Licensing Working Group/Minutes/2026-03-09
OpenStreetMap Foundation, Licensing Working Group (LWG) - Agenda & Minutes
9 March 2026, 18:00 UTC
Participants
- Kathleen Lu (Chairing)
- Dermot McNally
- Tom Lee
- Craig Allan (OSMF Chairperson)
Absent
- Simon Hughes
Administrative
Adoption of past minutes
- 2026-02-09 Approved
Minutes by Dorothea Kazazi.
Any updates on reported attribution cases?
Reports in OTRS:
- Ticket#2021081210000057 printed maps with false copyright
- Ticket#2022011910000082 interparcel.com: Dermot Emailed them on 10th Nov, no reply
- Ticket#2022012610000149 https://poster.printmijnstad.nl/editor/city
- Ticket#2022033010000217
- complaint that Aberdeen city council may not be attributing correctly – https://www.aberdeencity.gov.uk/news/consultation-starts-street-improvements-ashgrove-road
- Note that Aberdeen credits Ordnance Survey, so possible OS is using OSM as one of many sources and the full attribution is not getting carried through
- Ticket#2022032710000125 - https://www.evri.com/find-a-parcelshop
- Hermes UK changed name to evri. So this is an old issue.
- Ticket#2022062610000078 -
- Härryda, Sweden, uses OpenStreetMap for an app they developed. Inside the app there are no license references to OSM.
- You can see the app on the Google Apps store here: https://play.google.com/store/apps/details?id=se.harryda.medborgar.app&gl=US
- Ticket#2021120810000146 mondialrelay.fr not attributing correctly
- Ticket#2022120510000177 — Club Vosgien complaint – any reply?
Board items
OpenCollabMap query
Trademark agreement draft has been shared with the Board. Board has signed agreement.
hotelmap.com
| Email shared by the LWG |
|---|
| Dear LWG,
We sent this notice to Hotelmap.com a couple of weeks ago. We got no notice from them. I see this case as specifically problematic, as Hotelmap.com is deliberately changing Mapbox's attribution to hide OSM and add their own. I noticed the issue, as it's the official booking site for the Geospatial World Forum. How should we proceed with it? Can we send a more direct message? Best, Dear team at Hotelmap.com, We have noticed you are using OpenStreetMap-based tiles for the map background. Based on your page, it appears you are using Mapbox (I have checked this page https://hotelmap.com/MG968). However, using OSM data through a third party still requires citing the source of the map style and map data. We have noticed that this attribution is not present in Hotelmap.com. Mapbox provides guidance on its website (https://docs.mapbox.com/help/dive-deeper/attribution/) on how to attribute a map using its libraries and styles, including OSM-based ones. In addition, OpenStreetMap has a copyright page with more information on how to cite OSM data-based maps: https://www.openstreetmap.org/copyright. If you require any clarification, we would be happy to assist. Héctor Ochoa Ortiz¹ |
Hotelmap is a Mapbox customer and Tom Lee has reached out to them. Nothing to report yet.
From Operations: API/tile overuse abusers, 1. IPRoyal botnet issue, 2. Bright Data
| Emails shared by the LWG |
|---|
| From IPRoyal
---
Dear OpenStreetMap, Our Position Our Continued Commitment Conclusion --- From Paul Norman (OWG) There's a few issues
Grant may have more specifics since he's more in touch with the issue than I am. My main concern with giving them any data is it changes the framing from "we don't want any traffic from your proxy network" to a whack-a-mole where they can argue every instance of abuse --- From Tom Hughes (OWG) This all makes good sense, particularly the portions about revealing private details of OSM methodology, and the bit about wanting to avoid getting into a whack-a-mole situation. If we're unable to definitively associate IPs with this specific network, reporting false positives might also give them a pretext for ignoring our request. --- 2. Bright Data From OWG:
---
Dear Mr Baker, For clarity, our position is straightforward:
You asked for "full details" of what we characterise as scraping abuse and why Bright Data is involved. At a high level, the abuse we are addressing includes:
We publish full global data exports specifically so that third parties do not need to scrape operational websites/services: The data is available under the Open Database License (ODbL). Given these bulk download options, there is no operational necessity to extract OpenStreetMap data by scraping our public-facing websites and services. Accordingly, we do not authorise any Bright Data customer or user to access OpenStreetMap services via Bright Data's network for automated crawling/scraping or other high-volume automated collection, and we withdraw any implied permission for such access. Evidence and disclosure: Practical next steps for Bright Data:
For the avoidance of doubt, controls that merely restrict "unverified users", or that require us to pursue individual customers, will not be sufficient. We require measures that block all users' attempts to access OpenStreetMap services via Bright Data's services. # A current list of Bright Data egress IP addresses/ranges (for all relevant products: residential proxy, datacentre proxy, SDK/bandwidth-sharing, scraper tooling), or an alternative reliable method to identify Bright Data traffic (e.g., a stable header/token or published attribution mechanism), so we can validate attribution on our side. # A brief description of the customer controls and enforcement actions Bright Data will apply to prevent recurrence (e.g., domain blocks, customer suspension/termination for attempts to target OSM services, and monitoring/alerting). Once we have (2), we can compare against our logs and revert with a focused summary of what we can substantiate and what mitigations appear effective. --- From Bright Data’s counsel: Thank you for your email of 19 February which I have now been able to discuss with Bright Data. |
Issue: bot networks scraping the osm.org API and OSMF tiles.
Actions taken
- The operations team tried to get them to stop and some of them are pushing back.
- The operations team wrote politely, after feedback from the LWG, to several operators of proxy networks.
IPRoyal wrote back but they won't stop and they ask for more information. The operations team is resistant on providing more info, as it may provide more ways to them to evade.
LWG's stance seems to be: There is nothing that the LWG can do. We have provided legal language for communications to them.
The party that operates a proxy service probably doesn't want to:
- extend proactive guardrails to any party that asks for it
- particularly enable this customer
- subvert whatever detection systems we put in place
Suggestions
- share those IPs
- file a lawsuit - the Operations team would have to go to the board and ask for money
- ask the OPS what they ask the LWG to do. If they want to proceed with a lawsuit, they should ask the board for money.
Other points mentioned during discussion
- It is not possible for us to stop them by physical means.
- IPRoyal signaled a level of sophistication and familiarity with this kind of request that is unsurprising.
Action items
- Tom Lee to draft a reply to Paul that the LWG doesn't see any additional action that LWG can take. The Operations team can take the issue to the board, if they want to escalate, or they could consider accepting IP Royals offer. Tom will share the reply with Kathleen, before sending.
- Kathleen to modify Tom Lee's draft response to Paul and email the Operations team about Bright Data.
Second part of the discussion towards the end of the meeting:
OWG and scraping
Kathleen can copy the board when the LWG replies to the OWG.
These are requests routed through proxy services, hitting our tiles and API and overloading the infrastructure. OPS has been sending mutiple cease and desist letters to the services, in order to stop them from sending traffic to OSM. A couple of the services have pushed back, asking for the IP addresses we are seeing. The OWG is reluctant to provide that level of detail, as they might figure out how we detect them. Neither side wants to be the first to provide information.
The LWG can't do anything more.
Options
- Could hire a lawyer to sue them.
- No money for an attorney.
- Provide some IP addresses.
- This will probably not resolve the issue.
- Use a proprietary solution like Cloudflare.
- We were using Cloudflare and recently switched to Fastly.
Suggestions
- Craig proposed to talk with Paul and Grant.
- Technical solutions might probably be the easiest and cheapest for OSM to implement
Other points mentioned during discussion
- OWG does not have any easy technical solution.
- The data is free and they can have it via the planet files.
- AI is spreading widely and everyone wants to scrape data.
Done on March 9, 2026.
Redacted topic
Not discussed.
Queries to legal-questions
Large copyright infringement (Dopper - water taps) - Ticket#2025040310000645
| Email shared by the LWG | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| I am a long-time french OSM contributor, and I've been using Google Maps lately (I know, it's bad) for a hiking trip. I found out that a brand named "Dopper" (https://www.dopper.com/) has imported 130.000+ water tap POI from OpenStreetMap on Google Maps in Europe, in order to promote their water bottles.
Although I can't confirm that the 130 000 POIs have been "stolen" from OSM, 100% of those that I have checked have the exact same coordinates (even when the water tap doesn't exist anymore) on Google Maps and OSM. Here are a few examples:
Of course, they also use an OSM-based map on their website without attribution (https://www.dopper.com/products/tap-map), which reference all the water taps (same coordinates than OSM). Even if I can't prove that Dopper has been adding all of these water taps to the map, every Google Maps POI has a link to their website, and they have communicated on this marketing campaign on internet : https://localyse.eu/cases/localyse-helps-dopper-to-make-water-taps-visible-in-google-maps/ / https://weekend.levif.be/partenaires/dopper-au-top-5-faits-surprenants-sur-votre-gourde-durable-preferee/ / https://lehub.laposte.fr/la-marque-de-gourdes-dopper-ajoute-sur-google-maps-les-points-deau-potable. Were you aware of this Thank you in advance for your help, 15 June - Dermot sent letter to Dopper 11 August: Dermot’s draft letter for Google (version 2): Our contributor is concerned that many of the locations in question have been sourced from OpenStreetMap, citing identical geographical co-ordinates to many decimal places. This would represent a breach of OpenStreetMap’s Open Database Licence (ODbL), which requires attribution of source and sharealike. We assume that the import of such data into Google Maps would additionally violate your own requirements in terms of permitted data sources. We have made a good faith attempt to contact Dopper so that they can address these issues, but the available communications channels have not resulted in a response. We therefore feel that it is appropriate to make you aware of the issue so that you can act appropriately to ensure that both your terms and ours are being upheld. To illustrate the apparent OSM-sourcing, our contributor provided some examples of locations with matching co-ordinates:
We would be happy to be of any assistance possible in this matter. Kathleen emailed Eric Dickinson (product counsel for Google Maps), who replied that he would look into it. Previous action item: Dermot to check with original mapper on providing additional examples, if possible. Dermot had replied to the original correspondent asking for additional examples of problematic data. The original sender:
We haven't received a reply from Dopper - Dermot had contacted them via their online form. Previous action item: Kathleen to provide copy of analysis to Google.' Done on 25 January 2026. Dermot tried to find Dopper's contact information - they have not responded to his message via their webform. Contact informationDopper B.V. Dopper's registration Email addresses
Dermot might have emailed service@dopper.nl or info@dopper.nl and got redirected to the webform. Will check. Dopper CEO: Virginia Yanquilevich Suggestions
Other points mentioned during discussion
Previous action items'
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| LWG internal reference: https://otrs.openstreetmap.org/otrs/index.pl?Action=AgentTicketZoom;TicketID=65356 |
- Google has not replied but it seems they have removed Dopper as a source.
- The data might still be in the Dopper dataset.
- No point unless we want to go for legal action.
Input from OSMF Chair, Craig Allan, present at the meeting
- Dopper has removed many of the water taps in Amsterdam.
- Some water taps remaining
- presumably those are the ones that didn't coincide.
- some of the remaining water taps did not have a link to Dopper.
https://www.dopper.com/products/tap-map
- Attribution: They have an OSM basemap with points overlaid, without attribution to OSM.
- Share-alike: Assuming that they have both OSM and non-OSM data on their map, they have a share-alike problem.
Suggestion: We tell Dopper to release to us their non-OSM sources, as we are in favour of more open geodata.
Other points mentioned during discussion
- The ultimate goal for OSM is to be more open geo data.
- If they tell us that they don't own the non-OSM data:
- we will tell them that they have to discontinue using the OSM data mixed with non-OSM, as this would be a licence breach.
- they could have two separate layers, one from OSM and one for non-OSM.
Action items
- Dermot to check whether some of the water taps have been removed, as mentioned by Craig Allan.
- Dermot to follow up with Dopper regarding releasing non-OSM water tap sources listed on Dopper’s map.
EVRI delivery company using OSM without attribution? - Ticket#2026010610000189
| Email shared by the LWG |
|---|
| is this substantial or not
(Screenshot attached) Their main map is missing attribution: https://www.evri.com/find-a-parcelshop/#/ They are using these service: https://www.vectorine.com/ Previous action item: Tom Lee to reach out to Vectorine regarding compliance to ODbL, and if that doesn’t work, to Evri. |
| LWG internal reference: https://otrs.openstreetmap.org/otrs/index.pl?Action=AgentTicketZoom;TicketID=77004 |
Tom reached out, received word that EVRI acknowledged need for attribution.
GRAB and OSM attribution - Ticket#2026011810000246
| Email shared by the LWG |
|---|
| Hello, does OSM aware that GRAB is using open street map in South East Asia to manipulate drivers and riders in e-hailing and food delivery? Im not sure whether the screenshot below fulfill the term: provide credit to OSM by displaying our attribution notice, because in grab app, Open Street Map becomes GrabMaps. You guys are aiding grab to squeeze drivers and riders by giving them the map monopoly power where fares are not transparent and up-to-grab, without the transparency for driver and rider. I hope OSM stop grab from using OSM as they are not crediting OSM team in obvious way but taking every credit as their trophy.
Previous action item: Kathleen Lu to ask the mapper what happens when you click on the (i). Sent on February 9. No reply as of March 9, 2026. |
| LWG internal reference: https://otrs.openstreetmap.org/otrs/index.pl?Action=AgentTicketZoom;TicketID=77501 |
We haven't received a reply from the mapper with more details, as on 9 March.
Grab is an OSMF Corporate Member and they will work with us, if there is a problem.
Action item
Kathleen to ask the mapper what happens when you click on the (i).
Sent Feb 9. No reply as of March 9.
OpenMediaMap via legal@
| Email shared by the LWG |
|---|
| Just in case nobody has pointed this out <https://www.openstreetmap.org/user/hmaharoof/diary/408171>
On the site it claims that the name is trademarked fwiw and doesn't bother with any attribution of OSM. Cheers Previous action item: Kathleen to message them re trademark, homepage tile image, and attribution sent Feb 9:
Dear hmaharoof, Hello, |
We received a polite reply from them that they will find a new name for the project called "OpenMediaMap".
- Their diary entry https://www.openstreetmap.org/user/hmaharoof/diary/408171 currently still points to a page mentioning "OpenMediaMap".
- No newer diary entries from them.
Action item
Kathleen to ask them to notify us when the name change is complete.
March 9: Thank you Hasan, please let us know when your name change is complete. Best, Kathleen
Strava Ticket#2026021710000586
| Email shared by the LWG |
|---|
| Since last year I am working on a project in which I make use of OpenStreetMap data.
We are looking forward to making publications (maps), but I am not 100% sure I am making making the right interpretation from legal perspective. Here is what I do. I (Mart Reiling, Track-Landscapes) have made maps for 'Stichting Wandelnet' that visualise walkable infrastructure. The basis for that is OpenStreetMap highways. Though; important for these maps is the distinction on whether a pathway is publicly accessible or not. OSM sometimes contains tags for this, but often not, and tags may be wrong. What I tested to do here, is adding Strava Metro data (metro.strava.com), to make an estimation on accessibility based on whether a road has been used by a pedestrian that used Strava. Strava Metro data is also based on OpenStreetMap, meaning that you get numbers (amount of passages) of every road in OpenStreetMap. Basically; I devide OSM highways into two classes '(almost) not used' and 'used' by looking at usage/counts of Strava Metro. So that there are no raw Strava counts/numbers anymore. When a road is '(almost) not used', I expect that road as a non-public road. Then I also look at highway classes and tags; and based on the combination of these I make an estimation on accessibility. It then gets categorised as 'accessible', 'probably--accessible' or 'probably-not-accessible' or 'not-accessible', which determines how the road is visualised in the map (color, thickniss, or not shown at all). This is, as I understand it, a derivative database on which 'share alike' would be the case.
I have also asked Strava Metro on what is allowed on their behalf; they say that sharing highwayusage-class; being '(almost) not used' or 'used' would be allowed in a public webmap, if the region that the map shows has applied to Strava Metro. So for example, If i make/publish the map for province 'Utrecht' then the province of Utrecht must have access to Strava Metro. If the region that I show the map of has not applied to Strava Metro, then they only allow 'highwayaccessibility' classes. The case is actually really quite interesting for OpenStreetMap, because it would also mean that roads where accessibility is unclear, will be visible in a public webmap. OSM contributors (like myself) could use this to identify roads where tagging is missing or incorrect, and then improve that in OSM (after checking these roads in the field, or including their local knowledge, because data of usage never guarantees a certain level of accessibility). |
The sender:
- refers to roads that are already mapped on OSM.
- seems to draw inference from the fact that many Strava users can be seen to be going along a certain path.
- wants to decide based on the observations above, whether public access is permissible.
Reason for email: LWG's feedback on whether his project triggers share-alike.
On Sharealike
- Sharealike is not triggered, because he uses a type of data we don't manage. The quality of estimation about whether something is accessible, is not something that is mapped to OSM. So, it is not subject to share-alike, as there is no counter-part in OSM. It is a data type layered on top, that OSM does not use.
- The database that the sender is creating is either under the collective database guideline or horizontal layers - it is not attached to the ODbL features.
On information that could be used to improve OSM
- The sender suggests that the data he creates can be used as reminders for mappers to look at a road's public access and to update the tags, if necessary.
- The mappers would be checking, either on the ground, or satellite/street imagery e.g. regarding sidewalk presence, and would be the ones updating OSM. So, the mappers will be providing an independent source for OSM edits.
Other points mentioned during discussion
- A lot of mappers would be wary about the vagueness of the conclusion whether an OSM highway= is publicly accessible.
LWG's stance is
- Probability of accessibility is not a trait subject to sharealike because there's no equivalent in OSM.
- Should have no affect on Strava data.
- The information could be useful to mappers.
Action item
Kathleen to reply -- done March 9
Topic redacted
Minutes redacted after request.
LinkMyRide using OSM in App without attribution
| Email shared by the LWG |
|---|
| OpenStreetMap Ireland (local chapter) wishes to escalate this matter to LWG after sustained ignoring of many approaches by app creators. Seeks LWG approval for:
1. Dermot, in name of LWG, to approach app creators, reiterate complaint, demand assurances on provision of correct attribution and threaten to seek removal of their app from app stores on grounds of copyright infringement in the absence of this remediation. 2. If no resolution, proceed with formal process to request app store removal Back story: https://wiki.openstreetmap.org/wiki/Lacking_proper_attribution First spotted: 15th May 2025 by Anne, OSM Ireland Board 16th May: CEO of LinkMyRide claimed "We actually get our map data from Mapbox". Immediate reply sent to clarify actual data ownership and requirements. > Quickly responded to by LMR: "Ok! I wasn't aware of that! We are in the process of releasing a large update at the end of June. So I will make sure our tech team get that attribution added." Early July - email sent, no reply after 2 weeks Jan: email sent, no reply Early Feb: <screenshot> > LinkedIn request to connect was ignored. The view in OSM Ireland is that they are at worst willfully ignoring us, and at best, very lax. This is why we feel that the leverage of app distribution may be needed to ensure some focus. |
Issues
- No attribution in app.
- Communication ceased.
Points mentioned during discussion
- Dermot was not involved in any of the previous communications.
- They are a Mapbox customer.
- Tom Lee (Mapbox) is happy to contact them and get this resolved * he has participated in many similar calls with Guillaume.
Other points mentioned during discussion
- When a companies' customer gets an email from an institution they have never heard of,telling them that they have a copyright problem that's like that's pretty bad.
- Sometimes people leave companies, things get dropped and it is difficult to reestablish contact.
- The first contact was the CEO.
- Preferable to first try to resolve via Mapbox, than to escalate to the app store as a copyright infringement issue.
- They might be overstretched.
Action item
Tom Lee to reach out via Mapbox (and also connect with Dermot)
2026 LWG meeting times
Jan 12, at 18:00 UTC
Feb 09, at 18:00 UTC
Mar 09, at 18:00 UTC (US switch Mar 8, Europe switch Mar 29) (11am PDT/2pm EDT for US attendees)
Apr 20, at 17:00 UTC
May 11, at 17:00 UTC
Jun 08, at 17:00 UTC
Jul 13, at 17:00 UTC
Aug 17, at 17:00 UTC
Sep 14, at 17:00 UTC
Oct 19, at 17:00 UTC
Nov 16, at 18:00 UTC (same as normal hours for everyone)
Dec 14, at 18:00 UTC
Meeting adjourned 56 minutes after start.