Google Maps scraping and GDPR: a practical B2B overview
Updated July 22, 2026 · 7 min read
This is an overview written for people building B2B lead lists, not legal advice, and it can't be. Data-protection rules are interpreted differently across EU member states and the UK, guidance changes, and the answer for your situation depends on facts nobody writing a public guide can see. Nothing here promises that any particular use is compliant, and no tool — including this one — can make that promise on your behalf. Where the stakes are real, ask a data-protection lawyer in your market.
With that firmly said, here's the shape of the issue as it's usually discussed.
Where GDPR bites, and where it may not
GDPR governs personal data — information relating to an identified or identifiable living person. A limited company's main switchboard number and an info@ address are generally further from that definition than [email protected], which is usually treated as personal data even in a business context.
The complication in local business data is sole traders and partnerships. A one-person plumbing business is frequently a natural person trading under a name, and its contact details can be personal data even though it looks like a company. Local-business lists are full of exactly these, which is why “it's B2B so GDPR doesn't apply” is not a position you should build a process on.
Lawful basis, in outline
For B2B marketing, the basis usually discussed is legitimate interest, which requires you to actually balance your interest in marketing against the recipient's rights and expectations — and to be able to show you did. Regulators have published guidance on how that assessment should be documented; doing it properly is a written exercise, not a checkbox.
Separately, electronic marketing is governed by the ePrivacy rules as implemented nationally — PECR in the UK and equivalents elsewhere. These vary meaningfully: some countries permit unsolicited B2B email to corporate addresses with an opt-out, others are stricter, and the treatment of sole traders often differs from limited companies. The country you're emailing into matters more than the country you're sitting in.
Practices that generally help
- 1
Target relevantly
The narrower and more plausibly useful your targeting, the easier any balancing test is to argue. Emailing every business in a city is both worse marketing and a weaker position.
- 2
Say who you are and how you got the data
A clear sender identity and a plain statement that the contact details came from a public business listing is a low-cost transparency measure and generally expected.
- 3
Make opting out trivial and honour it immediately
One reply, or one click. Maintain a suppression list that survives re-scrapes — this is the single most important operational control, and re-adding someone on the next refresh is the classic failure.
- 4
Keep provenance and dates
Record where each row came from and when. If someone asks, being able to answer specifically is worth a great deal.
- 5
Don't hoard
Keep what you're using for a defined purpose, delete what you aren't. Enormous stale lists are risk without benefit.
- 6
Be ready to handle requests
Access, objection and erasure requests can arrive. Have a route for them that doesn't depend on one person remembering.
What a scraping tool can and can't do for you
Hubertino collects publicly listed business information from Google Maps and, where a business publishes it on its own website, a contact email and social links. What you do with that afterwards — who you contact, on what basis, with what content, in which country — is your processing, and the compliance obligations sit with you as the controller. No vendor's marketing copy changes that allocation.
The privacy policy sets out how business-listing data is handled here, including how a business can ask for its details to be removed. If you're building lists in Europe, reading it is a reasonable step before you start.
Rules of thumb, stated as rules of thumb
Public company contact details, narrowly targeted, honestly identified, with an instant opt-out, is the least contentious end of the spectrum. Named-individual addresses, broad untargeted sending, obscured sender identity, and ignored objections are the contentious end. Most disputes in practice start with an ignored opt-out rather than with the collection itself.
Again: this is orientation, not advice, and it is not a compliance guarantee. Get a qualified opinion for your market before scaling.
Common questions
Is scraping public business data illegal in the EU?
Collecting public business information isn't inherently unlawful, but where the data relates to an identifiable person, data-protection obligations apply to how you collect and use it. The use is what usually determines the answer, and the answer varies by country.
Do I need consent to send B2B email in Europe?
It depends on the country and on whether the recipient is a corporate subscriber or a sole trader. Some regimes permit corporate B2B email with a clear opt-out; others are stricter. Check the destination market's rules specifically.
Can a tool guarantee my campaign is compliant?
No. Compliance depends on your targeting, content, basis, record-keeping and jurisdiction — none of which a data source controls. Be sceptical of anyone claiming otherwise.