Is Telegram Scraping Legal? GDPR and Telegram's Rules in 2026
Is Telegram scraping legal? The honest answer depends on three things: what you collect, why you collect it and what you do next. This guide walks through GDPR and Telegram's own terms in plain language, with a table of what is generally fine, what is risky and what is off-limits. Checked against the primary sources on 23 September 2026. It is general information, not legal advice.
The short answer
There is no blanket yes or no. Reading public Telegram chats is ordinary use, but once you collect people's data for business, GDPR applies if those people are in the EU. Bulk exports, mass DMs and hoarding data are where legal and ban risk concentrate. Narrow, purposeful, transparent collection is far easier to defend.
Two separate rulebooks are in play. GDPR is law: breaking it can mean regulator orders and fines. Telegram's terms are a contract: breaking them can mean a limited or banned account. A plan can pass one test and fail the other, so check both.
What people mean by "Telegram scraping"
The word covers very different activities, and the legal picture changes with each one. Before you ask whether it is legal, name what you are actually doing.
Most requests we hear fall into one of four buckets. The first is low-risk. The last two are where regulators and Telegram's anti-spam systems tend to look.
Reading public groups and channels and noting relevant messages by hand.
Automatically collecting messages that match a topic, with the author and a link to the source.
Exporting a group's full member list (usernames, names, IDs) into a spreadsheet.
Enriching those lists with phone numbers and then sending bulk DMs.
Why GDPR applies to public Telegram groups
GDPR protects personal data: any information about an identifiable person (Article 4). A Telegram username, a display name, a profile photo and the text of a message all qualify. Posting in an open group does not change that.
There is one real exception. GDPR does not cover purely personal or household activity (Article 2(2)(c)). Reading a chat for your own interest sits outside it. Collecting names and messages to sell to those people does not, even if you are a solo freelancer.
Location matters less than people assume. Under Article 3(2), GDPR also covers companies outside the EU when they offer goods or services to people in the EU or monitor their behaviour. Systematically tracking what EU residents post in chats can count as monitoring.
European regulators have already fined companies for scraping "public" contact data. In December 2024 France's CNIL fined KASPR €240,000 for collecting LinkedIn contact details, including those of users who had limited who could see them, keeping them for five years and informing people late. In 2019 Poland's regulator fined Bisnode PLN 943,000 (about €220,000) for building a database from public registers without telling the people in it. A court later annulled part of that decision, but Poland's Supreme Administrative Court confirmed the core point: taking data from public registers does not remove the duty to inform.
In July 2026 the European Data Protection Board adopted guidelines on web scraping for generative AI. They state plainly that GDPR applies to scraping whenever it involves collecting, storing or organising personal data. They are open for public consultation until 30 October 2026.
- KASPR fine, CNIL
- €240,000
- Dec 2024, scraped LinkedIn contacts
- Bisnode fine, Poland
- PLN 943,000
- Mar 2019, public registers, no notice; core finding upheld
- Maximum fine
- 4%
- of global turnover, or €20M if higher
Four GDPR questions to answer before you collect anything
You do not need a legal department to think clearly about this. You need honest answers to four questions, written down before the first export.
1. What is your lawful basis? For B2B prospecting it is usually legitimate interest (Article 6(1)(f)). Recital 47 says direct marketing may qualify. It is not automatic, though. You must show a real interest, show that the processing is necessary for it, and show that it does not override the person's rights. Consent is rarely practical at scale.
2. Are you collecting the minimum? Article 5(1)(c) asks for data that is adequate, relevant and limited to your purpose. A person who asked for a supplier, plus the message and a source link, is a tight dataset. Ten thousand member IDs "for later" is not.
3. Will people know? Article 14 says that when you collect data from somewhere other than the person, you must tell them who you are, why you have their data and where it came from. You must do this within a month, or at your first message if you contact them.
4. Can you stop on request? Under Article 21, a person can object to direct marketing at any time, and then you must stop. Also skip anything touching health, religion, politics or sexuality. These are special category data under Article 9, and the exceptions are narrow.
Step 1: Name the interest
A specific, real business purpose, such as replying to people who asked for your service.
Step 2: Prove it is necessary
Could you reach the goal with less data? If yes, collect less.
Step 3: Balance it
Would the person reasonably expect this use of what they posted?
Step 4: Tell them and honour objections
Say who you are and where you saw them, and stop at the first no.
What Telegram's terms of service say about scraping
Telegram's rules are stricter than many scraper vendors suggest. We read the current versions on 23 September 2026. Here is what they say, in plain words.
The general Terms of Service forbid using Telegram "to send spam or scam users", and they warn that breaking the terms can lead to a temporary or permanent ban. The Terms of Service for Content Licensing go further. They prohibit access to user content "for any purpose other than ordinary, legitimate, and intended use of the Telegram platform as its user", with an exception for legitimate third-party clients, bots and Mini Apps that follow the rules. They also "firmly" prohibit scraping, indexing, harvesting or aggregating Telegram data to train, develop, benchmark or deploy AI and machine learning models. The ban reaches past training to running such models, too.
The developer terms add detail. The Bot Platform terms (section 4.3) bar collecting data "beyond what is essential" and name "scraping public group or channel contents" to build large datasets as prohibited. Bots also must not send unsolicited messages. The API terms ban actions taken on a user's behalf without their knowledge.
Enforcement usually starts with other users. According to Telegram's spam FAQ, an account reported for spam gets limited: it can only message people who saved its number or who wrote first. For a first offence that lasts a few days, and repeat offences get longer limits.
A limit hurts more than it sounds. If your sales run through one Telegram account, a spam limit also cuts you off from existing clients who never saved your number. Keep any bulk collection far away from the account you sell from, or better, skip it.
See also: How Telegram parser bots and scripts work, and their ban riskWhy exported member lists make poor lead lists
What is generally allowed under GDPR and Telegram's rules
The table below sums up the common scenarios. "Allowed" means generally defensible when done carefully, not guaranteed. Your facts, your country and your purpose can change the answer.
| Scenario | GDPR (EU residents) | Telegram's terms |
|---|---|---|
| Reading public groups as an ordinary member | Fine to read. Duties start when you store people's data for business | Ordinary use of the platform |
| Replying to one person who publicly asked for a service like yours | Often defensible: say who you are and where you saw them, stop on objection | Normal use, as long as it is a personal reply and not a template blast |
| Collecting topic-matched messages with author and source link | Needs a documented purpose, minimal fields and a retention limit | Automated collection is limited to what a compliant client or bot needs |
| Exporting a full member list to CSV | Hard to justify: bulk data, no individual purpose | Harvesting beyond ordinary use is prohibited |
| Mass DMs to a scraped list | Weak legitimate interest; national e-marketing rules may apply too | Spam: accounts get limited or banned |
| Saving phone numbers from profiles | Only if your purpose truly needs them; otherwise leave them out | Bots and API apps may not collect beyond what is essential |
| Storing posts about health, religion or politics | Special category data under Article 9: avoid it | No specific rule; the general terms still apply |
| Using scraped chats to train or run AI models | Needs its own lawful basis; the EDPB's 2026 scraping guidelines apply | Prohibited by the Content Licensing terms, including development and deployment |
| Keeping lead data for years "just in case" | Breaks storage limitation (Article 5(1)(e)) | Bots must delete data they no longer need |
Outside the EU: Russia and Ukraine
Many Telegram communities are Russian- or Ukrainian-speaking, and local law can be stricter than people expect.
In Russia, a change to Federal Law 152-FZ in force since 1 March 2021 (Article 10.1) replaced the old idea of "publicly available" data. Data a person made public can only be spread further on the terms of a separate consent. "I found it online" is weak ground there too.
Ukraine's Law "On Personal Data Protection" (2010) also requires a legal ground for processing. A new GDPR-aligned bill, No. 8153, passed its first reading in November 2024, so check its current status before you rely on the older text.
If your audience mixes EU residents with people in Ukraine, Russia or elsewhere, you rarely know who is where. The simplest safe approach is to apply the strictest set of rules to everyone: collect little, say who you are and stop on request.
A lower-risk workflow: reply to demand, not to lists
The most defensible pattern is also the most practical one: people reply more readily when you write about something they actually asked for. Find people who publicly asked for what you sell, reply to them one by one, and keep only what you need to follow up.
Look at the thread below. One person is describing a need, and nobody else in the chat is. A relevant, personal reply that says where you saw the message is easy to explain to that person, to Telegram and to a regulator.
Anyone else's card payouts delayed this week?
Launching our shop in Germany next month. Looking for a GDPR consultant to sort the privacy policy, the cookie banner and our old customer list. Budget is flexible.
Buying intentHot · 90
Pop-up market at Telliskivi on Saturday, come by
Write your purpose down in one sentence before you collect anything.
Keep the minimum: name or handle, the message, the source link and the date.
Open your first message with who you are and where you saw their post.
Stop at the first "not interested", and record that they objected.
Set a deletion date for leads that go nowhere, and actually delete them.
- Thousands of usernames and IDs, no reason to contact any of them
- Phone numbers collected "just in case"
- Template DMs that people report as spam
- Data kept indefinitely with no deletion date
- Only people who asked for what you offer
- The message, source link and date, nothing more
- A personal reply that says where you saw them
- Unanswered leads deleted on schedule
What a transparent first message looks like
Article 14 sounds bureaucratic, but in practice it fits in the first two lines of a normal reply. You say who you are, where you saw the message and why you are writing. Then you make it easy to say no.
Here is an example reply to the Tallinn post above: "Hi Olivia, I'm Jonas from a small data protection consultancy in Tallinn. I saw your post in E-commerce founders · Tallinn about your German launch. We set up privacy policies and cookie banners for online shops. Happy to share our prices, or just ignore this and I won't write again."
That message names the sender, the source and the purpose, and it offers an easy way out. If Olivia asks how you found her or what you keep about her, answer plainly. Under Article 15 she has a right to know, and a vague answer is exactly what the CNIL criticised in the KASPR case.
Who you are: your name and company.
Where you saw them: the group and the post.
Why you are writing: one sentence, tied to what they asked.
How to stop: say you will not write again if they are not interested.
Red flags in Telegram scraper marketing
Plenty of tools promise that scraping is safe. Treat these claims with care, because none of them survives a close reading of the rules above.
If a vendor says any of the following, ask what it is based on, and remember that the risk stays with you. Their terms rarely take it back from you.
"100% legal" or "GDPR-compliant because the data is public". Public visibility is not a lawful basis.
"No ban risk" while you run exports or DMs from your own account. Reports from recipients are what trigger limits.
"Export members of any group, even private ones." That is the least defensible data you could collect.
"Unlimited automated DMs." That describes spam under Telegram's terms.
No word on retention, deletion or objections. That usually means nobody has thought about it.
Where Leadgram fits, and where it doesn't
Leadgram is itself a collector of the kind this guide describes, so it is fair to hold it to the same rules. It reads public Telegram chats 24/7 and uses AI to score the messages it finds for buying intent. Under GDPR, that makes Leadgram responsible for what it keeps about the people who wrote those messages, and Telegram's terms apply to how it reads the chats. What you get is the result: each lead has a 0-100 score with a reason and the source message, so you can see why a person is relevant before you write. No Telegram account is needed on your side, so your own account is never the one doing the collecting.
We keep little of that data, and not for long. A lead is the message, the author's public name or handle, the source chat and link, the date, and the score with its reason. Where a phone number appears in a lead's public profile or message, Leadgram can store it; it stays out of CSV exports unless you switch it on in the export dialog. Leadgram does not export group member lists. Leads are deleted from the search index automatically 30 days after their last update.
If you wrote in a public chat and want to know what Leadgram holds about you, object to it or have it removed, write to [email protected]. A removed lead stays removed even if the same message is found again. Our data policy covers what the product stores.
A tool does not make outreach lawful for you. You decide who to contact and what to say, so under GDPR you are responsible for that step. The four questions above apply to every lead you act on. For a side-by-side view, see scraping vs AI search.
Example search — sign in free to run it
See also: Scraping vs AI search: the full comparisonHow the 0-100 buying-intent score worksTelegram outreach automation without spam
Frequently asked questions
Is Telegram scraping legal?
It depends on what you collect and why. Reading public chats is ordinary use. Collecting personal data for business brings in GDPR for people in the EU, and bulk harvesting or spam breaks Telegram's terms. Narrow, transparent, purpose-bound collection is much easier to defend. This is general information, not legal advice.
Is data from a public Telegram group still personal data?
Yes, whenever it identifies a person: a username, a name, a photo or the message itself. Regulators have fined companies for scraping publicly visible contact data, including the CNIL's €240,000 fine on KASPR in December 2024.
Can Telegram ban my account for scraping?
Yes. Telegram's terms allow temporary or permanent bans, and accounts reported for spam get limited so they can only message contacts or reply to people who wrote first. Bulk exports from your own account followed by mass DMs is the classic way people lose an account.
Is it legal to scrape Telegram members from a group?
It is the hardest case to defend. A full member list holds many people's data with no individual reason to contact any of them, which is a poor fit for GDPR data minimisation. Telegram's terms also prohibit harvesting beyond ordinary use.
Does GDPR apply if my company is outside the EU?
It can. Under Article 3(2), GDPR covers non-EU companies that offer goods or services to people in the EU or monitor their behaviour. Systematically tracking what EU residents post in Telegram chats may count as monitoring.
Find your next leads in Telegram
Run a search, review scored matches with the reason they fit and the source group, and export a clean list — all from public signal, no Telegram login.