Data Collection and Scraping Risk Checklist: Sources, Terms, Access, and Output

By ·

Sixteen phases for a data collection program, organized around the source register that replaces a single scraping policy. The early phases classify the material, test whether a gate existed under Van Buren, and determine whether a contract was formed and is enforceable - the sequence that actually decides these disputes. A dedicated phase runs the output analysis, which carries the uncapped statutory damages and is routinely done last or not at all. A worked comparison runs four different sources through the framework to show why one policy cannot cover them. The site-operator phases build the contractual, technical, and evidentiary position that makes a claim available, including seeded records and the API that converts scraping into licensing. Later phases cover the provenance record, retention and deletion, the cease-and-desist exchange from both sides, the injunction, and the governance controls that keep the register current.

IP and Technology > Information Technology | Checklist | Published 23 October 2025 - Updated 13 August 2026 | Casey Scott McKay - marksy.us

Summary. Sixteen phases for a data collection program, organized around the source register that replaces a single scraping policy. The early phases classify the material, test whether a gate existed under Van Buren, and determine whether a contract was formed and is enforceable — the sequence that actually decides these disputes. A dedicated phase runs the output analysis, which carries the uncapped statutory damages and is routinely done last or not at all. A worked comparison runs four different sources through the framework to show why one policy cannot cover them. The site-operator phases build the contractual, technical, and evidentiary position that makes a claim available, including seeded records and the API that converts scraping into licensing. Later phases cover the provenance record, retention and deletion, the cease-and-desist exchange from both sides, the injunction, and the governance controls that keep the register current.

Keywords: source register · material classification · gate analysis · van buren · hiq public data · browsewrap notice · clickwrap assent · account provenance · robots txt · rate limiting · technical measure circumvention · trespass to chattels metrics · output analysis · personal data stripping · biometric exposure · provenance record · retention and deletion · source intake gate · cease and desist response · licensing alternative


What this checklist is for

This is the working document for a scraping or data collection program, on either side. It does not re-teach the doctrine. If you cannot say in one sentence why Feist leaves a dataset unprotected, read Who Owns the Data? first. The reasoning behind each box is in Running or Defending a Data Scraping Program. This document tells you what to do, in order.

Who should use it. In-house counsel at a company whose product depends on collected data; outside counsel advising on a new pipeline or answering a demand letter; site operators building a defensible position against collectors; and diligence counsel who has just been told the target's dataset is "public information."

What you'll need before you start. A list of every source the pipeline touches — from network logs, not from the code, because the two differ; the terms of service for each, captured with a date; the robots.txt for each; the pipeline's ingestion and retention configuration; the account credentials used and how they were obtained; server-side collection volumes; and the product requirements, so you can ask what is actually used.

The worked matter. Wrenfield Labs builds commercial property analytics. It scrapes county assessor records; a commercial listing site behind a free account; a review platform's public pages; and a competitor's published market reports. It has one scraping policy covering all four.

| Phase | What you accomplish | Typical elapsed time | |---|---|---| | 1 | Build the source register | 2-5 weeks | | 2 | Classify the material per source | 1 week | | 3 | Test for a gate | 1 week | | 4 | Test whether a contract was formed | 1-2 weeks | | 5 | Test circumvention and system harm | 3-5 days | | 6 | Run the output analysis | 2-4 weeks | | 7 | Work the four sources to conclusions | 1-2 weeks | | 8 | Segment the pipeline and strip at ingestion | 4-10 weeks | | 9 | Build the provenance record | ongoing | | 10 | Set retention, minimization, and deletion | 4-8 weeks | | 11 | Site operator: build the contractual position | 4-8 weeks | | 12 | Site operator: build technical and evidentiary controls | 4-10 weeks | | 13 | Handle the cease-and-desist, either side | 2-6 weeks | | 14 | Prepare for the injunction motion | 6-10 weeks | | 15 | Price the licensing alternative | 2-8 weeks | | 16 | Install governance and review | ongoing |


Phase 1 — Build the source register


Phase 2 — Classify the material per source


Phase 3 — Test for a gate


Phase 4 — Test whether a contract was formed


Phase 5 — Test circumvention and system harm


Phase 6 — Run the output analysis


Phase 6A — Training-corpus additions

Where collected data feeds a model, three obligations attach on top of everything in Phase 6, and they should be recorded in the same register.


Phase 7 — Work the four sources to conclusions


Phase 8 — Segment the pipeline and strip at ingestion


Phase 9 — Build the provenance record


Phase 10 — Set retention, minimization, and deletion


Phase 11 — Site operator: build the contractual position


Phase 12 — Site operator: build technical and evidentiary controls


Phase 13 — Handle the cease-and-desist, either side


Phase 14 — Prepare for the injunction motion


Phase 15 — Price the licensing alternative


Phase 16 — Install governance and review


Phase 15A — Diligence: buying or selling a company whose product runs on collected data

Every issue in this checklist arrives in an acquisition as a representation the seller makes and the buyer accepts. Run this pass from either side.

What the buyer should request.

What the buyer should not accept.

What the seller should do twelve months before a process.

Phase 16A — Cost and timeline

| Task | Elapsed | Cost | |---|---|---| | Source register and classification | 2-5 weeks | $20k-$60k | | Per-source legal analysis | 1-2 weeks each | $8k-$25k each | | Pipeline segmentation and ingestion stripping | 4-10 weeks | $40k-$150k | | Provenance record, contemporaneous | ongoing | $15k-$40k/yr | | Provenance record, reconstructed under deadline | 6-12 weeks | $80k-$250k | | Retention automation and deletion proof | 4-8 weeks | $30k-$90k | | Site-operator contractual and technical build | 6-12 weeks | $50k-$160k | | Cease-and-desist exchange | 2-6 weeks | $10k-$40k | | Preliminary injunction, either side | 6-10 weeks | $150k-$500k | | Through judgment | 18-36 months | $600k-$2.5M | | Biometric class action exposure | — | uncapped statutory | | Licensed feed | 2-8 weeks | negotiated |

Key Authorities at a Glance

| Authority | What it provides | Phase | |---|---|---| | Feist Publications, Inc. v. Rural Telephone Service Co., 499 U.S. 340 (1991) | Facts unprotected; thin compilation protection | 2 | | 17 U.S.C. § 103 | Compilations | 2, 12 | | 17 U.S.C. § 107 | Fair use | 6 | | 17 U.S.C. § 1201 | Anti-circumvention; interoperability exemption | 5 | | 18 U.S.C. § 1030 | CFAA and the civil action | 3 | | Van Buren v. United States, 593 U.S. 374 (2021) | Gates-up-or-down reading | 3 | | hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022) | Public data likely outside "without authorization" | 3 | | 18 U.S.C. § 1839 | Reasonable measures | 12 | | Intel Corp. v. Hamidi, 71 P.3d 296 (Cal. 2003) | Trespass requires actual harm | 5 | | Andy Warhol Found. v. Goldsmith, 598 U.S. 508 (2023) | Transformative use narrowed | 6 | | 15 U.S.C. § 45 | FTC unfairness | 6 | | 740 ILCS 14 | Biometric identifiers; uncapped damages | 6 | | Tex. Bus. & Com. Code § 503.001 | Texas biometric statute | 6 | | Wash. Rev. Code ch. 19.373 | Consumer health data | 6 | | Cal. Civ. Code §§ 1798.100-1798.199.100 | Obligations over collected personal information | 6 | | Regulation (EU) 2016/679 | Lawful basis and notice | 6 | | Fed. R. Civ. P. 65 | Injunction and bond | 14 | | eBay Inc. v. MercExchange, L.L.C., 547 U.S. 388 (2006) | Injunction standard | 14 |

The five things people get wrong

One policy for every source. Four sources produce four answers, and a uniform policy is wrong for at least one of them — usually the one that generates the claim.

Analyzing access and stopping there. Whether you may collect is half the question. Whether you may hold and use what you collected is the half with the uncapped statutory damages.

Keeping the raw pages "in case we need them." That converts a transient copy into a retained corpus, with every copyright and privacy consequence that follows.

Reconstructing provenance under deadline. Five to ten times the cost, a worse document, and a diligence finding that could have been avoided for $20,000 a year.

Treating "public record" as "unrestricted." Government data frequently carries bulk-access restrictions and fees, and those are contractual or statutory and enforceable.

Related Documents

Articles

Guides

Checklists

Toolkits


This document is general information about the law, not legal advice, and does not create an attorney-client relationship. Trademark and copyright outcomes turn on specific facts. Marksy is not a law firm.

Read this article on Marksy