Guide
Last updated: July 28, 2026
Short answer: collecting publicly visible business information from Google Maps is generally lawful in the United States, and no US court has ever punished a business for using scraped public business listings. The legal questions that actually matter sit elsewhere: the difference between breaking a law and breaking a website's terms of service, and the rules that apply when you contact the people on your list. This guide walks through both in plain English.
Almost every confusion about scraping comes from mixing up two different things.
The law. In the US, the statute people worry about is the Computer Fraud and Abuse Act (CFAA), which criminalizes accessing a computer "without authorization". Courts have repeatedly declined to stretch that to cover public web pages. If information is visible to anyone with a browser and no login, accessing it at scale is not "unauthorized access" in the criminal sense.
Terms of service. Google's terms prohibit automated access without permission. But a terms-of-service breach is a contract issue between a platform and whoever agreed to its terms. It is not a crime, and the remedy is contractual: the platform can block you, close your account, or in extreme cases sue for breach of contract. In practice, platforms enforce scraping rules technically, with rate limits, blocks and captchas.
The case everyone cites is hiQ Labs v. LinkedIn. hiQ scraped public LinkedIn profiles; LinkedIn sent a cease-and-desist claiming CFAA violations. The Ninth Circuit Court of Appeals sided with hiQ on the criminal question, holding that scraping data that is publicly accessible, with no login wall, does not violate the CFAA. After a detour to the Supreme Court, the Ninth Circuit reaffirmed that holding in 2022, and the Supreme Court's own reasoning in Van Buren v. United States pointed the same way: the CFAA targets breaking into gated systems, not reading what is public.
Honesty requires the second half of the story: the same litigation later went badly for hiQ on the contract claims, because hiQ had created logged-in accounts that accepted LinkedIn's user agreement and scraped anyway. The lesson cuts cleanly in both directions. Public data, accessed publicly, is not a crime to collect. Logging into a platform, agreeing to its terms, and scraping from behind that login is where scrapers create real contractual exposure.
European privacy law applies whenever the data identifies a person, and a sole trader's email address can do exactly that. But GDPR does not ban processing public business data; it asks you to have a lawful basis and to respect people's rights. For business contact details published by the business itself, the usual basis is legitimate interest: relevant, professional, B2B contact. What GDPR expects of you in return:
The realistic compliance risk in lead generation is not the scraping, it is the emailing. Whatever tool builds your list, the moment you hit send you are inside marketing law:
We designed MapsData around the safe side of the lines above. It collects only what businesses publish publicly: name, category, address, phone, website, ratings, and email addresses the business puts on its own website. There is no login-walled scraping and no private data. Businesses that want their details excluded can email us and we remove them. And every export is built for compliant outreach: verification so you are not blasting dead inboxes, and filters that drop generic addresses when you want named contacts only.
Create a free MapsData account and get 500 Google Maps leads with emails every month. No card needed.
Get 500 free leads a month