US judge orders LinkedIn to remove any tech stopping hiQ Labs from scraping public profile data, after LinkedIn sent cease and desist letter in May
SAN FRANCISCO (Reuters) - A U.S. federal judge on Monday ruled that Microsoft Corp's (MSFT.O) LinkedIn unit cannot prevent a startup …
Context & Ripple Effects
The ruling lands a year after LinkedIn filed suit against 100 anonymous scrapers under the Computer Fraud and Abuse Act (invoking the CFAA), part of a broader campaign to wall off profile data that escalated with May's cease-and-desist letter to hiQ Labs. The judge's answer is blunt: technical blocks have to come down, because code cannot do what law does not permit.
The stakes run beyond one startup — hiQ built its business on analyzing public profiles, so LinkedIn's blocking technology was an existential threat delivered by server config rather than courtroom. How this dispute resolves will define what 'public' means on the social web.
First-order effects
- LinkedIn must dismantle the anti-scraping measures aimed at hiQ Labs, handing the startup immediate access to the public profile data its product depends on.
- Microsoft's LinkedIn unit loses its most direct enforcement lever — IP-level blocking — and is pushed back into arguing the case purely on CFAA interpretation in court.
Second-order effects
- LinkedIn's likely response is appellate escalation rather than compliance in spirit, keeping the CFAA question alive; the related coverage shows exactly that path, through a 2019 appeals-court rejection of LinkedIn's effort and eventually a SCOTUS vacatur that sent the dispute back down.
- Other data-dependent startups gain a working precedent that public-profile scraping is not computer trespass, lowering the legal risk premium on businesses built atop platform data.
Third-order effects
- If the pattern holds, the CFAA stops functioning as a gatekeeping tool for publicly accessible content, and platforms shift enforcement to contract terms, authentication walls, and privacy regimes — visible later in LinkedIn dropping EU ad targeting based on Groups participation after regulatory complaint.
- The endpoint, reached when a US appeals court reaffirmed that scraping publicly accessible content is legal, is a structural split: anything behind no login is fair game, and platform control over data migrates from code to law.
The trend: US courts are progressively stripping the Computer Fraud and Abuse Act of its power to block scraping of public web data, forcing platforms to defend data through privacy regulation and terms of service instead of technical locks.