10.4 Digital Advertising, Web Scraping, and Data Ethics

Key Takeaways

  • Interest-based ads, pixels, clean rooms, and customer-match uploads are marketing uses that still sit under FTC unfair-or-deceptive-practice authority, state sale/share and targeted-ad rules, and TCPA or the Telemarketing Sales Rule if the same data feeds a call or text.
  • Van Buren (2021) reads the Computer Fraud and Abuse Act as a gates-up-or-down access statute; the Ninth Circuit's hiQ opinions say scraping a public page after a cease-and-desist is unlikely 'without authorization,' but the case later ended in a party-specific injunction and is not a nationwide scraping license.
  • Circumventing authentication, paywalls, or technical access controls, or scraping logged-in data, remains a live Computer Fraud and Abuse Act and contract risk.
  • Collecting face geometry or a voiceprint through an ad unit or pixel can trigger Illinois Biometric Information Privacy Act duties and other state biometric statutes even when an advertising platform is the collector.
  • Body of Knowledge data ethics in this domain is fairness, secondary use, dark patterns, and vulnerable populations — the same themes the Federal Trade Commission has prioritized in commercial-surveillance and dark-pattern matters.
Last updated: August 2026

10.4 Digital Advertising, Web Scraping, and Data Ethics

Domain II.E performance indicators 3 through 5 take the marketing statutes from sections 10.2 and 10.3 and apply them to the advertising stack, to scraping, and to data ethics. Domain I.C already mapped cookies, pixels, software development kits, fingerprinting, and customer match. Do not re-litigate how a cookie is set. This section asks what legal and ethical duties attach when those tools become a marketing program.

Interest-based ads, pixels, clean rooms, and customer match

Interest-based advertising (IBA) (also called online behavioral advertising) selects an ad from activity observed over time and often across sites or apps, not from the single page the user is looking at. A contextual ad that says "running shoes" because the user is on a running-shoe article is a different, weaker privacy fact pattern. IBA becomes an exam problem when the profile includes sensitive inferences — pregnancy, debt stress, health condition, child's location — or when the user was told the data would be used only to fulfill an order.

A pixel (web beacon) is a script or tiny image that reports an event, a cookie or device identifier, and often a hashed email (advanced matching) back to an advertising platform. Opening a confirmation page or an email can fire it. The pixel is not a statute. The statute is whatever the pixel is doing: an FTC deceptive notice if the privacy policy said "we do not share with advertisers," a state sale/share or targeted-advertising opt-out if a comprehensive state law applies, COPPA if it collects from children under 13, or TCPA if the same identifier is later used to text a promotion.

A clean room is a restricted environment in which two parties contribute hashed or tokenized identifiers and compare overlap or measure conversions without handing each other the raw customer file. Clean rooms reduce some leakage risk. They do not make the processing anonymous if the parties can still act on a matched household. They do not erase a secondary-use problem if the original notice said "we use your email to ship the order" and the clean room is used to retarget non-buyers. They do not override a California "do not sell or share" or a Colorado targeted-advertising opt-out.

Customer match is the upload of hashed emails, phone numbers, or other first-party identifiers so an advertising platform can find those people among its logged-in users. Chapter 5 already flagged that an upload can be a sale, share, or targeted-advertising use under state law. The Domain II overlay is the downstream channel: if the match audience is then messaged by SMS, the TCPA and the National Do-Not-Call rules apply to the text, not the hash. Hashing is not consent.

CFAA and scraping — teach the live doctrine

The Computer Fraud and Abuse Act (CFAA), 18 U.S.C. § 1030, makes it a crime and a civil wrong to access a protected computer without authorization or to exceed authorized access. It is an access-control statute, not a general data-use statute.

Van Buren v. United States, 593 U.S. 374 (2021), is the Supreme Court's gates opinion. "Exceeds authorized access" means obtaining information from a part of the computer that is off-limits — a folder, database, or role the credentials do not open. It does not mean using authorized access for an improper purpose. A police officer who ran a license plate for a personal reason did not violate the CFAA because he was allowed to use that database. Purpose-based "you promised not to scrape" theories are weak CFAA theories after Van Buren.

hiQ Labs, Inc. v. LinkedIn Corp. is the scraping case candidates over-read. The Ninth Circuit in 2019, and again in 2022 after the Supreme Court vacated and remanded in light of Van Buren, held that hiQ had raised serious questions whether scraping publicly available profile pages after a cease-and-desist is CFAA "without authorization." The court's image is gates up or down: a public page with no authentication requirement has not erected a CFAA gate. That is not a holding that all scraping is lawful forever. After hiQ entered bankruptcy, the district court in November 2022 entered a stipulated permanent injunction that barred that company from scraping LinkedIn. A consent injunction against one defendant is not a nationwide CFAA rule, and it is not a repeal of the Ninth Circuit's public-page analysis.

Teach the 2026 doctrine in four sentences:

  1. Scraping a public, unauthenticated page is generally not a CFAA "without authorization" event under Van Buren's gates reading and the Ninth Circuit's hiQ opinions.
  2. The Department of Justice's 2022 CFAA charging policy likewise treats ordinary terms-of-service violations on public websites as a poor criminal case.
  3. Circumventing a login, paywall, robots-exclusion technical block, IP ban, or other access-control measure, or scraping logged-in or non-public data, can still be CFAA access without authorization, plus contract, trespass-to-chattels, copyright, and state privacy claims.
  4. Later district-court decisions (including public, logged-out scraping disputes against large platforms in 2024) are not Supreme Court resolutions. Do not recite hiQ as a permanent national license, and do not recite it as if the stipulated injunction rewrote the CFAA.

Biometric and voiceprint collection through ads

An ad unit that scans a face to see whether the viewer smiled, a virtual try-on that maps face geometry, or a voice-enabled ad that stores a voiceprint is a biometric collection. Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14, requires a written policy and a written release before collecting a biometric identifier (retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry) or biometric information. Domain V covers BIPA, Texas CUBI, and Washington's biometric statute in depth. The Domain II point is narrower: the advertising context does not exempt the collection. "The platform collected it, not our brand" is a vendor-management fact, not a statutory immunity. A voiceprint gathered to measure ad attention is still a voiceprint.

Data ethics and FTC overlap

The Body of Knowledge's data ethics prompt in the telecom and marketing domain is not a soft essay. It has four exam handles, and they match Federal Trade Commission priorities under section 5.

Fairness. Targeting on a sensitive inference — race or national-origin proxies, health condition, financial distress, a student's homework struggles — can be an unfair or discriminatory practice even when a sectoral statute does not name the inference. Housing, credit, and employment targeting have additional federal civil-rights overlays.

Secondary use. Data collected to complete a purchase, authenticate a cable subscriber, or deliver a school app is reused to train an ad model or to seed a clean room. Secondary use is how a lawful first collection becomes a deceptive or unfair later practice, and how a FERPA school-official vendor loses direct control.

Dark patterns. Interfaces that nag, shame, disguise ads as content, or obstruct unsubscribe and do-not-sell choices are an FTC enforcement theme (the Commission's Bringing Dark Patterns to Light report and later cases). A CAN-SPAM unsubscribe that is hidden, broken, or that demands extra data is both a statutory violation and a dark pattern. A cookie banner that makes "accept all" one click and "reject" a five-page maze is the same idea.

Vulnerable populations. Children (COPPA), students (FERPA and SOPPA-style laws), older adults, and people in debt are the populations the TSR advance-fee bans, COPPA, and section 5 already single out. Marketing that exploits a vulnerability is the fact pattern the Commission has said it will keep bringing.

Worked scenario. A retailer uploads a customer-match file of people who bought a pregnancy test, joins a clean room with a publisher to retarget them, drops a try-on pixel that captures face geometry, and instructs a vendor to scrape public review sites — then, after a cease-and-desist and an IP block, to keep scraping behind the login wall. The match-plus-clean-room retargeting is a secondary-use and state targeted-ad problem and may be an FTC unfairness problem if the original notice was limited to fulfillment. The face-geometry pixel is a BIPA-style collection. Public-page scraping after a paper cease-and-desist is a weak CFAA theory under hiQ and Van Buren. Continuing after a technical gate comes down, or while logged in, is a live CFAA and contract theory. If the same audience is then texted, add TCPA and the National Do-Not-Call rules. Ethics and statute stack; they do not cancel.

Loading diagram...
Advertising Stack, CFAA Gates, and Ethics Overlay
Test Your Knowledge

A vendor keeps copying public product-review pages after the site sends a cease-and-desist letter. The pages require no login. Which statement reflects the live Computer Fraud and Abuse Act doctrine?

A
B
C
D
Test Your Knowledge

A brand's unsubscribe page hides the opt-out behind five extra screens, demands a full Social Security number, and uses a 'No, I like paying too much' button. Which Body of Knowledge ethics problem is this, and which federal authority is the closest enforcement overlay?

A
B
C
D
Test Your Knowledge

A cosmetics brand adds a virtual try-on pixel that maps a shopper's face geometry and stores the template to retarget ads. The brand never offers a biometric consent form. What is the best Domain II statement?

A
B
C
D