In hiQ Labs, Inc. v. LinkedIn Corp., the Ninth Circuit held that scraping data from a publicly accessible website does not violate the federal Computer Fraud and Abuse Act. That was the headline win for data scrapers, but the case did not end there. hiQ ultimately lost on LinkedIn’s breach-of-contract and trespass claims, agreed to a $500,000 judgment and a permanent injunction in December 2022, and shut down. The full arc of the litigation is the part that matters: the CFAA cannot be used to police access to public data, but other laws still can.
What the Case Was About
hiQ Labs built its business on publicly visible LinkedIn profiles. Its bots collected information that users had chosen to display to anyone with a browser, and hiQ turned that data into workforce analytics for employers, including predictions about which employees were likely to leave.
In May 2017, LinkedIn sent hiQ a cease-and-desist letter demanding it stop accessing and copying data from LinkedIn’s servers. The letter argued the scraping violated LinkedIn’s User Agreement and warned that continuing would breach the CFAA, the Digital Millennium Copyright Act, California Penal Code ยง 502(c), and common-law trespass.1United States Court of Appeals for the Ninth Circuit. HiQ Labs v. LinkedIn Corp – Opinion LinkedIn also deployed technical measures to block hiQ’s bots. hiQ sued, asking a court to stop LinkedIn from interfering with its access to what hiQ argued was public information.
The CFAA Question at the Center of the Case
The Computer Fraud and Abuse Act makes it a federal crime to intentionally access a computer “without authorization” or to “exceed authorized access.”2Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers Penalties include fines and up to ten years in prison for certain offenses.
LinkedIn’s theory was that its cease-and-desist letter revoked hiQ’s permission to access LinkedIn’s servers, converting any further scraping into “unauthorized access” under the CFAA. If that argument had prevailed, any website operator could have turned public data into federally protected data by mailing a letter.
hiQ argued the opposite. The CFAA, it said, was written to punish hackers who break into password-protected systems, not to give website operators a veto over who may view pages they have chosen to make open to the world. Data visible to anyone with a browser, hiQ said, needs no special authorization to view.
How Van Buren Shaped the Ruling
In September 2019, the Ninth Circuit sided with hiQ and upheld a preliminary injunction preventing LinkedIn from blocking its access. LinkedIn appealed to the Supreme Court, which in the meantime decided Van Buren v. United States in June 2021. Van Buren was a 6-3 ruling involving a police officer who used his legitimate access to a law enforcement database to look up a license plate for personal reasons. The government argued this “exceeded authorized access,” but Justice Barrett, writing for the majority, held that a person exceeds authorized access only when they reach areas of a computer that are off-limits to them entirely, not when they use permitted access for improper purposes.3Supreme Court of the United States. Van Buren v. United States The Court warned that the government’s broader reading “would attach criminal penalties to a breathtaking amount of commonplace computer activity.”
The Supreme Court vacated the Ninth Circuit’s original hiQ decision and sent the case back for reconsideration in light of Van Buren.
The Ninth Circuit’s 2022 CFAA Holding
In April 2022, the Ninth Circuit reaffirmed its earlier conclusion. Scraping data from a website open to the general public does not violate the CFAA’s prohibition on unauthorized access.1United States Court of Appeals for the Ninth Circuit. HiQ Labs v. LinkedIn Corp – Opinion Following Van Buren’s logic, the court treated the CFAA as an on-off switch for access. Public websites have their gates open. When anyone with an internet connection can view a LinkedIn profile without a password or any other authentication step, there is no authorization barrier to breach.
The court drew a clean line between two categories of computer systems. In one, systems are open to the general public and no permission is required. In the other, access is restricted by authentication such as login credentials. The CFAA’s “without authorization” language applies only to the second category. A cease-and-desist letter cannot convert a publicly accessible page into a password-protected system.
The Ninth Circuit also described the CFAA as an “anti-intrusion statute,” not a tool for controlling how people use information they can already freely see. The law targets people who break into systems, not people who look at what is on display.
How hiQ Still Lost the Case
Winning on the CFAA did not save hiQ. The case returned to the district court, where LinkedIn pressed its breach-of-contract and state tort claims.
In November 2022, the district court ruled that hiQ had breached LinkedIn’s User Agreement, which expressly prohibits scraping profiles and creating false identities on the platform. The court found hiQ violated those terms both through its automated scraping and by using workers to create fake LinkedIn accounts. In December 2022, the parties filed a consent judgment that included a permanent injunction barring hiQ from scraping LinkedIn, a $500,000 judgment against hiQ, and hiQ’s agreement to liability for trespass to chattels and misappropriation. hiQ Labs is now permanently closed.
This is the part of the case that gets overlooked. The CFAA could not touch hiQ, but contract law could. Anyone who creates an account and agrees to a site’s terms of service has entered a contract, and scraping in violation of those terms is a straightforward breach. The distinction between accessing a site without an account, which the hiQ ruling largely protects, and accessing it after agreeing to terms that forbid scraping, is where most of the remaining legal risk lives.
What the Ruling Means for Scrapers
The case gives scrapers a real but narrow protection: the federal anti-hacking statute is not available to punish the collection of data from public pages. Everything else on the legal menu is still on the table.
Contract Claims
Breach of contract remains the strongest weapon for website owners. When a scraper creates an account and agrees to terms prohibiting automated collection, scraping is a breach. Enforceability depends on how the user agreed. Clickwrap agreements, where users must actively click “I agree,” are generally enforceable. Browsewrap agreements, where the site assumes consent from mere use, get much more skepticism, and courts have invalidated them when users had no clear notice. Scrapers who never create accounts and never click “I agree” face a much weaker contract argument. Later rulings against Meta and X in cases brought against Bright Data reinforced this dividing line: without proof that the scraper logged into an account, the terms-of-service argument struggled.
Trespass to Chattels
Website owners can sue scrapers for trespass to chattels, meaning interference with the site’s servers. The critical element is actual harm. In X Corp. v. Bright Data, the court dismissed a trespass claim because X could not show its servers were burdened, noting that automated scraping was no more taxing than ordinary browser traffic. Aggressive scraping that crashes servers or degrades performance is a different matter. Rate-limiting requests is a practical defense against a trespass claim.
Copyright
Raw facts are not copyrightable. The Supreme Court established this in Feist Publications, Inc. v. Rural Telephone Service Co., holding that facts do not owe their origin to an act of authorship and cannot be owned through copyright.4Justia U.S. Supreme Court Center. Feist Publications, Inc. v. Rural Telephone Service Co., Inc. Scraping factual data points like names, job titles, and company information is generally safe under this rule. But copyright does protect the creative selection, coordination, and arrangement of facts in a database, along with original written content such as articles, posts, and creative profile descriptions. Reproducing that content creates real infringement risk. This area is evolving quickly as courts address lawsuits over AI companies scraping copyrighted content for training data, with several major cases still pending as of 2025.
State Privacy Laws
The California Privacy Rights Act, effective January 1, 2023, broadened the definition of “personal information” to include information a consumer makes available to the general public. Publicly posted profile data can still qualify as regulated personal information, potentially triggering obligations around notice, purpose limitations, and consumer rights. Multiple other states have enacted comprehensive privacy laws with similar provisions. “Publicly available” does not mean “unregulated.”
The Geographic Limit
The Ninth Circuit covers the western United States. Other courts have reached similar conclusions about the CFAA and public data, and the D.C. federal court in Sandvig v. Barr held that violating a website’s terms of service does not trigger CFAA criminal liability, reassuring academic researchers studying algorithmic discrimination. But hiQ is not a Supreme Court ruling that binds every federal court. Anyone operating outside the Ninth Circuit should not assume the same analysis will apply without question.