How to scrape leads legally

Three separate things decide this: whether the data is genuinely public, what the source platform's terms of service say, and which jurisdiction the person you scraped is in. None of the three alone gives a full answer.

An admin approves every new account by hand. Nothing is created until then. We reply by email; no newsletter, no sequence.

app.salescrew.io/inbox
The unified reply inbox with classified threads

The short answer

  • Legality here is not a single yes-or-no question. It depends on whether the data is genuinely public, what the source platform's terms say about automated collection, and which jurisdiction the scraped person is in.
  • A platform's terms of service can prohibit scraping even data that is publicly visible on the page. Violating those terms carries its own risk, account termination or legal claims, separate from any data protection law.
  • GDPR governs how personal data about an EU or UK resident is processed, however it was collected. Scraped data is still subject to GDPR's lawful-basis requirements, even though the person never consented to being scraped.
  • Scraped data and a purchased list raise similar questions about origin and lawful basis. Neither is automatically safer, and both need verification before being treated as ready to use.

Why 'is it public' is not the whole question

A common assumption is that data visible on a public web page is fair game to collect and use. That misses two layers that also apply. First, the platform hosting the page has its own terms of service. Those often prohibit automated collection, even of content visible to any logged-out visitor. Violating them is a contractual matter between the scraper and the platform, separate from whether any data protection law was also broken. It carries its own consequences, from account bans to legal claims from the platform.

Second, data protection laws like GDPR govern how personal data about a specific person is processed, wherever or however it was obtained. If the scraped person is in the EU or UK, GDPR's requirement for a lawful basis applies to scraped data just as to any other collection method, even though the person never consented to being scraped in particular.

So "is it public" answers neither question on its own. A page can be fully public and still off-limits to scrape under the platform's terms. The resulting data can still trigger data protection obligations, depending on who the person is and where they are.

Three separate checks before scraping a source

CheckWhat it governs
Is the data genuinely public, with no login or paywall?A factual starting point, not a legal conclusion by itself
What does the source platform's terms of service say about automated collection?Contractual risk between the scraper and the platform
Where is the person located (EU/UK triggers GDPR; other jurisdictions have their own rules)?Data protection obligations for processing their personal data

What to actually do before building a scraping-based lead list

Read the specific platform's terms of service for the source you are considering. Do not assume a general "public data" rule applies to every site. Check where the bulk of the target list is located, and whether that triggers a specific regime like GDPR. Verify the resulting data before using it in outbound, the same way a purchased list needs verifying. Scraped data degrades and contains errors just as compiled lists do.

Disclosure: SalesCrew is our product. Its data bank can hold and segment a list whatever its origin, and suppression is enforced at send time. It does not evaluate whether a specific scraping method or source complied with that platform's terms or applicable data protection law. That assessment happens before the data reaches the product.

Terms of service violations and data protection law are two separate risks

Complying with GDPR does not mean a scrape did not also violate a platform's terms of service, and vice versa. Check both independently before treating a scraped source as safe to use. This is not legal advice.

Questions

Is scraping publicly visible data automatically legal?
Public visibility and a platform's terms of service are separate questions. Data can be publicly viewable on a page while the platform's terms still prohibit automated collection of it. Violating those terms carries its own risk, such as account bans or legal action, separate from data protection law.
Does GDPR apply to scraped data even if the person never agreed to be scraped?
Yes, if the person is in the EU or UK. GDPR governs how personal data is processed, however it was obtained. Scraped data about an EU resident is still subject to GDPR's rules on lawful basis, even though the person never consented to being scraped.
What is the practical difference between scraping and buying a purchased list?
Scraping collects data directly from its source. A purchased list was collected and compiled by someone else. Both raise similar legal questions about the data's origin and lawful basis. Both carry deliverability risk if the resulting list has not been verified.