Back in December we called out Google for filing a DMCA 1201 lawsuit over companies scraping Google’s results. Almost everything about the lawsuit seemed problematic, not the least of which is that Google’s entire business was built on scraping the web. To sue another company for scraping Google just felt… obnoxious. And now a judge has dismissed the lawsuit, though leaving it open for Google to refile.
Some background: now that we’re in the age of AI, access to all kinds of data has become more precious, which means we’re seeing more and more attempts to put a toll booth on parts of the open web, primarily aimed at AI companies. But the rest of us get locked out along the way. SerpAPI is one of the players in the space which (as its name implies) basically tries to create an unauthorized API for search engine result pages.
Last fall, Reddit sued SerpAPI and some others (including search AI company Perplexity), claiming that because SerpAPI was allowing others (like Perplexity) to access Reddit content via its scrape of Google, it was violating the DMCA’s anti-circumvention (DMCA 1201) clause. We found the whole thing to be an attack on the principles of the open web. It really seemed weird. Reddit had no copyright interest in its users’ posts (the users hold the copyright) and SerpAPI was scraping Google, not Reddit. Reddit has an API deal with Google, but none of the parties being sued were parties to that deal. The whole thing was just “we don’t like that this is happening, so we’re suing.”
Google’s case came a few months later and was quite similar, focused on SerpAPI. And while at least in this case (unlike Reddit) they could point out that SerpAPI was scraping their own site, it still makes no sense to claim that scraping an open website can be a 1201 anti-circumvention violation, no matter what “technological protection measures” you throw up to try to block scraping. The Reddit case continues to move forward with the defendants filing motions to dismiss, but the Google case has lapped them a bit, with the judge already dismissing the complaint, and pointing out (correctly!) that Google has no legitimate copyright claim to make here.
While SerpAPI tried a variety of different ways to kill the lawsuit, what seemed to stick is that Google was clearly stretching the way the DMCA 1201 is supposed to work. Remember, 1201 is the “anti-circumvention” part of the DMCA, and was initially written to protect DRM so that if people broke DRM (or even talked about how to break DRM) they could still be held liable for copyright infringement just for the act of circumventing the “technological protection measure.” This very broad and poorly worded law has created huge messes in its wake, including blatant abuses like companies arguing that you can’t use third-party printer ink or third-party garage door openers because of flimsy “technological protection measures” put into those devices, even though the underlying circumvention had nothing to do with copyright.
The court also looks at one of those earlier cases (regarding Lexmark’s printers), but concludes it doesn’t apply here — long story, not worth the detail, except to note that the precedent that mattered against Lexmark came from trademark law, not the DMCA, even though Lexmark had also tried (and failed) to use Section 1201 itself.
However, SerpAPI (rightly) also pointed out that Google is overclaiming what “SearchGuard” — the “technological protection measure” — actually protects here. As the court explains it, SearchGuard is basically a kind of CAPTCHA:
SearchGuard works by sending a JavaScript “challenge” to search queries that Google receives from unrecognized sources to confirm that they come from real users as opposed to automated software. Id. ¶ 29. Google’s computer system transmits JavaScript code that calls upon the user’s browser to send Google a “solve” for the challenge, i.e., to send Google specific information regarding the browser and user generating the request. Id. ¶ 29. For human users, the “solve” is relatively straightforward; their browsers run the JavaScript code and send back the required information seamlessly, without disrupting the user experience. Id. ¶ 29. However, automated systems that submit automated queries at a massive scale typically cannot solve the SearchGuard challenge. Id. As a result, SearchGuard denies them access to Google’s Search results.
But, as SerpAPI highlighted, SearchGuard has little to do with copyright. And that, at least, gets the court’s attention:
SerpApi contends that Google’s claims under the DMCA are subject to dismissal because SearchGuard is designed and functions to control access to and prevent the scraping of Google Search results regardless of whether they contain a copyrighted component, and because SearchGuard is not reasonably tailored to control access only with respect to any copyrighted component that may be included in Google Search results.
The Court agrees with SerpApi in part. To the extent that Google Search results do not contain any copyrighted content, SearchGuard cannot be said to effectively control access to a work protected under the Copyright Act. Here, Google alleges that SearchGuard controls access to Google Search results, which are compilations of publicly-available information that Google obtains from the internet and organizes for presentation to users on google.com based on relevance. See Compl. ¶¶ 13, 14, 27. SearchGuard controls access to Google Search results because its “purpose” is “to prevent unauthorized third parties from automatically accessing Google’s Search results” to scrape them, as such scraping activities impose a “deadweight loss” on Google. See id. ¶¶ 24, 26-27, 29. However, Google does not allege that google.com or the Google Search results displayed therein are protected under the Copyright Act. Importantly, Google alleges that Google Search results are “often” accompanied by a “Knowledge Panel” that may contain some copyrighted content that Google licenses from third parties, such as copyrighted images. Google does not allege that the “Knowledge Panel” is always included in Google Search results, or that the Knowledge Panel, if included in the Search results, always contains copyrighted content. See id. ¶¶ 14-16. Accordingly, Google’s allegations indicate a mix of content, some with copyrighted material and others without.
And that cuts against Google’s argument here:
Thus, because the DMCA does not apply where the work controlled by a technological measure is not protected under the Copyright Act, Google’s claims under 17 U.S.C. § 1201(a)(1)(A) and 17 U.S.C. § 1201(a)(2) are subject to dismissal as a matter of law to the extent that they are premised on instances where SearchGuard controls access to Google Search results that do not contain any copyrighted content.
Even more damning for Google is that when it’s using SearchGuard, that has literally nothing to do with “effectively controlling access to a [copyright-protected] work.” And that’s the entire point of 1201.
SerpApi argues that Google’s claims under the DMCA fail because it does not allege that it implemented SearchGuard to protect a copyrighted work with the “authority of the copyright owner” as required under 17 U.S.C. § 1201(a)(3)(B)….
The Court agrees. The plain language of 17 U.S.C. § 1201(a)(3)(B) makes clear that, for a technological measure to “effectively control[] access to a work” it must, among other things, “require[] the application of information, or a process or a treatment, with the authority of the copyright owner, to gain access to the work.” See 17 U.S.C. § 1201(a)(3)(B). The Ninth Circuit has interpreted the “with the authority of the copyright owner” element as requiring a plaintiff to allege and later prove that the technological measure in question was implemented and functioned with the authority of the copyright owner.
Google tried to argue that it somehow has the support of copyright holders to protect their work with SearchGuard, but the court is not impressed.
Google’s arguments do not compel a different conclusion. It contends that it is not required to allege facts indicating that it had the authority of the copyright owners to implement SearchGuard because the phrase “with the authority of the copyright owner” defines who may circumvent a technological measure to gain access to protected work and does not define who may deploy a technological measure to control access to a protected work…. This argument is unavailing. Google’s authorities interpret a different provision of the DMCA, namely 17 U.S.C. § 1201(a)(3)(A), which defines what it means to “circumvent a technological measure.” See Disney Enters., Inc. v. VidAngel, Inc., 869 F.3d 848, 863 (9th Cir. 2017) (“Section 1201(a)(3)(A) exempts from circumvention liability only those whom a copyright owner authorizes to circumvent an access control measure, not those whom a copyright owner authorizes to access the work.”) (citation and internal quotation marks omitted); Universal City Studios, Inc. v. Corley, 273 F.3d 429, 444 (2d Cir. 2001) (“[S]ubsection 1201(a)(3)(A) frees an individual to traffic in encryption technology designed or marketed to circumvent an encryption measure if the owner of the material protected by the encryption measure authorizes that circumvention.”). These authorities do not address the issue here, which is whether a technological measure must function “with the authority of the copyright owner” in order to “effectively control[] access to a work” under 17 U.S.C. § 1201(a)(3)(B).
Some of SerpAPI’s other arguments fail, but for now all the DMCA claims are dismissed, though Google can (and almost certainly will) refile regarding some more narrow claims. Specifically, Google cannot file claims regarding search results for which it does not hold the copyright, but could file more narrow claims regarding content where it does (such as the Knowledge Panel). That’s much more limited, and about the only reason to keep the case going is to be a nuisance to SerpAPI.
That might be worth it to Google, which really seems to dislike SerpAPI being out there and scraping their results. But it would be a much narrower case, and (in theory) SerpAPI could simply change its scraping to avoid Google-produced content. Either way, all of this remains quite silly. Google’s entire business was built on scraping the web. Suing someone else for scraping Google sure feels like pulling up the open internet ladder up after themselves.
SerpAPI’s comments on the dismissal make this point explicitly:
We’re pleased that the court rejected Google’s attempts to expand the DMCA to assert control over access to public pages. The internet’s founding principle – open access to usable information – is essential to driving innovation and ensuring everyone benefits from the promise of data. SerpApi will continue supporting developers, AI companies, researchers, and businesses that rely on access to public search information.
One would hope that this initial dismissal from the court gets the company to rethink this anti-open-internet strategy, but somehow I fear the old adage of “young companies innovate, old companies litigate” is starting to seep into Google.