Is Scraping LinkedIn and Cold Emailing Actually Legal

    The honest answers to the questions founders actually ask, with the official sources, and the reason the legal line is the lowest bar in the room.

    Artem Smirnov
    Artem Smirnov
    LinkedIn · 5 min read
    Artem Smirnov in a dark suit against a charcoal studio backdrop, next to the line 'Legal is not the question. Relevance is.'

    Want more B2B clients for your business?

    We help B2B companies fill their calendar with 10 to 100+ qualified sales calls per month. No paid ads.

    This is not legal advice. Outbound is my trade, law is not, and nothing below is a ruling on your situation. What I can do is point at the official texts, say plainly what they say, and tell you which question I think actually decides whether outbound helps or hurts your company. All source pages here were checked in September 2026.

    Founders pause perfectly good campaigns over this, often after reading a vendor article written to sell a compliance feature. So, the questions as they usually arrive.

    GDPR does not ban it and does not mention cold email. It governs how personal data is processed, and business contact details of a named person are personal data.

    Recital 47 of the regulation contains the sentence everyone in this industry leans on: "The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest." Read it carefully. "May be regarded as" gives you an argument to make, and you still have to make it. Legitimate interest is a balancing test between your interest and the rights of the person, and you are the one who has to be able to show your working, in writing, before you send.

    Whether your specific list, your specific message and your specific record-keeping clear that test is a question for someone qualified who can see all three. I am not going to tell you that any practice is safe, because I cannot see your setup and neither can any blog post that tells you it is.

    Where do those giant fine numbers come from?

    They are real, they are the maximums, and they are not the penalty for sending a badly targeted email.

    The European Commission's own enforcement page describes the options a data protection authority has, ending with a fine of up to 20 million euros or 4% of the business's total annual worldwide turnover. The same page lists a warning, a reprimand and a ban on processing as the other options, which tells you where most cases land. Those figures sit at the top of a scale that supervisory authorities apply according to the nature, gravity and duration of an infringement, whether it was intentional, and what you did about it.

    In the US the number quoted around this subject comes from the Federal Trade Commission, which states that "each separate email in violation of the CAN-SPAM Act is subject to penalties of up to $53,088". Per email, which is why it sounds terrifying when a vendor puts it in a headline. CAN-SPAM is mostly about honesty in the message itself: accurate headers and sender identity, a subject line that reflects the content, a working opt-out, and a valid physical postal address.

    Use these figures as what they are. A ceiling that exists, applied to serious cases, quoted at you by people selling software.

    Is scraping LinkedIn illegal?

    Two different questions live inside that one, and mixing them is how people end up confused.

    The first is contract. LinkedIn's User Agreement is explicit. Its "Don'ts" section names crawlers, scripts, robots, browser plugins and any other technology used, in its words, "to scrape or copy the Services, including profiles and other data". A separate clause in the same list rules out bots and unauthorized automated access. Breaking either is a breach of an agreement you accepted when you signed up. The consequence is usually not a court. It is your account, and the accounts of anyone on your team doing the same thing.

    The second question is data protection law, which does not care where the data came from as much as it cares what you then do with it and whether the person can find out you hold it.

    So "illegal" is the wrong frame. Against the platform's terms, yes, plainly. Legally risky, separately, depending on jurisdiction and conduct. And the practical risk lands first on the asset you need most, which is a working LinkedIn account with your name on it.

    Where your data comes from is a build decision taken long before the first send, and the way a list gets put together removes most of this problem without anyone having to read a regulation.

    Do I have to include an opt-out?

    Every regime I have read puts identity and opt-out at the centre, and both are cheap to do properly.

    The UK's Information Commissioner's Office, in its guide to PECR, draws a line between corporate subscribers and individuals, with sole traders and some partnerships treated as individuals rather than as companies. Its guidance states that you "must not disguise or conceal your identity" and that you must provide a valid contact address so people can opt out, and act on it promptly. That is the UK regulator describing the UK rules. Your regulator may draw the lines elsewhere, which is the whole reason this page names sources instead of giving instructions.

    The technical half of identity is the part outbound people forget. Publish SPF, DKIM and DMARC records before you send at any volume. You are claiming to be who you say you are; those records are how a receiving server checks it. The full setup is in the sending infrastructure I put in place before any campaign.

    My agency sends on my behalf. Whose problem is it?

    Yours, in every way that matters commercially. Your domain, your brand on the message, your name in the reply.

    Ask any agency three questions before you sign: where the data comes from, who is named as sender on the sequence, and what happens to the list when the contract ends. If the answers are vague, that vagueness is a preview. More of those questions are in what to ask before hiring a lead generation agency.

    So what do you actually do?

    Here is the part I care about more than any of the above.

    Reputation is worth more than money. Always. I check the reputation of a company before I agree to work with them, because being associated with the wrong people costs more than the contract pays. The same check runs on you, constantly, by people you will never speak to.

    Which means the compliance question has a floor and a ceiling. The floor is the law, and you clear it with advice from someone qualified plus the boring hygiene above. The ceiling is whether the person receiving your message thinks it was reasonable that you wrote to them at all.

    Nobody reports you to a regulator because an email was legal but stupid. They mark it as spam, tell a colleague, and your domain reputation and your name both take a small, permanent deduction. Do that ten thousand times and the legal question turns out to have been the least of it.

    That test is harder to pass than the legal one, and it starts long before any of this, with who ended up on the list at all.

    Get advice for your jurisdiction. Then go and read your own list as though you were on it.

    Want to get more B2B clients for your business?

    I help B2B companies book 10 to 100+ qualified sales calls per month with outbound. Let's see if it fits yours.

    Artem Smirnov
    Artem Smirnov

    I help B2B companies book qualified sales calls with cold email and LinkedIn outbound.

    Artem Smirnov

    Smirnov Consulting Group

    LinkedIn Growth and B2B Lead Generation agency in Prague

    contact@smirnovartem.com

    © 2026 Smirnov Consulting Group s.r.o.

    IČO 27377059

    Pobřežní 249/46, Karlín, 186 00 Praha, Česká Republika

    All Rights Reserved

    Smirnov Consulting Group is a Prague-based B2B outbound lead generation and LinkedIn growth agency. For B2B companies, we run LinkedIn and cold email campaigns that book qualified sales calls. For experts, founders and speakers, we build the LinkedIn positioning, profile, content and outreach that bring clients and opportunities. We work with clients in the USA, Canada, the UK, Germany, Switzerland, the UAE, Singapore, Australia and many others. Our outbound clients include construction, civil engineering, industrial and manufacturing companies, marketing, advertising and SEO agencies, software and IT firms, consultants, financial advisory firms and SaaS companies. Founder Artem Smirnov shares real campaigns, open numbers and screenshots with 56,000+ followers on LinkedIn, one of the largest audiences in B2B outbound. 12 years in outbound, 500+ B2B companies, 24 countries.