Davitashvili v. Grubhub

Headline: Second Circuit Affirms Dismissal of Grubhub Data Class Action

Citation: 131 F.4th 109

Court: Second Circuit · Filed: 2025-03-13 · Docket: 23-521
Published
This decision reinforces the importance of carefully analyzing terms of service and pleading specific factual allegations of unauthorized access to survive motions to dismiss under the CFAA. It also clarifies the scope of federal preemption for state law claims arising from similar conduct, potentially limiting plaintiffs' ability to pursue such claims in state courts. moderate affirmed
Outcome: Defendant Win
Impact Score: 30/100 — Low-moderate impact: This case addresses specific legal issues with limited broader application.
Legal Topics: Computer Fraud and Abuse Act (CFAA) unauthorized accessTerms of Service interpretationData scraping and data collectionFederal preemption of state law claimsClass action pleading standardsUnjust enrichmentConversion
Legal Principles: Strict construction of statutory language (CFAA)Implied license defenseFederal preemption doctrinePleading standards for class actions (Twombly/Iqbal)

Brief at a Glance

Grubhub's data collection was authorized by users agreeing to its Terms of Service, defeating claims of unauthorized access.

  • Always read Terms of Service before agreeing to use an online service.
  • Understand that agreeing to ToS grants permission for data collection and usage as outlined.
  • Be aware that challenging data practices as 'unauthorized' is difficult if disclosed in ToS.

Case Summary

Davitashvili v. Grubhub, decided by Second Circuit on March 13, 2025, resulted in a defendant win outcome. The Second Circuit affirmed the dismissal of a class action lawsuit against Grubhub, alleging violations of the Computer Fraud and Abuse Act (CFAA) and state law claims. The court held that the plaintiffs failed to plead sufficient facts to establish that Grubhub's data practices constituted unauthorized access under the CFAA, as the terms of service permitted such data collection. Furthermore, the court found that the state law claims were preempted by federal law or failed for similar pleading deficiencies. The court held: The court affirmed the dismissal of the Computer Fraud and Abuse Act (CFAA) claims, holding that the plaintiffs did not sufficiently plead unauthorized access because Grubhub's terms of service permitted the data collection practices at issue.. Plaintiffs failed to establish that Grubhub's alleged data scraping and use of information from third-party websites constituted unauthorized access under the CFAA, as the terms of service provided a license for such activities.. The court found that the state law claims for unjust enrichment and conversion were preempted by the CFAA, as they arose from the same alleged conduct that the CFAA governed.. Even if not preempted, the state law claims failed for lack of particularity in pleading, as the plaintiffs did not adequately allege how Grubhub's actions caused them specific harm or resulted in unjust enrichment.. The court rejected the plaintiffs' argument that Grubhub's alleged circumvention of technological measures constituted unauthorized access, finding the allegations conclusory and unsupported by factual detail.. This decision reinforces the importance of carefully analyzing terms of service and pleading specific factual allegations of unauthorized access to survive motions to dismiss under the CFAA. It also clarifies the scope of federal preemption for state law claims arising from similar conduct, potentially limiting plaintiffs' ability to pursue such claims in state courts.

AI-generated summary for informational purposes only. Not legal advice. May contain errors. Consult a licensed attorney for legal advice.

Case Analysis — Multiple Perspectives

Plain English (For Everyone)

A lawsuit against Grubhub was dismissed because the court found that when you agree to use their service, you give them permission to access your data as described in their terms. Therefore, their actions weren't considered unauthorized, and your claims under federal and state laws were unsuccessful.

For Legal Practitioners

The Second Circuit affirmed dismissal, holding that plaintiffs failed to plead unauthorized access under the CFAA, as assent to Grubhub's Terms of Service constituted authorization for the data practices. State law claims were also dismissed due to preemption or failure to state a claim.

For Law Students

This case illustrates that agreeing to a service's Terms of Service can grant authorization for data collection practices, defeating claims of 'unauthorized access' under the CFAA. Plaintiffs must plead specific facts showing access exceeded granted permissions, not just disagreement with data use.

Newsroom Summary

A federal appeals court ruled that Grubhub did not illegally access user data, finding that customers agree to data collection when they sign up for the service. The decision upholds the dismissal of a lawsuit against the food delivery company.

Key Holdings

The court established the following key holdings in this case:

  1. The court affirmed the dismissal of the Computer Fraud and Abuse Act (CFAA) claims, holding that the plaintiffs did not sufficiently plead unauthorized access because Grubhub's terms of service permitted the data collection practices at issue.
  2. Plaintiffs failed to establish that Grubhub's alleged data scraping and use of information from third-party websites constituted unauthorized access under the CFAA, as the terms of service provided a license for such activities.
  3. The court found that the state law claims for unjust enrichment and conversion were preempted by the CFAA, as they arose from the same alleged conduct that the CFAA governed.
  4. Even if not preempted, the state law claims failed for lack of particularity in pleading, as the plaintiffs did not adequately allege how Grubhub's actions caused them specific harm or resulted in unjust enrichment.
  5. The court rejected the plaintiffs' argument that Grubhub's alleged circumvention of technological measures constituted unauthorized access, finding the allegations conclusory and unsupported by factual detail.

Key Takeaways

  1. Always read Terms of Service before agreeing to use an online service.
  2. Understand that agreeing to ToS grants permission for data collection and usage as outlined.
  3. Be aware that challenging data practices as 'unauthorized' is difficult if disclosed in ToS.
  4. Consider alternative services if their data policies are unfavorable.
  5. Consult legal counsel if you believe a company has misused your data beyond agreed-upon terms.

Deep Legal Analysis

Standard of Review

De novo review, as the appeal concerns the interpretation of statutes and the sufficiency of pleadings, which are legal questions reviewed independently by the appellate court.

Procedural Posture

The case reached the Second Circuit on appeal from the United States District Court for the Southern District of New York, which dismissed the plaintiffs' class action complaint.

Burden of Proof

The plaintiffs, as the party seeking to bring the claims, bore the burden of proof. They needed to demonstrate sufficient facts to meet the pleading standards for their claims under the CFAA and state law.

Legal Tests Applied

Computer Fraud and Abuse Act (CFAA) - Unauthorized Access

Elements: Access to a computer without authorization or exceeding authorized access · Intentionally accessing a protected computer

The court found that the plaintiffs failed to allege facts showing Grubhub accessed its users' accounts without authorization or exceeded authorized access. The court reasoned that by agreeing to Grubhub's Terms of Service, users granted Grubhub permission to access and use their data in the manner described, thus negating the 'unauthorized access' element.

Statutory References

18 U.S.C. § 1030(a)(2) Computer Fraud and Abuse Act (CFAA) — This statute prohibits intentionally accessing a protected computer without authorization or exceeding authorized access and thereby obtaining information.

Key Legal Definitions

Unauthorized Access (CFAA): Under the CFAA, 'unauthorized access' means accessing a computer without permission or exceeding the scope of permission granted. In this context, the court determined that users' agreement to the Terms of Service constituted authorization for Grubhub's data collection practices.
Exceeding Authorized Access (CFAA): This refers to accessing a computer system in a way that goes beyond the permissions granted to the user or entity. The court found the plaintiffs did not sufficiently allege that Grubhub's actions fell into this category, as their data use was contemplated by the Terms of Service.
Terms of Service: The legally binding agreement between a service provider (like Grubhub) and its users. The court found that the plaintiffs' assent to Grubhub's Terms of Service provided authorization for the data practices at issue.
Preemption: A legal doctrine where a higher authority of law (federal law) overrides a lower one (state law). The court found that some of the plaintiffs' state law claims were preempted by federal law.

Rule Statements

By agreeing to the Terms of Service, users grant Grubhub permission to access and use their data in the manner described, which means that Grubhub’s access to user data was authorized.
The plaintiffs have not alleged facts sufficient to establish that Grubhub accessed their accounts without authorization or exceeded authorized access.
Because the plaintiffs’ state law claims are based on the same alleged conduct that forms the basis of their CFAA claim, and because the plaintiffs have failed to state a claim under the CFAA, the state law claims fail.

Remedies

Affirmed the dismissal of the class action lawsuit.

Entities and Participants

Key Takeaways

  1. Always read Terms of Service before agreeing to use an online service.
  2. Understand that agreeing to ToS grants permission for data collection and usage as outlined.
  3. Be aware that challenging data practices as 'unauthorized' is difficult if disclosed in ToS.
  4. Consider alternative services if their data policies are unfavorable.
  5. Consult legal counsel if you believe a company has misused your data beyond agreed-upon terms.

Know Your Rights

Real-world scenarios derived from this court's ruling:

Scenario: You use a popular app and later discover it collects more data than you expected. You want to sue the app company for unauthorized data access.

Your Rights: Your right to privacy regarding data collected by apps is limited by the terms of service you agree to. If the app's terms clearly state they can collect and use your data in the way they did, your ability to sue for unauthorized access is significantly weakened.

What To Do: Carefully read the Terms of Service and Privacy Policy before agreeing to use any online service. If you disagree with the data practices, consider not using the service or exploring alternatives with more favorable terms.

Is It Legal?

Common legal questions answered by this ruling:

Is it legal for a company to collect data about my usage of their service?

Depends. It is generally legal if the company clearly discloses its data collection practices in its Terms of Service or Privacy Policy, and you agree to those terms. If the collection or use of data goes beyond what was disclosed or authorized, it could be illegal.

This depends on the specific terms of service, the nature of the data collected, and applicable federal and state privacy laws.

Practical Implications

For Users of online platforms and apps

Users should be aware that agreeing to Terms of Service grants significant permission to companies regarding data collection and usage. This ruling makes it harder to challenge data practices as 'unauthorized' if they are disclosed in the ToS, even if users didn't fully read or understand them.

For Technology companies and service providers

This ruling reinforces the importance of clear and comprehensive Terms of Service and Privacy Policies. Companies can rely on user agreement to these documents as authorization for their data practices, strengthening their defense against claims of unauthorized access.

Related Legal Concepts

Terms of Service
The legal agreement between a user and a service provider outlining the rules an...
Computer Fraud and Abuse Act (CFAA)
A U.S. federal law that prohibits unauthorized access to computers and networks.
Data Privacy
The principles and practices governing the collection, use, storage, and sharing...
Class Action Lawsuit
A lawsuit filed by one or more individuals on behalf of a larger group of people...

Frequently Asked Questions (29)

Comprehensive Q&A covering every aspect of this court opinion.

Basic Questions (5)

Q: What is Davitashvili v. Grubhub about?

Davitashvili v. Grubhub is a case decided by Second Circuit on March 13, 2025.

Q: What court decided Davitashvili v. Grubhub?

Davitashvili v. Grubhub was decided by the Second Circuit, which is part of the federal judiciary. This is a federal appellate court.

Q: When was Davitashvili v. Grubhub decided?

Davitashvili v. Grubhub was decided on March 13, 2025.

Q: What is the citation for Davitashvili v. Grubhub?

The citation for Davitashvili v. Grubhub is 131 F.4th 109. Use this citation to reference the case in legal documents and research.

Q: What was the main issue in Davitashvili v. Grubhub?

The main issue was whether Grubhub's collection and use of user data constituted 'unauthorized access' under the Computer Fraud and Abuse Act (CFAA), or violated state laws.

Legal Analysis (12)

Q: Is Davitashvili v. Grubhub published?

Davitashvili v. Grubhub is a published, precedential opinion. Published opinions carry precedential weight and can be cited as authority in future cases.

Q: What topics does Davitashvili v. Grubhub cover?

Davitashvili v. Grubhub covers the following legal topics: Computer Fraud and Abuse Act (CFAA), Unauthorized access under CFAA, Terms of service interpretation, Data scraping, Preemption of state law claims, New York General Business Law § 349, Pleading standards for fraud and deceptive practices.

Q: What was the ruling in Davitashvili v. Grubhub?

The court ruled in favor of the defendant in Davitashvili v. Grubhub. Key holdings: The court affirmed the dismissal of the Computer Fraud and Abuse Act (CFAA) claims, holding that the plaintiffs did not sufficiently plead unauthorized access because Grubhub's terms of service permitted the data collection practices at issue.; Plaintiffs failed to establish that Grubhub's alleged data scraping and use of information from third-party websites constituted unauthorized access under the CFAA, as the terms of service provided a license for such activities.; The court found that the state law claims for unjust enrichment and conversion were preempted by the CFAA, as they arose from the same alleged conduct that the CFAA governed.; Even if not preempted, the state law claims failed for lack of particularity in pleading, as the plaintiffs did not adequately allege how Grubhub's actions caused them specific harm or resulted in unjust enrichment.; The court rejected the plaintiffs' argument that Grubhub's alleged circumvention of technological measures constituted unauthorized access, finding the allegations conclusory and unsupported by factual detail..

Q: Why is Davitashvili v. Grubhub important?

Davitashvili v. Grubhub has an impact score of 30/100, indicating limited broader impact. This decision reinforces the importance of carefully analyzing terms of service and pleading specific factual allegations of unauthorized access to survive motions to dismiss under the CFAA. It also clarifies the scope of federal preemption for state law claims arising from similar conduct, potentially limiting plaintiffs' ability to pursue such claims in state courts.

Q: What precedent does Davitashvili v. Grubhub set?

Davitashvili v. Grubhub established the following key holdings: (1) The court affirmed the dismissal of the Computer Fraud and Abuse Act (CFAA) claims, holding that the plaintiffs did not sufficiently plead unauthorized access because Grubhub's terms of service permitted the data collection practices at issue. (2) Plaintiffs failed to establish that Grubhub's alleged data scraping and use of information from third-party websites constituted unauthorized access under the CFAA, as the terms of service provided a license for such activities. (3) The court found that the state law claims for unjust enrichment and conversion were preempted by the CFAA, as they arose from the same alleged conduct that the CFAA governed. (4) Even if not preempted, the state law claims failed for lack of particularity in pleading, as the plaintiffs did not adequately allege how Grubhub's actions caused them specific harm or resulted in unjust enrichment. (5) The court rejected the plaintiffs' argument that Grubhub's alleged circumvention of technological measures constituted unauthorized access, finding the allegations conclusory and unsupported by factual detail.

Q: What are the key holdings in Davitashvili v. Grubhub?

1. The court affirmed the dismissal of the Computer Fraud and Abuse Act (CFAA) claims, holding that the plaintiffs did not sufficiently plead unauthorized access because Grubhub's terms of service permitted the data collection practices at issue. 2. Plaintiffs failed to establish that Grubhub's alleged data scraping and use of information from third-party websites constituted unauthorized access under the CFAA, as the terms of service provided a license for such activities. 3. The court found that the state law claims for unjust enrichment and conversion were preempted by the CFAA, as they arose from the same alleged conduct that the CFAA governed. 4. Even if not preempted, the state law claims failed for lack of particularity in pleading, as the plaintiffs did not adequately allege how Grubhub's actions caused them specific harm or resulted in unjust enrichment. 5. The court rejected the plaintiffs' argument that Grubhub's alleged circumvention of technological measures constituted unauthorized access, finding the allegations conclusory and unsupported by factual detail.

Q: What cases are related to Davitashvili v. Grubhub?

Precedent cases cited or related to Davitashvili v. Grubhub: 17 U.S.C. § 1030; Bell Atlantic Corp. v. Twombly, 550 U.S. 544 (2007); Ashcroft v. Iqbal, 556 U.S. 662 (2009).

Q: Did the court find that Grubhub accessed user data without authorization?

No, the Second Circuit found that Grubhub's access was authorized because users agreed to the company's Terms of Service, which permitted such data practices.

Q: What is the Computer Fraud and Abuse Act (CFAA)?

The CFAA is a U.S. federal law that prohibits intentionally accessing a computer without authorization or exceeding authorized access to obtain information.

Q: How did the court interpret the Terms of Service in this case?

The court interpreted the Terms of Service as a contract where users granted Grubhub permission to access and use their data in the ways described within the agreement.

Q: What happened to the state law claims against Grubhub?

The court dismissed the state law claims, finding they were either preempted by federal law or failed for similar pleading deficiencies as the federal claims.

Q: What does 'unauthorized access' mean under the CFAA?

It means accessing a computer system without permission or exceeding the scope of permission granted. In this case, agreeing to the Terms of Service was deemed sufficient authorization.

Practical Implications (5)

Q: How does Davitashvili v. Grubhub affect me?

This decision reinforces the importance of carefully analyzing terms of service and pleading specific factual allegations of unauthorized access to survive motions to dismiss under the CFAA. It also clarifies the scope of federal preemption for state law claims arising from similar conduct, potentially limiting plaintiffs' ability to pursue such claims in state courts. As a decision from a federal appellate court, its reach is national. This case is moderate in legal complexity to understand.

Q: Can I sue a company if I didn't read their Terms of Service?

Generally, no. By using the service after agreeing to the terms, you are typically bound by them, even if you didn't read them. This ruling emphasizes that agreement constitutes authorization.

Q: What should I do if I'm concerned about how an app uses my data?

Before using any service, carefully read its Terms of Service and Privacy Policy. If you disagree with the data practices, consider not using the service or seeking alternatives.

Q: Does this ruling mean companies can do anything they want with my data?

No, companies must still comply with applicable privacy laws and their own stated policies. However, this ruling suggests that data practices disclosed and agreed to in Terms of Service are less likely to be deemed illegal 'unauthorized access'.

Q: What is the significance of this ruling for users?

It highlights the importance of user awareness regarding the permissions granted through Terms of Service agreements and makes it more difficult to challenge data practices if they are disclosed in those terms.

Procedural Questions (4)

Q: What was the docket number in Davitashvili v. Grubhub?

The docket number for Davitashvili v. Grubhub is 23-521. This identifier is used to track the case through the court system.

Q: Can Davitashvili v. Grubhub be appealed?

Potentially — decisions from federal appellate courts can be appealed to the Supreme Court of the United States via a petition for certiorari, though the Court accepts very few cases.

Q: What is the standard of review used by the Second Circuit?

The Second Circuit reviewed the case de novo, meaning they examined the legal questions independently without giving deference to the lower court's decisions.

Q: What is 'de novo' review?

De novo review means the appellate court considers the legal issues from scratch, as if the trial court had not made any decision on them.

Cited Precedents

This opinion references the following precedent cases:

  • 17 U.S.C. § 1030
  • Bell Atlantic Corp. v. Twombly, 550 U.S. 544 (2007)
  • Ashcroft v. Iqbal, 556 U.S. 662 (2009)

Case Details

Case NameDavitashvili v. Grubhub
Citation131 F.4th 109
CourtSecond Circuit
Date Filed2025-03-13
Docket Number23-521
Precedential StatusPublished
OutcomeDefendant Win
Dispositionaffirmed
Impact Score30 / 100
SignificanceThis decision reinforces the importance of carefully analyzing terms of service and pleading specific factual allegations of unauthorized access to survive motions to dismiss under the CFAA. It also clarifies the scope of federal preemption for state law claims arising from similar conduct, potentially limiting plaintiffs' ability to pursue such claims in state courts.
Complexitymoderate
Legal TopicsComputer Fraud and Abuse Act (CFAA) unauthorized access, Terms of Service interpretation, Data scraping and data collection, Federal preemption of state law claims, Class action pleading standards, Unjust enrichment, Conversion
Jurisdictionfederal

Related Legal Resources

Second Circuit Opinions Computer Fraud and Abuse Act (CFAA) unauthorized accessTerms of Service interpretationData scraping and data collectionFederal preemption of state law claimsClass action pleading standardsUnjust enrichmentConversion federal Jurisdiction Know Your Rights: Computer Fraud and Abuse Act (CFAA) unauthorized accessKnow Your Rights: Terms of Service interpretationKnow Your Rights: Data scraping and data collection Home Search Cases Is It Legal? 2025 Cases All Courts All Topics States Rankings Computer Fraud and Abuse Act (CFAA) unauthorized access GuideTerms of Service interpretation Guide Strict construction of statutory language (CFAA) (Legal Term)Implied license defense (Legal Term)Federal preemption doctrine (Legal Term)Pleading standards for class actions (Twombly/Iqbal) (Legal Term) Computer Fraud and Abuse Act (CFAA) unauthorized access Topic HubTerms of Service interpretation Topic HubData scraping and data collection Topic Hub

About This Analysis

This comprehensive multi-pass AI-generated analysis of Davitashvili v. Grubhub was produced by CaseLawBrief to help legal professionals, researchers, students, and the general public understand this court opinion in plain English. This case received our HEAVY-tier enrichment with 5 AI analysis passes covering core analysis, deep legal structure, comprehensive FAQ, multi-audience summaries, and cross-case practical intelligence.

CaseLawBrief aggregates court opinions from CourtListener, a project of the Free Law Project, and enriches them with AI-powered analysis. Our goal is to make the law more accessible and understandable to everyone, regardless of their legal background.

AI-generated summary for informational purposes only. Not legal advice. May contain errors. Consult a licensed attorney for legal advice.

Related Cases

Other opinions on Computer Fraud and Abuse Act (CFAA) unauthorized access or from the Second Circuit: