Is Web Scraping Legal in the UK? Laws and Cases Explained (2026)
Published 2026-10-11 · Updated 2026-10-11 · By the Scrapeshop team
Web scraping is legal in the United Kingdom when you access only publicly available pages, do not extract a substantial part of a protected database, comply with any terms you have agreed to, and handle personal data under UK GDPR. No UK statute bans scraping. Four laws define the limits: the Computer Misuse Act 1990, the database right, UK GDPR with the Data Protection Act 2018, and contract law.
This guide explains each, the cases that shaped them, and what the UK’s missing commercial text-and-data-mining exception means in practice. General information current as of October 2026, not legal advice. The multi-country overview is in Is Web Scraping Legal? What the Law Actually Says.
Quick answer
Scraping public, non-personal data from UK websites is lawful. The Computer Misuse Act 1990 is not engaged by reading pages that are open to anyone; it is engaged by using credentials you are not entitled to, bypassing access controls, or persisting after an explicit revocation. Copyright does not protect facts, but the UK retained the EU database right after Brexit, so copying a substantial part of a curated database infringes. Terms and conditions are enforceable contracts where you accepted them, and the Court of Justice confirmed in Ryanair v PR Aviation (C-30/14, 2015) that operators of unprotected databases may restrict use by contract. Personal data remains personal data when public: UK GDPR requires a lawful basis and a privacy notice, and the ICO has pursued scrapers for ignoring both. The UK has no commercial TDM exception, so analysis of copyrighted text relies on fair dealing, licences, or the fact that facts are free.
Which UK laws govern web scraping?
| Law | What it covers | What it means for scrapers |
|---|---|---|
| Computer Misuse Act 1990, ss. 1 and 3 | Unauthorised access to computer material; unauthorised acts impairing operation | Public pages are implicitly authorised. Logins, bypassed controls, and post-revocation access are not. Overloading a server can be a s. 3 offence. |
| Copyright, Designs and Patents Act 1988 | Copyright in literary, artistic and compiled works; s. 29A non-commercial TDM exception | Facts are free; articles, photos and reviews are not. Commercial TDM has no exception, so copying copyrighted text for analysis needs a licence or fair dealing argument. |
| Copyright and Rights in Databases Regulations 1997 | Sui generis database right (15 years from completion) | Extracting or re-utilising a substantial part of a database built with substantial investment infringes. |
| UK GDPR and Data Protection Act 2018 | Processing personal data of UK residents | Need a lawful basis, a privacy notice (Art. 14), a legitimate interests assessment, and respect for objections. The Data (Use and Access) Act 2025 added recognised legitimate interests but did not exempt scraping. |
| Contract law | Terms and conditions, clickwrap and browsewrap | Binding where accepted; the strongest routinely successful claim against scrapers. Weaker against logged-out visitors. |
| Tort: trespass to goods, passing off | Interference with servers; misrepresentation of source | Rarely decisive. Relevant if scraping causes measurable harm or the scraped output misleads consumers. |
What cases shape UK web scraping law?
Ryanair v PR Aviation (CJEU C-30/14, 15 January 2015). PR Aviation scraped Ryanair’s flight data to run a comparison and booking site. The Court of Justice held that Ryanair’s flight database was protected by neither copyright nor the database right, which meant the statutory protections for lawful users did not apply, and Ryanair was therefore free to restrict use of its data by contract. Decided while the UK was an EU member, it remains retained case law and its logic is routinely applied: the weaker the intellectual property in the data, the more the terms and conditions matter.
British Horseracing Board v William Hill (CJEU C-203/02, 2004). The database right protects investment in obtaining, verifying and presenting existing data, not investment in creating the data. A fixture list or race card generated by the organiser may not qualify. This limits how many scraped sources can actually claim the right, but curated marketplaces, directories and review aggregators usually can.
Football Dataco v Sportradar (CJEU C-173/11, 2012; Court of Appeal 2013). Re-utilising database content on a server abroad still infringes in the UK if the data is targeted at UK users. Hosting a scraper outside the UK does not move the legal risk.
ICO v Clearview AI (2022 onwards).The Information Commissioner fined Clearview £7.5 million for scraping more than 20 billion facial images, including of UK residents. The First-tier Tribunal overturned the penalty in 2023 on the ground that Clearview’s foreign law-enforcement customers placed it outside UK GDPR’s territorial scope; the ICO appealed, and the Upper Tribunal sided with the ICO in 2025. The substantive point was never in doubt: scraping personal data from public pages is processing that needs a lawful basis.
When does scraping breach the Computer Misuse Act?
Section 1 requires that access be unauthorised and that you know it is. UK courts read “unauthorised” more broadly than US courts read the CFAA after Van Buren: authorisation can be withdrawn by clear notice, and using an account for a purpose its owner has prohibited can be unauthorised. For scrapers this means three practical rules:
- Do not log in with credentials you are not entitled to, and do not use a real user’s session to fetch data at scale.
- Treat a cease-and-desist letter or a targeted IP block as a revocation of authorisation. Continuing is where UK criminal exposure begins.
- Keep request rates far below anything that could impair the target. Section 3 covers reckless impairment, not only deliberate attacks.
Can I scrape personal data in the UK?
Yes, if you meet UK GDPR. The ICO’s position, restated in its 2024 consultation series on generative AI, is that web scraping of personal data can rely on legitimate interests only where the purpose is specific, the processing is necessary, and the balancing test accounts for people’s reasonable expectations. The practical requirements are a legitimate interests assessment written before scraping begins, a privacy notice reachable by the people concerned, a retention schedule, no special-category data without an Article 9 condition, and a working process for objections and erasure requests. B2B contact data is still personal data; the corporate subscriber exemption in PECR applies to marketing emails, not to the collection itself.
Why the missing TDM exception matters
Section 29A CDPA permits copies for text and data analysis only for non-commercial research. A commercial scraper that copies copyrighted text (articles, product descriptions, reviews) to analyse it has no statutory safe harbour and must rely on fair dealing, which is narrow, or on the content being unprotected facts, or on a licence. The 2022 proposal for a commercial exception was withdrawn in 2023; the 2024–25 consultation proposed an exception with a rights-holder opt-out, mirroring the EU. Until legislation passes, scrape facts freely, scrape expression carefully, and never republish it.
Checklist for scraping UK websites
- Access only logged-out pages. Never reuse real accounts or bypass access controls.
- Read the terms. If the site requires acceptance to use it, assume the anti-scraping clause binds you.
- Extract facts and fields, not substantial parts of curated databases or copyrighted prose.
- For personal data, complete a legitimate interests assessment and publish a privacy notice first.
- Respect robots.txt and rate-limit; it is evidence of good faith under both the CMA and UK GDPR.
- Stop on revocation and take advice before resuming.
See Web Scraping Best Practices for how to implement rate limiting, identification, and robots.txt handling.
Frequently asked questions
- Is web scraping illegal in the UK?
- No. The UK has no law against web scraping. Scraping public pages is lawful unless it involves unauthorised access under the Computer Misuse Act 1990, extraction of a substantial part of a protected database, breach of terms you agreed to, or processing personal data without a UK GDPR lawful basis.
- Does the Computer Misuse Act apply to scraping public websites?
- Section 1 criminalises causing a computer to perform a function with intent to secure unauthorised access. Reading pages open to everyone is authorised by implication. Logging in with credentials you are not entitled to use, or continuing after the operator has clearly withdrawn permission, risks crossing the line.
- Is scraping personal data legal in the UK?
- Only with a lawful basis under UK GDPR, usually legitimate interests, plus a privacy notice to the individuals. The ICO fined Clearview AI £7.5 million in 2022 for scraping faces from the public web; the tribunal dispute that followed turned on jurisdiction, not on whether scraping personal data needs a lawful basis.
- Does the UK have a text and data mining exception for commercial scraping?
- Not at the time of writing. Section 29A of the Copyright, Designs and Patents Act 1988 permits TDM only for non-commercial research. A broader exception proposed in 2022 was withdrawn in 2023, and the government consulted again in 2024–25 on an exception with a rights-holder opt-out. Check for new legislation before relying on it.
- Can website terms and conditions stop me scraping in the UK?
- If you accepted them, yes: breach of contract is the most common successful claim against scrapers. Ryanair v PR Aviation confirmed that where a website's data is not a protected database, the operator is free to restrict use by contract. Terms merely linked in a footer are weaker against logged-out visitors but not worthless.
- What is the UK database right?
- A 15-year right under the Copyright and Rights in Databases Regulations 1997 protecting databases that required substantial investment in obtaining, verifying or presenting their contents. Extracting or re-utilising a substantial part infringes it even where the individual facts are free.