Law / United States /
Washington
Washington Cybercrime Act, technological-access-barrier authorization test
RCW 9A.90.030, RCW 9A.90.040, RCW 9A.90.050
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 9 June 2016.
A computer misuse rule binding public and private bodies.
As of 29 August 2026.
What it requires
- Scraping a public page with no technological access barrier is not, by this statute's own definition, access without authorization, regardless of a posted policy or terms of service.
- A bare violation of a duty, agreement, or contractual obligation, such as an acceptable use policy or terms of service agreement, does not by itself satisfy this statute's without-authorization definition; only knowingly circumventing a technological access barrier does.
- White-hat security research, and circumventing a measure that does not effectively control access to a computer, are expressly excluded from without-authorization access under this statute.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
RCW 9A.90.040 (computer trespass, first degree) and RCW 9A.90.050 (second degree) prohibit gaining access to a computer system or electronic database without authorization.
RCW 9A.90.030(12) statutorily defines without authorization as knowingly circumventing technological access barriers to a data system to obtain information without the owner's express or implied permission, where the access measures are specifically designed to exclude or prevent unauthorized individuals from obtaining the information, but the definition expressly excludes white hat security research and circumventing a measure that does not effectively control access to a computer, and expressly excludes a bare violation of a duty, agreement, or contractual obligation such as an acceptable use policy or terms of service agreement.
This is a codified, narrow, gates-based authorization test, functionally aligned with the Ninth Circuit's hiQ v. LinkedIn reasoning and the gates-up-or-down logic of Van Buren v. United States: a public page with no technological access barrier cannot, by the statute's own definition, be accessed without authorization no matter what a posted policy says, and a bare ToS violation with no technical circumvention does not satisfy the definition either.
No Washington case law was found applying this definition to a scraping fact pattern specifically, so this is the plain statutory text rather than a litigated holding.
When LexLint raises it
crawls_web
Read the law
official text, Washington State Legislature (app.leg.wa.gov)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.