In a much-anticipated ruling this week addressing the confluence of website scraping and computer hacking law, the U.S. Court of Appeals for the Ninth Circuit became the latest federal court to limit the reach of the Computer Fraud and Abuse Act (CFAA). In hiQ Labs v. LinkedIn, the Ninth Circuit held, for a second time, that the automated capture of data from the publicly accessible pages of websites (that do not require the creation of an account for access) does not violate the CFAA’s prohibition on accessing a computer “without authorization.” The circuit court’s decision closely tracks the U.S. Supreme Court’s landmark ruling in Van Buren v. United States (2021), which narrowly interpreted the correlated “exceeds authorized access” provision of the CFAA. HiQ, like Van Buren before it, reads the CFAA to create a bright-line “gates-up-or-down inquiry.” Liability turns on whether there was an intrusion into a protected system, not whether data access amounted to a technical violation of the data holder’s terms of service. The decision creates breathing room for companies that mine public data for commercial use, just as state and federal regulators are ramping up data privacy protections. A Long and Twisting Road HiQ is a data…
Read More











