Showing posts with label Internet law. Show all posts
Showing posts with label Internet law. Show all posts

Wednesday, May 11, 2022

New Hampshire Supreme Court, Banaian v. Bascom, Docket No. 2020-0496

Internet Law

 

Tweeter

 

Defamation

 

Republishing Someone Else’s Content

 

Immunity?

 

Communications Decency Act, 47 U.S.C. § 230(c)(1) (2018) (CDA)

 

 

(…) Given that Congress declared that “‘no provider or user of an interactive computer service shall be treated as a publisher or speaker,’” the court found no basis “for concluding that Congress intended to treat service providers and users differently,” and that “the statute confers immunity on both.”

 

(…) Section 230 of the CDA abrogates the common law of defamation as applied to individual users.

 

 

 

 

The sole issue on appeal is whether the defendants, who retweeted a defamatory tweet (the retweeter defendants) initiated by another individual, are “users” within the meaning of the Communications Decency Act, 47 U.S.C. § 230(c)(1) (2018) (CDA), and therefore entitled to immunity from the plaintiff’s claims for defamation and reckless infliction of emotional distress.

 

 

(…) The retweeter defendants retweeted the original tweet. As a result, the plaintiff was subject to “school-wide ridicule,” was unable to work for approximately six months, and suffered financial, emotional, physical, and reputational harm.

 

 

The plaintiff sued a number of defendants for defamation and reckless infliction of emotional distress. These retweeter defendants moved to dismiss, arguing that the plaintiff’s claims against them were barred by section 230(c) of the CDA. The trial court agreed, determining that the retweeters’ actions of simply “clicking the. . . ‘retweet’ icon and republishing someone else’s content,” were shielded by section 230. Accordingly, the trial court dismissed the plaintiff’s case against these retweeter defendants.

 

 

The CDA provides in pertinent part that “no provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider.”  47 U.S.C. § 230(c)(1). An “interactive computer service” is “any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server, including specifically a service or system that provides access to the Internet.” 47 U.S.C. § 230(f)(2) (2018). An “information content provider” is “any person or entity that is responsible, in whole or in part, for the creation or development of information provided through the Internet or any other interactive computer service.” 47 U.S.C. § 230(f)(3) (2018). “No cause of action may be brought and no liability may be imposed under any State or local law that is inconsistent with” section 230. 47 U.S.C. § 230(e)(3) (2018). The statute sets forth findings and a statement of policy. See 47 U.S.C. § 230(a) & (b) (2018). Congress recognized the Internet as a “forum for a true diversity of political discourse, unique opportunities for cultural development, and myriad avenues for intellectual activity, ”and that the “Internet and other interactive computer services have flourished, to the benefit of all Americans, with a minimum of government regulation.” Id. § 230(a)(3)-(4). The stated policy of the United States includes the promotion of “the continued development of the Internet and other interactive computer services and other interactive media” and the preservation of “the vibrant and competitive free market” for such services, “unfettered by Federal or State regulation, ”as well as the encouragement of “the development of technologies which maximize user control over what information is received by individuals.” Id. §230(b)(1)-(3). Separated into its elements, section 230(c)(1) “only protects from liability (1) a provider or user of an interactive computer service (2) whom a plaintiff seeks to treat, under a State law cause of action, as a publisher or speaker (3) of information provided by another information content provider.” Teatotaller, LLC v. Facebook, Inc., 173 N.H. 442, 450 (2020) (quotation omitted); see Universal Communication Systems, Inc. v. Lycos, Inc., 478 F.3d 413, 418 (1st Cir. 2007). “Section 230 of the CDA provides broad immunity to entities that facilitate the speech of others on the Internet.” Teatotaller, LLC, 173 N.H. at 448 (quotation and ellipsis omitted); see Bennett v. Google, LLC, 882 F.3d 1163, 1166 (D.C.Cir.2018) (explaining that the intent of the CDA is “to promote rather than chill internet speech”). “There has been near-universal agreement that section 230 should not be construed grudgingly, but rather should be given broad construction.” Teatotaller, LLC, 173 N.H. at 449 (quotations omitted). The trial court found, and the plaintiff does not dispute, that Twitter falls within the definition of an “interactive computer service.” Twitter is a social media platform that “enables users to publish short messages to the general public called ‘tweets,’ to republish or respond to others’ tweets, and to interact with other users.” Campbell v. Reisch, 367 F. Supp. 3d 987, 989 (W.D. Mo. 2019). “A user ‘Retweets’ a Tweet when he or she elects to publish the original Tweet in full on his or her Twitter profile. A Retweet shows the original Tweet in full, including attribution to the person who initially published the Tweet.” McNeil v. Biaggi Productions, LLC, No. 3:15cv751, 2017 WL 2625069 at *3 n.13 (E.D. Va. June 16, 2017).

 

 

The meaning of “user” in the first element of section 230(c)(1) is the sole issue in this appeal.

 

 

(…) The trial court “recognized that the vast majority of the reported cases that address whether a defendant is immune from suit under Section 230 involve internet service providers. . . , and not individual users”Nonetheless, cases that have addressed this issue have determined that the broad immunity in the statute extends to individual usersFor example, in Barrett v. Rosenthal, 146 P.3d 510 (Cal. 2006), an individual who posted a copy of an article she had received via email on two newsgroup websites was sued for republishing defamatory information.  Barrett, 146 P.3d at 514.  The California Supreme Court addressed what “appeared to be the first published case in which section 230 immunity had been invoked by an individual who had no supervisory role in the operation of the Internet site where allegedly defamatory material appeared, and who thus was clearly not a provider of an ‘interactive computer service’ under the broad definition provided in the CDA.” Id. at 515. Employing “standard rules of statutory construction,” the court looked to the ordinary meaning of the word “user” to discern “legislative purpose. ”Id. at 526. In doing so, the court determined that the term “‘user’ plainly refers to someone who uses something, and the statutory context makes it clear that Congress simply meant someone who uses an interactive computer service.” Id. As the court reasoned, Section 230(c)(1) refers directly to the “user of an interactive computer service.” Section 230(f)(2) defines “interactive computer service” as “any information service, system, or access software provider that provides or enables computer access by multiple users to a computer server, including specifically a service or system that provides access to the Internet.” Section 230(a)(2) notes that such services “offer users a great degree of control over the information that they receive,” and section 230(b)(3) expresses Congress’s intent “to encourage the development of technologies which maximize user control over what information is received by individuals, families, and schools who use the Internet and other interactive computer services.” Thus, Congress consistently referred to “users” of interactive computer services, specifically including “individuals” in section 230(b)(3). Id. (ellipsis omitted). Given that Congress declared that “‘no provider or user of an interactive computer service shall be treated as a publisher or speaker,’” the court found no basis “for concluding that Congress intended to treat service providers and users differently,” and that “the statute confers immunity on both.” Id. at 527. Thus, the court concluded, “Congress employed the term ‘user’ to refer simply to anyone using an interactive computer service,” id. at 515, and held that section 230(c)(1) immunizes such individual users, id. at 513.

 

 

Subsequently, the United States District Court for the Eastern District of Virginia, noting that the CDA does not contain a definition of “user,” turned to the plain meaning of the word. Directory Assistants, Inc. v. Supermedia, LLC, 884 F. Supp. 2d 446, 452 (E.D. Va. 2012). Citing the dictionary definition of “user” as “someone who uses,” and the verb “to use” as “putting into action or service; avail oneself of; carry out a purpose or actions by means of; utilize,” the court reasoned that the defendants’ “action of compiling information from a website and e-mailing that information to others clearly constitutes use of that website and its services.” Id. There was no allegation that the defendants “engaged in the traditional role of a publisher of content by soliciting the posts, creating them, or altering them,” or that the defendants “actually wrote, created, or developed the allegedly defamatory content.” Id. at 453. Rather, the defendants were “downstream users of content created by other people and posted” on the websites at issue. Id. The court determined that “there is no authority in the statute or case law that makes a user responsible for the creation or development of posts on a website that is an interactive computer service” and that “in enacting the CDA, Congress prohibited courts from entertaining claims that would place both a computer service provider and user in a publisher’s role. ”Id. Accordingly, the court found that “a person who creates or develops unlawful content may be held liable, but . . . a user of an interactive computer service who finds and forwards via e-mail that content posted online in an interactive computer service by others is immune from liability.” Id. at 451.

 

 

Despite the plaintiff’s assertion to the contrary, we conclude that it is evident that section 230 of the CDA abrogates the common law of defamation as applied to individual users. The CDA provides that “no cause of action may be brought and no liability may be imposed under any State or local law that is inconsistent with this section.” 47 U.S.C. § 230(e)(3).  We agree with the trial court that the statute’s plain language confers immunity from suit upon users and that “Congress chose to immunize all users who repost the content of others.” That individual users are immunized from claims of defamation for retweeting content that they did not create is evident from the statutory language. See Zeran v. America Online, Inc., 129 F.3d 327, 334 (4th Cir. 1997) (explaining that the language of section 230 makes “plain that Congress’ desire to promote unfettered speech on the Internet must supersede conflicting common law causes of action”).

 

 

We hold that the retweeter defendants are “users of an interactive computer service” under section 230(c)(1) of the CDA, and thus the plaintiff’s claims against them are barred. See 47 U.S.C. § 230(e)(3). Accordingly, we uphold the trial court’s granting of the motions to dismiss because the facts pled in the plaintiff’s complaint do not constitute a basis for legal relief.

 

 

 

 

(New Hampshire Supreme Court, May 11, 2022, Banaian v. Bascom, Docket No. 2020-0496)

Monday, April 18, 2022

Data Scraping - Remedies

Data

 

Data Scraping

 

 

Remedies

 

Cease-and-Desist Letter

 

Trespass to Chattels

 

Copyright Infringement 

 

Misappropriation 

 

Unjust Enrichment 

 

Conversion

 

Breach of Contract 

 

Breach of Privacy

 

 

 

 

(…) Entities that view themselves as victims of data scraping are not without resort, even if the CFAA does not apply: state law trespass to chattels claims may still be available. And other causes of action, such as copyright infringement, misappropriation, unjust enrichment, conversion, breach of contract, or breach of privacy, may also lie. See, e.g., Associated Press v. Meltwater U.S. Holdings, Inc., 931 F. Supp. 2d 537, 561 (S.D.N.Y. 2013) (holding that a software company’s conduct in scraping and aggregating copyrighted news articles was not protected by fair use).

 

 

(…) LinkedIn’s cease-and-desist letter also asserted a state common law claim of trespass to chattels. Although we do not decide the question, it may be that web scraping exceeding the scope of the website owner’s consent gives rise to a common law tort claim for trespass to chattels, at least when it causes demonstrable harm. Compare eBay, Inc. v. Bidder’s Edge, Inc., 100 F. Supp. 2d 1058, 1070 (N.D. Cal. 2000) (finding that eBay had established a likelihood of success on its trespass claim against the auction-aggregating site Bidder’s Edge because, although eBay’s “site is publicly accessible,” “eBay’s servers are private property, conditional access to which eBay grants the public,” and Bidder’s Edge had exceeded the scope of any consent, even if it did not cause physical harm); Register.com, Inc. v. Verio, Inc., 356 F.3d 393, 437–38 (2d Cir. 2004) (holding that a company that scraped a competitor’s website to obtain data for marketing purposes likely committed trespass to chattels, because scraping could—although it did not yet—cause physical harm to the plaintiff’s computer servers); Sw. Airlines Co. v. FareChase, Inc., 318 F. Supp. 2d 435, 442 (N.D. Tex. 2004) (holding that the use of a scraper to glean flight information was unauthorized as it interfered with Southwest’s use and possession of its site, even if the scraping did not cause physical harm or deprivation), with Ticketmaster Corp. v. Tickets.Com, Inc., No. 2:99-cv-07654-HLH-VBK, 2003 WL 21406289, at *3 (C.D. Cal. Mar. 7, 2003) (holding that the use of a web crawler to gather information from a public website, without more, is insufficient to fulfill the harm requirement of a trespass action); Intel Corp. v. Hamidi, 30 Cal. 4th 1342, 1364 (2003) (holding that “trespass to chattels is not actionable if it does not involve actual or threatened injury” to property and the defendant’s actions did not damage or interfere with the operation of the computer systems at issue) (Fn. 21).

 

 

 

 

 

(U.S. Court of Appeals for the Ninth Circuit, April 18, 2022, HIQ Labs, Inc. v. LinkedIn Corp., Docket No. 17-16783, for Publication, p. 41)

 

 

E-Commerce - E-Mail

E-Mail

 

Privacy

 

 

The Stored Communications Act, enacted as part of the Electronic Communications Privacy Act of 1986, Pub. L. No. 99-508, 100 Stat. 1848, provides privacy protections for e-mail and other electronic communications by limiting the ability of the government to compel disclosure by internet service providers.

 

 

(U.S. Court of Appeals for the Ninth Circuit, April 18, 2022, HIQ Labs, Inc. v. LinkedIn Corp., Docket No. 17-16783, for Publication, p. 38)

Sunday, April 17, 2022

U.S. Court of Appeals for the Ninth Circuit, HIQ Labs, Inc. v. LinkedIn Corp., Docket No. 17-16783

Preliminary Injunction

Injunctive Relief

 

Declaratory Judgment

 

Temporary Restraining Order

 

To Use LinkedIn Public Profile Data

 

Non-Exclusive License

 

Ownership Interest

 

To Access a Computer Without Authorization

 

Tortious Interference with Contract

 

Legitimate Business Purpose

 

Cease-and-Desist Letters and Interference

 

California Law

Computer Fraud and Abuse Act (CFAA)

 

 

 

On Remand from the United States Supreme Court

 

 

On remand from the United States Supreme Court, the panel affirmed the district court’s order preliminarily enjoining LinkedIn Corp. from denying hiQ Labs, Inc., a data analytics company, access to publicly available member profiles on LinkedIn’s professional networking website.

 

The panel previously affirmed the preliminary injunction. The Supreme Court granted certiorari, vacated the panel’s judgment, and remanded for further consideration in light of Van Buren v. United States, 141 S. Ct. 1648 (2021). On remand, the panel again affirmed the preliminary injunction, concluding that Van Buren reinforced its determination that hiQ had raised serious questions about whether LinkedIn may invoke the Computer Fraud and Abuse Act (“CFAA”) to preempt hiQ’s possibly meritorious tortious interference claim.

 

The panel held that a plaintiff seeking a preliminary injunction must establish that it is likely to succeed on the merits, that it is likely to suffer irreparable harm in the absence of preliminary relief, that the balance of equities tips in its favor, and that an injunction is in the public interest. The court uses a “sliding scale” approach to these factors, so that when the balance of hardships tips sharply in the plaintiff’s favor, it need demonstrate only serious questions going to the merits. Applying this approach, the district court concluded that the balance of hardships tipped sharply in hiQ’s favor and that hiQ raised serious questions on the merits.

 

The panel held that the district court did not abuse its discretion in concluding on the preliminary injunction record that hiQ currently had no viable way to remain in business other than using LinkedIn public profile data for its “Keeper” and “Skill Mapper” analytics services, and that hiQ therefore had demonstrated a likelihood of irreparable harm absent a preliminary injunction.

 

The panel concluded that the district court properly determined that the balance of hardships tipped sharply in hiQ’s favor, when weighing the likelihood that hiQ would go out of business against LinkedIn’s assertion that an injunction threatened its members’ privacy and therefore put at risk the goodwill that LinkedIn had developed with its members.

 

The panel concluded that hiQ showed a sufficient likelihood of establishing the elements of its claim for intentional interference with contract, and it raised a serious question on the merits of LinkedIn’s affirmative justification defense. Further, hiQ raised serious questions about whether LinkedIn could invoke the CFAA to preempt hiQ’s possibly meritorious tortious interference claim. The CFAA prohibits accessing a “protected computer” without authorization. The panel concluded that to scrape LinkedIn data, hiQ needed to access LinkedIn servers, which were “protected computers.” At issue was whether, once hiQ received LinkedIn’s cease-and-desist letter, any further scraping and use of LinkedIn’s data was “without authorization” within the meaning of the CFAA. The panel concluded that hiQ raised a serious question as to whether the CFAA “without authorization” concept is inapplicable where, as here, prior authorization is not generally required but a particular person—or bot—is refused access. The panel concluded that the reasoning of Van Buren reinforced its interpretation of the CFAA, although Van Buren did not directly address the CFAA’s “without authorization” clause, but rather considered the statute’s “exceeds authorized access” clause.

 

Finally, the panel concluded that the district court properly determined that, on balance, the public interest favored hiQ’s position.

 

The panel affirmed the district court’s determination that hiQ had established the elements required for a preliminary injunction and remanded for further proceedings.

 

HiQ is a data analytics company founded in 2012. Using automated bots, it scrapes information that LinkedIn users have included on public LinkedIn profiles, including name, job title, work history, and skills. It then uses that information, along with a proprietary predictive algorithm, to yield “people analytics,” which it sells to business clients.

 

 

In May 2017, LinkedIn sent hiQ a cease-and-desist letter, asserting that hiQ was in violation of LinkedIn’s User Agreement and demanding that hiQ stop accessing and copying data from LinkedIn’s server. The letter stated that if hiQ accessed LinkedIn’s data in the future, it would be violating state and federal law, including the CFAA, the Digital Millennium Copyright Act (“DMCA”), California Penal Code § 502(c), and the California common law of trespass. The letter further stated that LinkedIn had “implemented technical measures to prevent hiQ from accessing, and assisting others to access, LinkedIn’s site, through systems that detect, monitor, and block scraping activity.”

 

 

HiQ’s response was to demand that LinkedIn recognize hiQ’s right to access LinkedIn’s public pages and to threaten to seek an injunction if LinkedIn refused. A week later, hiQ filed an action, seeking injunctive relief based on California law and a declaratory judgment that LinkedIn could not lawfully invoke the CFAA, the DMCA, California Penal Code § 502(c), or the common law of trespass against it. HiQ also filed a request for a temporary restraining order, which the parties subsequently agreed to convert into a motion for a preliminary injunction.

 

 

The district court granted hiQ’s motion. It ordered LinkedIn to withdraw its cease-and-desist letter, to remove any existing technical barriers to hiQ’s access to public profiles, and to refrain from putting in place any legal or technical measures with the effect of blocking hiQ’s access to public profiles. LinkedIn timely appealed.

 

 

We begin with the likelihood of irreparable injury to hiQ if preliminary relief were not granted. “Monetary injury is not normally considered irreparable.” Los Angeles Mem’l Coliseum Comm’n v. Nat’l Football League, 634 F.2d 1197, 1202 (9th Cir. 1980). Nonetheless, “the threat of being driven out of business is sufficient to establish irreparable harm.” Am. Passage Media Corp. v. Cass Commc’ns, Inc., 750 F.2d 1470, 1474 (9th Cir. 1985).

 

 

B. Balance of the Equities

 

Next, the district court “balanced the interests of all parties and weighed the damage to each in determining the balance of the equities.” CTIA - The Wireless Ass’n v. City of Berkeley, Calif., 928 F.3d 832, 852 (9th Cir. 2019) (internal quotation marks and citation omitted). Again, it did not abuse its discretion in doing so.

 

 

We conclude that the district court’s determination that the balance of hardships tips sharply in hiQ’s favor is not “illogical, implausible, or without support in the record.” Kelly, 878 F.3d at 713.

 

 

C. Likelihood of Success 

 

Because hiQ has established that the balance of hardships tips decidedly in its favor, the likelihood-of-success prong of the preliminary injunction inquiry focuses on whether hiQ has raised “serious questions going to the merits.” Alliance for the Wild Rockies, 632 F.3d at 1131. It has.

 

 

1.   Tortious Interference with Contract

 

HiQ alleges that LinkedIn intentionally interfered with hiQ’s contracts with  third parties. “The elements which a plaintiff must plead to state the cause of action for intentional interference with contractual relations are (1) a valid contract between plaintiff and a third party; (2) defendant’s knowledge of this contract; (3) defendant’s intentional acts designed to induce a breach or disruption of the contractual relationship; (4) actual breach or disruption of the contractual relationship; and (5) resulting damage.” Pac. Gas & Elec. Co. v. Bear Stearns & Co., 50 Cal. 3d 1118, 1126 (1990).

 

 

Under California law, tortious interference with contract claims are not limited to circumstances in which the defendant has caused the third party with whom the plaintiff has contracted to breach the agreement. “The most general application of the rule is to cases where the party with whom the plaintiff has entered into an agreement has been induced to breach it, but the rule is also applicable where the plaintiff’s performance has been prevented or rendered more expensive or burdensome and where he has been induced to breach the contract by conduct of the defendant, such as threats of economic reprisals.” Lipman v. Brisbane Elementary Sch. Dist., 55 Cal. 2d 224, 232 (1961), abrogated on other grounds by Brown v. Kelly Broad. Co., 48 Cal. 3d 711, 753 n. 37 (1989); see also Pac. Gas & Elec. Co., 50 Cal. 3d at 1129 (“We have recognized that interference with the plaintiff’s performance may give rise to a claim for interference with contractual relations if plaintiff’s performance is made more costly or more burdensome.”).

 

 

Third, LinkedIn’s threats to invoke the CFAA and implementation of technical measures selectively to ban hiQ bots could well constitute “intentional acts designed to induce a breach or disruption” of hiQ’s contractual relationships with third parties. Pac. Gas & Elec. Co., 50 Cal.  3d at 1126; cf. Winchester Mystery House, LLC v. Global Asylum, Inc., 210 Cal. App. 4th 579, 597 (2012) (indicating that “cease-and-desist letters . . . referring to a contractual or other economic relationship between plaintiff and any third party” could “establish . . . the . . . intent element of the interference claim”).

 

 

Under California law, a legitimate business purpose can indeed justify interference with contract, but not just any such purpose suffices. See id. at 55–56. Where a contractual relationship exists, the societal interest in “contractual stability is generally accepted as of greater importance than competitive freedom.” Imperial Ice Co. v. Rossier, 18 Cal. 2d 33, 36 (1941). Emphasizing the “distinction between claims for the tortious disruption of an existing contract and claims that a prospective contractual or economic relationship has been interfered with by the defendant,” the California Supreme Court instructs that we must “bring a greater solicitude to those relationships that have ripened into agreements.” Della Penna v. Toyota Motor Sales, U.S.A., Inc., 11 Cal. 4th 376, 392 (1995). Thus, interference with an existing contract is not justified simply because a competitor “seeks to further his own economic advantage at the expense of another.” Imperial Ice, 18 Cal. 2d at 36; see id. at 37 (“A party may not . . . under the guise of competition . . . induce the breach of a competitor’s contract in order to secure an economic advantage.”). Rather, interference with contract is justified only when the party alleged to have interfered acted “to protect an interest that has greater social value than insuring the stability of the contract” interfered with. Id. at 35.

 

 

(…) Second, LinkedIn’s means of interference is likely not a “recognized   trade practice” as California courts have understood that term. “Recognized trade practices” include such activities as “advertising,” “price-cutting,” and “hiring the employees of another for use in the hirer’s business,” Buxbom, 23 Cal. 2d at 546–47—all practices which may indirectly interfere with a competitor’s contracts but do not fundamentally undermine a competitor’s basic business model. LinkedIn’s proactive technical measures to selectively block hiQ’s access to the data on its site are not similar to trade practices previously recognized an acceptable justifications for contract interference.

 

 

(…) LinkedIn has only a non-exclusive license to the data shared on its platform, not an ownership interest.

 

 

 

1.   Computer Fraud and Abuse Act (CFAA)

 

 

Our inquiry does not end, however, with the state law tortious interference claim. LinkedIn argues that even if hiQ can show a likelihood of success on any of its state law causes of action, all those causes of action are preempted by the CFAA, 18 U.S.C. § 1030, which LinkedIn asserts that hiQ violated. The CFAA states that “whoever . . . intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains . . . information from any protected computer . . . shall be punished” by fine or imprisonment. 18 U.S.C. § 1030(a)(2)(C). The term “protected computer” refers to any computer “used in or affecting interstate or foreign commerce or communication,” 18 U.S.C. § 1030(e)(2)(B)—effectively any computer connected to the Internet, see United States v. Nosal (Nosal II), 844 F.3d 1024, 1050 (9th Cir. 2016), cert. denied, 138 S. Ct.  314 (2017)—including servers, computers that manage network resources and provide data to other computers. LinkedIn’s computer servers store the data members share on LinkedIn’s platform and provide that data to users who request to visit its website. Thus, to scrape LinkedIn data, hiQ must access LinkedIn servers, which are “protected computers.” See Nosal II, 844 F.3d at 1050. The pivotal CFAA question here is whether once hiQ received LinkedIn’s cease-and-desist letter, any further scraping and use of LinkedIn’s data was “without authorization” within the meaning of the CFAA and thus a violation of the statute. 18 U.S.C. § 1030(a)(2). If so, LinkedIn maintains, hiQ could have no legal right of access to LinkedIn’s data and so could not succeed on any of its state law claims, including the tortious interference with contract claim we have held otherwise sufficient for preliminary injunction purposes.

 

 

We have held in another context that the phrase “‘without authorization’ is a non-technical term that, given its plain and ordinary meaning, means accessing a protected computer without permission.” Nosal II, 844 F.3d at 1028. Nosal II involved an employee accessing without permission an    employer’s private computer for which access permissions in the form of user accounts were required. Id. at 1028–29. Nosal II did not address whether access can be “without authorization” under the CFAA where, as here, prior authorization is not generally required, but a particular person—or  bot—is refused access. HiQ’s position is that Nosal II is consistent with the conclusion that where access is open to the general public, the CFAA “without authorization” concept is inapplicable. At the very least, we conclude, hiQ has raised a serious question as to this issue. First, the wording of the statute, forbidding “access . . . without authorization,” 18 U.S.C. § 1030(a)(2), suggests a baseline in which access is not generally available and so permission is ordinarily required. “Authorization” is an affirmative notion, indicating that access is restricted  to those specially recognized or admitted. See, e.g., Black’s Law Dictionary (11th ed. 2019) (defining “authorization” as “official permission to do something; sanction or warrant”). Where the default is free access without authorization, in ordinary parlance one would characterize selective denial of access as a ban, not as a lack of “authorization.” Cf. Blankenhorn v. City of Orange, 485 F.3d 463, 472 (9th Cir. 2007) (characterizing the exclusion of the plaintiff in particular from a shopping mall as “banning”).

 

 

In recognizing that the CFAA is best understood as an anti-intrusion statute and not as a “misappropriation statute,” Nosal I, 676 F.3d at 857–58, we rejected the contract-based interpretation of the CFAA’s “without authorization” provision adopted by some of our sister circuits. Compare Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058, 1067 (9th Cir. 2016), cert. denied, 138 S. Ct. 313 (2017) (“A violation of the terms of use of a website—without more—cannot establish liability under the CFAA.”); Nosal I, 676 F.3d at 862 (“We remain unpersuaded by the decisions of our sister circuits that interpret the CFAA broadly to cover violations of corporate computer use restrictions or violations of a duty of loyalty.”) (…).

 

 

(…) For all these reasons, it appears that the CFAA’s prohibition on accessing a computer “without authorization” is violated when a person circumvents a computer’s generally applicable rules regarding access permissions, such as username and password requirements, to gain access to a computer. It is likely that when a computer network generally permits public access to its data, a user’s accessing that publicly available data will not constitute access without authorization under the CFAA. The data hiQ seeks to access is not owned by LinkedIn and has not been demarcated by LinkedIn as private using such an authorization system. HiQ has therefore raised serious questions about whether LinkedIn may invoke the CFAA to preempt hiQ’s possibly meritorious tortious interference claim.

 

 

 

(U.S. Court of Appeals for the Ninth Circuit, April 18, 2022, HIQ Labs, Inc. v. LinkedIn Corp., Docket No. 17-16783, for Publication)