Is Email Scraping Legal? A Practical Guide to GDPR, CAN-SPAM and Public Data
Is email scraping legal? A balanced 2026 guide to GDPR, CAN-SPAM, public data, lawful basis, and opt-out rules so you can build lists without breaking the law.
Is email scraping legal? The honest, lawyer-adjacent answer is: it depends on what you scrape, where your contacts live, and how you use the data afterward. Scraping publicly available business emails is broadly permitted in most jurisdictions, but the moment you send unsolicited mail — or handle personal data belonging to EU or UK residents — you step into a web of rules that carry real fines. This guide breaks down the actual laws (GDPR, CAN-SPAM, PECR, CASL), the concept of "lawful basis," and the practical steps that keep a scraped list on the right side of the line.
A quick disclaimer: this is educational content, not legal advice. Regulations change and enforcement varies. When in doubt, talk to a qualified attorney in your target markets.
Scraping vs. sending: two different legal questions
Most confusion comes from collapsing two separate activities into one. Keep them apart:
- Collecting the data — visiting a public web page and extracting an email address that someone chose to publish.
- Using the data — storing it, enriching it, and emailing the person.
The act of collecting public information is rarely the part that gets companies in trouble. Courts in the United States (notably hiQ Labs v. LinkedIn) have repeatedly signaled that scraping publicly accessible data does not, by itself, violate the Computer Fraud and Abuse Act. The legal risk concentrates almost entirely in the second step — what you do with the data and how you contact people.
So "is email scraping legal" is really two questions: Can I collect this? and Can I email this? The answers differ by region.
The United States: CAN-SPAM and public data
In the US, there is no federal law that bans scraping public email addresses. The controlling statute for commercial email is CAN-SPAM (2003), and — importantly — it is an opt-out regime, not opt-in. You do not need prior consent to send a first commercial email. You do need to:
- Not use deceptive headers or subject lines. The "From," "To," and routing must be accurate.
- Identify the message as an ad where applicable.
- Include a valid physical postal address.
- Offer a clear, working opt-out and honor unsubscribe requests within 10 business days.
Penalties can reach into the tens of thousands of dollars per email, so the mechanics matter. But scraping a business's public "contact us" email and sending a compliant, relevant pitch is legal in the US.
State laws add nuance. California's CCPA/CPRA treats personal information more strictly and gives residents the right to know and delete data, but it targets larger businesses and does not outlaw B2B prospecting outright.
The EU and UK: GDPR, lawful basis, and PECR
This is where scraping gets genuinely complicated. Under the GDPR, an email address that identifies a person (john.smith@company.com) is personal data — even in a business context. A generic address (info@company.com) usually is not.
To process personal data lawfully, you need one of six lawful bases. For cold outreach, the realistic option is legitimate interest (Article 6(1)(f)). Consent is the alternative, but you obviously can't get consent before scraping. Relying on legitimate interest requires you to:
- Run and document a Legitimate Interest Assessment (LIA) balancing your commercial interest against the individual's rights.
- Send a privacy notice — GDPR's transparency rule (Article 14) says that when you collect data not from the person directly, you must inform them, generally within one month, telling them what you hold and where you got it.
- Honor the right to object, access, and erasure immediately.
On top of GDPR sits PECR (UK) and the ePrivacy Directive (EU), which govern electronic marketing. The critical carve-out: the strict opt-in consent rule for marketing email applies mainly to individual subscribers (consumers). B2B email to corporate addresses — limited companies and LLPs — can often rely on the "soft opt-in" and legitimate interest, provided you offer an opt-out every time. Sole traders and partnerships are treated more like individuals.
Canada's CASL is the strictest of the major regimes: it is opt-in by default, with narrow exceptions for existing business relationships and published business addresses (where the message relates to the person's role).
What "public data" actually means
A common myth is "if it's public, I can do anything with it." Not quite. Public availability affects the balancing test under legitimate interest — a person has a lower expectation of privacy for an email they published on a company website than for one buried in a private database. But "public" does not erase someone's GDPR rights. They can still object and demand erasure.
Practically, this means the safest data to scrape and use is:
- Role-based or business addresses tied to a company, not a private individual.
- Data the person published themselves in a professional context.
- Contacts whose likely interest in your offer is reasonable and relevant (context matters — pitching CRM software to a sales director is defensible; pitching weight-loss supplements is not).
A practical compliance checklist
If you want to scrape emails and sleep at night, build these habits into your workflow:
| Step | What to do |
|---|---|
| Source | Prefer public, business, role-relevant addresses |
| Basis | Document legitimate interest (EU/UK) or rely on CAN-SPAM opt-out (US) |
| Verify | Validate addresses to avoid emailing dead or spam-trap accounts |
| Transparency | Have a privacy policy and be ready to send an Article 14 notice |
| Opt-out | Include a working unsubscribe in every email; honor it fast |
| Relevance | Only contact people plausibly interested in your offer |
| Records | Keep proof of source, date, and consent/basis for each contact |
Tools like Outsoci help with the technical side — pulling verified, deduplicated business emails from public sources and validating them before you send — but the legal responsibility for how you contact people always stays with you. Compliance is a process, not a product.
The bottom line
Email scraping is legal in most of the world when you target public business contacts and send relevant, compliant, opt-out-respecting mail. It becomes risky when you scrape personal data belonging to EU/UK residents without a lawful basis, ignore transparency duties, or blast irrelevant bulk mail. Treat scraping as the easy part and responsible sending as the discipline that keeps you compliant.
Frequently asked questions
Is scraping emails from Google or a website illegal?
Collecting publicly displayed email addresses is generally not illegal, and US courts have declined to treat public-data scraping as a computer-crime violation. The legal exposure comes from how you use those addresses — sending non-compliant marketing email or mishandling EU/UK personal data is where fines arise.
Do I need consent to send a cold email?
In the US, no — CAN-SPAM is opt-out, so a compliant first email without prior consent is legal. In the EU/UK you typically rely on legitimate interest for B2B corporate addresses (with an opt-out and privacy notice), while Canada's CASL generally requires opt-in consent. Consumer addresses are treated far more strictly everywhere.
Are business emails covered by GDPR?
Only if they identify an individual. A personal-style address like firstname.lastname@company.com is personal data under GDPR. A generic address like info@ or sales@ usually is not, because it doesn't identify a specific person — which is why role-based business addresses are the lowest-risk to work with.
How do I keep a scraped list compliant?
Scrape public business contacts, document your lawful basis, verify addresses before sending, publish a privacy policy, include a working unsubscribe in every message, keep the outreach relevant, and honor objection and deletion requests promptly. Keep records of where and when each contact was sourced.
Stop buying stale lead lists
Pull fresh, verified contacts from Google Maps and social media — export in one click.
Try Outsoci today →