EF Cultural Travel BV v. Explorica, Inc.
- Court
- Court of Appeals for the First Circuit (Federal circuit court)
- Decided
- 2001
- Citation
- 274 F.3d 577 (1st Cir. 2001)
- Standard applied
- CFAA § 1030 — “exceeds authorized access” via breach of a confidentiality agreement
What the court held
The First Circuit affirmed a preliminary injunction against a competitor that used a purpose-built scraper to harvest tour pricing from a rival's public website, holding the plaintiff was likely to succeed on its CFAA claim — but resting on a narrower basis than the district court. The scraper made more than thirty thousand queries and relied on internal tour codes whose meaning was not publicly understandable.
Why
The court grounded the likely CFAA violation in the confidentiality obligation owed by former employees who supplied the non-public tour codes, rather than in any general theory that scraping a public site exceeds authorised access. That narrowing is what limits the case: it is the insider's breach that made the access unauthorised, not the automation.
Our reading — not the court’s words
Why this matters in practice
This is the earliest well-known scraping case and it is frequently cited for more than it holds. The narrow ground — confidential information supplied by departing employees — is exactly the distinction hiQ later drew when refusing to extend the CFAA to genuinely public data. For an examiner the artefacts that matter are the ones showing where the non-public inputs came from: the codes, the credentials, or the internal documentation that made the collection possible.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · web scraping · confidentiality agreement · preliminary injunction
Cited 90times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on computer-crime statutes
- Van Buren v. United StatesSupreme Court of the United States · 2021A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by ob…
- LVRC Holdings LLC v. BrekkaCourt of Appeals for the Ninth Circuit · 2009An employee who is permitted to use his employer's computer does not access it “without authorization” under the CFAA by e-mailing company documents to himself…
- United States v. RodriguezCourt of Appeals for the Eleventh Circuit · 2010A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-busin…
- United States v. Nosal (Nosal I)Court of Appeals for the Ninth Circuit · 2012“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on…
- WEC Carolina Energy Solutions LLC v. MillerCourt of Appeals for the Fourth Circuit · 2012An employee “exceeds authorized access” only when he has approval to access a computer but uses that access to obtain or alter information falling outside the b…
- Facebook, Inc. v. Power Ventures, Inc.Court of Appeals for the Ninth Circuit · 2016A social-aggregation service that accessed a platform's user data with the users' consent did not violate the CFAA while it had the platform's implied permissio…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.