Skip to content
ScrapeshopScrapeshop

Learn

Is Web Scraping Legal in the USA? CFAA, hiQ and ToS (2026)

Published 2026-10-11 · Updated 2026-10-11 · By the Scrapeshop team

Web scraping is legal in the United States when you collect data from publicly accessible pages without bypassing authentication, without agreeing to and then breaching terms of service, without republishing copyrighted expression, and without collecting personal information in ways that state privacy laws prohibit. No federal statute bans scraping. The Computer Fraud and Abuse Act, once the main threat, no longer reaches public-data scraping after Van Buren and hiQ v. LinkedIn.

This guide walks through each federal theory and the main state laws, with the cases that decided them. General information current as of October 2026, not legal advice. For the global overview see Is Web Scraping Legal? What the Law Actually Says.

Quick answer

Scraping public US websites is not a federal crime. The Supreme Court held in Van Buren v. United States(2021) that the CFAA applies only when someone enters a part of a system that is off-limits to them, and the Ninth Circuit applied that “gates-up-or-down” test in hiQ Labs v. LinkedIn (2022) to hold that scraping public profiles is not unauthorised access. Two 2024 decisions, Meta v. Bright Data and X Corp. v. Bright Data, added that logged-out scraping does not breach platform terms that govern account use. The limits are elsewhere: using credentials or continuing after a cease-and-desist (CFAA, Power Ventures), breaching terms you accepted (hiQ lost on this), republishing copyrighted content (copyright, DMCA §1201), and collecting personal or biometric data (CCPA, BIPA, and the FTC). Facts remain free under Feist.

Which US laws govern web scraping?

LawWhat it coversWhat it means for scrapers
Computer Fraud and Abuse Act (18 U.S.C. §1030)Accessing a computer without authorisation or exceeding authorised accessPublic pages: not covered (hiQ, Van Buren). Logins, bypassed blocks, post-revocation access: covered (Power Ventures, Ryanair v. Booking).
Breach of contract (terms of service)Violating terms you agreed toThe most successful claim against scrapers. Requires assent: account creation, checkout, or clear clickwrap. Browsewrap against logged-out visitors is weak (Meta v. Bright Data).
Copyright Act and DMCA §1201Copying protected expression; circumventing access controlsFacts are free (Feist). Articles, photos and reviews are protected; analysis is often fair use, republishing is not. Defeating paywalls risks §1201.
State privacy laws: CCPA/CPRA, BIPA, and 19 other state actsCollecting and selling personal information; biometric identifiersScraped personal information is collected personal information with notice and opt-out duties. BIPA requires consent for face geometry (Clearview settlement).
Trespass to chattelsInterference with a computer system causing harmRequires measurable harm to servers (eBay v. Bidder's Edge). Rarely succeeds against rate-limited scrapers.
Trade secrets (DTSA) and state computer-crime statutesMisappropriation of confidential data; state analogues of the CFAAScraping data behind a login can be misappropriation (Compulife v. Newman). State statutes sometimes read more broadly than the CFAA.

What did hiQ v. LinkedIn and Van Buren decide?

Van Buren v. United States (Supreme Court, June 2021). A police officer used his valid database login for an improper purpose. The Court held he did not “exceed authorized access” under the CFAA, because the statute asks whether a person is allowed into the area of the system they entered, not whether their purpose was permitted. The resulting gates-up-or-down test is the lens for every scraping case since.

hiQ Labs v. LinkedIn (Ninth Circuit, April 2022). hiQ scraped public LinkedIn profiles. LinkedIn sent a cease-and-desist and blocked hiQ’s IPs. The Ninth Circuit, reaffirming its 2019 ruling after the Supreme Court remanded it in light of Van Buren, held that scraping pages with no gate is not access “without authorization”. In November 2022 the district court nevertheless found hiQ had breached LinkedIn’s User Agreement, because its employees had accepted those terms and hiQ continued after revocation. The parties settled. Takeaway: public data is not a CFAA matter, but contract claims survive.

Facebook v. Power Ventures (Ninth Circuit, 2016). Power accessed Facebook with users’ consent but continued after Facebook sent a cease-and-desist and blocked its IPs. That continued access violated the CFAA. Revocation plus a technical block is the point where a scraper of even consented data becomes an unauthorised one.

Ryanair v. Booking.com (D. Del., jury verdict July 2024). Booking.com was found liable under the CFAA for accessing password-protected myRyanair accounts through intermediaries. Damages were nominal, but the gate was down.

Do terms of service bind a scraper in the US?

Contract is where most scrapers actually lose, so the assent question matters. Courts enforce terms that a user affirmatively accepted: creating an account, ticking a box, or completing a checkout (Southwest v. Kiwi.com, 2021, where Kiwi had booked flights under Southwest’s terms). They are reluctant to bind visitors who never saw or accepted terms linked in a footer. In Meta v. Bright Data (N.D. Cal., January 2024) the court granted summary judgment to Bright Data: scraping public Facebook and Instagram pages while logged out did not breach terms that govern use of an account. In X Corp. v. Bright Data(May 2024) a different judge dismissed X’s contract and tort claims, reasoning that letting platforms use contract to control copying of content they do not own would upset the balance struck by copyright law. The Second Circuit reached a related conclusion in ML Genius v. Google (2022): contract claims that merely restate copyright are preempted.

Feist Publications v. Rural Telephone (1991) holds that facts and unoriginal compilations are not copyrightable. Prices, inventory, addresses, specifications, and schedules can be extracted without a copyright question. Original expression is protected, and the analysis then turns on fair use. Indexing, search, and statistical analysis of copyrighted text have generally been found transformative (Authors Guild v. Google, 2015). Republishing it has not. The 2025 AI training decisions sharpened this: Bartz v. Anthropic and Kadrey v. Meta found training on lawfully obtained books to be fair use while treating pirated copies differently, and Thomson Reuters v. Ross rejected fair use where the output competed directly with the source. DMCA §1201 adds an independent claim for circumventing an access control such as a paywall, regardless of what you do with the content afterwards.

State privacy and biometric laws

  • California CCPA/CPRA.Personal information scraped from the web is “collected”; businesses above the thresholds owe notice at collection, opt-out of sale or sharing, and deletion rights. The publicly-available exemption is narrow and does not cover social media profiles.
  • Illinois BIPA.Collecting face geometry or other biometric identifiers requires informed written consent. Clearview AI’s 2022 settlement with the ACLU barred it from selling its database to most private entities nationwide.
  • Other state acts. Virginia, Colorado, Connecticut, Texas, Oregon and more than a dozen other states now have comprehensive privacy laws with similar collection and opt-out duties. Several state computer-crime statutes are worded more broadly than the CFAA.
  • FTC Act §5. The Federal Trade Commission treats deceptive or unfair data collection as actionable, and has flagged scraping of personal data for AI as an enforcement priority.

Checklist for scraping US websites

  1. Stay logged out. Never use credentials, shared sessions, or intermediaries to reach gated pages.
  2. Do not create an account on the target site with the scraping entity; assent to terms is what makes contract claims work.
  3. Stop on a cease-and-desist or a targeted block. Continuing is what turned Power Ventures and hiQ against the scraper.
  4. Extract facts and fields. Do not republish articles, photos, or reviews, and do not defeat paywalls.
  5. Treat scraped personal information as regulated under CCPA and its peers; never collect biometrics.
  6. Rate-limit to avoid any argument of server harm, and identify your crawler.

See Web Scraping Best Practices for the engineering side of these rules.

Frequently asked questions

Is web scraping illegal in the United States?
No. Scraping publicly accessible pages is not a crime under the Computer Fraud and Abuse Act. The Ninth Circuit held in hiQ v. LinkedIn (2022) that public data is not protected by the CFAA, and the Supreme Court's Van Buren decision (2021) limited the statute to breaking into gated areas. Civil claims under contract, copyright, and state law remain possible.
Can I be sued for scraping a website in the US?
Yes, most often for breach of contract if you accepted terms of service, for copyright if you republish protected content, or under state privacy laws if you collect personal information. Meta v. Bright Data (2024) held that logged-out scraping of public pages did not breach Meta's terms, which govern account use.
Does the CFAA apply to scraping behind a login?
Yes. Van Buren's gates-up-or-down test means that accessing areas protected by a password without permission is unauthorised access. Facebook v. Power Ventures and Ryanair v. Booking.com show courts applying the CFAA to credentialed access that the operator had forbidden.
Is scraped data protected by copyright in the US?
Facts are not; Feist v. Rural (1991) holds that prices, specifications, addresses and similar data cannot be copyrighted. Creative expression such as articles, photographs, and reviews is protected, and republishing it wholesale infringes. Scraping it for analysis is usually defensible as fair use.
Does the DMCA apply to web scraping?
Section 1201 prohibits circumventing a technological measure that controls access to a copyrighted work. Defeating a paywall or encrypted content delivery to scrape protected content can violate it. Ordinary rate limits and CAPTCHAs on public pages are less clearly access controls, but circumventing them weakens every other defence.
Is scraping for AI training legal in the US?
Unsettled. In 2025 courts held that training on lawfully acquired books was fair use (Bartz v. Anthropic, Kadrey v. Meta) while copying from pirated sources was not, and Thomson Reuters v. Ross rejected fair use for a competing legal product. How the data was obtained matters as much as how it is used.