Home / Applying Web Scraping Legally: GDPR Guide
GDPR guide

Applying Web Scraping Legally: GDPR Guide

What can and can't you scrape under GDPR? A practical guide for e-commerce businesses that want to collect data without legal risks.

Request a scraper
Shopify Partner · Channable Gold Partner · 10+ years e-commerce

Web scraping and GDPR: what's allowed?

Web scraping is a powerful tool for e-commerce, but the GDPR (General Data Protection Regulation) sets limits on which data you can collect and how. The main rule: scraping public, non-personal data is allowed. Scraping personal data without a lawful basis is not allowed.

In practice, this means that scraping product prices, assortments, inventory, and general company information is legal. Scraping personal contact details (name + email of individuals) without permission is not allowed under GDPR.

Channify always works within GDPR frameworks. We scrape only public data, respect robots.txt, and take into account the terms of service of websites.

GDPR-compliant scraping: the checklist

1

Determine the data type

Is the data you want to scrape public and non-personal? Then it's almost certainly GDPR-compliant.

2

Check robots.txt

We check the robots.txt of the target website. Does it allow scraping of the desired pages? Then we proceed.

3

Check terms of service

We read the terms of service of the target website. Do they prohibit scraping? Then we look for alternative sources.

4

Apply rate limiting

We set reasonable scrape intervals to avoid overloading the target server. No DDoS-like requests.

5

Store and process data

The collected data is stored securely and used only for the agreed purpose. No resale to third parties.

Frequently asked questions about web scraping and GDPR

Is scraping competitor prices legal?

Yes. Product prices are public, non-personal data. Scraping competitor prices is a standard e-commerce practice and doesn't fall under GDPR. Both Bol.com and Amazon offer their own repricing tools that do the same thing.

Can I scrape company email addresses?

General company email addresses (info@, contact@, sales@) that are publicly displayed on the website are generally allowed. Personal email addresses (name@company.nl) of individuals fall under GDPR and may not be scraped without permission.

What does the European Database Directive say?

The Database Directive protects databases in which substantial investment has been made. Reusing substantial parts of a protected database can constitute infringement. In practice, this rarely applies to web scraping of individual pages, but does apply to massive extraction of complete databases.

Can I scrape marketplace reviews?

Reviews often contain personal data (name or alias of the reviewer). Scraping review text without the name may be allowed, but linking reviews to individuals falls under GDPR. We advise scraping only anonymized review data (stars, text without name).

What if a website prohibits scraping in their terms of service?

We respect terms of service. If a website prohibits scraping, we look for alternative sources for the same data. Often there are multiple sources available (e.g., branch maps instead of a company's own website).

Does Channify offer a legal guarantee?

Channify builds only GDPR-compliant scrapers and works within the legal frameworks. However, we're not a law firm. For complex legal questions about data collection, we refer to a specialized GDPR lawyer. Our scrapers are designed to minimize risks, though.

Want to be sure your scraper is GDPR-proof?

Edwin builds only GDPR-compliant scrapers. Tell us which data you want to collect and we'll assess the legal feasibility.

Request a scraper Or try the package finder