The coches.net Actor does not return private sellers' phone numbers. Not by default — at all, with no setting to change it, on a site that publishes them in its own page source. This article explains why that is the defensible engineering position rather than a missing feature.
What Article 14 actually requires
Article 14 of the GDPR covers the case where you obtain personal data from somewhere other than the person it concerns. When you do, you have to tell them: who you are, what you are doing with it, on what basis, how long you will keep it, and what rights they have. As a rule, within one month of obtaining the data.
It is not an obscure provision. It exists precisely because collecting data about people without their involvement is the situation most likely to leave them unaware — which is a description of scraping.
Why scraping is the textbook case of indirect collection
When somebody fills in your form, they know. When you read their advert and store their mobile number in a database, they do not. Article 14 is written for the second case, and no amount of the data having been publicly visible changes which case you are in.
Now do the arithmetic. Roughly 107,000 private sellers publish adverts on coches.net. Informing each of them within a month, individually, is not something I can do, and it is not something a user of the Actor can do either. The obligation does not become smaller because it is impractical.
Public is not the same as consented
This is the misconception the whole decision rests on. A phone number being visible on a web page means the person published it so that buyers could contact them about that car. It does not mean they agreed to be in a database, contacted by a dealer aggregator, or included in a dataset sold to third parties.
Public accessibility removes a technical barrier. It does not create a lawful basis, and it does not switch off the information duty.
The toggle that solves nothing
The obvious product decision is a setting: includePrivatePhones: false by default, and let the user turn it on if they believe they have a basis. It looks responsible. It is not.
What that setting actually does is transfer an obligation nobody can discharge to somebody who mostly will not realise they have accepted it. The tool keeps the appearance of caution while the consequence lands on a user who ticked a box in a form. Declining to collect the field is the only version of the decision that does not depend on somebody else's compliance work.
So: when seller_type is private, seller_phone is null. Always. There is no setting, and there will not be one.
Why dealer numbers are different
A dealer's number is a business contact detail, published by a commercial entity for the purpose of receiving commercial contact. The expectation attached to it is materially different from a private individual's mobile, and dealers are the segment that buys and sells at volume — which is to say, the segment most B2B use cases actually need.
Dealer numbers are returned on 100% of dealer listings and 100% of dealer profiles. That is not a loophole; it is the line drawn where the difference actually is.
What you still get
Every vehicle field for private listings: price, mileage, year, power, environmental badge, province, city, photos, publication date and the price rank where present. The car data is complete. What is missing is one column, and the listing URL in every row leads to the site's own contact form — which is the route the seller chose to offer.
If your analysis is about the market rather than about reaching individuals, nothing is missing at all. Note only that private listings carry the valuation on 38.2% against 86.6% for dealers, which is a bias to plan around.
Your own obligations do not disappear
Even with personal contact details excluded, you may still be processing personal data — a private seller's advert is data relating to an identifiable person once you combine it with anything else. What you keep, for how long, and what you do with it remains your decision and your exposure.
Anyone can ask to be excluded from future runs: data removal. That route exists because a removal process that only appears in a privacy policy is not a process.



