AI and the AI Act

Can a business reuse public data for products and AI training?

An open dataset, a public register and a private website offer different rights. Check reuse terms, database protection, personal data and TDM before collecting.

Maciej Lis Maciej Lis Polish attorney-at-law (radca prawny) 05 October 2026 11 min
Open dataPublic registersDatabase rightsScrapingTDMAI trainingGDPR

Adapted from the Polish article, originally published on 05 October 2026. The English version was published on 05 October 2026.

Suppose your team is building a market-analysis product. It plans to combine statistics from an open-data portal, information about individuals from a public register and a private company’s online catalogue. None requires a login. The collection pipeline is ready, and the team wants to train a model on the combined dataset.

Technical access is only the first step. The permission attached to each source needs checking before those inputs enter the product. An HTTP 200 response is unfortunately not a licence.

Publicly accessible data is not automatically available for unrestricted commercial reuse. Assess the source’s legal regime, rights in its content and database, access terms and personal data. AI training adds questions about text and data mining, or TDM.

The common framework discussed here is EU law. The public-register and statutory implementation examples use Poland; they should not be assumed to describe every Member State’s registers. Verified on 5 October 2026.

Start with the source, not the download format

SourceFirst checksUnsafe assumption
Open public-sector datasetReuse regime, terms, attribution, charges and third-party rightsEvery government-held record has the same permission
Public registerRegister legislation, access route, reuse rules, API and personal dataViewing one entry permits copying and reselling the whole register
Private online databaseCopyright, database rights, licences, terms and TDMNo login means permission to copy

The three inputs in our product need separate reviews even if they eventually feed the same pipeline.

Can open data support a paid product?

Yes, public-sector information can be reused commercially under the applicable framework. First establish that the dataset and proposed use fall within it. The Open Data Directive, 2019/1024, provides the EU framework. Poland implements it through the Act of 11 August 2021 on open data and reuse of public-sector information.

Reuse means using information for a purpose other than the public task for which it was produced. That can include an application, analysis or customer service. Published information and requests are available routes under the relevant rules.

Under the Polish Act, the starting point is reuse without conditions or charges, subject to statutory qualifications. Permitted terms can include identifying the source, when the information was obtained and whether it was modified. Exceptions to free supply can cover additional preparation costs, while libraries, museums and archives have distinct arrangements. Research data also has a specific scope, including public funding and prior availability.

For our statistical dataset, inspect the metadata and terms. Record the permitted transformations, onward supply and attribution. Check whether third parties hold rights in any of the material. Privacy, protected information and third-party rights limit the regime; government possession does not eliminate them.

What does an API add?

An API provides a retrieval mechanism. Permission to use the result comes from the applicable law and terms, not merely from the endpoint.

For designated high-value datasets, Implementing Regulation 2023/138 establishes enhanced requirements, including free availability, machine-readable formats, APIs and bulk download where specified in the Annex. Scope and exceptions still matter. These requirements do not automatically cover every public register. The Commission’s access guide explains this layer.

Public registers need a separate access and reuse analysis

A legal right to view an entry does not settle every downstream use. Identify the register’s legislation, disclosed fields, routes for obtaining a larger dataset and applicable reuse conditions.

Polish law provides a useful example of why the purpose of an access rule matters. Article 15 of the Act on computerisation of entities performing public tasks gives public bodies and qualifying entities performing public tasks free access to register data to the extent necessary for those tasks. Data obtained on that basis serves those tasks.

For a commercial product, paragraph 4 is relevant: supply for reuse for another purpose follows the Open Data Act. Article 15 is not a standalone permission to scrape any register commercially.

The current consolidated text also displays a future version of paragraph 2 that expressly refers to APIs, taking effect on 23 February 2027. It should not be treated as already applicable in October 2026, and it does not convert public-task access into unrestricted business use.

For the register information entering our product, establish both a valid retrieval and reuse route and a lawful basis for processing any personal data. They must fit what the product actually does.

Can a business copy a database of unprotected facts?

Individual facts may be outside copyright while the database remains protected. Separate rights in individual content, an original selection or arrangement, and investment in the database.

An original selection or arrangement can attract copyright protection, reflected in Article 3 of the Polish Copyright Act. A separate sui generis right protects qualifying substantial investment in a database and controls extraction or reuse of all or a substantial part. See Directive 96/9/EC and Poland’s Database Protection Act.

Not every table qualifies. In C-203/02, British Horseracing Board, the CJEU distinguishes investment in obtaining, verifying or presenting contents from investment in creating the data itself.

There is no universal row-count threshold for a substantial part. Both quantity and quality matter, including the investment associated with the extracted portion. Repeated, systematic collection of small portions can also infringe. Smaller scraping batches do not settle legality.

There is an important limit on the producer’s rights: lawful users of a publicly available protected database can use insubstantial parts, subject to restrictions protecting normal exploitation and the producer’s legitimate interests. Article 7 of the Polish Act invalidates conflicting contract terms within its stated scope. That does not authorise reconstructing the whole database through repeated small extractions or displace GDPR.

For the private catalogue in our example, assess protection, applicable terms and the planned volume and method. Contractual restrictions require attention to contract formation and mandatory exceptions. An API licence for internal analysis may have a different scope from permission to supply data to paying customers.

Public personal data is still personal data

A business must establish its own processing purpose, lawful basis and safeguards when the input identifies individuals. Combining sources may produce a much more detailed profile than any individual entry.

If relying on legitimate interests, identify the interest, assess necessity and balance individuals’ rights and reasonable expectations. Public availability is one factor, not the entire test. EDPB Opinion 28/2024 on AI models discusses this assessment, including public accessibility and reasonable expectations.

For indirectly collected data, GDPR Article 14 adds transparency obligations. Information is generally due within a reasonable period and no later than one month; first communication or disclosure can bring the deadline forward. Exceptions have conditions. A large number of records does not itself establish disproportionate effort. Relying on that exception requires assessment and appropriate safeguards, including making the information publicly available.

Set data limits, retention, update processes and handling of objections. Assess profiling consequences and any additional rules on solely automated decisions where their conditions are met. Special-category information, such as health data, needs a separate Article 9 condition. The exception for data manifestly made public by the individual does not automatically cover publication by someone else.

A publicly displayed contact address also does not establish permission for every marketing channel. Data-processing grounds and communication consent requirements need separate checks. In Poland, Article 398 of the Electronic Communications Law forms part of the latter layer.

Can the same dataset become commercial AI training material?

Sometimes, but public access alone is insufficient. Review lawful access, reuse, copyright, database rights, personal data and terms, then determine whether the specific copying or extraction can rely on TDM rules.

TDM is automated analysis of text or data to derive information, such as patterns and correlations. Articles 3 and 4 of the DSM Directive, 2019/790, distinguish:

  • Scientific research by qualifying research organisations and cultural-heritage institutions. This has defined beneficiaries, purposes and safeguards. Calling a startup project “research” does not establish eligibility.
  • General TDM, including commercial uses. This requires lawful access and applies where the rightholder has not appropriately reserved the relevant rights. Machine-readable reservations are particularly relevant for publicly available online material.

Poland implements the general mechanism in Article 26³ of the Copyright Act and Article 8a of the Database Protection Act. The rules require an express reservation appropriate to the way the material is made available; for public online access, they specify machine-readable format with metadata. Copies may be retained for TDM for as long as necessary for that purpose. Scientific research follows separate rules in Articles 26² and 8b.

This is not general permission to resell the source dataset or reproduce protected material in model outputs. Absence of a TDM reservation does not create a GDPR lawful basis either. Assess the actual reservation and its presentation rather than treating one robots.txt flag as a complete legal answer.

For a provider of a general-purpose AI model, or GPAI, the AI Act adds copyright-policy and public training-content-summary obligations. These do not automatically apply to every AI user. The Commission’s explanation of GPAI obligations covers their scope, including the continued application of these duties for qualifying open-source models. The AI Act does not grant a data licence.

Check when the model was placed on the market. GPAI obligations apply from 2 August 2025, with a compliance deadline of 2 August 2027 for providers of models placed on the market before that date. The transition does not supply rights to training material. See Articles 111 and 113 of the current AI Act.

A source review the product team can actually use

For the product at the start of this article, replace a single “public: yes” label with a record for each input:

  • Source and access. Who operates the source, which legal regime applies and what permits access? Retain the relevant terms version and retrieval date.
  • Intended use. Internal analysis, a paid product, onward supply or training? Check reuse conditions, attribution, rights, volume and collection method.
  • Personal data. Which fields identify people, why are they needed, what is the lawful basis, and how will transparency, minimisation, retention and rights work?
  • AI and TDM. Is access lawful, are rights reserved, what permits copies and how long will they be retained? Does the company’s role trigger GPAI duties?

You may be able to start with non-personal statistics where their terms permit the intended use. Keep register information and the private catalogue outside that part of the pipeline until reviewed. Combining inputs does not erase restrictions attached to their sources.

Connect these records with AI governance and the AI vendor-contract review if data or training is passed to a supplier.

Our technology legal services can review sources alongside the data flow and product plan. Send the source list and intended uses. The useful question is what the business will do with the data, as well as where it can obtain it.

Primary sources

Maciej Lis

Maciej Lis

Polish attorney-at-law (radca prawny)

IT and SaaS contracts, technology law, GDPR, information security and AI compliance.

View author profile
Back to Insights

Need to assess the risks of an AI deployment?

We help turn AI Act, data, vendor and security requirements into practical policies, documents and implementation decisions.

Book a free consultation

If the link does not open your email app, write directly to kontakt@lis.legal or copy the address.