Legal & Compliance

Are Residential Proxies Legal? Rules, Risks and Sourcing

Routing traffic through a rented home IP address breaks no law by itself. The exposure comes from the request you send, the data you keep, and how the household on the other end was recruited.

Published Updated 11 min readBy The Proxies.click Benchmark Team

Key takeaways

  • Using a residential proxy is lawful in the United States and the European Union, and no statute in either place prohibits routing your own traffic through a third-party IP address.
  • A proxy changes the apparent origin of a request and changes nothing about the legal duties attached to it, so contract, data protection and copyright obligations all survive the routing.
  • The Van Buren and hiQ line of reasoning narrowed the CFAA around publicly accessible data, while the same litigation showed that breach-of-contract claims based on site terms remain very much alive.
  • If your scraped data identifies people and you are established in the EU or targeting people there, you are a GDPR controller with lawful basis, notice, minimisation and erasure obligations.
  • Consent quality in the network you rent is a supply-chain risk you inherit, because an undisclosed bandwidth-sharing SDK can evaporate your pool and surface in your customers' vendor reviews.

Using a residential proxy is lawful in the United States and in the European Union. Neither has a statute making it an offence to send your own traffic through somebody else's IP address, and the technique is standard practice in market research, ad verification and brand protection. That is the easy half of the answer, and where most articles stop.

The harder half is that a proxy alters the apparent origin of a request and alters nothing else. Every duty attaching to the same request from your own address still attaches. What the proxy adds is a supply chain: a stranger's home connection, recruited by a company you have no contract with, under terms you have never read.

What the proxy changes, and what it leaves untouched

Separate the routing question from the conduct question. Almost every dispute is about the second.

ActivityDoes the proxy change the analysis?
Routing traffic through a rented residential IPNo, and the routing itself is lawful in the US and EU.
Reading pages a site publishes to anyone, logged outNo. Authorisation turns on the site's access controls rather than your egress address.
Logging in, using purchased or fabricated accounts, defeating an auth checkNo, and it can worsen the picture by suggesting deliberate evasion.
Collecting data that identifies peopleNo. Data protection duties attach to whoever decides the purpose.
Copying protected content or a substantial part of a databaseNo. Intellectual property claims are about the copying and reuse.
Continuing after a cease-and-desist or a technical blockNo, and it frequently turns a disagreement into a lawsuit.
Whether inserting a residential proxy changes the legal analysis of a given activity.

The CFAA and the line around authentication

The Computer Fraud and Abuse Act, 18 U.S.C. § 1030, reaches access "without authorization" and access that "exceeds authorized access". For two decades the open question was whether breaking a written rule, such as a term of service, could turn permitted access into a federal offence.

Van Buren v. United States (2021) answered part of it. The Supreme Court read "exceeds authorized access" narrowly: someone entitled to obtain information does not exceed authorised access by obtaining it for an improper purpose. The Court framed this as a gates-up-or-down inquiry, and declined to decide whether a purely contractual restriction, with no technical gate behind it, can supply the limit.

In the hiQ Labs v. LinkedIn litigation, the Ninth Circuit reasoned that scraping information a site makes available to the general public, with no authentication required, likely does not amount to access "without authorization". Read that with three limits in mind: one circuit, reasoning at the preliminary-injunction stage, about data behind no login. The scraper lost anyway. After the district court granted LinkedIn summary judgment on breach of contract in late 2022, the parties entered a stipulated consent judgment and permanent injunction. An agreed judgment sets no precedent, but the lesson is hard to miss.

Terms of service are the claim that keeps landing

Contract is the quiet workhorse of scraping disputes. It needs no proof of hacking, damage or bad intent, only assent to a set of terms and a breach of them.

Whether assent exists turns on how the terms were presented. Terms accepted by clicking through a registration flow stand on firmer ground than terms linked in a footer nobody saw. The trap is indirect assent: somebody in sales opened a corporate account years ago, or an engineer took a trial to inspect the markup. Your crawler runs logged out and the company is still bound.

The EU position is similar and reinforced by a specific ruling. In Ryanair v PR Aviation (Case C-30/14, 2015) the Court of Justice held that where a database is protected by neither copyright nor the sui generis database right, the Directive's mandatory lawful-user protections do not apply, leaving the owner free to impose contractual conditions subject to national law. An unprotected database can still carry an enforceable contract.

GDPR obligations when scraped data identifies people

Names, usernames tied to an individual, profile photographs, review text attributable to a person and IP addresses are all personal data. Public availability removes neither that status nor the need for a lawful basis. Under Article 3 the GDPR reaches you if you are established in the EU, or if you process data about people in the EU while offering them services or monitoring their behaviour.

  • A lawful basis under Article 6. Legitimate interests is the usual candidate, and it requires a documented balancing assessment weighing your purpose against the reasonable expectations of the people involved.
  • Transparency under Article 14. Data you did not collect from the person still carries a duty to inform them, generally within a month. The disproportionate-effort exemption is narrow and must be reasoned and recorded.
  • Special categories under Article 9. Data revealing health, political opinions, religious belief, trade union membership, sexual orientation or biometrics has no legitimate-interests route. Filter it out if your crawl can pick it up incidentally.
  • Minimisation and retention. Collect the fields you have a purpose for and run a deletion schedule. "We kept everything in case it became useful" is the sentence regulators quote back.
  • Data subject rights. Access, rectification and erasure requests must be servable, meaning you can locate one individual inside a scraped corpus. Retrofitting that into a flat archive is painful.

The proxy is irrelevant to all of it. You determine the purposes and means, so you are the controller whatever address the request left from. Where the provider handles personal data on your behalf, a processor relationship and an Article 28 agreement may be in play. Raise that with the vendor.

Individual facts do not attract copyright. The expression around them frequently does: article text, product photography, editorial descriptions. Building an internal index sits in a different risk band from republishing the material or training a public product on it, and that gap is where most of the argument happens.

The EU adds a layer with no direct US equivalent. Directive 96/9/EC gives a database maker a sui generis right where there was substantial investment in obtaining, verifying or presenting the contents, covering extraction of a substantial part and repeated systematic extraction of insubstantial parts. One long-standing limit matters here: the qualifying investment must be in collecting existing data, and money spent creating that data does not count, which is why several listings databases have failed to qualify.

Directive (EU) 2019/790 then carves out text and data mining. Article 3 covers research organisations and cultural heritage institutions with lawful access. Article 4 is a general exception for anyone with lawful access, subject to rightsholders reserving their rights in a machine-readable way for content published online. That mechanism is why robots directives and licence metadata carry legal weight in the EU that they lack in the US.

Jurisdiction multiplies the analysis

Four legal systems can attach to one request: the law where your company is established, the law governing the target and its terms, the law protecting the people whose data you collect, and occasionally the law where the exit sits. A UK company scraping a US site through a German exit for a dataset about French consumers has touched all four. Picking an exit geography on purely technical grounds can import rules you were not planning on, worth holding in mind alongside the proxy geotargeting guide.

Most residential bandwidth comes from software development kits embedded in free consumer applications, a mechanism described in what are residential proxies. The developer is paid per active device. The household gets a free app. Somewhere in that flow sits a disclosure, ranging from an explicit choice at install time to a clause buried in a licence nobody finished reading.

That paragraph decides whose data allowance your crawl consumes, whose IP reputation absorbs the consequences, and who fields the abuse complaint when somebody does something ugly. A workable test: if explaining the arrangement to the person whose router carries your traffic would be uncomfortable, the consent is thin. Thin consent carries an operational cost, because pools built on undisclosed SDKs churn hard whenever an app store removes a host application.

Questions worth putting to a vendor in writing

  1. Where does your residential bandwidth come from, by proportion across each sourcing model?
  2. Where in the user journey is bandwidth sharing disclosed, and can you show me that screen?
  3. Can a participant see their usage and stop taking part without losing the app?
  4. Do you compensate participants, and how?
  5. What know-your-customer checks do you run on buyers?
  6. What is your process when a household or an ISP complains about an exit?
  7. Will you put sourcing representations in the contract, with a termination right if they prove wrong?
  8. Do you offer a data processing agreement, and who are your subprocessors?

Judge the answers on specificity and speed. A vendor that meets the first question with "ethically sourced" and no mechanism has told you something.

Sourcing is a supply-chain risk you inherit

Treating consent as purely the seller's ethical problem understates your exposure. Four concrete risks land on the buyer.

  • Continuity. A pool assembled from a handful of host applications can lose most of its exits in a week when one is pulled. Your success rate drops and nobody explains why.
  • Procurement. Enterprise security reviews increasingly ask where proxy IP addresses originate. "We do not know" stalls deals.
  • Contractual. Without representations and an indemnity, a sourcing scandal at your provider becomes your problem and your remediation cost.
  • Evidentiary. If traffic attributed to a household is traced to your workload, a documented provenance chain beats improvising one afterwards.

The mitigation is ordinary vendor management: written representations on consent and disclosure, notice of material change to sourcing, a termination right, a data processing agreement where personal data flows, and an annual re-check. It applies with more force to anything free, for reasons set out in free proxy lists and their risks.

A defensible operating posture

None of this makes a programme bulletproof. It makes one explainable, which is usually what you need when somebody asks.

  1. Stay logged out unless you have a defensible reason to authenticate, and never fabricate accounts.
  2. Read the target's terms and record who at your company has ever accepted them.
  3. Honour robots directives and rate limits, and back off when a target signals distress. Techniques are in how to avoid getting blocked web scraping.
  4. Stop on receipt of a cease-and-desist and take advice before resuming.
  5. Filter personal data out at collection time unless you have a documented lawful basis.
  6. Log provenance: which provider, which exit country, which target, on what date, under which policy version.
  7. Write an acceptable-use policy for your crawlers and make engineers read it.
  8. Re-check sourcing representations annually, using the checklist in how to choose a proxy provider.

The discipline that keeps you inside the lines usually improves results anyway. Lower request rates, fewer authenticated sessions and tighter collection all shrink your footprint on the target. Our live benchmark table and its methodology document what we measure across every provider we track, and the engineering practice is in the web scraping proxy guide. For your own programme, talk to a lawyer.

Frequently asked questions

Are residential proxies legal in the US?

Yes. No US federal statute prohibits routing your traffic through a residential IP address you have lawfully rented, and businesses use residential proxies routinely for research, ad verification and security testing. Legal exposure comes from what you do through the proxy: bypassing authentication, breaching terms you accepted, infringing copyright, or mishandling personal data are all problems regardless of the network path.

Is web scraping with a proxy illegal?

Scraping information that a website publishes openly, without logging in and without defeating any access control, is generally treated as lawful in the US and the EU, and using a proxy does not change that assessment. The risk rises sharply once you authenticate, create accounts, ignore a cease-and-desist, or collect personal data without a lawful basis. The proxy is never the deciding factor.

Does using a proxy violate a website's terms of service?

Frequently, yes, because many terms prohibit automated access, circumventing technical measures, or both. Whether that matters depends on whether anyone at your organisation ever assented to those terms, which is usually decided by how they were presented and whether an account was created. Breach of contract does not require proof of hacking, which is why it is the claim plaintiffs most often succeed on.

Do I need consent from the people whose data I scrape?

Under the GDPR you need a lawful basis, and consent is only one of six. Most scraping programmes rely on legitimate interests, which requires a documented balancing assessment rather than a checkbox. You also owe affected individuals transparency information under Article 14 unless a narrow exemption applies, and you must be able to service access and erasure requests against your dataset.

What does ethically sourced actually mean for a proxy provider?

On its own, nothing. It is a marketing phrase with no standard behind it. A meaningful answer describes the mechanism: where the bandwidth comes from, at what point in the user journey sharing is disclosed, whether participants are compensated, whether they can see and stop their participation, and what happens when a household complains. Ask for those specifics in writing and judge how concrete the reply is.

Can I be held responsible for what happens on the exit node?

You are responsible for the traffic you generate, and that traffic appears to originate from a stranger's home connection. If your workload triggers an abuse complaint, the household and their ISP see it first. Keeping provenance logs, an acceptable-use policy and a provider contract with clear representations is the practical way to show which traffic was yours and under what terms.

See how the providers actually perform

Our benchmark tests 18 residential proxy providers around the clock from US and EU infrastructure. Success rate, latency, fraud score and price per 100GB, refreshed every five minutes.

Proxy Fundamentals9 min read

What Are Residential Proxies and How Do They Work?

Residential proxies borrow IP addresses that ISPs handed out to real households. That single fact explains their price, their latency, and why anti-bot systems treat them differently from server IPs.

Read the guide
Scraping & Automation11 min read

Proxies for Web Scraping: A Practical Setup Guide

Picking a pool is the short part of the job. This is the wiring: gateway credentials, session identifiers, retries that do not multiply your bill, and the instrumentation that shows which exits are failing.

Read the guide
Buying Guides10 min read

Free Proxy Lists: What You Actually Pay For Them

Somebody is paying for the bandwidth on those open ports. This is what they get in return, described mechanically, plus the short list of jobs where the trade is still acceptable.

Read the guide