Google v. SerpApi — DMCA Does Not Turn Every Anti-Scraping Barrier Into Copyright Protection

Case
Google LLC v. SerpApi, LLC
Court
United States District Court for the Northern District of California
Judge
Yvonne Gonzalez Rogers (Barack Obama, 2011)
Date Decided
July 20, 2026
Docket No.
4:25-cv-10826-YGR
Topics
DMCA anti-circumvention, web scraping, access controls, copyrighted search content

Background

Google sued SerpApi, a company that sells automated access to Google Search results, under the Digital Millennium Copyright Act (DMCA). Google alleged that SerpApi sent billions of automated queries and evaded SearchGuard, a JavaScript-based system Google introduced in 2025 to distinguish ordinary users from automated scrapers. According to the complaint, SerpApi masked automated queries as human traffic and reused successful challenge responses so that other browsers could gain access.

Google did not bring a conventional copyright-infringement claim. Instead, it relied on two DMCA anti-circumvention provisions: one bars bypassing a technological measure that effectively controls access to a copyrighted work, and the other bars trafficking in technology or services primarily designed to bypass such a measure. Google argued that some search results—particularly Knowledge Panels—include images or other copyrighted material licensed from third parties.

SerpApi moved to dismiss. It argued, among other things, that Google was not the copyright owner, that SearchGuard did not effectively control access to protected works, and that the complaint did not plausibly allege circumvention within the DMCA’s meaning.

The Court’s Holding

Chief Judge Yvonne Gonzalez Rogers dismissed both DMCA claims, but divided the ruling according to what appeared in the search results. Claims involving results with no copyrighted content were dismissed without leave to amend. The DMCA’s access-control provisions protect access to a “work protected” by copyright; an anti-bot system guarding uncopyrightable facts or other unprotected search output cannot satisfy that statutory requirement simply because it restricts automated access.

The court reached a narrower result for search results containing copyrighted components. It rejected SerpApi’s categorical argument that only a copyright owner may sue under the DMCA, concluding that the statute and its history do not limit standing that strictly. Google therefore was not disqualified merely because it licensed content owned by others.

Google’s pleading nevertheless failed because it did not allege facts showing that SearchGuard operated “with the authority of the copyright owner,” as the statutory definition of an effective access control requires. Saying that Google licensed images for Knowledge Panels did not establish that the licensors authorized Google to deploy SearchGuard to control access to those works. The court dismissed this portion with leave to amend because Google might be able to plead such authorization.

The court also rejected SerpApi’s theory that a measure cannot effectively control access when a human can view the material freely. A system can still qualify if it requires a process—here, completing the SearchGuard challenge—in the ordinary course of operation. The order stayed discovery until Google files an amended complaint and any resulting dismissal motion is resolved. Google received 21 days to amend.

Key Takeaways

  • The DMCA is not a general anti-scraping law. A technological barrier must control access to material protected by copyright, not merely to public-facing data or uncopyrightable search output.
  • A licensee may potentially sue under the DMCA even when it does not own the copyright, but it must plausibly connect its access-control measure to authority granted by the copyright owner.
  • Public availability does not automatically defeat DMCA protection. A technological challenge may “effectively control access” even when ordinary human visitors pass through it seamlessly.
  • The dismissal is only partly final: claims based on results without copyrighted content cannot be repleaded, while claims tied to copyrighted components may return in an amended complaint.

Why It Matters

The ruling draws an important boundary between controlling automated traffic and protecting copyrighted expression. Websites often use the same anti-bot layer across pages containing a mix of facts, licensed images, original text, and other material. Under this decision, deploying a technical barrier is not enough by itself; a DMCA plaintiff must identify the protected work and show that the barrier controls access with the copyright owner’s authority.

For scraping and AI-data businesses, the order is not a blanket permission slip. Contract, computer-access, copyright, and other claims may still apply, and Google may revive part of this case. But the decision makes clear that Section 1201 cannot automatically transform every bypass of an anti-bot challenge into copyright circumvention.

Full Opinion

Your browser cannot display this PDF inline.

Download the full opinion (PDF)

Leave a Comment

Scroll to Top