hiQ Labs, Inc. v. Linkedin Corporation

District Court, N.D. California·Decided April 19, 2021·No. 3:17-cv-03301·Unknown

Opinion

HIQ LABS, INC., Case No. 17-cv-03301-EMC

Plaintiff, ORDER DEFERRING IN PART AND v. DENYING IN PART PLAINTIFF’S MOTION TO DISMISS AND STRIKE Defendant. Docket No. 182

This case arises out of Plaintiff hiQ Labs, Inc.’s access to and use of public profiles of Defendant LinkedIn Corp.’s users. hiQ initiated this lawsuit against LinkedIn, bringing claims for, inter alia, declaratory relief, tortious interference, and unfair competition. In response, LinkedIn has asserted counterclaims, including violation of the federal Computer Fraud and Abuse Act, breach of contract, and misappropriation. Currently pending before the Court is hiQ’s motion to dismiss the counterclaims. Having considered the parties’ briefs and accompanying submissions, the Court hereby DEFERS in part and DENIES in part hiQ’s motion. LinkedIn is a company that provides a social network for professionals. See Countercl. ¶ 20. Members of LinkedIn “create individual profiles that serve as their professional profiles online.” Countercl. ¶ 21. Today, the company has more than 700 million members worldwide. See Countercl. ¶ 21. LinkedIn gives its members numerous privacy protections and privacy choices. For example: will permanently delete the account and all of the data that the member posted to LinkedIn within 30 days.” Countercl. ¶ 56 (alleging that this “helps ensure that members are the ones who have ultimate control over [their information]”). • Members can choose to have all or part of their profiles exempt from indexing by well-known search engines such as Google, Bing, and Duck Duck Go. See Countercl. ¶ 55. • When members update information in their profiles, they can choose whether to broadcast that change on LinkedIn. See Countercl. ¶ 57 (alleging that, if a member chooses the “Do Not Broadcast” setting, the “changes that the member makes to his or her profile will be visible, but the fact that the member made a change will not be broadcast to his or her LinkedIn connections or to anyone else”); see also Countercl. ¶ 58 (alleging that this feature was put in place “in response to feedback from LinkedIn members who were hesitant to update their profiles for fear that their co-workers or employers would suspect they were searching for a new job or otherwise thinking of leaving their current jobs”). “LinkedIn’s website and servers are not unconditionally open to the general public.” Countercl. ¶ 25. “This is because LinkedIn’s servers are protected by sophisticated defenses . . . that evaluate whether to grant each request made to LinkedIn’s servers.” Countercl. ¶ 25. These defenses “currently block hundreds of millions of requests to access guest profiles per day from bots and scrapers, which constitute the majority of the requests made to LinkedIn’s servers for guest profiles.” Countercl. ¶ 25. Examples of LinkedIn’s defenses include the following: • The Sentinel system. “Through Sentinel, LinkedIn maintains a list of IP addresses that are not permitted to make calls on LinkedIn’s servers because they either have in the past or are engaged in abuse.” Countercl. ¶ 27. • LinkedIn’s “robots.txt” file. The file “provides a set of instructions to any automated technologies visiting the LinkedIn site, as well as an explicit warning prohibited.” Countercl. ¶ 33. The file “does permit some webcrawlers (e.g., search engines such as Google or Bing) to crawl and index the site.” Countercl. ¶ 33; see also Countercl. ¶ 55 (alleging that that LinkedIn’s “Privacy Policy expressly informs members that search engines may index and display information in their profiles” but “LinkedIn limits such indexing to well-known search engines, such as Google, Bing and Duck Duck Go”; furthermore, “LinkedIn permits members to choose the parties of their profiles that search engines index, or to opt out of this feature entirely”). • LinkedIn’s “custom rules.” LinkedIn applies “over 200 custom rules . . . to requests made to its servers to determine whether the requests is from a human or bot.” Countercl. ¶ 30. Some of the rules fall under LinkedIn’s Guest Request Scoring System and Member Request Scoring System. The Guest Request Scoring System “monitors and limits page requests made by users who are not logged into LinkedIn. If unusual patterns or high levels of activity are detected, the user is redirected to LinkedIn’s log-in page and is prevented from viewing additional LinkedIn pages while not logged in.” Countercl. ¶ 32. “The Member Request Scoring System monitors page requests made by LinkedIn members while logged into their accounts. If high levels of activity are detected for certain types of accounts, the member is logged out and may either be warned, restricted, or challenged with a CAPTCHA in order to log back into LinkedIn.” Countercl. ¶ 31. • Password barrier. “Much of the information on LinkedIn’s website is behind a password barrier. Periodically, LinkedIn will prevent ‘logged-out’ users from viewing more than a certain number of pages before being asked to enter a user name and password to see more.” Countercl. ¶ 34. • The FUSE system. “FUSE scans and imposes a limit on the activity that an individual LinkedIn member may initiate on the site. This limit is intended to prevent would-be data scrapers utilizing automated technologies from quickly In addition to the above defenses, LinkedIn’s User Agreement “prohibits accessing and scraping of LinkedIn’s website through automated software and other technologies.” Countercl. ¶ 36; see also Countercl. ¶ 49 (citing § 8.2 of the User Agreement). Members of LinkedIn are subject to the User Agreement but so too are users and visitors of the LinkedIn website. See Countercl. ¶ 37. For example, “[t]he relevant version of the User Agreement, effective October 23, 2014, states that ‘You agree that by clicking “Join Now[,]” “Join LinkedIn” “Sign Up” or similar[] registering, accessing, or using our services . . . , you are entering into a legally binding agreement (even if you are using our Services on behalf of a company).’” Countercl. ¶ 37. Notwithstanding these measures, hiQ accesses and aggregates publicly available profiles on LinkedIn and uses the data for the data analytic tools it sells. A. hiQ’s First Amended Complaint (“FAC”) In its FAC, hiQ asserts the following claims for relief: (1) A declaratory judgment that hiQ has not violated and will not violate the Computer Fraud and Abuse Act of 18 U.S.C. § 1030 by accessing LinkedIn public profiles. (2) A declaratory judgment that hiQ has not violated and will not violate the Digital Millennium Copyright Act, 17 U.S.C. § 1201, by accessing LinkedIn public profiles. (3) A declaratory judgment that hiQ has not committed and will not commit common law trespass to chattels by accessing LinkedIn public profiles. (4) A declaratory judgment that hiQ has not violated and will not violate California Penal Code § 502(c) by accessing LinkedIn public profiles. (5) Intentional interference with contract. (6) Intentional interference with prospective economic advantage. (7) Unfair competition in violation of California Business & Professions Code § 17200. (8) Unlawful competition in violation of § 17200. (9) Fraudulent competition in violation of § 17200. B. LinkedIn’s Counterclaims In its responsive counterclaims, LinkedIn pleads the following causes of action against hiQ: (1) Violation of the Computer Fraud and Abuse Act, 18 U.S.C. § 1030. (2) Violation of the California Comprehensive Computer Access and Fraud Act, Cal. Pen. Code § 502 et seq. (3) Breach of contract. (4) Misappropriation. (5) Trespass to chatte

Free access — add to your briefcase to read the full text and ask questions with AI

hiQ Labs, Inc. v. Linkedin Corporation, (N.D. Cal. 2021).

hiQ Labs, Inc. v. Linkedin Corporation (hiQ Labs, Inc. v. Linkedin Corporation) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

International News Service v. Associated Press
248 U.S. 215 (Supreme Court, 1919)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Sammons & Sons v. Ladd-Fab, Inc.
138 Cal. App. 3d 306 (California Court of Appeal, 1982)
Balboa Insurance v. Trans Global Equities
218 Cal. App. 3d 1327 (California Court of Appeal, 1990)
American Cyanamid Co. v. American Home Assurance Co.
30 Cal. App. 4th 969 (California Court of Appeal, 1994)
United States Golf Ass'n v. Arroyo Software Corp.
81 Cal. Rptr. 2d 708 (California Court of Appeal, 1999)
Pollstar v. Gigmania, Ltd.
170 F. Supp. 2d 974 (E.D. California, 2000)
Kevin Nguyen v. Barnes & Noble Inc.
763 F.3d 1171 (Ninth Circuit, 2014)
Wesby v. District of Columbia
765 F.3d 13 (D.C. Circuit, 2014)
E. Bastheim Co. v. Schultz
188 P. 841 (California Court of Appeal, 1920)
United States v. Terry Christensen
828 F.3d 763 (Ninth Circuit, 2016)
United States v. Nathan Van Buren
940 F.3d 1192 (Eleventh Circuit, 2019)
National Basketball Ass'n v. Motorola, Inc.
105 F.3d 841 (Second Circuit, 1997)
hiQ Labs, Inc. v. LinkedIn Corp.
273 F. Supp. 3d 1099 (N.D. California, 2017)