B2b Intent-Data And Contact-Scraping Practices: A Doctrinal Analysis Of Legality Under Data Protection Law
Abstract The business-to-business ("B2B") sales and marketing industry now depends on a mature ecosystem of intent-data and contact-enrichment platforms that scrape, aggregate, infer, and resell professional identifiers such as names, job titles, corporate email addresses, and behavioural "buying signals." Industry practice frequently proceeds on the untested assumption that such data, because it is professional in character or drawn from ostensibly public sources such as LinkedIn and corporate websites, falls outside the reach of data protection law. This paper undertakes a doctrinal analysis of that assumption across three regimes: India's Digital Personal Data Protection Act, 2023; the European Union's General Data Protection Regulation; and the fragmented sectoral and state-law framework of the United States, read together with the Computer Fraud and Abuse Act jurisprudence culminating in hiQ Labs, Inc v LinkedIn Corp. It argues that the "publicly available data" exemption is doctrinally narrower, and more jurisdiction-specific, than industry practice assumes; that purpose-limitation and inference-based reasoning consistently narrow the exemption once data is aggregated or repurposed for commercial profiling; and that a distinct regulatory blind spot exists around "contact enrichment" techniques that generate new personal data through inference rather than mere collection. The paper concludes with doctrinally grounded recommendations for statutory and regulatory clarification.
Authors
- Gayatri V. Ware
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-09-30
- DOI
- https://doi.org/10.5281/zenodo.22722755
- Primary Topic
- Privacy, Security, and Data Protection
- Type
- article
- Field-Weighted Citation Impact
- 0.00