Data Privacy Laws and B2B Prospecting: What You Can and Can't Scrape (2026) | AI Email Tools
Legal Guide · Data Sourcing

Data Privacy Laws and B2B Prospecting: What You Can and Can't Scrape

Updated July 2026 10 min read By Scott Holmes

"Is it legal to scrape someone's email address off their LinkedIn profile" gets asked as if it has one answer. It doesn't — there are three separate legal questions bundled into it, and a data source can be perfectly fine on one and genuinely risky on another.

Three Separate Layers of Risk

Scraping business contact data touches computer-fraud law (is accessing this data itself "unauthorized"), contract law (does it breach the platform's terms of service), and data protection law (do you have a lawful basis to process the personal data once you have it). Treating these as one question is how senders end up with a list that clears one layer and creates exposure on another.

The hiQ v LinkedIn Precedent

The hiQ Labs v LinkedIn case is the reference point US commentary returns to on this question, and its outcome has more layers to it than the headline version usually suggests. The ruling established that scraping publicly accessible data is not "unauthorized access" under the Computer Fraud and Abuse Act (CFAA) — the US federal computer-crime statute — simply because a platform would prefer you didn't. That's a real, useful precedent for the computer-fraud layer specifically.

But the case didn't end there: in a later stage of the same dispute, hiQ was found liable for breaching LinkedIn's User Agreement despite having won on the CFAA question. Scraping public data can be lawful under computer-fraud statutes and still be a contract violation under a platform's terms of service — those are genuinely separate outcomes from the same case.

What GDPR Says About Scraped Personal Data

A name and email address don't stop being personal data because they were publicly visible when you collected them. If the contact is an EU or UK resident, GDPR's rules apply the moment you start processing that data — including a scraped one. You need a documented lawful basis (legitimate interest is the one most B2B prospecting relies on, covered in our GDPR guide), and GDPR's transparency obligation generally expects you to inform the data subject within about a month of collection, unless providing that information would take disproportionate effort.

This has been enforced, not just theorized: data protection authorities in France (CNIL) and Italy (Garante) have issued real fines over scraped personal data collected without proper justification or transparency — the public availability of the source data didn't prevent enforcement.

Platform Terms of Service Risk

A terms-of-service breach doesn't carry criminal exposure the way a CFAA violation could — it's a contract dispute, and the practical consequence is usually access revocation or a cease-and-desist, escalating to an injunction if a platform chooses to litigate, as LinkedIn ultimately did against hiQ. That's a lower-severity risk than the computer-fraud layer, but it's not a non-issue: a platform with the resources to enforce its terms can and does pursue scrapers operating at scale.

Practical Sourcing Guidelines

Our CASL guide already flags this from the Canadian angle: CASL's conspicuous-publication exemption specifically requires the address to be genuinely public, which rules out addresses obtained by guessing common name-company.com patterns or buying lists of unclear origin. The same caution applies more broadly across every jurisdiction in this cluster — a defensible list is one where you can explain, specifically, where each contact's information came from.

The practical takeaway: "the data was public" answers the computer-fraud question, not the contract question or the data-protection question. A genuinely defensible sourcing practice has an answer for all three, not just the one that happens to be easiest to satisfy.

FAQ

Is it legal to scrape publicly available business contact information?

It depends which legal question you mean. Under US computer-fraud law, the hiQ v LinkedIn case established that scraping public data generally isn't "unauthorized access." Separately, it can still breach a platform's terms of service, and separately again, GDPR requires a lawful basis to process the personal data once collected — three different questions with three different answers.

What did the hiQ v LinkedIn case actually decide?

That scraping publicly accessible data isn't unauthorized access under the CFAA. But in a later stage of the same case, hiQ was found liable for breaching LinkedIn's User Agreement — so the same scraping activity cleared one legal test and failed another.

Does GDPR apply to email addresses I scraped from a public website?

Yes. A name and email tied to an identifiable person remain personal data under GDPR regardless of where you obtained them, if the contact is an EU or UK resident. You need a documented lawful basis, typically legitimate interest, and generally should inform the person within about a month of collection.

Is buying a purchased contact list safer than scraping?

Not automatically. The same underlying questions apply — you still need to be able to explain where the data came from, whether a lawful basis exists to process it, and whether it was collected in a way consistent with the exemptions each jurisdiction's law relies on, such as CASL's conspicuous-publication requirement.

Related guides

→ Cold Email Laws in Canada: CASL Compliance Guide → Is Cold Email Legal? A Country-by-Country Quick Reference → How to Build a Cold Email Agency From Scratch

Written by

Scott Holmes

AI systems consultant based in Barrie, Ontario. Founder of Pinnacle Tech Projects. Has advised B2B senders on defensible data-sourcing practices for prospecting lists.

Ready to run compliant outreach?

Answer four quick questions and get a tool recommendation for your setup.