Is web scraping legal?

A plain-English guide to the legality of web scraping and extracting business-directory data — the laws that apply, what the courts have said, and how to collect public data responsibly.

General information, not legal advice. For your situation, consult a qualified lawyer.

Is web scraping legal?

Collecting publicly available information is generally legal in the US, the EU and similar jurisdictions, but “web scraping” is not a single yes-or-no question. Its legality depends on how you access the data, the website’s terms of service, copyright, and data-protection law — so it turns on what you collect, from where, and how you use it.

In practice, four things decide whether a given scraping project is lawful: how you access the site (public pages versus content behind a login), whether you agreed to terms that forbid it, whether the material is protected by copyright, and whether the data identifies real people. Extracting openly published business listings sits at the low-risk end of that spectrum; harvesting personal data behind an account sits at the high-risk end. This page walks through each factor and how it applies to business-directory data such as Yellow Pages.

What laws apply to web scraping?

No single law governs web scraping. Instead, several overlap: computer-access laws (like the US CFAA), the site’s terms of service, copyright and database rights, and data-protection laws such as the GDPR, PIPEDA and CCPA. Anti-spam laws then govern how you may contact the people or businesses you collect.

Law / rule What it governs Relevance to business-directory scraping
Computer Fraud and Abuse Act (US) Unauthorized access to a computer system Accessing public pages without logging in or bypassing controls is generally not a violation
Terms of service / contract The website’s own rules for use Scraping against a site’s stated terms can be a breach of contract, even for public data
Copyright & database rights Original content and compiled databases Individual facts (a phone number) aren’t copyrightable; copying a whole database can raise issues
GDPR (EU/EEA) Personal data that identifies an individual Applies when records identify a person; company firmographic data is lower-risk
PIPEDA (Canada) · CCPA/CPRA (California) Personal information of individuals Similar notice, purpose and opt-out duties when personal data is involved
CAN-SPAM · CASL · GDPR How you email, call or market to contacts Govern the outreach you send to the data you collect, not the collection itself

The takeaway: the collection and the use of data are governed separately. You can lawfully gather public business listings and still break the rules by emailing them without following anti-spam law — so both steps matter.

Is it legal to scrape publicly available data?

Collecting data that is genuinely public — visible to anyone without logging in — is broadly permitted, and US courts have found it does not by itself violate the Computer Fraud and Abuse Act. It is not a blanket licence, though: contract, copyright and privacy rules can still apply depending on the site and the data.

“Public” is the key word. Data shown to any visitor of a website is treated very differently from data behind a password, a paywall or a technical barrier. Bypassing access controls, using stolen credentials or ignoring a block moves a project from “reading a public page” toward “unauthorized access,” which is where the real legal risk begins. Business directories publish their listings openly for people to find, which is why extracting them is usually lower-risk than scraping a logged-in social network.

What did the hiQ Labs v. LinkedIn case decide?

In hiQ Labs v. LinkedIn, the US Ninth Circuit indicated that scraping data which is publicly available — without logging in or bypassing access controls — does not violate the Computer Fraud and Abuse Act. It did not make all scraping legal: a later ruling found hiQ had breached LinkedIn’s user agreement, and the case ultimately settled.

The case is the most-cited US authority on scraping public data. Its lasting point is narrow but useful: gathering information that a site shows to the public is not “hacking” under the CFAA. At the same time, the later contract finding is a reminder that a website’s terms of service can still bind you. The two rulings together explain why respecting each site’s terms — not just its login wall — matters.

Is scraping business data different from personal data?

Yes. Data-protection laws like the GDPR, PIPEDA and CCPA apply when information identifies an individual. Business firmographic data — a company name, office address and switchboard number — carries less risk than personal data, but an individual’s name or personal email can still count as personal data, so contact records must be handled carefully.

Extracting business-directory listings such as Yellow Pages is mostly firmographic: it describes organisations rather than private individuals. That is lower-risk. The line to watch is where a record names a specific person or gives a personal email address — at that point privacy law can apply, and you need a lawful basis for using it, especially for marketing in the EU, the UK and Canada. Treat every contact record as if it might contain personal data, and you stay on the safe side.

Is it legal to scrape Yellow Pages and business directories?

Extracting publicly listed business contact details — company name, address, phone and business email — is lower-risk than collecting personal data, because it is business information published for people to find. You should still respect each directory’s terms of service, avoid overloading its servers, and use the data only for legitimate business purposes.

Business directories exist precisely so that customers can discover and contact companies, so the listings are public by design. That makes directory data one of the more defensible sources to work with — provided you collect it at a reasonable rate, follow each site’s terms, keep it accurate, and use it for genuine B2B research and outreach rather than spam. Yellow Pages Scraper only gathers the fields a directory already publishes; how that data is used lawfully afterwards is the sender’s responsibility.

How do you scrape data legally and responsibly?

Collect only public business-listing fields, respect robots.txt and each site’s terms, limit your request rate so you don’t disrupt the service, keep the data accurate and secure, honour opt-out and deletion requests, and use it only for legitimate B2B purposes. Then follow anti-spam law whenever you contact the businesses you collected.

  • Collect only the public business fields a directory already displays
  • Respect robots.txt and each website’s terms of service
  • Limit your request rate so you never disrupt the service
  • Keep records accurate and secure; honour opt-out and deletion requests
  • Have a lawful basis and use the data for genuine B2B purposes
  • Follow CAN-SPAM, CASL and the GDPR when you email or call

Can you use scraped business data for sales outreach?

Yes, for legitimate business-to-business research and outreach — but how you contact people is regulated separately from how you collect the data. Anti-spam laws such as CAN-SPAM (US), CASL (Canada) and the GDPR (EU) set rules for consent, honest identification and an easy opt-out that you must honour.

Collecting a public phone number or business email is one step; emailing or calling it is another, and that second step is where most rules bite. Identify yourself honestly, give a working way to opt out, respect do-not-contact requests, and — in Canada and the EU especially — make sure you have a lawful basis to reach out. Used this way, directory data powers legitimate lead research; used to blast unsolicited spam, it breaks the law regardless of how the data was obtained.

Extract business data the responsible way

Yellow Pages Scraper collects the public business listings you need for legitimate B2B research — try the free trial and see how it works.

Frequently Asked Questions

Is web scraping legal?

Collecting publicly available information is generally legal in the US, EU and similar jurisdictions, but "web scraping" is not a single yes-or-no question. It is governed by a site's terms of service, copyright law and data-protection laws such as the GDPR, so legality depends on what you collect, from where, and how you use it. This is general information, not legal advice.

Is it legal to scrape Yellow Pages or a business directory?

Extracting publicly listed business contact details — company name, address, phone and business email — is lower-risk than collecting personal data, because it is business information published for people to find. You should still respect each directory's terms of service, avoid overloading its servers, and use the data for legitimate business purposes. This is general guidance, not legal advice.

Is scraping personal data different from scraping business data?

Yes. Data-protection laws like the GDPR (EU), PIPEDA (Canada) and the CCPA (California) apply when the information identifies an individual. Business firmographic data — a company name, office address and switchboard number — carries less risk than personal data, but an individual's name or personal email can still be personal data, so handle contact records carefully and have a lawful basis for B2B outreach.

What does the LinkedIn (hiQ) case say about scraping public data?

In the US hiQ Labs v. LinkedIn litigation, courts indicated that accessing data that is publicly available, without logging in or bypassing access controls, does not by itself violate the Computer Fraud and Abuse Act. It did not make all scraping legal — contract, copyright and privacy claims can still apply — but it supports the view that collecting public listings is not automatically "hacking".

How do I scrape business data responsibly?

Collect only public business-listing fields, respect robots.txt and each site's terms, limit your request rate so you do not disrupt the service, keep the data accurate and secure, honour opt-out and deletion requests, and use it only for legitimate B2B purposes such as sales research — never for spam. Following anti-spam rules (CAN-SPAM, CASL, GDPR) governs how you may contact the businesses you collect.

Does Yellow Pages Scraper only collect public data?

Yes. It gathers the business information that directories already publish openly — the same details a person could read on each listing — and does not bypass logins or access controls. How you use that data lawfully and responsibly is your responsibility as the sender.