The Ninth Circuit’s ruling in the hiQ Labs v. LinkedIn CFAA case held that scraping publicly available data from a website does not violate the federal Computer Fraud and Abuse Act. A public webpage has no login, no password, and no gate to breach, so accessing it cannot be “without authorization” under the statute. That was a clean win for hiQ on the federal hacking question. It was also not the end of the case. hiQ eventually paid LinkedIn $500,000, deleted the data it had collected, destroyed its scraping code, and shut down the business the ruling was supposed to save.
How the Fight Started
hiQ Labs was a data analytics company. It ran automated bots against publicly visible LinkedIn profiles and used the results to build two products: Keeper, which predicted which employees were likely to be recruited away, and Skill Mapper, which summarized worker abilities. Every profile it touched was set to public by the user. No account was needed to view any of it.
LinkedIn sent hiQ a cease-and-desist letter demanding the company stop accessing its servers, then rolled out technical measures to block the bots. hiQ’s entire business ran on that data, so the letter was existential. The company sued, asking a court to keep the pipeline open and arguing LinkedIn was using the CFAA to eliminate a competitor from a market built on public information.
What the CFAA Says and What LinkedIn Argued
The Computer Fraud and Abuse Act, codified at 18 U.S.C. § 1030, makes it a federal crime to access a “protected computer” without authorization or to exceed authorized access to obtain information.1Office of the Law Revision Counsel. 18 U.S. Code 1030 – Fraud and Related Activity in Connection with Computers LinkedIn’s theory was that its cease-and-desist letter revoked hiQ’s authorization. Any scraping after that letter was therefore unauthorized access, and unauthorized access to a computer connected to the internet is a federal computer crime.
hiQ’s answer was that the profiles it scraped required no password, no login, and no account. Under LinkedIn’s theory, anyone who ever visited a LinkedIn profile without signing in would be violating federal law the moment the site’s operator decided to object. The CFAA was written to punish people who break into protected systems, not people who view pages the open internet already displays.
The Ninth Circuit’s Holding
In September 2019, the U.S. Court of Appeals for the Ninth Circuit granted hiQ a preliminary injunction forcing LinkedIn to stop blocking its bots.2United States Court of Appeals for the Ninth Circuit. hiQ Labs, Inc. v. LinkedIn Corporation – Opinion The court drew a line between breaking into a password-protected system and visiting a website open to anyone. The CFAA’s “without authorization” language was written for the first situation, not the second. Public websites don’t require permission. There is no credential to present.
LinkedIn appealed to the U.S. Supreme Court. In June 2021, rather than deciding the scraping question directly, the Supreme Court vacated the Ninth Circuit’s judgment and sent the case back for reconsideration in light of a separate CFAA ruling issued that same term: Van Buren v. United States.
How Van Buren Sharpened the Answer
Van Buren involved a police officer who used his valid credentials for a law enforcement database to look up a license plate for an unauthorized purpose. The Supreme Court held that misusing legitimate access is not “exceeding authorized access” under the CFAA. It adopted a “gates-up-or-down” test: either a user can reach a particular area of a system or they can’t, and the statute cares about the gate, not the user’s reason for walking through it.3Supreme Court of the United States. Van Buren v. United States
On remand in April 2022, the Ninth Circuit applied that test and reaffirmed its earlier conclusion. It identified three categories of computer systems under the CFAA: those open to the public with no permission required, those where authorization has been granted, and those where authorization is required but hasn’t been given. A public website falls into the first. A computer hosting publicly available webpages, the court wrote, “has erected no gates to lift or lower in the first place.”2United States Court of Appeals for the Ninth Circuit. hiQ Labs, Inc. v. LinkedIn Corporation – Opinion The court also pointed to the CFAA’s own password-trafficking provision, which frames authorization as a question of authentication. Public-facing content on a public site has no authentication system. The data hiQ collected sat behind no access controls. The statute simply did not reach it.
Why hiQ Still Paid $500,000
This is the part the headline version of the case leaves out. hiQ won the CFAA question decisively. It lost almost everything else.
Once the CFAA claim was cleared, the case returned to the U.S. District Court for the Northern District of California, where LinkedIn pressed a breach of contract claim. LinkedIn’s User Agreement expressly prohibited scraping. In November 2022, the district court ruled that hiQ had breached that agreement. hiQ had also created fake accounts on the platform, which further weakened its position.
The case ended in a settlement. hiQ paid LinkedIn $500,000 in damages. It was permanently barred from scraping LinkedIn in any form. It was required to delete all LinkedIn member data in its possession and to destroy every piece of software and source code it had built to collect or analyze that data. hiQ also accepted liability for trespass to chattels and misappropriation. A landmark CFAA victory ended with the winning company dismantling itself.
What the Ruling Actually Means for Scraping Public Websites
Within the Ninth Circuit, which covers California, Washington, Oregon, and several other western states, the holding is settled: the CFAA does not criminalize collecting data from a public website. That is a meaningful protection. It is also narrower than it sounds, because the CFAA was only one of several legal theories LinkedIn raised, and the others did the real damage.
Terms of Service Still Bind
The most practical lesson from hiQ is that a website’s terms of service can be enforced as a contract even when the CFAA doesn’t apply. A cease-and-desist letter can establish that a commercial scraper had notice of those terms. Courts have been more willing to enforce browsewrap agreements against businesses and sophisticated parties than against ordinary consumers, but for any commercial scraping operation, the safer assumption is that the terms are enforceable and that breaching them carries real damages.
Trespass to Chattels
This common-law tort protects against interference with someone else’s property, including their servers. It requires showing measurable harm to the system, such as a scraper hitting a site hard enough to slow it down or drive up hosting costs. hiQ accepted liability on this theory as part of its settlement.
Copyright
Scraping raw facts generally doesn’t create copyright problems. The Supreme Court held in Feist Publications v. Rural Telephone Service Co. that facts are not copyrightable and that a factual compilation is protected only when its selection and arrangement show some minimal creativity.4Justia Law. Feist Publications, Inc. v. Rural Telephone Service Co., 499 U.S. 340 Names, job titles, and employment histories are facts. Scraping full articles, creative content, or substantial portions of copyrighted text is a different question, evaluated under the four-factor fair use analysis in federal law.5Office of the Law Revision Counsel. 17 U.S. Code 107 – Limitations on Exclusive Rights: Fair Use
The Limits of the Precedent
The Ninth Circuit’s CFAA ruling is binding only in its jurisdiction. Other federal circuits have not all addressed whether scraping public sites violates the CFAA, and the Supreme Court declined to resolve the question when it had the chance. A scraper operating outside the Ninth Circuit cannot assume the same protection.
The deeper limit is the one hiQ itself proved. Clearing the CFAA is necessary and nowhere near sufficient. The terms of service, the technical impact on the target’s servers, and the copyright status of the content each create independent legal exposure that the Ninth Circuit’s ruling does nothing to touch. hiQ won the federal computer crime question and still ended up writing a $500,000 check and shredding its own code. Any business built on scraping has to plan for every one of those other theories, because winning on the CFAA is not the same as winning the case.