Guide

Is it legal to scrape Google Maps?

Last updated: July 28, 2026

Short answer: collecting publicly visible business information from Google Maps is generally lawful in the United States, and no US court has ever punished a business for using scraped public business listings. The legal questions that actually matter sit elsewhere: the difference between breaking a law and breaking a website's terms of service, and the rules that apply when you contact the people on your list. This guide walks through both in plain English.

Not legal advice. We build lead software, we do not practice law. For decisions that depend on your jurisdiction or industry, talk to a lawyer.

Breaking the law vs. breaking terms of service

Almost every confusion about scraping comes from mixing up two different things.

The law. In the US, the statute people worry about is the Computer Fraud and Abuse Act (CFAA), which criminalizes accessing a computer "without authorization". Courts have repeatedly declined to stretch that to cover public web pages. If information is visible to anyone with a browser and no login, accessing it at scale is not "unauthorized access" in the criminal sense.

Terms of service. Google's terms prohibit automated access without permission. But a terms-of-service breach is a contract issue between a platform and whoever agreed to its terms. It is not a crime, and the remedy is contractual: the platform can block you, close your account, or in extreme cases sue for breach of contract. In practice, platforms enforce scraping rules technically, with rate limits, blocks and captchas.

What hiQ v. LinkedIn actually decided

The case everyone cites is hiQ Labs v. LinkedIn. hiQ scraped public LinkedIn profiles; LinkedIn sent a cease-and-desist claiming CFAA violations. The Ninth Circuit Court of Appeals sided with hiQ on the criminal question, holding that scraping data that is publicly accessible, with no login wall, does not violate the CFAA. After a detour to the Supreme Court, the Ninth Circuit reaffirmed that holding in 2022, and the Supreme Court's own reasoning in Van Buren v. United States pointed the same way: the CFAA targets breaking into gated systems, not reading what is public.

Honesty requires the second half of the story: the same litigation later went badly for hiQ on the contract claims, because hiQ had created logged-in accounts that accepted LinkedIn's user agreement and scraped anyway. The lesson cuts cleanly in both directions. Public data, accessed publicly, is not a crime to collect. Logging into a platform, agreeing to its terms, and scraping from behind that login is where scrapers create real contractual exposure.

What about GDPR and business data?

European privacy law applies whenever the data identifies a person, and a sole trader's email address can do exactly that. But GDPR does not ban processing public business data; it asks you to have a lawful basis and to respect people's rights. For business contact details published by the business itself, the usual basis is legitimate interest: relevant, professional, B2B contact. What GDPR expects of you in return:

  • Contact people about things relevant to their business, not consumer offers sprayed at work inboxes.
  • Say who you are and where you got their details if asked.
  • Make opting out effortless, and honor it permanently.
  • Delete data you have no ongoing reason to hold.

The rules that actually catch people: outreach laws

The realistic compliance risk in lead generation is not the scraping, it is the emailing. Whatever tool builds your list, the moment you hit send you are inside marketing law:

  • CAN-SPAM (US): no deceptive subject lines, include a physical address, honor unsubscribes promptly. Cold B2B email is legal in the US if you follow it.
  • GDPR + PECR (UK/EU): B2B cold email under legitimate interest is defensible in most member states, but identify yourself and offer a clean opt-out.
  • CASL (Canada): the strictest of the three; implied consent rules for B2B exist but are narrow. Read them before mailing Canadian lists.

How MapsData handles this

We designed MapsData around the safe side of the lines above. It collects only what businesses publish publicly: name, category, address, phone, website, ratings, and email addresses the business puts on its own website. There is no login-walled scraping and no private data. Businesses that want their details excluded can email us and we remove them. And every export is built for compliant outreach: verification so you are not blasting dead inboxes, and filters that drop generic addresses when you want named contacts only.

Practical guidelines

  1. Scrape public data only; never from behind a login you agreed terms for.
  2. Keep outreach relevant to the recipient's business.
  3. Follow CAN-SPAM, GDPR/PECR or CASL depending on where your leads live.
  4. Honor opt-outs forever, not just for the current campaign.
  5. When in doubt about your specific situation, ask a lawyer, not a forum.

Frequently asked questions

Can I get in legal trouble for scraping Google Maps?
US courts have held that collecting publicly accessible data is not a crime under the Computer Fraud and Abuse Act. The realistic risks are contractual (a platform enforcing its terms of service against accounts that scrape while logged in) and downstream (breaking outreach laws like CAN-SPAM or GDPR when you contact the leads). Scraping public listings without logging in, then doing compliant outreach, is how the industry operates.
Does GDPR stop me from using scraped business data?
No, but it regulates how you use it. Publicly listed business contact details can generally be processed under the legitimate-interest basis for relevant B2B outreach. You still need to identify yourself, explain where you got the address, make opting out easy, and honor objections. Consumer inboxes are a different story and need consent in most of Europe.
Is it against Google's terms of service to scrape Google Maps?
Google's terms of service prohibit automated access without permission. A terms-of-service breach is a contract matter between Google and whoever agreed to those terms, not a criminal one, and in practice Google enforces it technically, with blocks and captchas, rather than through lawsuits against businesses using lead data.

Try it on your own market

Create a free MapsData account and get 500 Google Maps leads with emails every month. No card needed.

Get 500 free leads a month
MapsData © 2026 Hiive Arts Home Pricing Privacy Policy Terms of Service