Facebook, Inc. v. Power Ventures, Inc.
- Court
- Court of Appeals for the Ninth Circuit (Federal circuit court)
- Decided
- 2016
- Citation
- 844 F.3d 1058 (9th Cir. 2016)
- Standard applied
- CFAA § 1030 — revocation of permission by cease-and-desist
What the court held
A social-aggregation service that accessed a platform's user data with the users' consent did not violate the CFAA while it had the platform's implied permission. It did violate the CFAA and California Penal Code § 502 once the platform sent a cease-and-desist letter and blocked its IP address and it nonetheless continued to access the platform's computers. Its promotional messages did not violate the CAN-SPAM Act because they were not materially misleading.
Why
The court treated authorisation as something the computer owner grants and can withdraw: a user's permission to use the user's own data does not carry permission to access the platform's systems, and an express revocation plus technical blocking put the defendant on notice that continued access was unauthorised. It distinguished the period before the letter, when access had been tolerated, from the period after.
Our reading — not the court’s words
Why this matters in practice
Power Ventures is the source of the rule that a cease-and-desist letter can turn tolerated access into a CFAA violation, and hiQ is the limit on it — a letter cannot create an authorisation gate over data that is public to begin with. Between them they mark out the operative distinction for anyone conducting automated collection: whose permission is needed, and whether the data sits behind a login. The case also separates consent from the user and consent from the platform, which are routinely conflated in data-scraping arguments.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · cease and desist · scraping · IP blocking
Cited 96times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on computer-crime statutes
- Van Buren v. United StatesSupreme Court of the United States · 2021A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by ob…
- LVRC Holdings LLC v. BrekkaCourt of Appeals for the Ninth Circuit · 2009An employee who is permitted to use his employer's computer does not access it “without authorization” under the CFAA by e-mailing company documents to himself…
- United States v. RodriguezCourt of Appeals for the Eleventh Circuit · 2010A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-busin…
- United States v. Nosal (Nosal I)Court of Appeals for the Ninth Circuit · 2012“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on…
- WEC Carolina Energy Solutions LLC v. MillerCourt of Appeals for the Fourth Circuit · 2012An employee “exceeds authorized access” only when he has approval to access a computer but uses that access to obtain or alter information falling outside the b…
- Sewell v. BernardinCourt of Appeals for the Second Circuit · 2015Addressing a question of first impression in the circuit, the court held that the CFAA and Stored Communications Act limitations periods run from discovery of t…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.