No KYC — no ID, no selfie, no documents · Pay in crypto: BTC, USDT, USDC, ETH, SOL, LTC · Top up from $25 · UK & EU residential from $0.36/GB
Buy with crypto

Guide

Are residential proxies legal in the UK and EU? (2026)

A plain-English overview of the UK and EU rules that apply when you collect web data through a proxy, with links to the primary texts. Checked on 5 October 2026. Not legal advice.

Last updated: · 13 min read

Quick answer

Are residential proxies legal in the UK and EU?

Yes. Using a residential proxy is legal in the UK and the EU. Legality depends on what you do through it. Unauthorised access is a crime under the UK Computer Misuse Act 1990. Scraped personal data falls under GDPR, and database rights and site terms can limit reuse. PontProxy, a no-KYC UK & Europe residential and 4G/5G proxy provider, permits public-data work only, from $0.36/GB, paid in crypto.

UK and EU rules at a glance

Using a proxyLegal in the UK and the EU; no general ban on proxy use
Unauthorised access (UK)Computer Misuse Act 1990, s.1 — up to 2 years in prison on indictment
Illegal access (EU)Directive 2013/40/EU, Art. 3 — made a crime in each member state's law
Personal dataUK GDPR + Data Protection Act 2018; EU GDPR (Regulation (EU) 2016/679)
Maximum data protection fines£17.5m or 4% of worldwide turnover (UK); €20m or 4% (EU), whichever is higher
DatabasesSui generis right: Directive 96/9/EC, Art. 7; UK: regulation 16, SI 1997/3032
Text and data miningEU: Directive (EU) 2019/790, Arts 3–4 (Art. 4 allows opt-outs); UK: CDPA s.29A, non-commercial research only
Website termsContract law; CJEU Ryanair v PR Aviation (C-30/14, 15 January 2015)
PontProxy policyPublic-data uses only — see our Acceptable Use Policy
KYC and paymentNo KYC — no ID, no selfie, no documents. Pay in crypto.

Yes. No UK law prohibits using a proxy server, including a residential or 4G/5G mobile proxy. Businesses use proxies every day for price monitoring, ad verification, SEO tracking and app testing.

The law looks at the activity, not the tool. Four sets of UK rules matter most when you collect web data:

  • Computer Misuse Act 1990: accessing data without authorisation.
  • UK GDPR and the Data Protection Act 2018: collecting personal data, even when it is public.
  • Copyright and database right: copying protected content or a substantial part of a database.
  • Contract law: the terms of the websites you visit.

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. It amends the UK GDPR and the 2018 Act in stages, so check the ICO's current guidance before a new project.

Yes. EU law does not ban proxies either. The same activity-based rules apply, and most of them are harmonised across the 27 member states:

  • Illegal access: Directive 2013/40/EU requires each member state to punish intentional access to an information system "without right", where a security measure is infringed.
  • Personal data: the GDPR (Regulation (EU) 2016/679) applies directly in every member state.
  • Databases: Directive 96/9/EC gives database makers a sui generis right.
  • Text and data mining: Directive (EU) 2019/790 sets two exceptions, which member states had to transpose by 7 June 2021.

National criminal and contract law still differ. A project that collects data in Germany and one in Spain can face different details.

When does using a proxy become a crime under the Computer Misuse Act?

It becomes a crime when you access data you know you are not authorised to access. Section 1 makes it an offence to make a computer perform a function to secure unauthorised access, knowing that it is unauthorised. Section 17(5) treats access as unauthorised when you are not entitled to control it and lack consent from someone who is.

Typical examples involve logins and security controls, not public pages:

  • logging into accounts that are not yours, including with leaked passwords (credential stuffing);
  • reaching content behind a login without the owner's permission;
  • using another person's API keys or session cookies.

The maximum penalty for a section 1 offence is two years in prison on indictment. Section 3 covers unauthorised acts that impair a computer's operation and carries up to ten years. Flooding a site with requests until it slows down can fall under section 3.

Does GDPR apply when you scrape public web pages?

Yes, whenever the pages contain personal data. In August 2023, the ICO and 11 other authorities issued a joint statement on scraping. It says that publicly accessible personal information "is still subject to data protection and privacy laws in most jurisdictions". The EDPB said in July 2026 that the GDPR applies to web scraping when it includes personal data processing.

If you collect names, profiles, usernames or contact details, you need to:

  • have a lawful basis: for private companies, usually legitimate interests (Article 6(1)(f));
  • minimise: data must be "adequate, relevant and limited to what is necessary" (Article 5(1)(c));
  • inform people: Article 14 applies to data you did not collect from them, with an exception for disproportionate effort;
  • protect and delete: keep the data secure and only for as long as you need it.

Price tables, product specifications and stock levels usually contain no personal data. That is why price monitoring and SERP tracking raise fewer GDPR questions than scraping social profiles.

What do European regulators say about scraping?

Regulators accept some scraping, but under strict conditions. We checked each document below at its source.

RegulatorDocument and dateKey point
ICO (UK) and 11 other authoritiesJoint statement on data scraping and the protection of privacy, 24 August 2023Publicly accessible personal data is still protected; sites must guard against unlawful scraping
CNIL (France)Focus sheet on web scraping under legitimate interest, 19 June 2025Define precise collection criteria, exclude unneeded data, delete irrelevant data, respect robots.txt and CAPTCHA signals
Autoriteit Persoonsgegevens (Netherlands)Guidance on scraping by private organisations and individuals, published 1 May 2024Private parties can usually rely only on legitimate interest, even for public data; scraping often makes this hard or impossible
EDPB (EU)Guidelines on web scraping in the context of generative AI, adopted 8 July 2026; consultation until 30 October 2026Purpose limitation and transparency need particular attention; scrape from reliable sources and minimise data

The CNIL and EDPB texts focus on AI training data. Their data minimisation measures are still a useful benchmark for other scraping projects.

Can a website's terms of service forbid scraping?

Yes, terms of service can restrict scraping as a matter of contract. In Ryanair v PR Aviation (C-30/14, 15 January 2015), the CJEU looked at a database protected neither by copyright nor by the sui generis right. It ruled that the Database Directive does not stop the maker from laying down contractual limits on its use, subject to national law.

Whether a visitor is bound by terms they never clicked depends on national contract law. A breach of terms is usually a civil matter, not a crime. It can still lead to account bans, damages claims or injunctions.

Practical rule: read the terms of each target. If they ban automated access, ask for permission, or use an official API or a licensed data feed.

Is copying data from a website a database right infringement?

It can be, if you take a substantial part. Under Article 7(1) of Directive 96/9/EC, the EU sui generis right protects a database that required a substantial investment. That investment can be in obtaining, verifying or presenting the contents. The maker can then prevent extraction or re-use of all or a substantial part of it.

Two details matter for scrapers:

  • Repeated small extractions count. Article 7(5) forbids repeated and systematic extraction of insubstantial parts that conflicts with normal exploitation of the database.
  • The right lasts 15 years, counted from 1 January of the year after the database was completed (Article 10(1)).

The UK has the same right in the Copyright and Rights in Databases Regulations 1997. Regulation 16 says repeated and systematic extraction of insubstantial parts may amount to a substantial part.

What do the text and data mining exceptions allow?

They allow copying for automated analysis, within limits. Directive (EU) 2019/790 defines text and data mining as automated analysis of text and data to generate information such as patterns, trends and correlations.

  • Article 3 (EU): research organisations and cultural heritage institutions may mine works they can lawfully access, for scientific research. Contract terms cannot override this (Article 7(1)).
  • Article 4 (EU): anyone may mine lawfully accessible content for any purpose, including commercial use. The exception does not apply if the rightholder has expressly reserved it, for online content by machine-readable means, for example.
  • Section 29A (UK): a person with lawful access may copy a work for computational analysis for non-commercial research. Contract terms that prevent this are unenforceable (section 29A(5)).

As of October 2026, section 29A is the only text and data analysis exception in the UK Copyright, Designs and Patents Act 1988. Commercial mining of copyright works in the UK therefore needs a licence or another exception. In both regions, treat robots.txt rules and clear reservations in site terms as opt-outs.

How do you scrape compliantly through a proxy?

Use this 8-point checklist before the first request. It reflects the laws and regulator guidance above.

  1. Collect public data only

    Stay on pages anyone can see without logging in. Do not access login-walled or paywalled content without the owner's permission.

  2. Read robots.txt and the site terms

    Check /robots.txt and the terms before you start. RFC 9309 says robots rules are not access authorisation. The CNIL still lists respecting them as a required measure for personal data.

  3. Honour text and data mining opt-outs

    If a site reserves text and data mining, do not rely on Article 4. Ask for a licence or use an official API.

  4. Respect rate limits

    Throttle requests, spread them over time and back off on HTTP 429 (Too Many Requests) or 503 responses. Never load a site so hard that it slows down for other users.

  5. Avoid personal data

    Filter out names, profiles and contact details you do not need. If you do need personal data, document your lawful basis and a legitimate interests assessment first.

  6. Take only what you need from databases

    Extract the fields you need, not a copy of the whole database. Avoid repeated, systematic extraction that replaces the original service.

  7. Keep records

    Log your purpose, sources, dates and deletion schedule. Records help you answer a data subject, a site owner or a regulator.

  8. Use a provider with clear rules

    Choose a proxy provider with a published acceptable use policy and an abuse desk. PontProxy blocks online banking, government portals, payment processors and outgoing email (SMTP ports 25, 465 and 587).

What does PontProxy allow and block?

PontProxy allows legitimate public-data work only. Permitted uses include public-data web scraping, SEO and SERP tracking, and price and ad verification. Brand protection, market research, social media management and app or website geo-testing are also allowed. The full rules are in our Acceptable Use Policy.

  • Blocked targets: online banking, government portals, payment processors and outgoing email (SMTP ports 25, 465 and 587).
  • Prohibited: fraud, account takeover, credential stuffing, spam, DDoS and any unauthorised access.
  • Abuse desk: [email protected]; reports reviewed within 24 hours.
  • Data we keep: account number, order history, payment records and per-day traffic totals; connection metadata (timestamp, target domain, bytes) kept 7 days for abuse handling, then deleted.

No KYC — no ID, no selfie, no documents. Pay in crypto. We apply GDPR data minimisation to ourselves: we do not collect ID documents we do not need. Details are in our privacy policy, terms and no-KYC page.

Does a proxy change who is legally responsible?

No. A proxy changes the IP address a website sees. It does not change which laws apply to you or who is responsible for the requests. You remain the controller of any personal data you collect, and you remain bound by any terms you accepted.

Proxy providers can also receive lawful requests from authorities. Our privacy policy lists what we keep and for how long.

Proxy legality: frequently asked questions

Web scraping is legal in the UK when you collect public data, respect site terms and handle personal data lawfully. No statute bans scraping as such. The Computer Misuse Act covers unauthorised access, and UK GDPR covers personal data. Copyright and database right protect content, and contract law covers terms of service. Non-commercial research also benefits from the section 29A exception.

Yes. EU law does not ban VPNs or proxies. Your activity is what counts. Illegal access to information systems is a crime under national laws based on Directive 2013/40/EU, and personal data falls under the GDPR. Using a proxy for public-data scraping, price checks or ad verification is a common and lawful business practice.

Not always. Consent is one of six lawful bases in Article 6 GDPR. Private companies usually rely on legitimate interests instead, after a balancing test. The Dutch data protection authority says scraping often makes that test hard or impossible to pass. The CNIL lists required safeguards, such as precise collection criteria and deleting irrelevant data. If you can avoid personal data, do so.

Not by itself. RFC 9309, the robots exclusion standard, says its rules are not a form of access authorisation. Regulators still treat it as relevant. The CNIL lists respecting robots.txt among the required measures for scraping personal data. The Dutch authority says ignoring it weighs against the scraper. In the EU, a machine-readable reservation can also opt content out of the Article 4 mining exception.

Can I scrape a website that requires a login?

Only with the owner's permission. Content behind a login is not public. Accessing it against the conditions you accepted can breach contract, and using someone else's credentials can be unauthorised access under the Computer Misuse Act. Our Acceptable Use Policy prohibits account takeover and credential stuffing, and we act on abuse reports.

Generally yes, when the prices are public and you collect them at a reasonable rate. Prices and product data usually contain no personal data, so GDPR rarely applies. Check each retailer's terms and robots.txt, avoid copying a substantial part of a product database, and throttle your requests. Our price monitoring page shows a practical set-up.

Is it lawful to buy proxies without KYC?

Yes. Paying in crypto without uploading an ID is lawful; what matters is how you use the proxies. PontProxy applies GDPR data minimisation and does not collect ID documents. Instead, it enforces an Acceptable Use Policy, blocks online banking, government portals, payment processors and outgoing email (SMTP ports 25, 465 and 587), and runs an abuse desk. No KYC — no ID, no selfie, no documents. Pay in crypto.

What happens if someone misuses a PontProxy proxy?

We review abuse reports sent to [email protected] within 24 hours. Breaches of the Acceptable Use Policy lead to a warning, suspension or termination without refund, depending on severity. For abuse handling we keep limited records: account number, order history, payment records and per-day traffic totals; connection metadata (timestamp, target domain, bytes) kept 7 days for abuse handling, then deleted. When you report abuse, include the time, the target and the IP address involved.

Collect public UK and EU data the compliant way

Residential IPs from $0.36/GB, used under a clear Acceptable Use Policy. No KYC — no ID, no selfie, no documents. Pay in crypto.

Sources (18)
  1. Computer Misuse Act 1990, section 1 (unauthorised access to computer material) — legislation.gov.uk (2026-10-05)
  2. Computer Misuse Act 1990, section 3 (unauthorised acts with intent to impair) — legislation.gov.uk (2026-10-05)
  3. Computer Misuse Act 1990, section 17 (interpretation) — legislation.gov.uk (2026-10-05)
  4. Directive 2013/40/EU on attacks against information systems — EUR-Lex (2013-08-12)
  5. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex (2016-04-27)
  6. UK GDPR, Article 5 (principles) — legislation.gov.uk (2026-10-05)
  7. Data Protection Act 2018, section 157 (maximum penalties) — legislation.gov.uk (2026-10-05)
  8. Data (Use and Access) Act 2025 — legislation.gov.uk (2025-06-19)
  9. Directive 96/9/EC on the legal protection of databases — EUR-Lex (1996-03-11)
  10. Copyright and Rights in Databases Regulations 1997, regulation 16 — legislation.gov.uk (2026-10-05)
  11. Judgment in Case C-30/14, Ryanair Ltd v PR Aviation BV (ECLI:EU:C:2015:10) — Court of Justice of the EU (2015-01-15)
  12. Directive (EU) 2019/790 on copyright in the Digital Single Market — EUR-Lex (2019-04-17)
  13. Copyright, Designs and Patents Act 1988, section 29A — legislation.gov.uk (2026-10-05)
  14. Joint statement on data scraping and the protection of privacy — ICO and 11 data protection authorities (2023-08-24)
  15. La base légale de l'intérêt légitime : fiche focus sur la collecte par moissonnage (web scraping) — CNIL (2025-06-19)
  16. Handreiking scraping door particulieren en private organisaties — Autoriteit Persoonsgegevens (2024-05-01)
  17. EDPB sheds light on anonymisation and web scraping for generative AI — European Data Protection Board (2026-07-08)
  18. RFC 9309: Robots Exclusion Protocol — IETF (2022-09)

From $0.36/GB · no KYC

Buy proxies