Pull leads from Google Maps without scraping, and stay on the right side of the CNIL
Which data is legally usable, what the CNIL really says about B2B prospecting, and how to build a compliant local list without mass scraping.
"How to scrape Google Maps" is one of the most common searches French sales teams run. The instinct makes sense: local data is right there, visible, free. The problem is not seeing it. It is collecting and using it without breaking the law.
GDPR applies the moment data identifies a person, even when that data is public. Google Maps is a goldmine of context for local outbound. So the useful question is not "how do I harvest as fast as possible", it is "what should I collect, and how do I stay compliant".
- In B2B, the CNIL allows email prospecting without prior consent if the subject relates to the person's role and an unsubscribe link is provided. B2C requires consent.
- Collect role-based data (business name, professional phone, generic email, sector). Avoid personal mobiles and named emails unrelated to the role.
- Mass scraping is fragile: legally risky, technically brittle, and destructive to your deliverability.
- The compliance checklist and unsubscribe wording are below, copyable.
What the CNIL actually says about B2B prospecting
The rule is more permissive than most think, but it has precise limits. The CNIL separates B2B from B2C.
In B2B, you can email-prospect a person in the context of their role, without prior consent, under two conditions: the subject of the message relates to their professional role, and an easy way to opt out (unsubscribe) is present in every send. Emailing "sales@durand-garage.com" about invoicing software is legitimate. Pitching them a cruise is not.
In B2C, the logic flips: prior consent is required before any send. A sole trader operating under their own name blurs the line, when in doubt, treat them with B2C safeguards.
Public data is not free data. GDPR does not care where you found the information, it cares what you do with it.
Which Google Maps data is usable
Google Maps exposes two kinds of data. The first is business data: name, address, displayed phone, website, category, hours. The second is personal data: a named email, an executive's name, sometimes a mobile. Sorting the two is the whole point.
Business name, public professional phone, role-based email (contact@, sales@). This data serves the commercial relationship without targeting a person in their private capacity.
first.last@company.com is personal data. Usable in B2B if the subject touches the person's role, but you owe them the right to object and disclosure of the data's origin.
A mobile number tied to a person is almost always private. The legal risk is out of proportion with the commercial value.
Google reviews sometimes name clients. That data is not yours and has no prospecting value. Do not extract it.
Why mass scraping is a bad bet
Beyond the law, mass scraping is a bad operational trade. It fails on three fronts at once.
Legally, harvesting thousands of listings without filtering means building a personal-data file whose purpose and quality you can no longer guarantee. You pile up personal mobiles, off-role named emails, and third-party data. The more volume, the more risk.
Technically, a mass extraction depends on the source's structure at one moment in time. The first layout change breaks the script, and you are left with a frozen base that rots fast: roughly one local listing in five changes information every year (closures, relocations, new numbers).
For deliverability, it is the worst part. A big unqualified list contains invalid addresses and spam traps. Sending to it tanks your sender reputation, and your emails land in junk, including the ones meant for good prospects.
The compliant method: build small, targeted, clean
The alternative to mass scraping is not "do nothing". It is a targeted local search, query by query, where you keep only role-based data and where compliance is built into the collection itself. Here is the approach.
One trade, one city. "Plumber in Annecy" beats "tradespeople in France". A narrow list can be qualified by hand and stays current.
As you add a row, keep the business name, professional phone, role-based email, website. Discard everything else immediately.
Note the source and collection date for each row. That is what lets you answer a data-origin request and purge at the right time.
Every email ships with a working unsubscribe link and a role-relevant subject. An objection removes the row and adds it to a permanent suppression list.
The compliance checklist to drop into your process
Here is the checklist we apply ourselves, plus an unsubscribe wording ready to paste into an email footer. None of this needs a lawyer, only discipline at collection time.
COMPLIANCE CHECKLIST: local B2B list (GDPR / CNIL)
COLLECT (useful public data, B2B prospecting)
[ ] Business name
[ ] Postal address and service area
[ ] Publicly displayed professional phone
[ ] Website (audit and context source)
[ ] Business category / sector
[ ] Generic role-based email (contact@, sales@)
AVOID (legal or quality risk)
[ ] A named executive's personal email unrelated to their role
[ ] Personal mobile numbers
[ ] Any data about clients mentioned in reviews
[ ] Mass automated collection that breaches the source's terms
OBLIGATIONS ON EVERY SEND
[ ] Subject relevant to the recipient's professional role
[ ] Sender identity clearly stated
[ ] One-click, working unsubscribe link
[ ] Handle opt-out requests within 30 days max
[ ] Disclose data origin if asked
UNSUBSCRIBE WORDING (paste in email footer)
"You are receiving this message in a professional B2B context.
To stop being contacted, reply STOP or click here: {{unsubscribe_link}}.
Your data is deleted within 30 days."The email footer is not a formality. It is what turns a legally fragile cold email into perfectly defensible B2B prospecting: sender identity, one-click opt-out, stated deletion window.
Open the demo campaigns and judge the lead quality yourself, no card required. Worst case, you lose ten minutes.
Where AutoLeads fits
None of the above requires AutoLeads. You can run your local searches by hand, keep only role-based data, and manage opt-outs in a spreadsheet. AutoLeads runs a targeted live search, not a mass harvest: query by niche and area, surfacing useful professional contact data, not personal mobiles or third-party data. We help you build a small, clean list faster, we do not sell you a giant file you cannot defend.
If you remember one thing: stop chasing "how to scrape more", and start by sorting what you are actually allowed to use. A compliant local list, even a small one, beats a mass file that burns your domain and your reputation.
Frequently asked questions
Is scraping Google Maps illegal in France?
It is not extracting public data that is the problem, it is what you collect and how you use it. Mass-collecting personal data (a named email, a mobile number) to prospect without a legal basis, or in breach of the source's terms, exposes you. GDPR applies the moment there is personal data, even public data.
Can you send a B2B cold email without prior consent?
Yes, in B2B. The CNIL allows email prospecting toward a person in the context of their professional role without prior consent, provided the subject relates to that role and an easy way to opt out (unsubscribe) is included. In B2C, prior consent is required.
Is a named email like first.last@company.com personal data?
Yes. An email that identifies a natural person is personal data under GDPR, even if it is professional and public. You can use it in B2B if the subject relates to the person's role, but you must honor the right to object and disclose the data's origin on request.
Why avoid mass scraping if the data is public?
Three reasons. Legal: mass-collecting personal data without filtering raises risk and complicates GDPR compliance. Technical: mass extractions break at the first change in the source's structure and produce stale data. Quality: a huge unqualified list destroys your deliverability faster than it fills your pipeline.
How long can you keep this data?
The CNIL recommends a retention period proportionate to the purpose. For prospecting, data with no interaction should generally be deleted after around three years from the last contact. Anyone who objects must be removed without delay and can be kept on a suppression list so they are never contacted again.
Do you need AutoLeads to build a compliant list?
No. You can run a local search by hand, keep only role-based data, and manage opt-outs in a simple spreadsheet. AutoLeads runs a targeted live search (not a mass harvest) and only surfaces useful professional contact data, but the compliant approach described here works without us.