Scraping and reuse of platform data: the legal framework

Scraping and reuse of platform data

This article sets out a general legal framework under Dutch and European law. It is not advice on any particular situation. The outcome of a scraping question always depends on the precise facts: the technique used, the nature of the data, how it is stored, the intended exploitation and the technical configuration of the source.

Public does not mean free to use

Anyone who collects data from an online platform and makes it available elsewhere operates in an area often described as grey, but which on closer inspection is better defined than assumed. The question arises for price comparison services, recruitment tools and market research firms, and in recent years above all for parties gathering training data for AI models at scale.

No statute prohibits the collection of publicly available data as such. Equally, the reverse does not hold: the fact that data is visible without logging in does not mean it is free to reuse. Anyone collecting, storing and reusing data operates at the intersection of five fields: database rights, copyright, contract law, criminal law and the General Data Protection Regulation. What determines the outcome is not whether the data was public, but how it was obtained, stored and made available again.

Three models of data collection, three risk profiles

It helps to distinguish three ways of operating. With linking and embedding, the service refers only to material the platform itself has already made public. With independent retrieval and storage, the service collects data, keeps it on its own servers and serves it from there. In the third model the same occurs, but a login wall, a token requirement, a CAPTCHA or another technical access restriction is bypassed in the process.

The first model carries the lowest risk profile: there is no new public in the copyright sense as long as the material was already freely accessible, and no technical restriction is circumvented. That does not make it risk free: framing, misleading presentation, trade mark use or the transfer of personal data such as IP addresses through embeds may still create exposure. The second model is arguable and depends heavily on the scale and nature of what is taken. The third is by far the most exposed, because it can trigger civil, criminal and data protection liability at once.

The matrix below gives a first, provisional indication rather than a fixed rule of law.

Method of collectionCivil and IP riskData protection riskCriminal riskKey test
Linking and embeddingLow to moderateLimited (IP address transfer)NegligibleNo new public (Svensson); no circumvention of restrictions (VG Bild-Kunst)
Independent retrieval and storageModerate to highHigh where personal data is involvedLow where the source is publicSubstantial part of the database; substantial investment; valid GDPR basis
Circumvention of restrictionsVery highVery highReal (art. 138ab Dutch Criminal Code)Breaking security or use of a false key; breach of contract; tort

Database rights: the substantial investment

For a platform the sui generis database right is normally the most promising basis. Directive 96/9/EC, implemented in the Dutch Databases Act, protects the maker of a database against the extraction or re-utilisation of a substantial part of its contents, and also against the repeated and systematic extraction of smaller parts where this conflicts with normal exploitation.

Creating versus obtaining

In British Horseracing Board v William Hill (C-203/02) the Court of Justice held that only investment in obtaining, verifying and presenting existing data counts, and not the cost of creating it.

User generated content

For platforms whose content is contributed free of charge by users, that distinction cuts both ways and is not automatically favourable. On the one hand the platform does not create the data, which opens the door to protection. On the other, obtaining it costs nothing: users upload voluntarily and on their own initiative, so there is little to invest at that stage. Protection therefore does not follow from the size of the dataset, but only where the platform can show substantial investment in what happens after collection: verification, moderation and clean-up, quality control, indexing and the infrastructural presentation of the data. Whether those investments together meet the threshold is a question of fact to be substantiated per platform and per dataset, with figures on staff, infrastructure and systems rather than a reference to the size of the user base.

Meta search engines and scrapers

In Innoweb v Wegener (C-202/12) the Court held that a service which forwards real-time search queries to another party’s database and displays the results in its own interface re-utilises that database, regardless of whether the data is stored locally on a permanent basis. That goes to the heart of many scrapers and alternative interfaces, even where they retain nothing.

The text and data mining exception

Articles 3 and 4 of the DSM Directive, implemented in articles 15n and 15o of the Dutch Copyright Act, provide an exception for text and data mining. For commercial parties that exception applies only where the rightholder has not expressly reserved its rights, and the reservation must be recorded in machine readable form, for example through API metadata, contractual provisions or robots.txt instructions.

Copyright and platform interfaces

On platforms carrying user content, copyright is routinely attributed to the wrong party. Posts and images belong in principle to their individual authors, provided the work is the author’s own intellectual creation within the meaning of Infopaq (C-5/08). Short, factual posts often fail that threshold, so in many cases there is simply nothing to protect.

Who may enforce

Terms of use normally grant the platform only a non-exclusive licence. Three questions are frequently conflated here: the substantive copyright, which remains with the author; the right to prohibit an infringement, which in principle belongs only to the rightholder or an exclusive licensee; and the capacity to bring proceedings, which the platform may hold where it has secured an express mandate from rightholders.

Under Dutch law a merely non-exclusive licensee has no independent right of action for infringement. The platform can, however, act on its own rights separately from the content: copyright in the graphical user interface, the database structure and icons, and trade mark rights in trade names and logos. A service that adopts those elements in order to appear familiar hands the platform a ground it did not have in respect of the underlying content.

Linking and copying

Three lines of Court of Justice case law govern here. Hyperlinking to a source that is already freely accessible is not a new communication to the public (Svensson, C-466/12). Downloading a work and placing it on one’s own server is, because the work thereby becomes available to a different public (Renckhoff, C-161/17). And circumventing technical protection measures reaches a public the rightholder did not have in mind, which likewise constitutes a new communication to the public (VG Bild-Kunst, C-392/19).

Contract law: terms of use and the Ryanair paradox

Virtually every platform prohibits automated access in its terms. The first question, however, is whether a contract came into being at all, and that differs materially between public visitors and registered accounts. A mere browse-wrap, a reference at the foot of the page, rarely binds a visitor under Dutch law unless active acceptance can be established. With a click-wrap, where terms are expressly accepted on registration, the terms are in principle binding, and automated account creation quickly becomes a breach in its own right.

The Ryanair paradox

In Ryanair v PR Aviation (C-30/14) the Court of Justice held that where a database is protected by neither copyright nor the sui generis right, the mandatory user rights under the Database Directive do not apply. The operator may then restrict reuse extensively by contract. The weaker the intellectual property position, the stronger the contractual one may prove. Following that preliminary ruling the case returned to the Dutch courts, and the Hague Court of Appeal held that the prohibition on database use in Ryanair’s terms was not, contrary to the earlier finding, void as a matter of course.

Nullity where the database is protected

Where a database does enjoy sui generis protection, a contractual prohibition on the extraction of insubstantial parts is void under article 15 of the Database Directive. That protection is available only to a party qualifying as a lawful user, a status which in turn depends on how access to the database was obtained.

The practical weakness of a contractual claim

It binds only the counterparty and not its end users, loss is difficult to quantify where the platform is free of charge, and a workable penalty clause is often absent. A contractual basis is therefore almost always combined with database rights, copyright or tort.

Criminal law limits: unauthorised access

Not every breach of access conditions amounts to unauthorised access, and the debate moves to that conclusion far too readily. Article 138ab of the Dutch Criminal Code requires intentional and unlawful intrusion into an automated system, for example by breaking security, a technical intervention, the use of a false key or the assumption of a false identity.

Sending requests faster than the provider intended, ignoring robots.txt, or registering an account under a pseudonym or with fictitious details does not in itself amount to intrusion. A public registration form is open to everyone and nothing is broken. That may well breach the terms of use, but that is a civil matter.

Criminal exposure increases as soon as concrete technical access barriers are defeated: reusing captured authentication tokens or API keys, or deliberately circumventing interactive anti-bot and CAPTCHA systems. The legal characterisation does not follow automatically from the name of the technique used. Whether something qualifies as intrusion, a technical intervention or the use of a false key remains a fact-specific assessment turning on how the security mechanism operates, the intent of the user and the nature of what is bypassed.

Data protection in large scale scraping

Once scraped data is directly or indirectly traceable to natural persons, including usernames, profile pictures, posts, IP addresses and profile statistics, the scraper normally qualifies as controller: the party determining the purposes and means of the processing.

In practice legitimate interests is often relied upon. That is a possible basis and not an automatic licence: it requires an assessment of purpose limitation, necessity and subsidiarity, and a balancing exercise in which the reasonable expectations of the data subject also weigh. Where sensitive data, large scale monitoring or profiling is involved, that balance may fall the other way.

Article 14(5)(b) GDPR provides an exemption from the information duty where informing is impossible or would involve disproportionate effort, which is frequently the case with data collected at scale. That exemption affects the information duty alone. Purpose limitation and data minimisation, the record of processing activities, the rights of data subjects including access, objection and erasure, appropriate security measures, and where processing is large scale a data protection impact assessment, all continue to apply in full.

The mere fact that personal data appears publicly on a platform does not deprive the data subject of their rights and is no licence for further processing or profiling. This is also the one part of the framework enforced not by the platform but by the supervisory authority and the individuals concerned, which makes it a risk that exists regardless of whether the source takes action.

Checklist for those collecting personal data

  • What data exactly is collected, and is it ordinary or special category personal data?
  • What is the specific purpose of the processing?
  • What is the legal basis, and does it survive a necessity and balancing assessment?
  • How are data subjects informed, and does an exemption from the information duty apply?
  • For how long is the data retained?
  • Is data transferred outside the European Economic Area?
  • Is a data protection impact assessment required given the scale and nature of the processing?
  • Can access, rectification and erasure requests actually be executed technically?

AI training data: a distinct concern

Training AI and language models on scraped data adds further legal layers on top of the frameworks above. Collecting, storing and training are not the same thing and each carries its own test. Collecting and temporarily storing training data may fall within the text and data mining exception; using that data to train a model and commercially exploiting its output is a separate act which must be assessed afresh against copyright, database rights and the GDPR.

Commercial AI developers may in principle rely on the mining exception, but only for as long as platforms have not implemented a machine readable opt-out. Where training data consists in part of a substantial part of a protected database, the sui generis right remains relevant regardless of whether the exception covers the copyright element.

Under the GDPR, collecting personal data for training purposes requires a sound legal basis and, at scale, an impact assessment. A specific compliance risk is that the right to erasure and the right to rectification are difficult to apply to parameters already absorbed into a trained model: removal from the model is rarely a straightforward technical operation. That tension between legal obligation and technical feasibility is a live concern for supervisory authorities. The Ryanair logic applies here too: platforms with weak intellectual property protection can still restrict reuse for AI training extensively through their terms, provided a contract has come into being.

Enforcement and litigation practice

Establishing the conduct is rarely the difficult part. Server logs, IP ranges, browser fingerprinting and request patterns link traffic to accounts. Platforms also embed canary data: synthetic, inconspicuous data points which prove origin when they surface elsewhere. With open source projects the source code is public and documents precisely which endpoints are called.

Harder is finding a party to hold liable where the operation sits behind proxy servers or anonymous domains. Disclosure of identifying details may then be sought from an intermediary such as a hosting provider, on the criteria set out by the Dutch Supreme Court in Lycos v Pessers.

Civil enforcement proceeds mainly through interim proceedings, on the basis of tort or intellectual property infringement, where a plausible case suffices and an urgent injunction with penalty payments is sought. Given the cost and evidential burden of full proceedings, platforms in practice often combine technical measures with notices to hosting providers, CDN services, app stores and domain registrars. The Digital Services Act provides a standardised notice procedure for that purpose. It does not itself determine whether conduct is unlawful; it offers only a faster route to address it, and its application depends on the role of the service concerned and the nature of the notice.

Frequently asked questions

Is scraping public websites prohibited in the Netherlands?

No. No statute categorically prohibits the collection of publicly available data. Whether it is permitted depends on what is collected, how access was obtained and what is then done with it. Publicly accessible does not mean freely reusable.

May I use platform data for a commercial service?

That requires assessment along four lines in each case: does the dataset contain a substantial part of a protected database, does it include copyright protected works, has a contract with the platform come into being, and is personal data being processed. The mere fact that profiles are visible without logging in answers none of those four questions.

Is breaching terms of use a criminal offence?

Not in itself. Breach of contract is a civil matter. Criminal liability arises only where there is intrusion within the meaning of article 138ab of the Dutch Criminal Code, which presupposes broken security, a technical intervention, a false key or a false identity.

Is creating an account under a pseudonym unauthorised access?

In principle no. A public registration form is open to everyone and nothing is broken. It may well breach the terms of use. The position differs where anti-bot or CAPTCHA systems are circumvented in order to automate that registration, or where tokens are used that were not issued to the user.

May I use scraped data to train an AI model?

The text and data mining exception leaves room, but for commercial parties only for as long as the rightholder has not made a machine readable reservation. Database rights and the GDPR continue to apply independently, and collecting, storing and training are three legally distinct acts, each to be assessed separately.

What counts as a substantial part of a database?

This is measured both quantitatively and qualitatively and is not a fixed percentage. Systematically extracting small quantities may also infringe where it conflicts with normal exploitation. The assessment is factual and differs per dataset.

Do I need a legal basis if the personal data is already public?

Yes. Publicity does not deprive data subjects of their rights. A party determining the purposes and means is the controller and needs a legal basis, in practice usually legitimate interests, which must survive a necessity and balancing assessment.

What can a platform do about scraping in practice?

Usually not full proceedings. Cutting off access, deploying technical measures and filing notices with hosting providers, CDN services, app stores and registrars. Where proceedings are brought, they are almost always interim proceedings, in which a plausible case suffices. The hardest part is identifying an anonymous operator.

How does a platform strengthen its own position?

By documenting its investment in verification, moderation, indexing and presentation in concrete terms, by recording acceptance of its terms on registration rather than relying on a reference at the foot of the page, by implementing a machine readable mining reservation, and by configuring technical measures so that their circumvention is both demonstrable and legally meaningful.

Sources

CJEU 9 November 2004, C-203/02 (British Horseracing Board v William Hill)

CJEU 16 July 2009, C-5/08 (Infopaq)

CJEU 19 December 2013, C-202/12 (Innoweb v Wegener)

CJEU 13 February 2014, C-466/12 (Svensson)

CJEU 15 January 2015, C-30/14 (Ryanair v PR Aviation)

CJEU 7 August 2018, C-161/17 (Renckhoff)

CJEU 9 March 2021, C-392/19 (VG Bild-Kunst)

Hague Court of Appeal 3 April 2018, ECLI:NL:GHDHA:2018:61 (Ryanair v PR Aviation, on referral)

Dutch Supreme Court 25 November 2005, ECLI:NL:HR:2005:AU4019 (Lycos v Pessers)

Directive 96/9/EC (Database Directive), implemented in the Dutch Databases Act

Directive (EU) 2019/790 (DSM Directive), arts. 3 and 4; Dutch Copyright Act arts. 15n and 15o

Dutch Copyright Act, arts. 1 and 27

Dutch Criminal Code, art. 138ab

Regulation (EU) 2016/679 (GDPR), arts. 4, 5, 6, 14, 15-21, 30, 32 and 35

Regulation (EU) 2022/2065 (Digital Services Act)

Dutch Civil Code Book 6, arts. 162 and 217; Dutch Code of Civil Procedure, arts. 254 and 1019

Law & More advises both companies processing third party data and parties seeking to protect their own data collections. Please feel free to contact us for an assessment of a specific situation.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

Explore acquittal to understand its significance, how it works in law, and its implications for

Article 15 of the General Data Protection Regulation—embedded in Dutch law through the Algemene Verordening

The European AI Act introduced major changes on 2 February 2025, making certain AI practices

Your organization detects unusual network activity. Your IT team investigates and finds unauthorized access to

Data breaches happen every day in the Netherlands. When they do, someone must take responsibility.

Can a company simply amend its general terms and conditions? The short answer: not always.

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.