Legal / Acceptable use
Acceptable use policy
Version 2026-07-28Effective 2026-07-28
Scope and spirit
This policy forms part of the terms of service and applies to everyone using worldgovdata — the portal, the API and the account area — whether or not they have paid us anything.
It is short on purpose. The service exists so that people can use public statistics easily, and a policy that hedges every use case out of existence would defeat that. There are three things we actually care about: do not break the law, do not damage the service for other people, and do not redistribute data under terms its original publisher did not grant. Clause 02 is what that leaves you free to do, and it is most of everything.
What you may do — which is nearly everything
You do not need our permission for any of this, and we would rather state it explicitly than let a prohibition list imply the opposite:
- Commercial use. Build a paid product on the API. Use it inside a company. Charge your own customers. Nothing here restricts you to non-commercial use, subject only to the licence a given indicator carries.
- Publication. Put the figures in a paper, a book, a dashboard, a newspaper article, a policy brief or a thesis. Credit the source, and cite us if you like.
- Caching and storage. Store what you fetch in your own database. Please do — repeatedly re-fetching the same series is worse for both of us than caching it once.
- Derivation. Compute indices, transform, model, chart, aggregate, and combine our data with anyone else’s.
- Training machine-learning models on the statistics — subject, as always, to the licence the underlying provider attached to that data.
- Redistribution of open-licensed data. Where a provider published under CC BY or a similarly permissive licence, that licence permits redistribution and we do not take it away. Carry the attribution.
- Automation. Scheduled jobs, bulk extraction, pipelines that refresh nightly. That is what the API is for and what the credits price.
Illegal and harmful use
You must not use the service:
- to do anything unlawful, or to help someone else do something unlawful;
- to infringe intellectual property, privacy, publicity or contractual rights belonging to anyone;
- to distribute malware, run a phishing operation, or as any part of the infrastructure of an attack on a third party;
- to harass, threaten, defame or endanger anyone, or to build a tool whose evident purpose is to do so;
- to attempt to identify individuals — for instance by combining these aggregates with another dataset in order to single someone out. The data is country-level and contains no personal data; treating it as raw material for re-identification is out of bounds even where it would be technically ingenious;
- in breach of sanctions or export control law, or from a jurisdiction we are not permitted to supply.
Do not damage the service
The API is shared infrastructure. Rate limits exist so that one heavy user cannot make the service unusable for everyone else; they are documented in the documentation and they are generous.
You must not:
- attempt denial of service, volumetric load testing, or any deliberate attempt to exhaust capacity;
- circumvent, evade or attempt to evade rate limits, quotas or credit metering — for example by rotating IP addresses, distributing requests across accounts, or scraping the portal in order to get metered data without paying for it;
- create multiple accounts to collect the free credit grant more than once. One person or organisation, one account;
- probe, scan or test the security of the service or its infrastructure, except under clause 07;
- interfere with another user’s access, attempt to access another account, or use a key that is not yours;
- introduce anything designed to disrupt, damage or gain unauthorised access to the service or its data.
Keys and accounts
- Do not share your key. Not with a colleague’s side project, not in a public repository, not in a browser bundle or a mobile app, and not in a support ticket. A key is a credential.
- Do not resell access to the API. You may build a product on top of it — that is encouraged — but you may not sell, sublicense, rent or expose raw access to our API as though it were your own service, or act as a reseller of our credits.
- Do not misrepresent the service. Do not present worldgovdata as your own product, imply that we endorse or have reviewed yours, or use our name or wordmark in a way that suggests affiliation.
- Do not remove attribution. Provenance travels with every value we serve. Stripping it out is a breach of both this policy and, usually, the provider’s licence.
- Keep your account details true. An account opened with a false identity, or used on behalf of someone who is suspended, is a breach.
The data, and the licences that come with it
We can only give you what the original publisher gave us. Every indicator carries an access tier, and the tier travels with the data in every response.
| Tier | What it means | What you may do |
|---|---|---|
| open | The provider published under a licence that permits redistribution — usually CC BY. | Everything in clause 02, including redistribution, with attribution to both the provider and worldgovdata and any share-alike term honoured. |
| display_only | We hold the right to show the figure, not to let you redistribute it. Export and bulk endpoints never serve it, and the API returns 403 display_only. | Read it on the site. Do not scrape it, do not republish it, do not build a mirror of it. This restriction is not ours and we cannot lift it. |
Attribution, concretely
Name the original provider and worldgovdata, and link back where the medium allows it. The provider name and licence for every indicator are on the sources page and in every API response. Full guidance is in the licensing documentation.
Do not misrepresent the numbers
Do not present a figure as ours when it is a provider’s, alter values and continue to attribute them to the source, strip the year or the unit so a comparison misleads, or suggest an institution endorses a conclusion it never drew. Where our harmonised value and the publisher’s original disagree, the publisher’s governs and should be cited.
Security research is welcome
The conditions are the ones on that page: report privately first, test only against your own account, take no more data than the minimum needed to demonstrate the issue, stop and tell us if you encounter someone else’s data, and no denial of service, no social engineering, nothing physical.
Reports go to connect@worldgovdata.com. We acknowledge within 3 business days.
Reporting abuse
If you see the service being used in breach of this policy — a key posted publicly, a product misrepresenting our data, an account scraping around metering — tell us at connect@worldgovdata.com. Include what you saw and where. We investigate every report, we will not disclose who reported something without asking first, and we will tell you what came of it where we can.
What happens if you breach this
Our response is proportionate to what actually happened. Most breaches are accidents — a key in a repository, a script with no backoff — and the fix is a conversation.
- We tell you. For anything that looks unintentional, the first step is an email explaining what we saw and what needs to change.
- We throttle. A key generating load that threatens the service may be rate-limited further while we sort it out.
- We revoke a key. Immediately, if we believe it is compromised or is being used abusively. You can create a new one.
- We suspend. For a serious or repeated breach, or where there is an immediate risk. We tell you why and what would lift it, unless the law prevents us.
- We terminate. For a material breach not fixed within 14 days of us asking, or immediately for one that cannot be fixed. Unused credits are forfeited only to the extent that is proportionate — see clause 15 of the terms.
If we get it wrong, say so at connect@worldgovdata.com. We will reinstate the account and, if you would rather leave, refund the balance.
Changes
We may update this policy as the service changes or as new kinds of abuse appear. Any change bumps the version stamp at the top of the page, and a change that materially restricts what you are currently permitted to do is notified to account holders at least 30 days before it takes effect.
Unsure whether something is allowed? Ask before you build it: connect@worldgovdata.com. A yes takes a day; discovering a no after six months of work takes considerably longer.