The question arrives as one sentence and contains three, which is why the answers people find online contradict each other. "Is this legal" can mean is the technology lawful, is this particular proxy mine to use, or is the thing I plan to do through it allowed. Those have different answers, and only one of them is usually the reason someone gets into trouble.
We run a free proxy list, so we have an obvious interest in the first answer being reassuring. It largely is. The second question is the one that deserves more attention than it gets, and it is the one our own measurement data speaks to directly.
Nothing here is legal advice. It is a map of which question is which, written by people who operate this infrastructure rather than by lawyers, and the local answer where you live is a matter for someone qualified there.
Question one: is using a proxy lawful?
In most of the world, yes, and unremarkably so. A proxy is an intermediary that relays a request, which is the same shape as a corporate web gateway, a school filter, a content delivery network and every VPN sold on television. Businesses run them by the thousand for caching, filtering, security and testing. There is no general prohibition on routing your own traffic through a machine that agrees to relay it.
The exception is jurisdictional rather than technical. A number of countries regulate circumvention tools directly: approval regimes for VPN providers, restrictions on unapproved services, penalties that in practice fall on operators more often than on users but are written broadly. Those rules change often, are enforced unevenly, and are exactly the situation where general articles are worth the least. If you are somewhere that treats this as a regulated activity, get current local advice, and treat any confident claim in an English-language blog post about your country's law with suspicion.
For everyone else, the technology is not the issue, and the conversation should move to the next question.
Question two: whose computer is that?
This is the one almost nobody asks, and it is the most interesting thing about free proxy lists specifically.
A public free proxy list is assembled by scanning the internet for machines that answer on proxy ports and forward traffic. Some of those are deliberately public services. Many more are servers misconfigured by accident: a default that was never changed, a test left running, a device shipped with an open port. The scanner does not ask permission, because there is nobody to ask, and the operator usually learns nothing about it either way.
Our own engine has discovered 589,918 free proxies and run 129,131,311 checks against them. 362,018 of those addresses never completed a single successful request in their entire recorded history, which is what the population looks like when it is assembled by scanning rather than by anyone offering anything. Roughly 4,023 were answering at the most recent measurement.
What a free proxy population actually looks like
- 590K
- Addresses discovered
- 362K
- Never worked once
- 4K
- Answering right now
- 129M
- Checks run
found by scanning, not by anyone offering
no successful request, ever
at the last measurement
by our own engine
Source: HProxy verification engine, measured 2026-08-11
The legal shape of that is worth stating plainly. Using a computer you were never authorised to use is the conduct that computer-misuse laws in most countries were written to address, whatever the local statute is called. Nobody is being prosecuted for browsing a news site through a stranger's misconfigured server, and the risk of that is not why this matters. It matters because it is the honest description of what a public free proxy usually is, and because it explains the behaviour everyone notices: addresses that vanish without warning, because somebody fixed their configuration.
The same fact underlies the security half, which we cover separately in are free proxies safe. An operator who did not intend to run a proxy is not maintaining it, not securing it, and not accountable for what passes through, and an operator who did intend it has a reason you cannot see.
We publish a free list anyway, and we say what is on it. That is the position we have argued in when free proxies are fine: for a throwaway lookup, checking whether a page is geo-blocked, or seeing what a site serves elsewhere, a short-lived shared address is a reasonable tool. For anything carrying credentials, personal data or money, it is the wrong one, regardless of which law applies.
Question three: what are you doing through it?
The simplest rule on this page. A proxy changes the address a site sees. It does not change how any legal system characterises your conduct.
Reading public pages at a considerate rate is treated very differently from defeating an authentication control, and the presence of a proxy is irrelevant to which of those you did. If an activity would be lawful from your own connection, routing it through a proxy does not make it unlawful. If it would be unlawful, the proxy has not helped, and the belief that it has is where people get themselves into real trouble.
Two areas deserve their own paragraph because they come up constantly.
Terms of service are a contract, not a statute. Most sites prohibit automated access somewhere in their terms. Breaching that generally means the site can suspend you, block you, or pursue a civil claim, not that you have committed an offence, and the two get blurred together constantly in coverage of this subject. It is a real consequence and it is a different category, worth understanding rather than dismissing.
Personal data brings its own regime. Collecting information about identifiable people engages data-protection law in Europe and a growing list of comparable regimes elsewhere, and those obligations attach to you as the collector regardless of the network path. Publicly visible does not mean freely processable, the proxy is not part of that analysis, and this is the area where getting proper advice actually pays for itself.
The six scenarios people are actually asking about
Almost every version of this question is really one of these. Each gets sorted the same way: is the tool lawful, is the proxy yours to use, and what is the activity.
Watching a streaming service from another country. The tool is fine and the proxy is fine if you are paying for one. The activity is a terms-of-service matter with the service, which can restrict or close the account, and it is not a criminal question in ordinary circumstances. The practical obstacle usually arrives first: streaming platforms categorise commercial address ranges aggressively, so most free and VPN addresses simply fail.
Getting around a block at school or work. The legal layer is rarely the interesting one; the policy layer is. On a device or network your school or employer controls, this is their rulebook and their disciplinary process, and a proxy does not make the traffic invisible to a managed device. Our free proxy for school post is honest about how well it works, which is less well than people expect.
Buying limited-release sneakers or tickets. Terms of service prohibit automation almost universally, so that layer is clear. Tickets carry an extra one in the United States, where federal law specifically addresses circumventing the security measures ticket sellers use to enforce purchase limits, which puts that particular case in a different category from most bot activity. We cover the practical side in proxies for ticketing without pretending the rules are not there.
Running several accounts on one platform. A terms question in the ordinary case, and something quite different when the extra accounts exist to obtain money, rewards or credit that would not otherwise be given, which is fraud regardless of the network path. The line is what the accounts are for, not how many there are, which is why our survey proxies page sells geo-targeted research access and says in plain words that it will not help anyone farm rewards.
Testing your own site from other countries. Entirely unremarkable on all three questions, and one of the cleanest uses of a proxy there is. You are the site owner, the traffic is yours, and the only thing you are defeating is your own CDN's geography.
Collecting public pricing or public data. Generally lawful in the ordinary case, subject to the terms of the site and to data-protection law the moment anything identifiable about a person is involved. The proxy is not part of that analysis. What matters is the rate you request at, whether you went around an authentication control, and what category of data you took.
Notice what none of those six turned on: the proxy. In every case the interesting question was the activity or the contract, and the network path was a detail. That is the single most useful thing to internalise about this subject.
Why the operator's answer matters more than yours
There is a second half to this that individual users rarely think about, and it is where the actual enforcement in this industry has landed.
The legal weight in proxy networks has fallen on supply, not on demand. The takedowns worth reading about were about how pools were built: 911 S5 assembled roughly nineteen million addresses through free VPN apps before it was dismantled, RSOCKS sold a botnet of compromised devices as a residential pool, and NetNut had domains seized in an action tied to a supply of around two million compromised consumer devices. Not one of those was about what a customer scraped.
That is the practical reason to care where your addresses come from even when your own use is entirely ordinary. A network built without consent is a network that can disappear on a Tuesday, taking your access with it, and the buyer discovers this at the same moment as everyone else. How to vet a proxy provider covers the questions that separate the two, and who owns your proxy provider covers how hard some of them are to answer.
What this means in practice
Five things worth carrying away, which is about as far as a general article can honestly go.
- The tool is almost never the legal problem. Unless you are somewhere that regulates circumvention specifically, using a proxy is ordinary.
- Prefer a proxy someone meant to provide. Whether that is a paid provider or a genuinely public service, the difference between offered and merely reachable is the whole of question two.
- Judge the activity, not the network. If you would hesitate to do it from your own address for legal reasons, the proxy has changed nothing that matters.
- Know which rules you are breaking. Terms of service, data-protection duties and criminal law are three different systems with three different consequences, and treating them as one blur leads to both needless worry and misplaced confidence.
- A provider with rules is a better sign than one without. An acceptable-use policy that gets enforced protects the pool you are buying into, which is a practical benefit as much as a legal one, and we made that argument in full in no-KYC residential proxies.
If the work has outgrown the point where a scanned open port is an acceptable dependency, that is usually a quality decision before it is a legal one. Our proxy checker will show you what any address really is before you trust it, the free list is there with its uptime measured rather than claimed, and residential proxies start at $0.50/GB for a single gigabyte when the answer is an address somebody is deliberately providing to you.