Other · 11 min read · 15 min 54 sec listen · Published 21 July 2026

Is It Legal to Collect and Display Public Business Data from Google Maps and Justdial in India?

Understand the legalities of collecting public business data from Google Maps and Justdial in India, including scraping, DPDP Act, and platform terms.

Is It Legal to Collect and Display Public Business Data from Google Maps and Justdial in India?
One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.

Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.

TL;DR: Collecting and organizing publicly visible business information from platforms like Google Maps and Justdial treads a fine legal line. While the data itself is public, scraping it may violate platform terms of service and could attract liability under the Information Technology Act, 2000. The DPDP Act, 2023 also imposes obligations on how you process and display personal data, including phone numbers and email addresses. Charging users for access may require additional compliance. Always consult an advocate experienced in data protection and technology law before building such a platform.

A tech entrepreneur from Indore, Priya Sharma, wanted to build a business listing platform. She planned to collect publicly available business data from sources like Google Maps, Justdial, and business websites. The data included business names, categories, addresses, phone numbers, and public reviews. Her goal was to organize this information and make it searchable for users, potentially charging a subscription fee.

Priya approached the Chamber of Advocate Sudhir Rao after her initial research raised more questions than answers. She had spoken to a general practitioner who gave vague advice about "just being careful." That wasn't enough for a venture with significant commercial risk. Advocate Sudhir Rao and his office examined the platform's design, the sources of data, and the intended use. They identified the key legal hurdles — platform terms, data protection law, and potential liability under the IT Act. With a clear legal framework, Priya restructured her platform to minimize risk while still creating value for users. Advocate Sudhir Rao's expertise in technology and data protection law helped secure a clear roadmap that allowed the client to proceed safely.

Key Facts of the Case

  • The client planned to collect publicly visible business information from Google Maps, Justdial, and other online directories.
  • Data included business name, category, address, phone numbers, email addresses, website URLs, and public reviews.
  • No private data, login-based information, or data behind paywalls was targeted.
  • The platform would organize this data and make it searchable, with a potential subscription-based model.
  • Key legal concerns revolved around platform terms of service, the DPDP Act 2023, and the Information Technology Act, 2000.
  • The client had not scraped any data yet — she sought legal clarity before development.
  • Advocate Sudhir Rao's office provided a structured compliance checklist covering data processing, consent requirements, and platform-specific restrictions.
Is it legal to collect and organize publicly visible business information from platforms like Google Maps and Justdial?

Yes and no. The information itself is public, so collecting it manually is generally not illegal. But here's the catch — the method of collection matters. If you scrape or use automated tools, you might violate the platform's terms of service. That's not automatically a crime, but it can lead to civil claims or your data sources being blocked. And if that data includes personal information like phone numbers or email addresses, the DPDP Act kicks in.

Can this information legally be displayed to users on another platform?

Generally, yes — as long as you don't misrepresent it as original or violate a platform's copyright. But the DPDP Act requires you to have a legitimate purpose for processing personal data. Compiling phone numbers and emails for a paid directory may need consent or a clear legal basis. You can't just republish someone else's data without considering their rights.

Does it matter if the information includes publicly listed phone numbers and email addresses?

Absolutely. Under the DPDP Act, 2023, phone numbers and email addresses are personal data — even if publicly listed. You need to comply with data processing obligations, including notice, purpose limitation, and data security. And the consent requirement is strict for non-public personal data. Publicly available data has some exemptions, but you need to be careful.

Would scraping or automatically collecting this information create separate legal issues?

Yes. Automated scraping may violate platform terms of service. This could get your IP address blocked or lead to a cease-and-desist letter. More seriously, it could attract liability under Section 43 of the Information Technology Act, 2000 for unauthorized access or damage to a computer system. Some platforms also seek injunctions against scrapers. So the method matters just as much as the data.

Do the terms and conditions of platforms like Google Maps or Justdial restrict this type of data collection or reuse?

Yes, they do. Google Maps' terms prohibit scraping and unauthorized commercial use of its data. Justdial also restricts automated collection and reuse of business listings. Even if the data is public, these platforms own the compilation and presentation. Violating their terms can result in account termination, legal action, or being permanently blocked from their services.

Would it be legal to charge users for access to the organized/searchable information?

Charging for access doesn't make the collection illegal by itself. But if the original collection was improper — say, in violation of terms or data protection law — monetizing that data amplifies the liability. The DPDP Act also requires that the purpose of processing be specified at the time of collection. If your original purpose didn't include charging users, you may need fresh consent from data principals.

Are there any concerns under India's DPDP Act or other applicable laws?

Significant concerns. The DPDP Act, 2023 applies to all personal data collected online, including from public sources. You must process data lawfully, provide notice, and appoint a data fiduciary. If you handle significant volumes of data, you may also need a Data Protection Officer. Cross-border data transfer restrictions also apply. The Information Technology Act, 2000 covers computer-related offences including unauthorized access and data theft. And if your platform hosts user-generated content, the IT Act's intermediary guidelines also apply.

Advice in Such Cases

Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.

Second, document your data sources and methodologies. Keep clear records of where data comes from, how it's collected, and what you do with it. This helps in compliance audits or if a platform sends a legal notice. Third, build consent flows into your platform from day one. Even if you rely on public data exemptions, having a mechanism for data principals to opt out or correct their information reduces risk. This category of matter involves nuanced procedural and evidentiary strategies around data protection, platform terms, and IT Act compliance — things a general practitioner may not be fully familiar with. Engaging an advocate who regularly handles technology law matters typically leads to faster and better outcomes.

Applicable Sections of Law

The Digital Personal Data Protection Act, 2023 is the primary law governing how personal data — including business contact information — must be processed, stored, and shared. The Information Technology Act, 2000, specifically Sections 43 and 66, addresses unauthorized access, data theft, and computer-related offences. Section 66 covers hacking, while Section 66E deals with violation of privacy. Section 43 penalizes unauthorized access and damage to computer systems. The Indian Contract Act, 1872 governs the enforceability of platform terms of service. And Copyright law under the Copyright Act, 1957 may apply if your platform reproduces substantial creative content from the source directories.

Jurisdiction — Where to File the Case

For disputes arising from data scraping or breach of platform terms, the jurisdiction is typically determined by the platform's terms of service — often the High Court of the state where the platform's Indian entity is based. For criminal complaints under the IT Act, the police station with territorial jurisdiction over the place where the alleged offence occurred or where the computer system is located can register an FIR. For civil suits seeking injunctions against data misuse, the District Court or High Court with territorial jurisdiction over the place where the plaintiff resides or carries on business will have jurisdiction. Jurisdiction matters because filing in the wrong court wastes time, money, and effort.

If You Are the Victim

  • Document every instance of unauthorized data collection — take screenshots, capture URLs, and save timestamps.
  • Check the platform's terms of service and user guidelines — these define what constitutes misuse.
  • Send a cease-and-desist notice through an advocate before escalating to litigation.
  • File a complaint with the cybercrime portal or local police station under the IT Act.
  • Consider a civil suit for injunction and damages if the misuse causes commercial harm.

Documents You Must Keep Ready

  • Identity proof (Aadhaar, PAN, or Voter ID)
  • GST registration certificate if you are a business
  • Copy of the platform's terms of service (screenshots or PDFs)
  • Records of any communications with the data collector
  • Evidence of data scraping (server logs, IP addresses, timestamps)
  • Proof of business registration or incorporation
  • Invoices or bank statements showing commercial impact
  • Copy of the cease-and-desist notice, if sent

What Evidence Is Required?

  • Server logs or access logs showing automated scraping activity
  • IP addresses and timestamps of the scraping activity
  • Screenshots of the copied data being displayed on the other platform
  • Witness testimony from technical experts who can confirm the scraping method
  • Forensic evidence of unauthorized access to computer systems (if applicable)
  • Business records showing loss or competitive harm
  • Copies of terms of service at the time of collection

How Courts Typically Approach Such Cases

Indian courts are increasingly aware of data rights and platform integrity. In technology law matters, courts tend to balance commercial interests with privacy and contractual rights. They are likely to examine the method of data collection — manual vs automated — and whether the collector had a legitimate purpose. Courts also consider whether the data collector complied with the DPDP Act's notice and purpose requirements. Injunctions are commonly granted when there is clear violation of platform terms or evidence of data scraping involving personal information. The court may also order the preservation of logs and other digital evidence.

  • Notice stage: Cease-and-desist notice sent by the aggrieved party (1-2 weeks).
  • Civil suit filing: Plaint filed with the appropriate court (1-2 months).
  • Interim injunction hearing: Court hears arguments for temporary relief (1-3 months).
  • Written statement: Defendant files its defense (1-2 months).
  • Discovery and evidence: Document inspection, witness examination (3-6 months).
  • Final arguments and judgment: Court hears both sides and pronounces judgment (3-6 months).
  • Appeal: Either party may appeal to a higher court (6-18 months).

Understanding the Costs

The total cost of a matter like this varies significantly from one case to the next — it depends on the complexity of the dispute, the forum involved, the number of hearings, and the specific facts of your situation. There is no single fixed figure that applies to everyone.

A professional advocate can give you an accurate estimate only after reviewing all your facts and documents in a consultation.

Can the Matter Be Settled Out of Court?

Yes. Many data-related disputes are resolved through settlement. The parties may agree on a licensing arrangement, a takedown protocol, or a compensation package. Mediation and conciliation are effective tools in technology law disputes where both sides want to avoid prolonged litigation. If the matter involves criminal allegations under the IT Act, the offence may not be compoundable, but a settlement can often lead to a withdrawal of the complaint. For civil cases, a compromise deed can be filed in court under Section 89 of the CPC, or the parties can approach a Lok Adalat for a binding settlement. Settlement is advisable when the costs of litigation outweigh the potential recovery and both sides seek a pragmatic resolution.

Common Mistakes People Make

  • Scraping without reading platform terms: Terms of service are legally binding. Ignoring them can lead to account bans and legal action.
  • Not documenting the data collection method: If you can't prove how you collected the data, you'll struggle to defend the legitimacy of your platform.
  • Assuming public data is free to use: Public visibility doesn't mean unrestricted commercial use. The DPDP Act and platform rights still apply.
  • Engaging a lawyer without technology law experience: A general practitioner may not understand scraping, server logs, or the DPDP Act's nuances. Domain-specific experience affects procedural strategy, evidence handling, and outcome significantly.
  • Charging users without DPDP Act compliance: Monetizing personal data collected from public sources requires clear notice, purpose specification, and possibly consent.
  • Ignoring cross-border data flow restrictions: If your platform uses servers outside India, the DPDP Act's data localization requirements may apply.

FAQs People Normally Have

Can I scrape Google Maps data for my own business use?

Probably not. Google's terms prohibit scraping. Doing so may get your IP blocked and could lead to legal action. Even for internal use, you risk violating their terms.

Does the DPDP Act apply to business contact information?

Yes. Phone numbers and email addresses of business owners are considered personal data under the DPDP Act, even if publicly available. You must process them lawfully.

What happens if a platform sends a cease-and-desist notice?

Take it seriously. Consult an advocate immediately. Responding properly can avoid escalation to litigation. In some cases, you can negotiate a licensing arrangement.

Is charging users for access to business listings legal?

It can be, but only if your data collection and processing comply with platform terms, the DPDP Act, and the IT Act. Charging doesn't fix a fundamentally unlawful collection method.

How long does a data scraping lawsuit typically take?

From notice to final judgment, expect 12 to 24 months for a contested civil suit. Appeals can add a year or more. Early settlement is usually faster and cheaper.

This article is general legal information, not legal advice. Consult a qualified advocate about your specific situation.

Advocate Sudhir Rao, Supreme Court of India

Was this article useful?

/5 (0 ratings)