Computer Fraud and Abuse Act (unauthorized access and the gates-based authorization test)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 12 October 1984.
A computer misuse rule binding public and private bodies.
As of 29 August 2026.
What it requires
- Scraping a public, unauthenticated page does not by itself expose you to Computer Fraud and Abuse Act (CFAA) liability (hiQ Labs v. LinkedIn, 9th Cir. 2022).
- Do not continue accessing a site, or circumvent a technical block, after the operator has sent an individualized notice revoking your access (Facebook v. Power Ventures, 9th Cir. 2016).
- A CFAA win does not clear you of state-law exposure: hiQ itself was ultimately held liable under contract and trespass-to-chattels theories for the same conduct.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The Computer Fraud and Abuse Act (CFAA) prohibits intentionally accessing a protected computer without authorization, or exceeding authorized access.
The Supreme Court held in Van Buren v. United States (593 U.S. 374, 2021) that exceeding authorized access is a gates-up-or-down inquiry into files or areas an existing permission structure puts off limits, not a purpose-based test, and the Ninth Circuit held in hiQ Labs v. LinkedIn (31 F.4th 1180, 2022) that without authorization does not reach a computer presumptively open to all comers, so a public, unauthenticated page has erected no gate at all.
The line runs through revocation: in Facebook v. Power Ventures (844 F.3d 1058, 9th Cir. 2016), discussed inside the hiQ opinion, liability attached once the scraper, after an individualized cease-and-desist, circumvented an IP block to keep reaching password-protected profiles. hiQ's own case did not end there: on remand it entered a stipulated consent judgment (N.D. Cal., filed Dec.
2022, secondary-sourced) holding it liable for breaching LinkedIn's User Agreement and for California trespass to chattels and misappropriation, for $500,000 and a permanent injunction, despite winning the CFAA claim outright. Section 1030 was added by the Counterfeit Access Device and Computer Fraud and Abuse Act of 1984, Pub.
L. 98-473, title II, § 2102(a); the without-authorization and exceeds-authorized-access language the courts above construe was already present in that original 1984 enactment, so the section dates to its original commencement rather than to the 1986 amendments that broadened its reach to protected computers generally.
When LexLint raises it
crawls_web
Read the law
official text, Office of the Law Revision Counsel (uscode.house.gov)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.