Web scraping is standard now.
Businesses use it to track markets, watch competitors, find leads, and make smarter decisions. But even so, most organizations still don’t fully grasp the legal risks, especially the web scraping legal cases shaping the industry today.
A lot of people assume: “If it’s public, it’s safe to scrape.” However, that’s not always true. Another common belief: “Breaking a website’s Terms of Service means we’re breaking the law.” Yet that’s not always true either. Courts have shown, over and over, that web scraping legality depends on a bunch of factors. How did you access the data? Did you have to log in? Do privacy laws apply?
Hop on a free call with our experts to gauge how web scraping can benefit your businessIs web scraping the right choice for you?
In the last ten years, some major web scraping court cases have drawn the boundaries. As a result, they’ve shaped how judges think about unauthorized access, public data, privacy, and technical blocks.
Understanding these rulings helps you size up your risk. It helps you design a smarter collection strategy. And it helps you avoid expensive lawsuits before they even start.


Here are the 5 cases that define the web scraping space today.
- hiQ Labs v. LinkedIn
- Meta v. Bright Data
- Ryanair v. PR Aviation
- Clearview AI and Privacy Enforcement Actions
- Google v. SerpAPI
CFAA (Computer Fraud and Abuse Act) – U.S. law that criminalizes unauthorized computer access. Courts use it to decide whether scraping public data counts as “hacking.” BIPA (Biometric Information Privacy Act) – An Illinois state law that requires explicit consent before collecting biometric data like facial scans or fingerprints. GDPR (General Data Protection Regulation) – European privacy law that requires a lawful basis to collect personal data. Violations can trigger massive fines. DMCA (Digital Millennium Copyright Act) – U.S. law that bans bypassing technical protection measures, such as anti‑bot systems. EU Database Directive – European law that protects databases if they require substantial investment or creative effort. Contract Law (Terms of Service) – General legal rules that can turn a website’s Terms of Service into a binding contract, which may restrict scraping even without hacking or copyright claims.
1. hiQ Labs v. LinkedIn: The Case That Defined “Public” Data Under U.S. Law
This case changed the whole conversation. Even years later, it’s the one everyone cites when they ask: “Can my business scrape public data?”
Background
hiQ Labs made workforce analytics tools. Their products helped employers spot attrition risks and skill gaps. To make those tools work, hiQ scraped info from public LinkedIn profiles.
LinkedIn hated it.
Consequently, in 2017, they sent a cease-and-desist letter. They also put up technical roadblocks to stop hiQ. LinkedIn argued that hiQ’s scraping violated the Computer Fraud and Abuse Act (CFAA)—a federal law meant to stop unauthorized computer access.
The Court’s Decision
Here’s where it gets interesting. The hiQ vs LinkedIn case went to the Ninth Circuit. The court said there’s a huge difference between public web data and data behind a login screen.
The judges pointed out that the CFAA was made to fight digital trespassing and hacking. But public LinkedIn profiles were open to anyone with a browser. Therefore, there was no gate to bypass. So scraping that public data didn’t count as “unauthorized access” under the CFAA.
Why This Matters to Your Business
Before hiQ, websites often used the CFAA as a weapon against scrapers. This ruling took that weapon away—at least for public data.
For you, it sets a key rule: public info is treated differently from restricted info.
Also, just because a site tells you to stop—or even sends a lawyer’s letter—doesn’t automatically make your scraping a CFAA violation.
What the Ruling Didn’t Say
Don’t misread this. The court didn’t give a green light to all scraping.
They ruled only on CFAA claims involving public data. They didn’t touch copyright, personal data protection laws, contract disputes around LinkedIn user agreement scraping, or other claims that could still bite you depending on your specific project.
Your Key Takeaway
This case drew one of the most important lines in scraping legality: public data and authenticated data are not the same. If you’re grabbing info from pages anyone can see, you’re in a different legal zone than if you’re trying to get behind login walls or customer portals.
2. Meta v. Bright Data: Why Terms of Service Aren’t the Final Word on Scraping
hiQ said public data isn’t a CFAA violation. Meta v. Bright Data tested whether that same logic applies to Terms of Service violations.
Background
In 2023, Meta sued Bright Data. Bright Data was collecting publicly available information from Facebook and Instagram—stuff you could see without logging in.
Meta said Bright Data violated its Terms of Service and wanted to stop them from selling that data. The industry watched closely because the outcome would affect anyone grabbing public social data.
The Court’s Decision
In January 2024, a federal judge in California sided with Bright Data.
The judge said Meta’s ToS didn’t ban Bright Data from collecting public info while logged out.
The court also agreed that Bright Data wasn’t acting as a “user” of the platform when they weren’t logged in. Since the info was available to any visitor, the court wouldn’t call it a contract violation.
Why This Matters to Your Business
This case reinforced the public vs. restricted line from hiQ. Courts can treat public social media content the same as other public data access rights that apply to public web content generally.
It also underlined a point many miss: ToS alone don’t create a CFAA violation. Courts still look at how you accessed it, whether you had to log in, and whether it was truly public.
Your Key Takeaway
Meta v. Bright Data gave public scraping a stronger legal footing in the US. Again, public data and authenticated data get different treatment. If you’re pulling from public pages, you’re not in the same boat as someone sneaking behind user accounts.
3. Ryanair v. PR Aviation: The European Warning on Contract Law and Scraping
hiQ and Bright Data were about public data. However, this case is different: Can a website use its Terms of Service (ToS) to prohibit scraping, even if copyright and database laws don’t apply and the website doesn’t sell the scraped data?
Background
PR Aviation ran a flight comparison site. They helped people compare fares. To do that, they scraped Ryanair’s flight prices and schedules.
Ryanair said no.
Their Terms and Conditions clearly banned automated data extraction—unless you had a written license. Since PR Aviation didn’t have one. So Ryanair sued.
The Court’s Decision
The EU’s top court sided with Ryanair. The court said the EU’s Database Directive didn’t protect Ryanair’s database. But that didn’t matter.
The court still said Ryanair could impose contract restrictions. Because users had to accept the terms before seeing the data, those terms were a binding contract. So Ryanair could use contract law to block scrapers, even without copyright protection.
Why This Matters to Your Business
This shows that not every scraping fight is about copyright or hacking. Sometimes, it’s just contract law.
It also shows that cross-border data laws matter: US courts often look at “public access.” On the other hand, European courts might look more at the contract you clicked “agree” to.
Your Key Takeaway
ToS might not automatically create liability under US hacking laws. But they can still create real legal risk under contract law, especially in other countries. If you operate in multiple markets, you have to consider both where the data comes from and where you collect it.
4. Clearview AI: When “Public” Data Triggers Multi-Million Dollar Privacy Fines
Moving on, all the earlier cases were about access, authorization, and contracts. Now, Clearview brought in a whole new headache tied to web scraping and privacy laws: can public data still break privacy laws?
Background
Clearview AI built a facial recognition tool. They scraped billions of images from public websites—social media, news sites, everywhere. Then they turned those images into biometric IDs you could search.
Clearview argued: “It’s public. We’re just collecting public info.” However, regulators and privacy advocates fired back. They said Clearview was scooping up sensitive personal data without consent, raising serious concerns under personal data protection laws.
The legal fights spanned the US, Canada, the UK, France, Italy, the Netherlands, and Australia.
Regulatory Actions and Settlements
From 2020 to 2025, Clearview faced lawsuits, investigations, fines, and enforcement orders.
In the US, a BIPA settlement cost them over $50 million. In another BIPA case, they stopped working with non‑government entities.
European regulators also came down hard, enforcing strict online data regulations. France, Italy, the Netherlands, and the UK issued fines, arguing that Clearview had no lawful basis under GDPR. In 2024, Dutch regulators fined them €30.5 million.
Why This Matters to Your Business
This case shattered the assumption that “public” means “free to use for anything.”
Privacy regulators said, loud and clear, that public availability doesn’t erase privacy rights. That’s especially true for faces, biometrics, and other personal info.
It also exposed the gap between scraping law and privacy law, underscoring the risks of automated data collection businesses face when personal data is involved. You might avoid hacking claims, but you can still get crushed by privacy rules.
Your Key Takeaway
Check privacy compliance separately from scraping legality. Before you collect at scale, ask not just how you’re accessing the data, but what it contains. If it’s personal or biometric data, privacy laws in different jurisdictions may apply.
5. Google v. SerpAPI: The Pending Case That Could Change Scraping Methods Forever
Previous cases set rules for public data, ToS, and privacy. This new one is about something else: does bypassing anti-bot systems get you in trouble, even if the data itself is public?
Background
In December 2025, Google sued SerpAPI.
SerpAPI sells structured search results to businesses and developers. Google says SerpAPI scraped at a massive scale using automated requests and IP rotation to dodge Google’s anti-bot defenses.
Google claims this strains its infrastructure and disrupts its technical protections. They also say some content in search results is copyrighted.
But SerpAPI disagrees. They say the info is public—anyone can see it in a browser without logging into Google.
Why This Matters to Your Business
This one isn’t about whether the data is public. It’s about how you collect it.
It raises questions courts haven’t fully settled:
- Does dodging anti-bot systems create extra legal risk?
- How do DMCA anti-circumvention rules apply to scraping?
- Should technical protection measures be legally protected, even when the content is public?
- How do we balance public access against platforms’ efforts to block bots?
Potential Industry Impact
The outcome could hit many businesses that use search data:
- SEO platforms
- Search intelligence providers
- SERP monitoring tools
- Competitive intelligence services
- AI companies training on search data
The case is still pending, so we don’t have final answers yet. But the decision could reshape how courts look at anti-bot protections.
Your Key Takeaway
In short, this case points to an emerging trend. Future scraping fights might focus more on your methods than on whether the data is visible. Pay close attention not just to what you collect, but how you collect it.
What Web Scraping Legal Cases Tell You About Web Scraping Laws
Look at these cases together, and you see a pattern. It’s not one simple rule. Instead, courts might look at your activity through different lenses: hacking laws, contract law, copyright law, privacy law, or anti-circumvention rules—depending on the details.

Nevertheless, one theme holds steady: public data access rights matter more than ever. Courts are usually more open to scraping public info than to scraping login-protected systems.
But “public” doesn’t make you bulletproof. Clearview proved privacy laws can still apply. Ryanair proved contracts can still bite. Google v. SerpAPI proves collection methods are under the microscope now.
The bottom line for you: compliance depends on your project’s specifics. The data source, the collection method, the type of data, and the jurisdictions involved—all of it matters, which is exactly why web scraping legal issues keep coming up across industries.
Reducing Legal Exposure: Why CTOs Are Turning to Specialized Scraping Partners
These web scraping legal cases show one thing clearly: web scraping compliance isn’t a single rule. You’ve got to think about data access, privacy, contracts, methods, and jurisdictions. As your data needs grow, managing that gets complex.

Many companies reduce risk by setting clear compliance rules before they start collecting, forming the foundation of ethical web scraping. That means reviewing sources, checking regulations, avoiding restricted systems, and documenting how you’ll use the data. These steps catch problems early.
Why Engineering Teams Can’t Solve Legal Risk Alone
However, building all of that internally to manage ongoing web scraping legal issues requires legal, technical, and operational resources. That’s why large businesses prefer web scraping companies to handle these. They usually have dedicated processes for vetting sources, tracking legal changes, and running large-scale collections.
Good providers also handle the operational headaches that affect compliance. They run the infrastructure, adapt to site changes, enforce quality controls, and set policies for data collection and delivery.
So, working with an experienced web scraping partner can cut your compliance risk and free your team to actually use the data.
ScrapeHero: A Compliance-Focused Web Scraping Partner
ScrapeHero’s web scraping service makes compliance a core part of the process, not an afterthought. Before we collect anything, we evaluate the target source, your requirements, applicable regulations, and potential risks. That helps you spot issues early and make smart choices.
We also stick to established practices that lower risk: we collect public data, avoid restricted systems, respect personal data protection laws, and keep our policies aligned with regulations, an approach rooted in strong enterprise data governance.
Reducing Your Compliance and Operational Risk
Compliance never stays still.
Websites change, regulations evolve, and courts keep ruling.
However, ScrapeHero monitors those shifts and adapts our processes as needed. That means you get web data without having to build in-house expertise across scraping law, privacy, infrastructure, and operations.
Why Businesses Pick ScrapeHero
Companies choose us when they need web data for market research, competitive intel, pricing analysis, or AI projects—and they want a structured, compliant approach. Instead of wrestling with legal reviews, infrastructure, and ongoing maintenance, they focus on using the data to drive decisions.
In short, getting web data responsibly takes ongoing effort, not just tech. ScrapeHero, the best web scraping company, helps you cut compliance and operational risk through a structured, compliance-first approach to data collection.
Final Thoughts
The legal landscape around scraping keeps shifting. But a few principles are clear from these web scraping legal cases. Courts treat public data differently from login-protected data. Privacy laws can apply even to public info. ToS can create obligations depending on where you are. And fights over anti-bot measures are still unfolding.
For you, compliance depends on more than just the data. Collection methods, data types, privacy, and laws all factor in. If you understand these factors and work with an experienced partner like ScrapeHero, you can use web data responsibly—while keeping your legal risk and operational headaches low.
What if you're breaking a law you didn't even know existed?
FAQs
Not automatically—but if the data includes personal information about EU residents, you need a lawful basis to collect and process it. Scraping public profiles or biometric data without one, as seen in the Clearview AI case, can trigger major GDPR fines.
hiQ Labs scraped public LinkedIn profiles for its workforce analytics tools, and LinkedIn attempted to block it, citing the CFAA. The Ninth Circuit ruled that scraping publicly accessible data isn’t “unauthorized access” under the CFAA, since there’s no login wall to bypass.
Scraping public LinkedIn profiles isn’t automatically a CFAA violation, per the hiQ ruling. But it can still raise issues under LinkedIn’s user agreement, copyright law, or privacy regulations, so “not illegal under one law” doesn’t mean “risk-free.”
Van Buren v. United States (2021) narrowed the CFAA, ruling that misusing access you’re already authorized to have isn’t a federal hacking crime. It reinforced the idea that the CFAA targets unauthorized access, not how someone uses data they were allowed to see.
Yes—through technical measures like rate limiting and anti-bot systems, or through legal tools like Terms of Service and contract law, as Ryanair successfully did against PR Aviation. Whether those blocks hold up legally depends on the method and jurisdiction.
Scraping publicly available data is generally not a CFAA violation in the US, based on rulings like hiQ v. LinkedIn and Meta v. Bright Data. But legality still depends on what you scrape, whether you bypass logins, and whether privacy or copyright laws apply.
You may face a breach-of-contract claim rather than a hacking charge, since courts in Meta v. Bright Data found that ToS violations alone don’t equal CFAA violations if you’re not logged in. Outside the US, contract law (as in Ryanair v. PR Aviation) can carry more weight.
Yes—Ongoing cases like Google v. SerpAPI are actively shaping how courts view anti-bot circumvention and technical protection measures, areas the law hasn’t fully settled. Each new case adds detail to where the legal lines sit.
Risks span unauthorized access claims, breach of contract, copyright infringement, and privacy violations, depending on what’s scraped and how. The biggest factors are whether the data is public or login-protected, whether it contains personal information, and which jurisdictions are involved.