Compliance
Is LinkedIn scraping legal?
Short answer
Collecting public LinkedIn profile data is not a crime in the US: that is what the courts held in hiQ Labs v. LinkedIn. It does break LinkedIn’s User Agreement, so the practical risk is to your LinkedIn account, not a criminal charge. And if the people are in the EU or the UK, their names, job titles and work emails are personal data under the GDPR even when anyone can see them, so you need a lawful basis, must tell them where you got their data and must stop when they object.
Three separate questions
“Legal” means three different things here
People asking whether scraping LinkedIn is legal usually mix up three questions with different answers:
- Is it a crime to access the data? This is computer-access law, such as the US Computer Fraud and Abuse Act. For public profiles, the answer from the hiQ case is no.
- Does it break LinkedIn’s rules? This is contract law. The User Agreement forbids scraping, so yes, and LinkedIn can act against the account that does it.
- May you use the data you collected? This is data-protection and marketing law: the GDPR, the UK GDPR, ePrivacy rules, CAN-SPAM. It depends on where the people are and what you do with their data.
The court case
What hiQ Labs v. LinkedIn decided
hiQ Labs collected public LinkedIn profiles to sell analytics to employers. In 2017 LinkedIn told it to stop and blocked it, and hiQ went to court. The case ran for six years:
- 2019. The Ninth Circuit Court of Appeals held that scraping profiles anyone can see without logging in is likely not “access without authorization” under the Computer Fraud and Abuse Act.
- 2021. The Supreme Court sent the case back to be reconsidered in light of Van Buren v. United States, which narrowed that law.
- 2022. The Ninth Circuit reached the same conclusion again. Later that year the district court found that hiQ had breached LinkedIn’s User Agreement, in part by using fake accounts, and the parties settled with a judgment against hiQ.
The lesson most people take from it is half right. Scraping public data is not a federal crime in the US, but LinkedIn won on its contract, and data you can see only after logging in is a weaker position than data on public profiles.
LinkedIn’s terms
What LinkedIn’s User Agreement forbids
LinkedIn’s User Agreement forbids using software, scripts, crawlers, browser plugins or add-ons to scrape or copy profiles and other data from the service. Every LinkedIn member has accepted it, so a member who scrapes is in breach of a contract with LinkedIn.
In practice LinkedIn enforces this on accounts: warnings, limits on search and profile views, temporary restrictions and, for repeated abuse, closure. That is the real risk for a sales team, and it is managed by keeping volumes and pace close to how a person works. We wrote that up in how to scrape LinkedIn without getting banned.
GDPR
Using LinkedIn leads under the GDPR
Public does not mean free to use. A name, a job title and a work email of a person in the EU or the UK are personal data, and the GDPR applies to whoever collects them, wherever that company is. For B2B prospecting the usual checklist is:
- Pick a lawful basis. For B2B outreach it is usually legitimate interest (Article 6(1)(f)). Write down a short assessment: why you contact this role, why it is relevant to them, and why it does not override their interests.
- Collect only what you need. Work email, job title, company and the profile link are enough for prospecting. Leave out personal emails and anything about private life.
- Tell people where you got their data. When the data does not come from the person, Article 14 requires you to inform them, at the latest in your first message if you contact them. One line in the first email covers it: who you are, where you found them and how to opt out.
- Honour objections for good. Under Article 21 a person can object to direct marketing at any time, and you must stop. Keep a suppression list so they are not re-imported from the next export.
- Do not keep data forever. Set a retention period for leads who never replied and delete them after it.
- Check the local email rules. The GDPR sits next to national e-marketing laws. The UK allows marketing email to company addresses with an opt-out; some EU countries, Germany for example, generally require prior consent even for B2B email. In the US, CAN-SPAM requires honest headers, a postal address and a working unsubscribe.
Where Scrupp fits
How Scrupp handles this
- You are the controller, Scrupp is the processor. You decide who to look up and why; Scrupp finds and enriches contacts on your instruction. A Data Processing Addendum is ready to sign: see data protection.
- Business contact data. Scrupp returns work emails and phone numbers together with the job title and company you need for B2B prospecting.
- No automated actions on LinkedIn. Scrupp does not send messages, connection requests or profile visits on your behalf. It exports and enriches leads; outreach happens in your own tools.
- Data in the EU, removal on request. Our primary servers and backups are in the EU. Anyone who wants their contact data removed can email iv@scrupp.com. Details are on our GDPR page.
FAQ
Questions about scraping LinkedIn and the law
Is it legal to scrape LinkedIn?
Collecting publicly visible profile data is not a crime under the US Computer Fraud and Abuse Act, according to the Ninth Circuit in hiQ Labs v. LinkedIn. It does breach LinkedIn’s User Agreement, which forbids scraping, so LinkedIn can restrict your account. If the people you collect are in the EU or the UK, the GDPR applies to that data even though it is public.
Can LinkedIn ban my account for scraping?
Yes. The User Agreement prohibits scraping, including through browser extensions, and LinkedIn enforces it by limiting or restricting accounts. Keep volumes and pace close to normal use; see how to scrape LinkedIn without getting banned.
Does the GDPR apply if my company is outside the EU?
Yes, if the people you collect or contact are in the EU. The GDPR follows the person whose data it is, not the location of the company. The UK has its own almost identical UK GDPR.
Can I send cold emails to people I found on LinkedIn?
In the US, yes, if you follow CAN-SPAM: honest headers and subject, a postal address and a working opt-out. In the EU and the UK you need a lawful basis, usually legitimate interest for B2B, plus the national e-marketing rules. The UK allows marketing email to company addresses with an opt-out; some EU countries, Germany for example, generally require prior consent even for B2B email.
Who is responsible for the data, me or Scrupp?
You are the controller of the leads you collect and contact: you choose who to target and why. Scrupp acts as your processor when it finds and enriches contacts on your instruction, and offers a Data Processing Addendum for that.
Is this legal advice?
No. This page explains the general rules as we understand them. Laws differ by country and change, so check your own use with a lawyer.
Build a B2B lead list with work emails
Export LinkedIn and Sales Navigator searches with work emails and phone numbers to CSV or your CRM.
No credit card