All articles
Compliance guide8 min read

Pull leads from Google Maps without scraping, and stay on the right side of the CNIL

Which data is legally usable, what the CNIL really says about B2B prospecting, and how to build a compliant local list without mass scraping.

"How to scrape Google Maps" is one of the most common searches French sales teams run. The instinct makes sense: local data is right there, visible, free. The problem is not seeing it. It is collecting and using it without breaking the law.

GDPR applies the moment data identifies a person, even when that data is public. Google Maps is a goldmine of context for local outbound. So the useful question is not "how do I harvest as fast as possible", it is "what should I collect, and how do I stay compliant".

The gist in 30 seconds
  • In B2B, the CNIL allows email prospecting without prior consent if the subject relates to the person's role and an unsubscribe link is provided. B2C requires consent.
  • Collect role-based data (business name, professional phone, generic email, sector). Avoid personal mobiles and named emails unrelated to the role.
  • Mass scraping is fragile: legally risky, technically brittle, and destructive to your deliverability.
  • The compliance checklist and unsubscribe wording are below, copyable.

What the CNIL actually says about B2B prospecting

The rule is more permissive than most think, but it has precise limits. The CNIL separates B2B from B2C.

In B2B, you can email-prospect a person in the context of their role, without prior consent, under two conditions: the subject of the message relates to their professional role, and an easy way to opt out (unsubscribe) is present in every send. Emailing "sales@durand-garage.com" about invoicing software is legitimate. Pitching them a cruise is not.

In B2C, the logic flips: prior consent is required before any send. A sole trader operating under their own name blurs the line, when in doubt, treat them with B2C safeguards.

Public data is not free data. GDPR does not care where you found the information, it cares what you do with it.
The line to remember

Which Google Maps data is usable

Google Maps exposes two kinds of data. The first is business data: name, address, displayed phone, website, category, hours. The second is personal data: a named email, an executive's name, sometimes a mobile. Sorting the two is the whole point.

1
Rule 1
Favor role-based data

Business name, public professional phone, role-based email (contact@, sales@). This data serves the commercial relationship without targeting a person in their private capacity.

2
Rule 2
Handle named emails with care

first.last@company.com is personal data. Usable in B2B if the subject touches the person's role, but you owe them the right to object and disclosure of the data's origin.

3
Rule 3
Never collect personal mobiles

A mobile number tied to a person is almost always private. The legal risk is out of proportion with the commercial value.

4
Rule 4
Ignore third-party data in reviews

Google reviews sometimes name clients. That data is not yours and has no prospecting value. Do not extract it.

The public-data trap
"It's public, so I'm allowed" is the most common mistake. The CNIL treats personal data as protected even once published. An executive displaying their email on a listing does not hand you a blank check for any use, only for an expected, fair use.

Why mass scraping is a bad bet

Beyond the law, mass scraping is a bad operational trade. It fails on three fronts at once.

Legally, harvesting thousands of listings without filtering means building a personal-data file whose purpose and quality you can no longer guarantee. You pile up personal mobiles, off-role named emails, and third-party data. The more volume, the more risk.

Technically, a mass extraction depends on the source's structure at one moment in time. The first layout change breaks the script, and you are left with a frozen base that rots fast: roughly one local listing in five changes information every year (closures, relocations, new numbers).

For deliverability, it is the worst part. A big unqualified list contains invalid addresses and spam traps. Sending to it tanks your sender reputation, and your emails land in junk, including the ones meant for good prospects.

B2B
Email prospecting without prior consent, with opt-out
B2C
Prior consent required before any send
30 d
Max time to handle an opt-out request

The compliant method: build small, targeted, clean

The alternative to mass scraping is not "do nothing". It is a targeted local search, query by query, where you keep only role-based data and where compliance is built into the collection itself. Here is the approach.

1
Step 1
Target a narrow niche and area

One trade, one city. "Plumber in Annecy" beats "tradespeople in France". A narrow list can be qualified by hand and stays current.

2
Step 2
Keep only role-based data

As you add a row, keep the business name, professional phone, role-based email, website. Discard everything else immediately.

3
Step 3
Record the origin and date

Note the source and collection date for each row. That is what lets you answer a data-origin request and purge at the right time.

4
Step 4
Wire up opt-out from the first send

Every email ships with a working unsubscribe link and a role-relevant subject. An objection removes the row and adds it to a permanent suppression list.

The compliance checklist to drop into your process

Here is the checklist we apply ourselves, plus an unsubscribe wording ready to paste into an email footer. None of this needs a lawyer, only discipline at collection time.

Compliance checklist + unsubscribe
COMPLIANCE CHECKLIST: local B2B list (GDPR / CNIL)

COLLECT (useful public data, B2B prospecting)
[ ] Business name
[ ] Postal address and service area
[ ] Publicly displayed professional phone
[ ] Website (audit and context source)
[ ] Business category / sector
[ ] Generic role-based email (contact@, sales@)

AVOID (legal or quality risk)
[ ] A named executive's personal email unrelated to their role
[ ] Personal mobile numbers
[ ] Any data about clients mentioned in reviews
[ ] Mass automated collection that breaches the source's terms

OBLIGATIONS ON EVERY SEND
[ ] Subject relevant to the recipient's professional role
[ ] Sender identity clearly stated
[ ] One-click, working unsubscribe link
[ ] Handle opt-out requests within 30 days max
[ ] Disclose data origin if asked

UNSUBSCRIBE WORDING (paste in email footer)
"You are receiving this message in a professional B2B context.
To stop being contacted, reply STOP or click here: {{unsubscribe_link}}.
Your data is deleted within 30 days."

The email footer is not a formality. It is what turns a legally fragile cold email into perfectly defensible B2B prospecting: sender identity, one-click opt-out, stated deletion window.

See for yourself
Don't take our word for it

Open the demo campaigns and judge the lead quality yourself, no card required. Worst case, you lose ten minutes.

When you genuinely need volume
Some cases demand volume (national coverage, a very dispersed niche market). Be honest about the cost: the more volume you add, the more you must industrialize compliance (automatic filtering, purging, handling objections at scale) and protect deliverability (segmentation, domain warm-up, multiple senders). Volume is not free, it shifts the work onto compliance and infrastructure. If you lack that capacity, a small clean list will convert better.

Where AutoLeads fits

None of the above requires AutoLeads. You can run your local searches by hand, keep only role-based data, and manage opt-outs in a spreadsheet. AutoLeads runs a targeted live search, not a mass harvest: query by niche and area, surfacing useful professional contact data, not personal mobiles or third-party data. We help you build a small, clean list faster, we do not sell you a giant file you cannot defend.

If you remember one thing: stop chasing "how to scrape more", and start by sorting what you are actually allowed to use. A compliant local list, even a small one, beats a mass file that burns your domain and your reputation.

Frequently asked questions

Is scraping Google Maps illegal in France?

It is not extracting public data that is the problem, it is what you collect and how you use it. Mass-collecting personal data (a named email, a mobile number) to prospect without a legal basis, or in breach of the source's terms, exposes you. GDPR applies the moment there is personal data, even public data.

Can you send a B2B cold email without prior consent?

Yes, in B2B. The CNIL allows email prospecting toward a person in the context of their professional role without prior consent, provided the subject relates to that role and an easy way to opt out (unsubscribe) is included. In B2C, prior consent is required.

Is a named email like first.last@company.com personal data?

Yes. An email that identifies a natural person is personal data under GDPR, even if it is professional and public. You can use it in B2B if the subject relates to the person's role, but you must honor the right to object and disclose the data's origin on request.

Why avoid mass scraping if the data is public?

Three reasons. Legal: mass-collecting personal data without filtering raises risk and complicates GDPR compliance. Technical: mass extractions break at the first change in the source's structure and produce stale data. Quality: a huge unqualified list destroys your deliverability faster than it fills your pipeline.

How long can you keep this data?

The CNIL recommends a retention period proportionate to the purpose. For prospecting, data with no interaction should generally be deleted after around three years from the last contact. Anyone who objects must be removed without delay and can be kept on a suppression list so they are never contacted again.

Do you need AutoLeads to build a compliant list?

No. You can run a local search by hand, keep only role-based data, and manage opt-outs in a simple spreadsheet. AutoLeads runs a targeted live search (not a mass harvest) and only surfaces useful professional contact data, but the compliant approach described here works without us.

Book a demo