory showing information sources (government records, media archives, vendor-provided datasets, web-scraped content)
- State applicability analysis confirming which laws apply to your processing activities
- Access to statutory text for Cal. Civ. Code § 1798.140, Va. Code § 59.1-571, C.R.S. § 6-1-1303, Utah Code Ann. § 13-61-101, and Conn. Sub. Bill No. 6, § 1
- Legal review capacity to interpret edge cases where definitions diverge
This isn't a self-service tool. You're creating a legal record that may be scrutinized by regulators.
The Classification Matrix
Copy this table structure into your data governance documentation:
DATA SOURCE CLASSIFICATION MATRIX
Data Source: [Description of information source]
Collection Method: [How you obtained it]
Date Classified: [YYYY-MM-DD]
Reviewer: [Name, Title]
┌─────────────────────────────────────────────────────────────────┐
│ CALIFORNIA (CPRA) │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test: │
│ □ Available from federal/state/local government records │
│ □ Consumer made available from those records │
│ □ Business has reasonable basis to believe lawfully made public │
│ │
│ Widely Distributed Media Test: │
│ □ Available from widely distributed media │
│ □ Consumer has not restricted to specific audience │
│ │
│ Classification: □ Publicly Available □ Personal Information │
│ Notes: [Specific statutory basis] │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ VIRGINIA (CDPA) │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test: │
│ □ Lawfully made available from federal/state/local records │
│ │
│ Widely Distributed Media Test: │
│ □ Lawfully made available through widely distributed media │
│ │
│ Classification: □ Publicly Available □ Personal Data │
│ Notes: [Specific statutory basis] │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ COLORADO (CPA) │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test: │
│ □ Lawfully made available through federal/state/local records │
│ │
│ Mass Media Exception (for sales classification): │
│ □ Consumer intentionally made available via mass media channel │
│ □ To general public (not restricted audience) │
│ │
│ Classification: □ Publicly Available □ Personal Data │
│ Notes: [CPA does NOT treat widely distributed media as publicly │
│ available for most purposes] │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ UTAH (UCPA) │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test: │
│ □ Lawfully made available from federal/state/local records │
│ │
│ Widely Distributed Media Test: │
│ □ Lawfully made available from widely distributed media │
│ │
│ Consumer Intent Test: │
│ □ Consumer has not restricted information to specific audience │
│ │
│ Classification: □ Publicly Available □ Personal Data │
│ Notes: [Utah adds consumer intent requirement] │
└─────────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────────┐
│ CONNECTICUT (CTDPA) │
├─────────────────────────────────────────────────────────────────┤
│ Government Records Test: │
│ □ Lawfully made available from federal/state/local records │
│ │
│ Widely Distributed Media Test: │
│ □ Lawfully made available from widely distributed media │
│ │
│ Consumer Intent Test: │
│ □ Consumer has not restricted information to specific audience │
│ │
│ Classification: □ Publicly Available □ Personal Data │
│ Notes: [Connecticut mirrors Utah's approach] │
└─────────────────────────────────────────────────────────────────┘
CROSS-STATE SUMMARY:
Treated as publicly available in: [List states]
Treated as personal information in: [List states]
Requires state-specific handling: □ Yes □ No
COMPLIANCE IMPACT:
□ Subject to access requests in: [States]
□ Subject to deletion requests in: [States]
□ Subject to sale/sharing opt-out in: [States]
□ Requires [purpose disclosure](/glossary/purpose-disclosure) in: [States]
NEXT REVIEW DATE: [YYYY-MM-DD]
How to Customize It
For each data source:
Start with the most restrictive test. If information fails Colorado's government-records-only standard, it's personal data under CPA regardless of how other states classify it.
Government records analysis:
Don't assume federal databases qualify automatically. You need a reasonable basis to believe the consumer lawfully made the information public from those records (California standard). Document which specific government database you're relying on and when you verified its public status.
Widely distributed media:
This doesn't mean "findable via Google." The information must come from media sources with broad public distribution. A personal blog with 50 readers doesn't qualify. A LinkedIn profile might, but only if the consumer hasn't restricted viewing to connections (Utah and Connecticut add this intent requirement).
Colorado's mass media exception:
Note that Colorado includes an exception for information "intentionally made available by a consumer to the general public via a channel of mass media," but this applies to specific compliance obligations like classifying data transfers as sales. It doesn't make the information "publicly available" for purposes of the statutory definition. Document this separately if you're relying on it.
State-specific divergence:
When information qualifies in some states but not others, your data inventory must flag this. You can't apply a single classification across your entire processing environment. Consider a scenario where you've collected professional email addresses from a business directory: if that directory is a widely distributed media source, it may be publicly available in California, Virginia, Utah, and Connecticut but still personal data in Colorado.
Edge cases requiring legal review:
- Information from paywalled databases
- Social media profiles with privacy settings
- Professional directories with opt-out mechanisms
- Archived web content that was later removed
- Information "lawfully obtained" from the internet that California separately exempts as "truthful information that is a matter of public concern" (this is a different exemption than publicly available information)
Validation Steps
1. Cross-reference with your DSAR workflow
Pull your last 20 access requests. For each instance where you excluded information as "publicly available," verify it passes the classification test in every applicable state. If you can't document the basis, reclassify it.
2. Audit vendor contracts
If you're purchasing data that vendors label as "public," require them to specify which state definitions they're using. Their classification may not match yours.
3. Test with regulatory guidance
When state attorneys general publish enforcement priorities or FAQs, check whether your classifications align with their interpretation. If there's ambiguity, document your reasoning.
4. Review quarterly
Information status changes. A government database that was public may become restricted. A media source may remove content. Set a recurring review for high-risk data sources.
5. Document non-compliance risk
If you're treating information as publicly available in one state but not another, calculate your exposure. How many consumer requests would you need to honor? What's the cost of segmenting your data handling by state? Sometimes it's cheaper to treat everything as personal data than to maintain state-specific classifications.
The risk of misclassifying data as publicly available isn't theoretical. If you exclude information from a consumer access request because you believe it's public, and a regulator disagrees, you've violated the statute. Your classification matrix is your defense. Make it defensible.




