Legal and Privacy Challenges of Data Scraping

Legal and Privacy Challenges of Data Scraping in the Digital Age

Data Scraping – beyond the familiar term, what secrets does it hold? We explore the complex world of data scraping and examine the legal and privacy aspects of gathering publicly available information, a practice that is widely used but often misunderstood.

What is Data Scraping?

Data scraping, also known as data harvesting, can be confusing when it comes to gathering publicly available information. Many people, including those in data protection, have long believed that using publicly accessible data from platforms like LinkedIn or other social media sites is legally permissible. The argument is that, by sharing their information on platforms like LinkedIn, individuals have essentially consented to others using their data for various purposes. However, this assumption is not entirely accurate.

Some businesses claim full compliance with data protection regulations, arguing that they use only publicly available information from LinkedIn, which they consider safe because individuals consent to this use by sharing their data on social media. They also point to LinkedIn’s privacy policy, which they believe permits the use of personal information and argue that users expect to be contacted when they leave such information on the platform. Some of these arguments come from data protection consultants.

It’s important to clarify that while LinkedIn allows people to create professional profiles, post articles and comments, search for jobs, and connect with others to expand their professional networks, this does not grant unrestricted access to their data for any purpose. LinkedIn’s Privacy Policy states that personal information is visible to others but does not imply that it can be used for any purpose without limitations.

How does Article 14 of GDPR regulate Data Scraping?

Now, let’s focus on an important aspect: Article 14 of the General Data Protection Regulation (GDPR), which many companies overlook. This article applies when personal data is obtained from sources other than the data subject, such as public databases, third-party providers, or intermediaries. According to Article 14, the controller must promptly inform the data subject of this information, ideally within one month of obtaining their personal data.

Regarding the lawful basis for data scraping, you must demonstrate that you have explicit consent from individuals before extracting their personal information if you intend to scrape the personal data of EU and UK residents. Obtaining consent is often the primary and, in many cases, the only lawful method for scraping personal data from EU and UK residents. Alternatively, web scrapers can rely on a legitimate interest as the legal basis for scraping, storing, and using this personal data.

However, to comply with GDPR principles, you need a strong, well-justified legitimate interest, as a vague or weak one may not be sufficient.

In most situations, government bodies and law enforcement agencies, among others, can make a reasonable case for having a legitimate reason to scrape the personal data of EU and UK citizens. They often do so for the broader benefit of the public.

What the regulators say

In light of this, the Information Commissioner’s Office, along with eleven other data protection and privacy authorities worldwide, has issued a joint statement urging the safeguarding of individuals’ personal data against illegal data scraping on social media platforms. The statement explicitly outlines the privacy risks that can arise from such scraping, even though many people believe these platforms are secure.

As the joint statement notes, many data protection authorities have seen increased reports of mass data scraping from businesses and other websites. The reports raise several privacy concerns, including the use of scraped data for:

Targeted Cyberattacks

For instance, when identity and contact information is scraped and shared on ‘hacking forums,’ malicious actors may use this data for precise social engineering or phishing attacks.

Identity Fraud

Scraped data can be exploited to submit fraudulent loan or credit card applications or to impersonate individuals by creating fake social media accounts in their name.

Monitoring, Profiling, and Surveillance

Scraped data may be utilised to populate facial recognition databases and provide unauthorised access to authorities for surveillance purposes.

Unauthorised Political or Intelligence Activities

Foreign governments or intelligence agencies might use scraped data for unauthorised purposes, potentially compromising individuals’ privacy.

Unwanted Direct Marketing or Spam

Scraped data often includes contact information that can be exploited to send large volumes of unsolicited marketing messages, resulting in spam.

These privacy concerns highlight the need for vigilant monitoring and regulation of data scraping to protect individuals from misuse and privacy violations.

If you have additional questions or want more data protection advice and insights, contact us at info@gdprlocal.com or reach out directly on LinkedIn.

About the Author

Zlatko Delev

Head of Commercial & Country Manager

Zlatko Delev is Head of Commercial and Country Manager at GDPRLocal, where he leads the company’s commercial strategy and market presence. He brings international experience across sales, marketing, and customer success, along with a legal background from his studies at Iustinianus Primus Law School in Skopje, Macedonia.

Zlatko sits at the front line of GDPRLocal’s client relationships, guiding organisations through the first stages of their compliance journey and helping them understand where they stand and where they need to go on GDPR, information security, and the emerging landscape of AI regulation. His role bridges commercial strategy with practical data protection knowledge, ensuring clients get clear, actionable direction from their very first conversation with GDPRLocal.

Alongside his commercial focus, Zlatko has trained extensively in project management and organisational leadership, including risk management, stakeholder communication, agile methodology, and digital marketing, a broad skill set that supports his structured, delivery-focused approach to growing GDPRLocal’s business internationally.