Sandvig v. Sessions, 315 F. Supp. 3d 1 (D.D.C. 2018) was decided by the United States District Court for the District of Columbia on March 30, 2018 (No. Civil Action No. 16-1368 (JDB)). The court denied the motion to dismiss for lack of standing and allowed the as-applied Free Speech and Free Press claim to proceed. It dismissed the First Amendment overbreadth and petition claims and the Fifth Amendment vagueness and nondelegation claims, because on the court's narrower reading the Access Provision does not sweep widely enough to make them plausible. Breaching a website's terms of service is not by itself exceeding authorized access.
The question before the court
Does the CFAA's access provision criminalise breaching a website's terms of service, and if it is read narrowly, may researchers who must create false tester profiles and scrape public pages still press a First Amendment challenge to it?
The governing rule
The Access Provision, 18 U.S.C. § 1030(a)(2)(C), punishes whoever intentionally accesses a computer without authorization or exceeds authorized access and thereby obtains information from any protected computer. 'Protected computer' is defined at § 1030(e)(2)(B) to include any computer used in or affecting interstate or foreign commerce or communication, which covers essentially every Internet-connected machine including web servers. 'Exceeds authorized access' is defined at § 1030(e)(6) as accessing a computer with authorization and using that access to obtain or alter information the accesser is not entitled so to obtain or alter. The penalty structure at § 1030(c)(2) makes a first violation a misdemeanor unless one of three aggravating conditions applies. The court read those provisions against §§ 1030(a)(4) and (a)(5), which carry their own fraud and damage requirements, and decided the constitutional claims under the Free Speech, Free Press and Petition Clauses of the First Amendment and the Fifth Amendment vagueness and nondelegation doctrines, on Rule 12(b)(1) and 12(b)(6) motions.
How the court applied it
The plaintiffs were four academic researchers and a media organisation planning audit studies of algorithmic discrimination in housing, employment and credit. Their methods required creating false tester profiles and scraping results, both of which breach the target sites' terms of service. Because the claims were purely constitutional and brought pre-enforcement, the court first had to decide how far the statute reaches. It rejected the government's broad reading. The text of § 1030(e)(6) is most naturally read as limited to the spatial scope of permitted access: the accesser must already have permission and must use that presence to obtain information he is not entitled to obtain, so the phrase addresses insiders straying rather than outsiders breaking in. 'Entitled' functions as a synonym for authorized, and nothing in the definition turns on the accesser's purpose. Statutory context confirmed it, since importing a purpose element would flatten the difference between the Access Provision and § 1030(a)(4), which requires intent to defraud, and would blur the misdemeanor and felony tiers. On the constitutional side, the court treated recording the contents of public websites as arguably carrying a First Amendment interest and found the government had offered nothing to show that prosecuting harmless false statements in account creation advances any anti-theft or anti-trespass interest.
What the court concluded
The court denied the motion to dismiss for lack of standing and allowed the as-applied Free Speech and Free Press claim to proceed. It dismissed the First Amendment overbreadth and petition claims and the Fifth Amendment vagueness and nondelegation claims, because on the court's narrower reading the Access Provision does not sweep widely enough to make them plausible. Breaching a website's terms of service is not by itself exceeding authorized access.
From the opinion
- “the phrase "exceeds authorized access" refers not to an outside attack but rather to an inside job” — Part C, interpreting the statutory definition at 18 U.S.C. § 1030(e)(6) and contrasting it with 'unauthorized access'.
- “In neither instance does the statute focus on how the accesser plans to use the information.” — Close of the textual analysis, after reading 'entitled' as a synonym for authorized.
- “plaintiffs' attempts to record the contents of public websites for research purposes are arguably affected with a First Amendment interest” — First Amendment analysis, treating scraping as no different in kind from taking notes or photographs in a public forum.
Why it matters for cyber conflict
Keeping terms of service outside the criminal access provision preserves the security research and platform auditing that underpins public understanding of how systems are attacked and how they behave. A statute broad enough to reach every clickwrap breach would put defenders and journalists in the same category as intruders.
Editorial note: this case note was drafted with AI assistance by the JLCW Research Desk, checked against the text of the opinion, and reviewed by a human editor before publication. Every quotation above is carried through from the opinion itself. See our editing policy.
Read the opinion: Sandvig v. Sessions on CourtListener. This note is a summary prepared by the Journal, not legal advice, and not a substitute for the opinion itself.
More on Private Sector · All case notes · Peer-reviewed scholarship