Law note · Washington

Washington Cybercrime Act, technological-access-barrier authorization test

cite RCW 9A.90.030, RCW 9A.90.040, RCW 9A.90.050 stage IN FORCE in force since 2016-06-09 kind Computer misuse binds public and private bodies reviewed 2026-08-29

What it asks of an app

  • Scraping a public page with no technological access barrier is not, by this statute's own definition, access without authorization, regardless of a posted policy or terms of service.
  • A bare violation of a duty, agreement, or contractual obligation, such as an acceptable use policy or terms of service agreement, does not by itself satisfy this statute's without-authorization definition; only knowingly circumventing a technological access barrier does.
  • White-hat security research, and circumventing a measure that does not effectively control access to a computer, are expressly excluded from without-authorization access under this statute.

When LexLint raises it

  • crawls_web

What we found

RCW 9A.90.040 (computer trespass, first degree) and RCW 9A.90.050 (second degree) prohibit gaining access to a computer system or electronic database without authorization.

RCW 9A.90.030(12) statutorily defines without authorization as knowingly circumventing technological access barriers to a data system to obtain information without the owner's express or implied permission, where the access measures are specifically designed to exclude or prevent unauthorized individuals from obtaining the information, but the definition expressly excludes white hat security research and circumventing a measure that does not effectively control access to a computer, and expressly excludes a bare violation of a duty, agreement, or contractual obligation such as an acceptable use policy or terms of service agreement.

This is a codified, narrow, gates-based authorization test, functionally aligned with the Ninth Circuit's hiQ v. LinkedIn reasoning and the gates-up-or-down logic of Van Buren v. United States: a public page with no technological access barrier cannot, by the statute's own definition, be accessed without authorization no matter what a posted policy says, and a bare ToS violation with no technical circumvention does not satisfy the definition either.

No Washington case law was found applying this definition to a scraping fact pattern specifically, so this is the plain statutory text rather than a litigated holding.

← Back to the example  ·  Lint your app →