Applying Web Scraping Legally: GDPR Guide
What can and can't you scrape under GDPR? A practical guide for e-commerce businesses that want to collect data without legal risks.
Request a scraperWeb scraping and GDPR: what's allowed?
Web scraping is a powerful tool for e-commerce, but the GDPR (General Data Protection Regulation) sets limits on which data you can collect and how. The main rule: scraping public, non-personal data is allowed. Scraping personal data without a lawful basis is not allowed.
In practice, this means that scraping product prices, assortments, inventory, and general company information is legal. Scraping personal contact details (name + email of individuals) without permission is not allowed under GDPR.
Channify always works within GDPR frameworks. We scrape only public data, respect robots.txt, and take into account the terms of service of websites.
What you can and can't scrape under GDPR
What's allowed: public business data
Prices, products, inventory, assortment, general contact details (info@, company phone number). This is non-personal data and freely available.
Learn moreWhat's not allowed: personal data
Name + email combinations of individuals, personal phone numbers, profile data from personal accounts. This falls under GDPR.
Learn moreRespect robots.txt
A website's robots.txt indicates which pages can be crawled. We always respect this, even if it means certain data isn't scrapable.
Learn moreComply with terms of service
Some websites prohibit scraping in their terms of service. We always check this and respect any restrictions.
Learn moreRate limiting
We don't send excessive requests to a website. Our scrapers use reasonable intervals to avoid overloading the server.
Learn moreNo login bypass
We don't scrape data behind login screens or paywalls. If data isn't publicly accessible, we don't scrape it.
Learn moreGDPR-compliant scraping: the checklist
Determine the data type
Is the data you want to scrape public and non-personal? Then it's almost certainly GDPR-compliant.
Check robots.txt
We check the robots.txt of the target website. Does it allow scraping of the desired pages? Then we proceed.
Check terms of service
We read the terms of service of the target website. Do they prohibit scraping? Then we look for alternative sources.
Apply rate limiting
We set reasonable scrape intervals to avoid overloading the target server. No DDoS-like requests.
Store and process data
The collected data is stored securely and used only for the agreed purpose. No resale to third parties.
Frequently asked questions about web scraping and GDPR
Is scraping competitor prices legal?
Yes. Product prices are public, non-personal data. Scraping competitor prices is a standard e-commerce practice and doesn't fall under GDPR. Both Bol.com and Amazon offer their own repricing tools that do the same thing.
Can I scrape company email addresses?
General company email addresses (info@, contact@, sales@) that are publicly displayed on the website are generally allowed. Personal email addresses (name@company.nl) of individuals fall under GDPR and may not be scraped without permission.
What does the European Database Directive say?
The Database Directive protects databases in which substantial investment has been made. Reusing substantial parts of a protected database can constitute infringement. In practice, this rarely applies to web scraping of individual pages, but does apply to massive extraction of complete databases.
Can I scrape marketplace reviews?
Reviews often contain personal data (name or alias of the reviewer). Scraping review text without the name may be allowed, but linking reviews to individuals falls under GDPR. We advise scraping only anonymized review data (stars, text without name).
What if a website prohibits scraping in their terms of service?
We respect terms of service. If a website prohibits scraping, we look for alternative sources for the same data. Often there are multiple sources available (e.g., branch maps instead of a company's own website).
Does Channify offer a legal guarantee?
Channify builds only GDPR-compliant scrapers and works within the legal frameworks. However, we're not a law firm. For complex legal questions about data collection, we refer to a specialized GDPR lawyer. Our scrapers are designed to minimize risks, though.
Want to be sure your scraper is GDPR-proof?
Edwin builds only GDPR-compliant scrapers. Tell us which data you want to collect and we'll assess the legal feasibility.
Request a scraper Or try the package finderReady to explore?
Explore our services
Web Scraping Services
Explore all scraping options of Channify.
View servicesShopify Services
Build your Shopify store with AI. Build together or we build it for you.
View servicesPackage Finder
Not sure which service you need? Take the 60-second finder.
Try the finderChannel Finder Wizard
Not sure which sales channel fits your products? Take the 4-step wizard and discover your best channels.
Start the wizard