Which country's law applies to my scraper? ยท three places, and how to find the third

About this documentUpdated ShowHide

Sean McDermott, Co-Founder and CEO, UnGovr

Written by Sean McDermott (with AI assistance) using the LexLint law library, which supplied every legal instrument, status and date on these pages, and the handbook and insight documents on lexlint.io that carry the depth behind each one.

Every law named here links to its summary page on lexlint.io, translated to English (if needed) and restructured to a standard format for human and code use. Every case links to the court's or the regulator's own record where one could be reached.

© 2026 UnGovr, publishing as LexLint. The text and the figures are licensed under Creative Commons Attribution-ShareAlike 4.0: share and adapt them, including commercially, with credit to LexLint (UnGovr) and under the same licence. Please contact LexLint at hello@ungovr.org to discuss other terms. Logos and wordmarks belong to their owners.

Corpus figures as of .

Legal information, not legal advice. This document describes the law as written and dated; it does not apply it to any system. The notice at the foot says what that means.

Where you are, where the scraper runs, and where the target site has legal standing. The first two you know. The third takes a method, and the method is a ladder of evidence from a legal notice down to a domain ending.

1Three places

Where you are

Your organisation is under the law of the place it is established, meaning where it is registered or has an office or staff. That law applies to you everywhere, including when your scraper reads a site in another country.

Where the scraper runs

Where the machine your scraper runs on sits (a cloud region, a vendor's servers, a laptop) is the one fact almost no law depends on, with two exceptions. A data-localisation rule can require certain records to stay inside one country, and then where your copies sit matters. And copyright asks where a copy was made, which is where your scraper made it.

Where the site has legal standing

This one takes work, and the rest of this document is about it.

2Where the site is, for each body of law

A site does not have one location. Each body of law asks its own question, so the answer is a short list: the home of the company that runs the site (its operator), the homes of the people on its pages, and, for the terms, whatever place the terms name.

Body of lawWhere the site is, for this bodyWhat tells you
Computer misuse and unauthorised access Where the machine you reached belongs, which means the operator's country. A site in the US is under the federal Computer Fraud and Abuse Act whichever state it is in. The operator's establishment
Contract (the terms) being researched The terms page: the clause naming the governing law, and the one naming the courts
Copyright and text and data mining Where the copyright owner is, and where the copy is made (for once, where your scraper runs). The EU's mining exception and its opt-out are Article 4 of the 2019 copyright directive. The legal notice; the copyright line on the pages; where your scraper runs
Database right being researched The legal notice
Privacy being researched The privacy policy, which names the controller; the audience the site serves
Anti-circumvention being researched The same as for copyright
Unfair competition and hot news (taking a rival's fresh news) being researched The legal notice; where the site sells

A cell that says being researched is a gap in our reading, not a finding that no law applies, and our research on the question will fill it.

3How to find out where a site is: the evidence, in the order to trust it

Most of that table depends on one question: where is the site's operator? No website states it in one standard place, so you weigh evidence, strongest first.

RungWhat you can findWhereHow far to trust it
1 The site belongs to a government body UnGovr's own index of official domains, which the free tool below reads Authoritative, and the one case where the tool answers outright
2 An entry in a company register for the operator the site names The register the legal notice points to; for larger companies, the global index of legal entity identifiers High, but slow, and it needs a name from a lower rung first. Search that exact name, never the closest match.
3 A legal notice naming the operator and where it is based, the controller the privacy policy names, or the terms' governing law A footer link, required across the EU by Article 5 of the e-Commerce Directive; Germany's Impressum page is the model Medium, and the rung most people will actually reach. The terms' choice of law speaks to contract only, not to criminal or privacy law.
4 The country of incorporation in the site's security certificate The certificate behind your browser's padlock, the extended-validation kind only Medium; fewer sites carry one each year
5 The person or company that registered the domain The domain's public Whois or RDAP record Low. Hidden for most .com-style domains since 2018, often replaced by a privacy service, and often not the operator.
6 A parent domain the index knows The free tool's check one level up: for parks.example.gov it also checks example.gov Inferred, not stated
7 The domain ending The name itself: .de, .fr, .io Inferred, and weak. A .de site is usually run from Germany, but no .io site is run from the British Indian Ocean Territory: .io is sold as a vanity name, and the free tool refuses to guess from twelve such endings.
8 The language, currency and delivery area The pages themselves Evidence about the market, not the operator. These are the signals the EU's General Data Protection Regulation uses to decide whom a site is offered to, not where it is.

One piece of evidence is left out on purpose, though most people reach for it first: where the site's server is. An IP address lookup tells you where the nearest copy of the site is served from, usually a content delivery network near you, not where the operator is. The free tool refuses an IP address for that reason, and computer misuse, the one body of law the server could speak to, is better answered by the operator's country.

The rule for weighing it: two independent signals from rungs 1 to 3 that agree make a place. One makes a probable place. Anything weaker makes a question to write down, which section 6 answers.

4What the free tool answers

LexLint's free tool for this question, resolve_domain_jurisdiction, takes a domain name from a developer or the AI coding assistant they work with. It answers a government site with authority, from UnGovr's index of official domains, and checks the parent domain when the one you asked about is not in the index. Otherwise it infers a country from the country-code ending, except for twelve endings sold as vanity names, and it refuses an IP address outright.

For a private company's site on .com it answers unknown, because nothing in the name says where the company is. The ladder above is what you do next, starting with the site's legal notice. The developer reference is at https://mcp.lexlint.io/.

5When a model is in the loop

If an AI model reads what you collect, ask whose model it is: the place where its provider is established joins your list. If a general-purpose AI model is trained on what you collect, its provider owes a duty of its own to respect the opt-outs site owners publish against mining, under Article 53 of the EU's AI Act (since ). The handbook's document on where the parties are carries the rule for each body of law.

6When you cannot tell

When the evidence runs out and you cannot tell where a site is, assume the stricter of the places it could be, and write down that you could not tell and what you checked. That note belongs in the record that the careful-scraper document, later in this brief, tells you to keep.

The long read. Where the parties are, and whose law that makes applicable carries the depth behind this document, with every citation and its date.