Legal public data collection: how to get B2B leads without breaking GDPR
What public data collection done right looks like — official sources, respecting GDPR and terms, deduplication and clean delivery. Where the line runs between legal and abusive scraping, and what a real project delivers.

“Data collection” sounds, to many, like a gray area. It doesn’t have to be. The difference between a legal project and abusive scraping isn’t technical — it’s about sources and respect: what you gather, from where, and whether you respect the source’s rules and people’s rights.
A public data collection and lead generation project done right costs us 2,000–6,000 RON and starts from a simple principle: only public data, from legitimate sources, within GDPR.
Where the line runs between legal and abusive
| Legal | Abusive |
|---|---|
| Public registries, official open data | Data behind a login |
| Directories with terms that allow it | Bypassing a protection / captcha |
| Sources with clear opt-in | Ignoring robots.txt and terms |
| Calibrated volume, without hurting the source | Hammering that takes the source down |
| Lawful basis + transparency + opt-out | Collecting personal data with no basis |
Our rule is the left column, entirely. If a source forbids automated collection, we respect it — there’s no “but it was public, so we could”.
“It’s public” doesn’t mean “it’s free of GDPR”
The most common misconception. The fact that a business email appears on a website doesn’t remove it from Regulation 2016/679 — a business email is still personal data. You can collect and use such data, but on a lawful basis (for B2B, usually legitimate interest) and with obligations that come with it:
- transparency — the person must be able to learn that you hold their data and where it came from;
- right to object — they must be able to ask to be removed, easily;
- minimization — you collect what you need, not everything possible.
That’s why this ties closely to compliance in general — see the GDPR kit. A data project without the legal part solved isn’t an advantage, it’s a liability.
What a correct project actually delivers
Raw data doesn’t bring you clients. The value is in the processing:
- structured aggregation from public sources (registries, official data, directories with acceptable terms);
- enrichment — completing and verifying the useful fields;
- deduplication — a list with duplicates is noise, not a tool;
- clean delivery, CSV or API, so you can use it directly in your CRM or workflows.
And if it’s a recurring need (price monitoring, periodic list updates), collection becomes an automation that runs on its own, at a pace that respects the sources.
Legitimate use cases
- B2B lists from public registries and directories, for prospecting;
- price monitoring of public prices, for competitive positioning;
- market research — aggregating public data across a sector;
- enrichment of your existing database with verified public data.
We’ve built flows like this in B2B projects such as Vimax Groups — where correctly structured data makes the difference between a list and a sales tool.
In short
Public data collection is perfectly legal when you respect three things: the sources (only public/official), the source’s rules (terms, robots) and GDPR (lawful basis, transparency, opt-out). A correct project costs 2,000–6,000 RON and gives you a clean, deduplicated, ready-to-use list — not a chaotic file that puts you at risk. Tell us what data you need and what for, and we’ll tell you what’s legally feasible.
(This isn’t legal advice — for sensitive data or large volumes, we check the lawful basis together before starting.)