Is web scraping legal?
A balanced, plain-English look at the questions that matter when you collect business data from the web: public versus private data, website terms, data protection and anti-spam laws, and practical habits that keep your prospecting responsible.
This is not legal advice. It is general information to help you ask the right questions. Laws differ by country, change over time and depend on the facts of each case. Before you rely on any of it, consult a qualified lawyer in the countries where you operate and where the people you contact are.
1. The short answer
There isn't one answer for every case. Collecting publicly available information is not illegal in itself in many countries, but several separate questions decide whether a particular use is lawful:
- What you collect: public business information, or data behind a login; company details, or personal data about individuals.
- How you collect it: through your own account at a normal pace, or by bypassing technical barriers or overloading a site.
- Which rules apply: the site's terms of service, computer misuse laws, data protection laws, copyright and database rights.
- What you do with it: relevant B2B outreach with a clear opt-out, or bulk unsolicited messages, resale or profiling.
Most of the legal risk in B2B prospecting comes from the last point: how you store and use personal data, and how you send your messages.
2. Public vs private data
Public data is information anyone can see without logging in, such as a company's website, its published contact email, or a business listing on a map. Data behind a login is only visible to account holders, and access to it is governed by the account's terms. Private data, such as private messages or information shared only with connections, is not meant for collection at all.
Two points are often misunderstood:
- Public doesn't mean free of rules. A name and work email on a public web page are still personal data under laws like the GDPR, so data protection obligations still apply when you collect and use them.
- Getting around barriers raises the risk. Bypassing logins, paywalls, captchas, IP blocks or other technical measures is treated more seriously in many legal systems than reading what is openly published.
3. Website terms vs the law
Many websites' terms of service restrict automated access or scraping. Breaking a site's terms is usually a contract matter between you and the site, rather than a crime. It can still have consequences: the site may suspend or close your account, block your access, or in some cases bring a legal claim for breach of contract.
This is separate from laws such as computer misuse statutes, data protection law and copyright, which apply whether or not you have an account. Read the terms of each site you collect from, especially where you are signed in to an account that you agreed terms for.
4. hiQ v. LinkedIn
hiQ Labs v. LinkedIn is a US case often cited in discussions about scraping. hiQ collected data from public LinkedIn profiles, and LinkedIn tried to stop it. The US Court of Appeals for the Ninth Circuit found that accessing data on public web pages, which anyone can view without logging in, was unlikely to be access “without authorization” under the federal Computer Fraud and Abuse Act.
That is a narrow point about one US law. Later in the same litigation, the court found that hiQ had breached LinkedIn's user agreement, and the case ended in a settlement in 2022. The case doesn't mean that scraping is always allowed: contract terms, data protection and privacy laws, copyright and laws outside the US can all still apply, and courts in other cases and countries may reach different results.
5. GDPR and personal data
If you collect or use personal data about people in the EU or the UK, or you are based there, the EU or UK GDPR is likely to apply, even when the data was publicly available. Key obligations include:
- Lawful basis: many B2B prospectors rely on legitimate interests, which needs a balancing test between your interest and the person's rights and reasonable expectations.
- Transparency: when you collect data from a source other than the person, you generally need to tell them who you are, why you have their data, where it came from and what their rights are, at the latest when you first contact them.
- Data minimisation: collect only what you need for your purpose.
- Rights: people can object to direct marketing at any time and ask for access to, or deletion of, their data.
- Security and retention: keep data secure and don't keep it longer than you need.
European data protection authorities have taken action against companies that scraped personal data without a lawful basis or without telling people. See our GDPR and data protection page for how roles work when you use QuickExtract.
6. India's DPDP Act, 2023
India's Digital Personal Data Protection Act, 2023 governs the processing of digital personal data in India, and of data processed outside India in connection with offering goods or services to people in India. It requires a lawful ground for processing, such as consent or certain legitimate uses, and gives individuals rights to access, correction, erasure and grievance redressal.
The Act says it doesn't apply to personal data that the individual has made publicly available, or that someone was legally required to publish. How far that exclusion reaches in practice depends on the rules made under the Act and on how it is interpreted, so don't assume it covers every public profile or web page. Other laws, such as the Information Technology Act, 2000, may still apply.
7. Anti-spam laws
Collecting an email address is one question. Sending marketing email to it is another, covered by separate laws:
United States: CAN-SPAM Act
Allows commercial email without prior consent, but requires accurate sender information, a subject line that isn't misleading, a valid physical postal address, and a clear way to opt out. Opt-out requests must be honoured promptly.
EU and UK: GDPR and e-privacy rules
Marketing email is covered by the ePrivacy rules as each EU country has implemented them, and by the PECR in the UK, alongside the GDPR. Rules for business addresses vary: some countries allow B2B email with an opt-out, while others require prior consent even for business recipients. Check the rules in each recipient's country.
India: IT Act, 2000
India doesn't have a dedicated anti-spam law for email. The Information Technology Act, 2000 and the DPDP Act, 2023 can still apply to how you collect data and send messages, and commercial calls and SMS are regulated separately.
Other countries
Some countries, such as Canada under CASL, generally require consent before sending commercial email. If you contact people in many countries, plan for the strictest rules that apply.
8. Copyright and databases
Facts, such as a company's name or phone number, are generally not protected by copyright, but the way they're presented can be, and photos, descriptions and other content are often protected. In the EU and UK, a database right can also protect a substantial investment in compiling a database. Use collected data for your own outreach rather than republishing or reselling someone else's content or listings.
9. Practical guidelines
These habits don't replace legal advice, but they reflect what many laws and regulators expect:
- Use your own accounts. Collect only what your own account can see, and follow the terms you agreed to. Don't share or rent accounts.
- Keep a reasonable pace. Don't overload websites or bypass captchas, IP blocks or other barriers. Slow down when a site pushes back.
- Stay B2B and relevant. Contact people in their professional role about something genuinely related to their job or company.
- Collect only what you need. Skip fields you won't use, and delete leads you no longer need.
- Be transparent. Say who you are and where you found the person's details, and link to your privacy notice.
- Make opting out easy. Include a simple opt-out in every message and honour it quickly.
- Honour deletion requests. Remove the person from your lists, exports and other tools, and keep a suppression list so they aren't added again.
- Don't resell raw lists. Selling or publishing personal data you scraped carries far more risk than using it for your own outreach.
- Write it down. Record your lawful basis, your balancing test and your retention period.
10. How QuickExtract fits
QuickExtract is designed to support these habits, but how you use it, and the data you collect with it, is your responsibility under our Terms of Service.
- Your own sessions: Sales Navigator scrapes use your own signed-in Sales Navigator account. QuickExtract doesn't scrape regular LinkedIn searches.
- Built-in pacing: Sales Navigator reads 100 leads per page with a 3-second pause, one scrape runs at a time, and website crawls have a Go slow mode that visits one site at a time, about 5 seconds apart.
- Business contact points: the free email finder looks for company emails, such as contact@ and hello@, published on the company's own website.
- LinkedIn excluded from autosave: the autosave feature never reads LinkedIn pages.
- Control over your data: delete leads and groups from your dashboard at any time.
See our Disclaimer and Privacy Policy for more.
11. When to call a lawyer
Consult a lawyer before you start a new prospecting program, contact people in a new country, collect data from a new kind of source, receive a complaint or legal letter, or plan to share or sell data. A short review of your lawful basis, your notices and your sending practices is far cheaper than fixing a problem later.
Build relevant B2B lists, at your own pace.
Extraction and company emails are free. Verified person emails cost $29 for 2,000.