One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.
Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.
Priya Nambiar was a postgraduate student from Kochi, studying at a university abroad. Around early March 2024, she began receiving an alarming volume of unsolicited WhatsApp messages from unknown Indian mobile numbers — all promoting so-called "assignment writing services." Within weeks, the count crossed 600 messages. The senders clearly had access to her number, which she had shared only in a few closed student accommodation groups on WhatsApp.
Priya first filed a complaint with the university's IT grievance cell and separately sent an email to the Telecom Regulatory Authority of India's consumer helpdesk. Neither produced any concrete action. The numbers kept multiplying. By the time she had blocked over 800 contacts, she decided to explore formal legal remedies in India and reached out to Advocate Sudhir Rao.
This wasn't merely a nuisance. It raised serious questions about unauthorised access to personal data, commercial solicitation without consent, and the legality of academic fraud facilitation services operating openly from Indian numbers. With a structured approach covering data protection law, telecom regulations, and cybercrime provisions, the matter was taken forward. Priya received relief in the form of formal takedown notices, a police complaint that was duly registered, and the targeted numbers were reported to the Department of Telecommunications for disconnection. The earlier, unguided efforts had gone nowhere. Engaging an advocate who regularly handles cybercrime and data privacy matters made a measurable difference, both in speed and in the legal strategy adopted.
Advice in Such Cases
Consult with Lawyer: The very basic and important step to start is talk to Lawyer / advocate. You should not hesitate in paying his consultation fee i.e. might be in range of Rs. 10,000 to 50,000 depends case to case. He is helping you in this situation to come out. He is expert in the domain and can help you explain the procedure which you might have never explored. A good lawyer can get the issues resolved much faster than you think.
Document everything before you block: Before blocking each number, take screenshots capturing the sender's number, the message content, and the timestamp. Courts and police require this evidence. Don't rely on memory. Preserve records systematically, ideally in a cloud folder with dated filenames, because reconstructing this later is practically impossible.
File a complaint with TRAI and DoT: Report the unsolicited commercial messages through the Sanchar Saathi portal and the DND (Do Not Disturb) registry. TRAI has specific regulations on commercial communication, and telecom operators are obligated to act on verified spam complaints. And here's the thing — most people skip this step entirely, and it's often the fastest route to getting numbers disconnected.
Report to the Cyber Crime portal: Lodge a complaint at cybercrime.gov.in. These matters, involving data harvesting from WhatsApp groups and mass unsolicited contact, can attract provisions under the Information Technology Act and the Bharatiya Nyaya Sanhita. This type of matter involves procedural and evidentiary considerations that general practitioners may not be fully familiar with. An advocate with specific experience in cybercrime and data privacy law can ensure the right sections are cited from the outset, which directly affects how seriously the complaint is treated.
Applicable Sections of Law
Several legal provisions apply here, spanning data protection, telecom regulation, and criminal law:
- Section 66A IT Act (historical) / Section 351(3) BNS: Sending messages that cause annoyance, inconvenience, or are grossly offensive through electronic communication devices is punishable. Section 351(3) BNS specifically covers criminal intimidation and threatening/annoying communication via electronic means.
- Section 43 and Section 66 of the Information Technology Act, 2000: Unauthorised access to data and systems, including harvesting contact numbers from closed group platforms without consent, attracts civil and criminal liability.
- Digital Personal Data Protection Act, 2023 (DPDP Act): Processing personal data (including a phone number) without the data principal's explicit consent is a violation. The DPDP Act provides for complaints to the Data Protection Board of India once it is fully operational.
- TRAI Telecom Commercial Communications Customer Preference Regulations, 2018: Sending unsolicited commercial communications to registered DND subscribers and scraping numbers from platforms for marketing without consent violates these regulations, attracting action against the telecom subscriber.
Punishment and Penalties
- Section 351(3) BNS: Punishment of imprisonment up to two years, or fine, or both.
- Section 66 IT Act: Imprisonment up to three years and/or fine up to Rs. 5,00,000 for unauthorised access and data theft.
- DPDP Act, 2023: Financial penalties up to Rs. 250 crore for significant data breaches or non-consensual processing by entities; individual violations carry penalties determined by the Data Protection Board.
- Cognizable / Non-Cognizable: Section 66 IT Act offences are cognizable. Section 351(3) BNS offences may be non-cognizable in some instances, requiring a Magistrate's direction to investigate.
- Bailable / Non-Bailable: Section 66 IT Act is bailable. Most telecom regulation violations carry regulatory penalties, not imprisonment.
- Compoundable: Certain IT Act offences are compoundable with the permission of the court.
Jurisdiction — Where to File the Case
Jurisdiction matters more than most people realise. For criminal complaints under the IT Act and BNS, territorial jurisdiction lies with the police station in the area where the victim received the offending message, which in cross-border cases involving Indian SIM-based numbers can include the victim's last known address in India or the place of origin of the message. For NRI or overseas victims, the Cyber Crime police stations in major cities such as Bengaluru, Mumbai, or Hyderabad accept online complaints through cybercrime.gov.in regardless of physical location. TRAI complaints are filed with the telecom service provider and escalated to the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) if unresolved. Filing in the wrong forum leads to delays, objections, and potential dismissal at the threshold stage — and that's a waste of time nobody can afford.
What if Police Refuse to File FIR?
Police sometimes treat mass-spam complaints as low-priority. And here's what you can do if they refuse:
- Submit a written complaint to the Superintendent of Police (SP) or Deputy Commissioner of Police (DCP) of the Cyber Crime division under Section 173(4) BNSS, requesting direction to the concerned station to register the FIR.
- File a private complaint directly before the Judicial Magistrate First Class under Section 175(3) BNSS — the Magistrate can direct the police to investigate.
- Approach the High Court under Article 226 of the Constitution for a writ of mandamus directing registration of the FIR, as affirmed in Lalita Kumari v. Government of UP, 2014, which makes it mandatory for police to register FIRs in cognizable offences.
- File a complaint before the National Cyber Crime Reporting Portal (cybercrime.gov.in), which routes the matter to the concerned state cyber cell directly.
Rights of the Accused
If any person is accused in such a matter, Indian law protects the following rights:
- Right against self-incrimination under Article 20(3) of the Constitution — no person can be compelled to be a witness against themselves.
- Right to legal representation under Article 22 — every accused has the right to consult and be defended by an advocate of their choice.
- Right to be produced before a Magistrate within 24 hours of arrest, as guaranteed under Article 22(2) and Section 58 BNSS.
- Right to receive a copy of the FIR and to be informed of the grounds of arrest, as held in D.K. Basu v. State of West Bengal, 1997.
- Right to apply for bail at the earliest opportunity, including anticipatory bail if arrest is apprehended.
Bail Provisions
Offences under Section 66 of the IT Act are bailable in nature, meaning the accused is entitled to bail as a matter of right. Now, before you act, understand the anticipatory bail option too. It can be sought under Section 482 BNSS if there's apprehension of arrest, which is particularly relevant where the accused fears action following a cyber complaint. Regular bail, post-arrest, is governed by Section 480 and Section 483 BNSS. Typical bail conditions in cyber spam cases include surrendering the SIM cards used, not deleting electronic records, and not contacting the complainant. Bail strategy in IT Act matters often turns on the nature of the alleged offence, digital evidence already preserved, and whether a chargesheet has been filed.
Quashing of FIR / Case
The accused, if an FIR is registered, can approach the High Court under Section 528 BNSS, which preserves the court's inherent powers to quash FIRs where no prima facie offence is disclosed or where the proceedings constitute an abuse of process of law. In spam/unsolicited messaging cases, quashing may be viable if the accused can demonstrate the messages were sent through automated systems without personal intent, or where there's a genuine error in identification of the SIM holder. The Supreme Court's principles in State of Haryana v. Bhajan Lal, 1992 continue to guide courts on when quashing is appropriate. Compoundable offences, once a settlement is reached, may also form a basis for quashing.
If You Are the Victim
- Take screenshots of every unsolicited message — including the sender's number, message text, and timestamp — before blocking anyone.
- Export your WhatsApp chat history with key senders as a backup file and store it in a secure, date-stamped cloud folder.
- File a complaint on cybercrime.gov.in under the "Other Cyber Crimes" category, specifically mentioning data scraping from WhatsApp groups and unsolicited commercial messaging.
- Report each number on the Sanchar Saathi portal (sancharsaathi.gov.in) and through your telecom provider's spam reporting mechanism under TRAI regulations.
- Consult an advocate experienced in IT Act and data privacy matters who can assess whether a police complaint, TRAI complaint, and/or DPDP Act complaint should be pursued simultaneously for maximum effect.
Documents You Must Keep Ready
- Aadhaar card and PAN card (identity proof of the complainant)
- Screenshots of all unsolicited WhatsApp messages with timestamps and sender numbers visible
- Exported WhatsApp chat backup files (as .txt or .zip) containing the message records
- A list of all blocked numbers with approximate dates of first contact
- Proof of membership in the WhatsApp groups from which your number appears to have been scraped (screenshot of group info/member list)
- Any email correspondence with the telecom provider or TRAI regarding prior complaints
- University or institution ID confirming your enrollment and the groups you were part of
- A written chronological account of events — when messages started, how frequently, and what was communicated
What Evidence Is Required?
- Primary digital evidence: Screenshots and exported chat logs are primary evidence of the unsolicited communication, admissible under Section 63 of the Bharatiya Sakshya Adhiniyam, 2023 (BSA) as electronic records.
- Call Detail Records (CDR): These can be obtained through police channels to establish the origin and volume of messages sent from specific numbers.
- WhatsApp group membership records: Demonstrating that your number was accessible only through specific closed groups establishes the likely source of the data scrape.
- List of blocked contacts: A documented, timestamped list of 800+ blocked numbers corroborates the scale and systematic nature of the activity.
- Evidence of similar complaints: Other group members who received identical messages serve as corroborative witnesses, strengthening the case that this was targeted harvesting.
- TRAI DND registration proof: If you were registered on the DND list, this directly establishes a regulatory violation.
How the Police Behave in Such Cases
Make no mistake — cyber spam complaints are not always treated with urgency at the station level. Officers at local police stations may lack familiarity with IT Act provisions and may attempt to redirect you to the cyber cell. The cyber cell, in turn, may request extensive documentation before registering a formal FIR. Frankly, in cross-border cases where the victim is abroad, there can be additional friction around jurisdiction. Persistence, a well-drafted written complaint, and legal representation typically make a significant difference in how promptly the complaint is processed. Cyber cells in major cities like Bengaluru and Pune tend to be better equipped for such matters.
Timeline of Legal Process
- Week 1-2: Filing of online cybercrime complaint and TRAI complaint; gathering and organising all evidence.
- Week 2-4: Police/cyber cell acknowledgment; possible summons to the complainant for a statement.
- Month 1-3: FIR registration (if police agree); preliminary investigation, CDR analysis, identification of the accused.
- Month 3-6: Arrest (if applicable), remand proceedings, bail hearing.
- Month 6-18: Filing of chargesheet under Section 193 BNSS; committal to trial court if offence is sessions-triable.
Advocate Sudhir Rao, Supreme Court of India