Guides / Compliance

Is Web Scraping Legal? A Practical Guide for Lead Generation

Collection is rarely where companies get hurt. Access method and outreach are. A plain-English map of where the legal risk actually sits.

Published 2026-07-26 · 9 min read · by Lead Mining Company

This is general information, not legal advice. We build data software; we are not a law firm, and nothing here creates a lawyer-client relationship or tells you that any particular practice is lawful for you. The law here is federal, state and contractual all at once, it varies by jurisdiction, and it moves. Before you build or buy a collection program, have a lawyer review your specific sources, your specific data and your specific use.

The question "is web scraping legal" does not have a yes or no answer, and anyone who gives you one is selling something. The useful version of the question is narrower: which parts of collecting public data carry real risk, where does that risk actually come from, and what can you change about how you work to reduce it.

In the United States, collecting information that is genuinely publicly available is broadly lawful. That is the starting position, not the finish line. The risk almost never attaches to the raw fact that you gathered data. It attaches to how you got access to it and what you did with it afterwards. Those are two different failure modes, governed by different bodies of law, and most companies that get into trouble got there through the second one.

Access risk and use risk are separate problems

Hold the two apart in your head, because the controls are different.

Access risk is about the manner of collection. Did you go around a login? Break a technical barrier? Agree to terms and then violate them? Hammer a server hard enough to degrade it? These questions produce computer-misuse claims, breach-of-contract claims and sometimes trespass-style claims.

Use risk is about what happens next. Did you republish someone's copyrighted text? Compile a profile of an identifiable person and sell it? Call a number on a do-not-call list? These produce copyright claims, privacy claims and telemarketing claims — and in practice this is the category that generates the letters.

A collection program can be clean on access and catastrophic on use. It happens constantly.

The Computer Fraud and Abuse Act and the authorisation question

The Computer Fraud and Abuse Act is the federal anti-hacking statute. It is written around the idea of accessing a computer without authorisation, or exceeding authorised access. Because almost every server on the internet is a computer, plaintiffs have spent years trying to use it against data collection.

We are going to describe the principle rather than name cases, because the details matter and half-remembered citations are worse than none. The direction United States courts have moved in is toward reading "authorisation" as something with a technical meaning rather than a purely contractual one. Where information is served to anyone who asks for it, with no credential required, the argument that a visitor lacked authorisation to view it is a much harder argument to make. Where information sits behind a login, a paywall, a subscriber agreement or a technical access control, the argument gets substantially easier — and if you defeated that control, it gets easier still.

The operational lesson is blunt and it does not require a law degree.

If you had to log in, pay, sign up, or defeat a control to see it, you are on materially weaker ground than if you simply requested a page the way any member of the public would.

That is why our own collection work is built around public, unauthenticated pages. Not because a login makes something automatically criminal, but because the moment authentication is in the picture the analysis becomes fact-specific, expensive and uncertain. A cease-and-desist letter can also change your position: continuing after you have been told to stop is a different set of facts from never having been told.

Related access issues

  • Volume and load. Requesting politely, at low rates, with proper identification, is not just courtesy. Degrading someone's service is the fact pattern that turns a boring dispute into an aggressive one.
  • Circumvention. Rotating identities to evade a block, or bypassing a bot check, is conduct a court can characterise as knowing evasion. It reads badly regardless of the legal theory.
  • State computer-crime statutes. Many states have their own analogues to the federal statute, and they are not all worded the same way.

Terms of service is a contract problem, not a hacking problem

This is the distinction people most often miss. Even where a site's terms do not turn access into a computer-misuse claim, they can still be an enforceable contract. Breaching a contract is its own cause of action with its own remedies.

Two situations look different in practice. Terms you actively accepted — you clicked, you registered, you agreed — are far more likely to bind you. Terms merely linked in a footer, which you never acknowledged, are a weaker basis for a contract claim, though not always a hopeless one for the site owner.

Practically: read the terms of any source that matters to your business, keep a record of what they said and when, and decide deliberately rather than by default. If a source's terms prohibit automated collection and you rely on that source heavily, that is a business risk your counsel should price, not a technicality to wave away. Our own terms exist for the same reason everyone else's do.

Copyright protects original expression. It does not protect facts. A phone number, an address, a permit issue date, a company name — these are facts, and no one owns them.

Three qualifications matter for lead data:

  • Compilations can carry protection in the selection and arrangement of the material, even when the underlying facts do not. Copying an entire curated database wholesale is a different act from extracting the facts you need.
  • Text and images are expression. A listing description, a review, a marketing paragraph, a photograph — all of these are somebody's copyrighted work. Storing them and republishing them are separate decisions, and republication is the risky one.
  • Databases attract other theories too, including state-law claims that vary by jurisdiction.

The safe pattern for lead generation is to extract the facts and leave the prose and the photographs where you found them.

Personal data and business data carry different risk profiles

Data about a company — its name, its main line, its published address, the role of an executive — sits in a much calmer part of the map than data about an identified individual. Privacy regimes are generally built around personal information, and B2B contact data has historically attracted lighter treatment.

Then reality intervenes. The small operator is the case that breaks the tidy distinction. A sole trader's "business number" is the phone in their pocket. Their "business address" is their house. Their "business email" is a personal address they also use for their children's school. Nothing about calling that data B2B changes what it actually is.

If your target market is small owner-operators — short-term rental hosts, independent contractors, one-person firms — you should assume a meaningful share of your records are personal data wearing a business label, and design accordingly.

State privacy statutes are the fast-moving part

California has a comprehensive consumer privacy regime and has been the most active state in this area. Several other states have enacted their own comprehensive privacy laws, and the list has grown steadily. They differ in who they cover, what thresholds trigger them, what rights consumers get and what obligations fall on businesses that sell or share personal information.

We are not going to summarise specific sections here, because getting them slightly wrong would be worse than useless. What you should take away is structural:

  • Obligations can attach to collecting personal information, not only to selling it.
  • Some regimes impose notice duties even where you collected the data indirectly.
  • Some create registration or disclosure obligations for businesses that broker personal data.
  • The applicable state is generally driven by where the individual is, not where you are.

If you hold personal data on residents of multiple states at any scale, this is a question for counsel, and it is the specific question most worth paying for.

Government and public records are the steadiest ground

Records that a public body publishes are published so that the public can use them. Permit registers, business filings, licence rosters, property records and court indexes exist in the open by design. As a category, this is the most defensible source available for lead generation, which is why so much of our data mining work starts there.

Two conditions still apply. First, redistribution rules vary. Some jurisdictions attach conditions to bulk data or to commercial reuse, and some records are open for inspection but restricted for marketing use. Second, public availability is a statement about the record, not a statement about the person. A permit being public does not mean the owner has agreed to hear from you.

Outreach is where most people actually get hurt

If you take one thing from this page, take this. The legal exposure in lead generation is concentrated overwhelmingly in contact, not collection.

Calls and texts fall under the Telephone Consumer Protection Act, which carries statutory damages per violating message and is a routine subject of class actions. Automated dialing, prerecorded voices and messages to wireless numbers are the sharp edges. Several states have their own stricter telemarketing statutes on top.

Do-not-call obligations run federally and at state level, and an individual who registered their personal number is registered whether or not they also own a rental.

Email falls under CAN-SPAM, which is far lighter than the phone rules but still requires accurate headers, honest subject lines, a real postal address and a working opt-out that you honour promptly.

The single most expensive misconception in this industry is the belief that finding a number in a public record constitutes permission to dial it. It does not. Public availability is not consent. Those are unrelated concepts that happen to involve the same phone number. We wrote a longer treatment of this in our guide to calling short-term-rental owners under the TCPA and do-not-call rules.

A practical checklist

Reduces risk

  • Prefer public, unauthenticated sources, and government records above all.
  • Collect slowly, identify your agent honestly, and respect published crawl preferences.
  • Extract facts; leave copyrighted prose and photographs behind.
  • Record where every field came from and when, so you can answer questions about provenance later.
  • Scrub against do-not-call registries and maintain your own suppression list.
  • Honour deletion and opt-out requests quickly, and keep evidence that you did.
  • Have counsel review the program before it scales, and again when you enter a new state or a new data category.

Increases risk

  • Creating accounts, bypassing paywalls, or defeating bot controls to reach data.
  • Continuing to collect from a source after being told in writing to stop.
  • Republishing scraped descriptions, reviews or images as your own content.
  • Treating an individual's personal mobile number as a business line because they own property.
  • Assembling detailed profiles of identifiable individuals from many sources.
  • Assuming a vendor's assurances protect you. Liability for outreach generally follows the sender.

How we approach it

We build collection systems that read public pages and public records the way a member of the public would, at a rate that does not burden anyone's server, storing facts rather than expression, with provenance recorded per field. That is a posture, not a guarantee, and we do not offer legal opinions about your use case.

What we can do is build to a standard your lawyer can review, and tell you plainly when a source you have asked for is one we will not touch. If you want to talk through a specific source list before committing to it, get in touch.

Again: this is general information, not legal advice, and nothing above says any practice is lawful for you. Your sources, your jurisdiction, your data and your intended use all change the analysis. Consult a qualified attorney before you build, buy or dial.

More guides