Scraping powers a huge share of the world’s B2B data — and in India its legality depends on what you scrape, how, and what you do with it.
The three legal pressure points
- IT Act, Section 43: accessing a computer resource “without permission” invites liability. Bypassing logins, CAPTCHAs, or technical blocks is the danger zone; reading openly-served public pages is far more defensible.
- Contract law: a site’s Terms of Service can prohibit scraping. Breaching browsewrap terms is a weaker claim than clickwrap — but a claim nonetheless.
- DPDP Act: “publicly available” personal data gets a carve-out only when the individual made it public themselves. Scraping personal contact details from a directory someone else published does not automatically clear consent requirements.
Safer sourcing hierarchy
1) Government registries designed for public verification (GST, MCA) → 2) data licensed from consenting sources → 3) open-web scraping of business (not personal) information → 4) anything behind a login: don’t.
The takeaway
Registry-first sourcing isn’t just legally safer — it’s fresher and more accurate than scraped contact soup.
This article is general information, not legal advice.