hiQ Labs, Inc. v. LinkedIn Corporation, 31 F.4th 1180 (9th Cir. 2022) was decided by the United States Court of Appeals for the Ninth Circuit on April 18, 2022 (No. 17-16783). The panel affirmed the preliminary injunction barring LinkedIn from denying hiQ access to public member profiles and remanded for further proceedings. It held that hiQ had raised serious questions as to whether the 'without authorization' concept reaches computers for which permission is not generally required at all. Because this was a preliminary injunction on a sliding scale, the panel decided that hiQ raised serious questions, not that scraping public pages is lawful as a final matter.
The question before the court
Where a website's pages are open to anyone with a browser and no credential is required, does a cease-and-desist letter aimed at one scraper make its continued automated collection access 'without authorization' under the Computer Fraud and Abuse Act?
The governing rule
18 U.S.C. § 1030(a)(2)(C) punishes one who 'intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains ... information from any protected computer.' The panel read that clause alongside § 1030(a)(6), the password-trafficking provision, and alongside the parallel language of the Stored Communications Act, 18 U.S.C. § 2701(a). It applied Van Buren v. United States, 141 S. Ct. 1648 (2021), which construed the 'exceeds authorized access' clause and framed liability under both clauses as a 'gates-up-or-down inquiry.' The procedural standard was the preliminary injunction test, applied on the Ninth Circuit's sliding scale, under which a plaintiff whose balance of hardships tips sharply need show only serious questions going to the merits.
How the court applied it
The case reached the panel on remand from the Supreme Court, which had vacated the earlier judgment for reconsideration in light of Van Buren. The panel read the statute as contemplating three kinds of systems: those open to the general public where no permission is required; those where authorization is required and has been given; and those where it is required and has not been given. Public LinkedIn profiles, reachable by anyone with an Internet connection, sat in the first category, and for that category the burglary analogy that ran through the congressional debates does not fit. Van Buren reinforced rather than unsettled that reading. Its gates metaphor presupposes a gate that can be raised or lowered, and a server hosting freely accessible pages has built none. The panel also distinguished the two authorities LinkedIn pressed. Nosal II involved a database no one could reach without credentials, and Power Ventures involved data behind Facebook's username and password authentication, which Power Ventures obtained by having users hand over their logins. Both concerned systems whose authorization gate was down. The panel added a caveat: a server hosting public pages may still hold areas that do require authorization, and entering those without it would violate § 1030(a)(2)(C).
What the court concluded
The panel affirmed the preliminary injunction barring LinkedIn from denying hiQ access to public member profiles and remanded for further proceedings. It held that hiQ had raised serious questions as to whether the 'without authorization' concept reaches computers for which permission is not generally required at all. Because this was a preliminary injunction on a sliding scale, the panel decided that hiQ raised serious questions, not that scraping public pages is lawful as a final matter.
From the opinion
- “With regard to websites made freely accessible on the Internet, the "breaking and entering" analogue invoked so frequently during congressional consideration has no application” — Conclusion of the panel's three-categories reading of the CFAA, placing public LinkedIn profiles in the category where no permission is required.
- “that computer has erected no gates to lift or lower in the first place” — Applying Van Buren's gates-up-or-down inquiry to a computer hosting publicly available webpages.
- “Nosal II and Power Ventures control situations in which authorization generally is required and has either never been given or has been revoked” — Distinguishing the two Ninth Circuit precedents LinkedIn relied on, both involving credential-protected systems.
Why it matters for cyber conflict
The decision draws the outer edge of computer-intrusion liability at the authentication gate, which matters when the conduct under scrutiny is bulk collection of open-source data by a foreign or state-linked collector rather than an intrusion into a protected system. It also shows a private letter cannot by itself convert public browsing into a federal offence.
Editorial note: this case note was drafted with AI assistance by the JLCW Research Desk, checked against the text of the opinion, and reviewed by a human editor before publication. Every quotation above is carried through from the opinion itself. See our editing policy.
Read the opinion: hiQ Labs, Inc. v. LinkedIn Corporation on CourtListener. This note is a summary prepared by the Journal, not legal advice, and not a substitute for the opinion itself.
More on Private Sector · All case notes · Peer-reviewed scholarship