Skip to content
PLOTLEADS

Explainer · sourced · not legal advice

IS SCRAPING GOOGLE MAPS LEGAL?

by Usama Zafar, who builds and maintains PlotLeads · last reviewed 13 August 2026

The short answer

Collecting business names, phone numbers, and addresses from public Google Maps listings has not been treated as a federal computer crime in the cases US courts have actually decided. It can still breach Google’s terms — but that is a contract question between you and Google, not a criminal one. And the collection is not where your real exposure is. What you do with the list afterwards is: CAN-SPAM, the TCPA, and state telemarketing statutes carry penalties assessed per email and per call, and one of them lets the person you called sue you directly.

Everything below is either a direct quote from a linked primary source or a reading of one that is flagged as a reading. I am not a lawyer, this is not legal advice, and you should not make a go/no-go call on an outreach programme from a vendor’s website. The point of the links is that you can check every claim here against the original text in about ten minutes.

Untangling the question

“IS IT LEGAL” IS FOUR QUESTIONS IN A TRENCH COAT

Most of the confusion on this topic comes from collapsing four separate legal regimes into one yes/no. They have different sources of law, different decision-makers, and wildly different odds of ever affecting you. Separating them is most of the work.

Four distinct legal questions behind “is scraping Google Maps legal”, what governs each, and the realistic exposure for a US business-to-business buyer.
What you’re really askingWhat governs itRealistic exposure — US B2BWeight
“Could I be prosecuted for collecting this?”The Computer Fraud and Abuse Act, 18 U.S.C. § 1030Low on public listing data. The reported cases turn on logins, fake accounts, and bypassing technical barriers — not on reading a page anyone can open.Low
“Am I breaking Google’s rules?”Google’s Terms of Service and the separate Google Maps Additional Terms — contracts, not statutesReal, and the answer depends on which document and which clause. Google’s remedies are contractual: rate limits, IP blocks, account termination, a breach-of-contract claim.Contested
“Can Google or the businesses sue me over the data itself?”State torts (trespass to chattels, misappropriation) and copyrightA company name and a phone number are thin copyright material. The tort claims that have stuck involved server burden or credentialed access, not the facts in the listing.Low
“Can I be fined for using the list?”CAN-SPAM, the TCPA, the FTC Telemarketing Sales Rule, and state “mini-TCPA” statutesThis is the one that bites. Penalties are assessed per email and per call, and the TCPA carries a private right of action.Highest

Notice where the weight lands. The row everyone searches about is the first one; the row that has actually cost US companies money is the last one. The rest of this page is arranged in that order anyway, because that is the order people ask in — but if you only read one section, read the one on what you do with the list.

Case law

WHAT US COURTS HAVE ACTUALLY HELD

Three decisions carry most of the weight, and they moved in the same direction over three years. Read together, they draw one line clearly and leave a second line blurry.

June 2021 · Supreme Court

Van Buren v. United States narrowed the CFAA

A police officer ran a licence-plate lookup he was allowed to run, for a reason he was not allowed to run it for. The Government said that “exceeded authorized access” under the Computer Fraud and Abuse Act. The Court, 6–3, said no, and framed the test structurally: “liability under both clauses stems from a gates-up-or-down inquiry—one either can or cannot access a computer system, and one either can or cannot access certain areas within the system.”

Justice Barrett spelled out why the broader reading was untenable: “If the ‘exceeds authorized access’ clause criminalizes every violation of a computer-use policy, then millions of otherwise law-abiding citizens are criminals.” The opinion names terms-of-service breaches specifically — embellishing a dating profile, using a pseudonym — as things that should not be federal crimes.

Why it matters here: breaching a website’s terms is not, by itself, a federal crime. Read the opinion (PDF).

April 2022 · Ninth Circuit

hiQ Labs v. LinkedIn — and the ending nobody quotes

On remand in light of Van Buren, the Ninth Circuit affirmed the injunction stopping LinkedIn from blocking hiQ’s scraper, holding that “when a computer network generally permits public access to its data, a user’s accessing that publicly available data will not constitute access without authorization under the CFAA.” Where free access is the default, the court reasoned, selectively cutting one party off is better described as a ban than as a withdrawal of “authorization”.

That sentence is the one every scraping vendor quotes. Here is the part they leave out. In December 2022 the parties settled, and hiQ stipulated to a $500,000 judgment against it. The stipulated liability included breach of LinkedIn’s user agreement and a CFAA violation grounded partly on hiQ using fake accounts to reach password-protected pages.

Why it matters here: the case is not “scraping is legal”. It is “public pages get one analysis, logging in gets another” — and the contract claim survived the CFAA claim’s collapse. hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022).

January 2024 · N.D. Cal.

Meta Platforms v. Bright Data pushed on the contract side

Meta sued a scraping company for breach of its Facebook and Instagram terms. Judge Chen granted summary judgment for the scraper, on the reasoning that a party scraping while logged out was not a “user” bound by those terms at the moment it collected the data: “The Facebook and Instagram Terms do not bar logged-off scraping of public data; perforce it does not prohibit the sale of such public data.”

Do not over-read it. This is a district-court ruling interpreting the specific wording of one platform’s contract. It is not a rule that terms of service evaporate whenever you log out, and a differently-drafted contract can reach non-account-holders. But it is the clearest recent statement of the same hinge Van Buren and hiQ both turn on.

Why it matters here: the login is the hinge. All three cases are easier for the collector when there was no account, no credential, and no barrier bypassed. Meta Platforms, Inc. v. Bright Data Ltd., No. 3:23-cv-00077 (N.D. Cal. 23 Jan. 2024).

The contract

WHAT GOOGLE’S TERMS ACTUALLY SAY

There are two documents, not one, and almost every article on this topic quotes an outdated version of the first. Both are quoted here verbatim, with the effective dates, so you can tell when this page has gone stale.

Document 1 · Google Terms of Service · effective 30 July 2026

“using automated means to access content from any of our services in violation of the machine-readable instructions on our web pages (for example, robots.txt files that disallow crawling, training, or other activities)”

Read the conditional. The current wording does not flatly ban automated access — it bans automated access in violation of the machine-readable instructions. Older versions of this document contained a blunter prohibition on “robots, spiders or scrapers”, and that is the sentence most blog posts on this question are still quoting. Separately, Google’s enforcement clause lists “scraping content that doesn’t belong to you” among the conduct that can get your account terminated. Read the current terms.

Document 2 · Google Maps/Google Earth Additional Terms · effective 27 January 2026

Section 2 opens by making compliance “a condition of your license to use Google Maps”, then lists what you may not do. Two clauses matter here:

“mass download or create bulk feeds of the content (or let anyone else do so)”

“use Google Maps to create or augment any other mapping-related dataset (including a mapping or navigation dataset, business listings database, mailing list, or telemarketing list) for use in a service that is a substitute for, or a substantially similar service to, Google Maps”

The second clause is the one people misquote by stopping at “telemarketing list”. It is qualified: it bars building such a dataset for use in a service that substitutes for, or is substantially similar to, Google Maps. Whether a sales prospecting list counts as a “substantially similar service to Google Maps” is a genuinely arguable question that no court has settled; anyone telling you it is obviously fine, or obviously prohibited, is guessing. The first clause carries no such qualifier, and it is the harder one to argue around at volume. Read the Maps terms.

SO WHAT DO GOOGLE’S MACHINE-READABLE INSTRUCTIONS ACTUALLY SAY?

Because the current Terms of Service condition the prohibition on robots.txt, that file stops being trivia and becomes the operative text. Almost nobody writing about this question has opened it. Here is the relevant excerpt from google.com/robots.txt, fetched 13 August 2026:

User-agent: *
Disallow: /search
...
Disallow: /maps/
Allow: /maps/@
Allow: /maps/search/
Allow: /maps/place/

That is an excerpt — the real file is several hundred lines and the Allow rules for /maps/ run to about two dozen. The two that matter are there: /maps/place/ and /maps/search/ are the paths that carry business listings, and both are explicitly allowed to every user agent, while /search stays disallowed. Under RFC 9309, the Robots Exclusion Protocol standard, “the most specific match found MUST be used” — a longer Allow beats a shorter Disallow.

Be careful what you take from that.

  • It does mean the “in violation of the machine-readable instructions” condition in the main Terms is not automatically satisfied for those two paths.
  • It does not touch the Maps Additional Terms’ mass-download clause. That is a separate contract with no robots.txt condition in it.
  • It does not stop Google rate limiting you, serving CAPTCHAs, or blocking your IP range. That is not a legal question at all — Google is entitled to defend its own servers, and at any real volume it will.
  • It will change. Google rewrites this file. The link above is the whole point: this is the one paragraph on the page you can falsify in thirty seconds.

Where the real exposure is

THE RISK ISN’T THE LIST. IT’S THE CALL.

Almost every article on this topic stops at the collection question, which is exactly backwards. Nobody in US home-services B2B has been prosecuted for downloading a contractor’s published phone number. People do get sued over the call they made to it. Three regimes to know.

Email · CAN-SPAM

There is no B2B exemption

This is the most common misconception in sales teams. 15 U.S.C. § 7704 applies to commercial email full stop; it does not care that the recipient is a company. Six obligations: accurate header information, a subject line that is not misleading, identification of the message as an advertisement, a valid physical postal address, a working opt-out mechanism that stays live for at least 30 days, and honouring an opt-out within 10 business days.

Penalties are assessed per message, not per campaign — the FTC’s compliance guide puts the inflation-adjusted cap at $53,088 for each non-compliant email. Section 7704(b) adds “aggravated violations” where addresses were “obtained using an automated means from an Internet website” that posted a notice against transferring addresses, which is worth knowing if you plan to harvest inboxes off contractor websites.

Phone · TCPA and do-not-call

Two regimes people keep merging

The FTC’s Telemarketing Sales Rule exempts most B2B calls: 16 C.F.R. § 310.6(b)(7) covers “[t]elephone calls between a telemarketer and any business to induce the purchase of goods or services”. Two carve-outs survive: the misrepresentation and threat/intimidation prohibitions in § 310.3(a)(2) and (4) still bind you, and calls selling nondurable office or cleaning supplies are not exempt at all.

The FCC’s national do-not-call rule is a different instrument. 47 C.F.R. § 64.1200(c)(2) is written for “[a] residential telephone subscriber”, which is why a business’s published landline generally sits outside the registry. Generally.

The trap specific to this data

The TCPA’s restriction on autodialed and artificial/prerecorded calls attaches to the number, not to the relationship — and a large share of small home-services operators publish a mobile number as their business number on Google Maps. A one-person roofing outfit does not have a switchboard. That means a CSV of contractors is not cleanly “a list of business landlines”, and the B2B exemption you read about in the TSR does not cure the cell-phone problem, because it is a different statute.

Manual dialling is a materially different risk profile from an autodialer, a prerecorded drop, or an AI voice agent. If your plan involves the second category, that is the specific question to take to a compliance attorney — not “can I scrape this”.

State law adds a layer the federal analysis misses. Florida’s Telephone Solicitation Act, Texas SB 140 (in force since 1 September 2025, with a private right of action and statutory damages up to $5,000 per violation), and a growing set of other “mini-TCPA” statutes define solicitation more broadly than the federal rules and do not all mirror the B2B exemption. Roughly a dozen states also run their own do-not-call registries with their own scope.

On privacy law, for a US rep calling US businesses the GDPR is generally not the operative regime — Article 3(2) reaches non-EU controllers only where they offer goods or services to, or monitor, people who are in the EU. Two caveats are worth naming anyway. A sole trader’s name and mobile number is personal data even when it is used commercially, so “it’s a business contact” is not a blanket exemption anywhere. And in the US the closer analogue is state law: California’s CPRA ended the CCPA business-to-business exemption on 1 January 2023, so business-contact data about California residents is in scope for any company that meets the CCPA thresholds.

Our own position

WHERE PLOTLEADS SITS, PLAINLY

It would be convenient to write all of the above and not say where we stand in it. Here is the honest version, including the parts that are not flattering.

  • We pull public Google Maps listing data through a third-party Apify actor at search time. We do not run our own crawler, and we do not use logins, accounts, or credentialed access to obtain this data — which is the distinction the hiQ record turned on. The mechanism is written up in full on how we build these lists.
  • We do not verify contact details. Each row is what the business published about itself on its own listing. No phone is dialled to confirm it, no website is tested, no decision-maker name or personal email is appended from a broker.
  • We do not check any number against the national or any state do-not-call registry. There is no suppression step in the product — not a deferred one, not a partial one. If your programme needs DNC scrubbing, you run it yourself or through a compliance vendor before you dial.
  • Compliance for your outreach is yours. That is not a disclaimer buried in a footer; it is section 3 of the Terms of Service you agree to, and it is the honest description of what a vendor can possibly know about how you use a CSV.
  • PlotLeads is operated from Sweden as a sole proprietorship, so our own handling of this data sits under the GDPR. A business that wants its listing removed from our data can email support@plotleads.com; the Privacy Policy sets out how that works.

One more, because it is the question behind the question. If you’re weighing buying a list against running your own scraper, the legal analysis on this page is broadly the same either way — the same statutes, the same terms, the same outreach rules. What differs is who carries the operational burden: the blocks, the CAPTCHAs, the proxy rotation, the rewrite every time the page structure changes. If you want the mechanics of doing it yourself, that is a different page — exporting Google Maps to CSV covers the steps, and what our scraper does covers the tool.

Common questions

SHORT ANSWERS

Is scraping Google Maps illegal in the US?+

No US court has held that collecting publicly displayed business listings is a crime, and the leading cases point the other way: Van Buren narrowed the Computer Fraud and Abuse Act in 2021, and in hiQ v. LinkedIn the Ninth Circuit held that accessing data on a network that generally permits public access is unlikely to be access without authorization under the CFAA. That is not the same as saying it is permitted. It can still breach Google's terms of service, which is a contract question between you and Google rather than a criminal one.

Does scraping Google Maps violate Google's terms of service?+

It depends which document you read. Google's main Terms of Service, effective 30 July 2026, prohibit using automated means to access content in violation of the machine-readable instructions on Google's pages, such as robots.txt. The separate Google Maps and Google Earth Additional Terms prohibit mass downloading or creating bulk feeds of Google Maps content. Breaching either is a contract matter, and Google's remedies are rate limiting, blocking, account termination, or a civil claim, not criminal referral.

Does Google's robots.txt block crawling Google Maps business listings?+

Not for the listing paths. As published at google.com/robots.txt and checked on 13 August 2026, the rules that apply to all user agents disallow /maps/ but explicitly allow /maps/place/ and /maps/search/, which are the paths that carry business listings. Under RFC 9309, the Robots Exclusion Protocol standard, the most specific matching rule wins, so those two paths are permitted. Google's separate Maps Additional Terms still restrict bulk extraction regardless of robots.txt.

Is it legal to cold call or cold email businesses from a scraped list?+

The rules on outreach are stricter than the rules on collection, and this is where most of the real exposure sits. CAN-SPAM applies to commercial email with no business-to-business exemption and its penalties are assessed per message. The FTC's Telemarketing Sales Rule exempts most business-to-business calls under 16 CFR 310.6(b)(7), and the FCC's national do-not-call rule is written for residential telephone subscribers, so a published business landline is generally outside it. But the TCPA's restrictions on autodialed and prerecorded calls attach to the number dialed, and many small home-services businesses publish a mobile number as their business line.

Does PlotLeads check phone numbers against the do-not-call registry?+

No. PlotLeads does not verify phone numbers and does not scrub them against the national do-not-call registry or any state registry. There is no suppression step in the product. Each row is what the business publishes on its own Google Maps listing. Do-not-call suppression, consent records, calling windows, and opt-out handling are the buyer's responsibility.

Is this page legal advice?+

No. It is a sourced summary written by the person who builds PlotLeads, who is not a lawyer. Every case, statute, regulation, and terms-of-service document referenced here is linked so you can read the primary text yourself. If you are running outreach at scale, or planning to use an autodialer, a prerecorded message, or an AI voice agent, get advice from a telemarketing-compliance attorney before you start.

Primary sources

READ IT YOURSELF

Every claim above traces to one of these. They are linked because a summary written by a non-lawyer is only worth reading if you can check it.

Disclaimer

This page is general information, not legal advice, and reading it does not create a lawyer—client relationship. It was written by Usama Zafar, who builds PlotLeads and is not a lawyer. US law on scraping is unsettled and moving, it varies by circuit and by state, and the terms-of-service documents quoted here are rewritten by Google without notice. The effective dates above are exactly so you can tell how stale this is. Before you launch an outreach programme — and especially before you point an autodialer, a prerecorded message, or an AI voice agent at a list of phone numbers — get advice from a qualified telemarketing-compliance attorney about your specific facts.