hiQ Labs, Inc. v. LinkedIn Corp.
- Court
- Court of Appeals for the Ninth Circuit (Federal circuit court)
- Decided
- 2022
- Citation
- 31 F.4th 1180 (9th Cir. 2022)
- Standard applied
- CFAA § 1030(a)(2) — “without authorization” and public data
What the court held
On remand from the Supreme Court after Van Buren, the Ninth Circuit again affirmed a preliminary injunction requiring LinkedIn to stop blocking a data-analytics company from scraping publicly available member profiles. It held that Van Buren reinforced serious questions about whether the CFAA reaches access to data open to anyone with a web browser, and therefore whether the statute could pre-empt the scraper's tortious-interference claim.
Why
The court read Van Buren's gates-up-or-down framing to imply that the CFAA presupposes some authorisation gate; where a profile is public, there is no gate to pass. It distinguished earlier cases involving data behind a username-and-password system, and noted that LinkedIn had not alleged the scraping caused the kind of technological harm the statute addresses. It observed that website operators are not without remedies — trespass to chattels, copyright, and contract claims may remain available.
Our reading — not the court’s words
Why this matters in practice
This is the leading authority on the legality of scraping public web data, and the reasoning has become the practical test: ask whether the data sits behind an authentication barrier. For anyone building an OSINT or evidence-collection workflow, that distinction separates routine collection from potential CFAA exposure, and a cease-and-desist letter alone does not appear to create the barrier. Note the procedural posture — this is a preliminary-injunction record, not a final merits ruling, so the questions were held to be serious rather than resolved.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · web scraping · public data · OSINT
Cited 84times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on computer-crime statutes
- Van Buren v. United StatesSupreme Court of the United States · 2021A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by ob…
- LVRC Holdings LLC v. BrekkaCourt of Appeals for the Ninth Circuit · 2009An employee who is permitted to use his employer's computer does not access it “without authorization” under the CFAA by e-mailing company documents to himself…
- United States v. RodriguezCourt of Appeals for the Eleventh Circuit · 2010A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-busin…
- United States v. Nosal (Nosal I)Court of Appeals for the Ninth Circuit · 2012“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on…
- WEC Carolina Energy Solutions LLC v. MillerCourt of Appeals for the Fourth Circuit · 2012An employee “exceeds authorized access” only when he has approval to access a computer but uses that access to obtain or alter information falling outside the b…
- Facebook, Inc. v. Power Ventures, Inc.Court of Appeals for the Ninth Circuit · 2016A social-aggregation service that accessed a platform's user data with the users' consent did not violate the CFAA while it had the platform's implied permissio…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.