One of my clients recently had a case which I am explaining below and if you are stuck in such similar situation, here is what to do.
Note: Due to attorney-client privilege, I cannot disclose complete case details or identify the actual parties involved. However, I am sharing the essential facts and legal approach so that if you find yourself in a similar situation, you can understand the available solutions and legal remedies.
TL;DR: A website scraping notice is not automatically a criminal or civil defeat. Scraping publicly visible pages is often defensible unless you bypassed access controls, took personal data, or breached a binding contract. Reply through an advocate, preserve evidence, and do not ignore the notice.
Around 18 March 2025, Rohan Gupta, a data analyst in Indore, found a courier packet on his desk. Inside was a legal notice from a Gurugram-based e-commerce platform. The notice accused him of scraping their publicly visible product pages using an automated price-comparison script. It demanded ₹25 lakh and an immediate takedown of his website. Rohan had spent eight months building the tool as a side project. He had never logged in, never bypassed a CAPTCHA, never touched any private user data. A local lawyer he first consulted told him to apologise and negotiate. Rohan did. The company's advocate rejected the apology and threatened criminal action under the IT Act. That didn't work. He then approached the Chamber of Advocate Sudhir Rao. Advocate Sudhir Rao and his office reviewed the technical logs and the website's terms of use. They argued that scraping publicly accessible data without circumventing any access control is not unauthorised access under Section 43 of the Information Technology Act, 2000. They sent a detailed reply challenging the legal basis and preserving Rohan's position on fair dealing. Within three weeks, the company dropped the damage claim. The matter ended with no payment and Rohan continuing his tool under clear restrictions. Advocate Sudhir Rao's expertise in this domain helped secure the order in favour of the client.Key Facts of the Case
- Rohan Gupta, a data analyst in Indore, received a legal notice around 18 March 2025 from a Gurugram-based e-commerce platform.
- The allegation was scraping publicly visible product pages using an automated price-comparison script.
- The notice demanded ₹25 lakh in damages and immediate removal of the comparison tool.
- No login, CAPTCHA bypass, or access-control circumvention was involved.
- No private user data or non-public pages were accessed by the client.
- The client initially received generic advice to apologise, which did not resolve the dispute.
- Advocate Sudhir Rao's office replied on Section 43 of the Information Technology Act, 2000, arguing that scraping publicly accessible data without circumventing any access control is not unauthorised access.
- The company dropped the damage claim within three weeks. No payment was made and the client retained his tool with clear restrictions.
What does a website scraping notice usually allege?
A website scraping notice in India typically mixes three claims: unauthorised access under the Information Technology Act, breach of the website’s terms, and loss of business or data. The first claim is often the weakest when the scraped pages were visible to anyone with a browser and no login, CAPTCHA, or other access control was bypassed.
Section 43 of the IT Act, 2000 imposes a civil penalty for accessing a computer system without permission. If the pages were open to the public, permission to view them is usually implied. Merely using a script to read faster does not by itself turn viewing into access without permission. Section 66 can make certain computer-related acts criminal, but only when there is dishonest or fraudulent intent. A price-comparison tool built as a side project rarely shows that intent, though the facts of each case matter.
Is scraping public data a crime in India?
Not automatically. Criminal liability under Section 66 of the IT Act requires more than copying visible web pages. The prosecution would need to show dishonest or fraudulent intent, or that some access control was bypassed. If the scraper never logged in, never solved a CAPTCHA, and never accessed password-protected areas, the criminal route is hard to sustain.
Civil claims are different. A company can argue that the scraper breached the website’s terms of use or caused loss through the copying. But a browsewrap term — a condition hidden in a footer or a terms page that no one clicks — may not bind a visitor in India. Courts are more willing to enforce a clickwrap agreement where the user actually took a step to accept terms.
When can a website scraping notice succeed?
A demand is stronger when the scraping involved:
- login, CAPTCHA, IP-blocking, or rate-limit bypass;
- personal data of users, especially contact details or payment data;
- access to non-public pages, APIs, or authenticated dashboards;
- an explicit clickwrap agreement prohibiting automated access;
- republication of substantial portions that goes beyond factual comparison.
The outcome also depends on what the recipient did after the notice. An apology without legal argument can be read as admission. Replying through an advocate with a technical and legal position often changes the trajectory, as it did here after the initial apology failed.
What should you do after receiving a website scraping notice?
Do not ignore it. Do not send an angry or apologetic reply from your personal email. Instead, take these steps:
- Keep the original notice, envelope, and courier receipt.
- Save the exact pages you scraped, the date of access, and the script logs.
- Obtain the website’s terms of use as they existed on the date of scraping, preferably through an archive.
- List what data was public, what was not, and whether you ever logged in or bypassed any control.
- Have an advocate send a focused reply within the notice period, usually seven to fifteen days, identifying the legal basis for the demand.
We only have one side of this story, and the result in Rohan’s case does not guarantee the same outcome in yours. A single login, a CAPTCHA solve, or a copy of a private page can change the analysis completely.
Frequently Asked Questions
Is scraping a public website illegal in India?
Not by itself. Scraping publicly visible pages is often defensible unless you bypass access controls, access restricted areas, or collect personal data. The conduct and the website’s terms decide the issue.
Can I be arrested for scraping data?
Arrest is uncommon for ordinary scraping of public pages. Criminal liability under the IT Act usually requires dishonest or fraudulent intent, or circumvention of security measures. A civil claim is far more likely.
What should I not do after a website scraping notice?
Do not reply admitting fault, do not delete the logs, and do not continue scraping while the notice is pending. Deleting evidence can hurt you even if the underlying claim is weak.
Do I need to pay the damages demanded?
No. A demand is not a judgment. Many demands are inflated and are meant to force a quick settlement. The right reply can significantly reduce or end the claim, but only on solid facts.
If you have received a similar demand, send the notice, the date, and a two-line note on whether you logged in or bypassed any control through the contact page. Keeping the original packet and envelopes helps.
This article is general information, not legal advice on your specific situation.
Advocate Sudhir Rao, Supreme Court of India
Facing a similar matter? Speak to a Delhi criminal defence lawyer — Advocate Sudhir Rao appears in bail, trial and appellate matters before the Delhi District Courts, the Delhi High Court and the Supreme Court of India.