Google sued a company for doing what Google itself does for a living: scrape the public web at scale.
On July 20, 2026, a federal court threw out the core of that lawsuit.
The case is Google LLC v. SerpApi, LLC, filed in the Northern District of California. At stake: can a platform use copyright law to fence off a page anyone can already view in a browser.
Here’s what Google alleged, what SerpApi argued back, what the judge actually ruled, and what’s still open.
Timeline: From Complaint to Dismissal
The docket moved fast for a federal copyright case. Google filed in December. SerpApi had a ruling in its favor seven months later.
| Date | Event |
|---|---|
| Jan 2025 | Google launches SearchGuard, its bot-detection system for Search |
| Dec 19, 2025 | Google files suit against SerpApi in the Northern District of California |
| Jan 23, 2026 | SerpApi’s general counsel publicly vows to fight the case |
| Feb 20, 2026 | SerpApi files its motion to dismiss |
| Mar 23, 2026 | SerpApi moves to stay discovery; the case management conference is vacated |
| Apr 6, 2026 | Google files its opposition brief |
| May 6, 2026 | SerpApi files its reply |
| Jul 20, 2026 | Judge Yvonne Gonzalez Rogers grants SerpApi’s motion, in part |
The full docket, including the complaint and every motion, is public on CourtListener, Case No. 4:25-cv-10826-YGR. That’s the record itself, not a summary of it. Anyone can pull the actual filings from there.
Seven months is fast for a federal case to reach a ruling on the merits of a motion to dismiss. Neither side asked for an extension past the standard briefing schedule. Judge Gonzalez Rogers, who also serves as Chief Judge of the district, ruled directly from the papers without oral argument on the merits, even though a hearing had originally been calendared for May 19, 2026.
What Google Said SerpApi Was Doing
Google filed its complaint on December 19, 2025. The case landed before Chief Judge Yvonne Gonzalez Rogers in the U.S. District Court for the Northern District of California.
Google built its claim around SearchGuard. The system launched in January 2025. It sends a JavaScript challenge to any search query arriving from an unrecognized source. A real browser solves the challenge automatically. Automated systems, at scale, usually can’t.
Google’s complaint alleged SerpApi solved that challenge anyway, then reused the solved token across other queries that never solved it themselves. It also alleged SerpApi masked its bots to look human and rotated crawler identities to dodge blocks. In Google’s own telling, SerpApi used shady back doors to reach content Google licenses from third parties: images inside Knowledge Panels, real-time data in Search features, and more.
The numbers in the complaint were large. Google said SerpApi’s query volume rose as much as 25,000% over two years. Statutory damages under DMCA Section 1201 run $200 to $2,500 per circumvention act. Multiplied across hundreds of millions of daily automated queries, the theoretical exposure dwarfs SerpApi’s reported annual revenue of a few million dollars.
Google pleaded two distinct claims. The first, under 17 U.S.C. § 1201(a)(1)(A), targeted SerpApi’s own act of circumventing SearchGuard to reach results. The second, under § 1201(a)(2), targeted SerpApi’s business of providing a service whose purpose, Google argued, was that same circumvention, sold to customers like Perplexity and other AI and analytics companies. Google framed the harm on four fronts: the cost of answering billions of automated queries, the erosion of its investment in licensed content, the threat to its relationships with content licensors, and the expense of building SearchGuard in the first place, which Google said took tens of thousands of person-hours.
That last point mattered to Google’s framing. Its complaint described SerpApi’s business as parasitic, built on infrastructure Google paid to construct and defend. Whether that framing survives contact with copyright law, rather than just public sympathy, is a separate question, and it’s the one the case actually turned on.
Google’s blog post drew a sharp before-and-after. It described its own crawler as one that honors robots.txt and industry-standard crawling protocols, then contrasted that against SerpApi’s alleged cloaking and constantly rotating bot identities. The framing did real work for Google’s narrative, even where it didn’t do much for the DMCA claim itself. A company that scraped the entire public web to build its index was positioning a much smaller scraper as the bad actor, on the theory that Google’s crawler asks first and SerpApi’s allegedly doesn’t. That’s a meaningful distinction in practice. It just isn’t a copyright distinction, which is part of why the framing didn’t save the broader claim.
SerpApi’s Defense: Standing, Circumvention, and the DMCA’s Scope
SerpApi filed its motion to dismiss on February 20, 2026. The filing argued Google’s suit “never gets out of the starting gate.”
The first argument was standing. The DMCA’s anti-circumvention rules protect copyright owners, not website operators generally. SerpApi’s brief pointed out that Google is neither the author nor the exclusive licensee of the content indexed in its own search results. That content belongs to the publishers, authors, and creators Google crawled to build its index in the first place.
“The problem is, no one owns the internet.” Julien Khaleghy, SerpApi CEO
The second argument targeted the technological measure itself. The DMCA defines circumvention narrowly: to descramble, decrypt, or otherwise impair a protection system. SerpApi argued that solving a JavaScript puzzle, or mimicking a browser’s fingerprint, isn’t the same as picking a lock or breaking encryption. It called this distinction mimicry, not circumvention.
SerpApi’s 31-page brief framed the dispute as three formal questions for the court: whether Google has DMCA standing as a non-owner, whether SearchGuard was implemented with a copyright owner’s authority, and whether SearchGuard controls access to a copyrighted work at all. A fourth thread ran through the whole filing: whether mimicking a browser even counts as circumvention under the statute’s own definition.
The motion also leaned on precedent. SerpApi cited the Ninth Circuit’s 2022 hiQ Labs v. LinkedIn decision, which warned against “information monopolies” over public data. That case was decided under the Computer Fraud and Abuse Act, not the DMCA, but SerpApi used its reasoning as persuasive support anyway: a platform shouldn’t get to use litigation to lock down data anyone can already see with a browser. Separately, SerpApi pointed to Impression Products v. Lexmark, arguing a technical lock on one entry point doesn’t control access to information sitting wide open at another. SerpApi’s own phrasing stuck with reporters: Google’s search results are the front door, and they’re already open.
SerpApi ran the math on Google’s own numbers, too. Using the minimum statutory rate, it calculated damages at $7.06 trillion. Using the maximum rate, exposure would exceed the entire U.S. gross domestic product. SerpApi used that gap to argue Congress never intended Section 1201 to reach a dispute like this one, rather than the DVD-encryption and software-piracy cases the statute was written for.
What the Judge Actually Ruled
Judge Gonzalez Rogers issued her order on July 20, 2026. She granted SerpApi’s motion to dismiss both of Google’s DMCA claims, but the order split cleanly into two tracks.
| Claim scope | Outcome | Why |
|---|---|---|
| Plain search results, no copyrighted content | Dismissed without leave to amend | The DMCA only protects “a work protected under the Copyright Act.” Results with nothing copyrighted have nothing for SearchGuard to protect. |
| Knowledge Panel images, licensed by Google | Dismissed with leave to amend | Google never alleged SearchGuard operates with the authority of the images’ actual copyright owners, a requirement under Section 1201(a)(3)(B). |
The judge’s own words on the first track were direct:
“SearchGuard cannot effectively control access to a work protected under the Copyright Act.”
That line permanently kills the general case: an ordinary results page, made of links and snippets pulled from across the web, isn’t itself a copyrighted work. Google’s own complaint had admitted Knowledge Panels are only “often” present and “may” contain copyrighted material, which the court read as an admission that most results carry nothing copyrightable at all.
The second track stays alive, narrowly. Google’s licenses might authorize SearchGuard to protect specific images. Google just didn’t plead the actual terms of those licenses, so the judge gave it 21 days to try again.
It’s worth being precise about what SerpApi did not win. The court rejected SerpApi’s standing argument outright, holding that the DMCA’s “zone of interests” covers “any person injured” by a Section 1201 or 1202 violation, not just owners and exclusive licensees. The statute’s own text goes further than SerpApi wanted, and the judge said so plainly.
The court also rejected SerpApi’s no-circumvention argument. Google had adequately alleged circumvention as a factual matter, the order found, by describing how SerpApi allegedly masked automated queries to look human and syndicated a single solved challenge out to browsers that never solved it themselves. Whether that conduct violates the DMCA still depends on whether a copyrighted work sits behind the challenge, which is exactly the piece Google’s complaint didn’t establish for ordinary results.
For the authority requirement on the Knowledge Panel claims, the judge cited the Ninth Circuit’s MDY Industries v. Blizzard Entertainment line of reasoning: a valid access control has to be put in place by, or with the authority of, the actual copyright owner. Google argued its licensing deals implied that authority. The court wasn’t persuaded, because Google’s complaint never described what those license terms actually said. That’s a fixable gap, on paper, which is why the judge left the door open instead of closing it.
Discovery is stayed until the amended complaint is resolved. SerpApi’s own motion to stay discovery was denied as moot, and Google’s motion to compel discovery responses was denied too, since there’s currently no live claim to take discovery on. SerpApi has posted the order itself alongside its own summary of the win.
How the Scraping and SEO Community Reacted
Coverage broke fast, and it leaned one direction. Techdirt’s Mike Masnick framed the irony bluntly: Google built an empire by scraping the entire web without asking, then sued a much smaller company for doing a version of the same thing to Google. The Register picked up SerpApi’s own framing that solving a puzzle isn’t picking a lock. Search Engine Journal and Search Engine Land both described the outcome as a relief for the rank-tracking and competitive-intelligence tools that quietly sit underneath a large share of the SEO industry’s daily workflow.
The stakes for that industry are concrete, not abstract. SerpApi’s API sits underneath rank trackers, keyword-research tools, and paid-search dashboards that thousands of marketing teams check every morning. Had Google won the broad version of its claim, scraping a results page could have carried DMCA-level statutory damages regardless of whether a human visitor sees the exact same page for free. That’s the outcome the tooling layer of the SEO industry was watching for, more than the fate of any single vendor.
It’s also not the first friction point in this fight. In September 2025, Google removed the num=100 parameter that had let tools pull 100 organic results in a single request, forcing ten requests where one used to suffice, a tenfold cost increase that several SEO platforms confirmed publicly. When a workaround appeared weeks later, Google identified and blocked it within five days. This lawsuit sat on top of an already-tightening year for anyone building on Google’s search data.
That relief has a ceiling, too. This ruling doesn’t touch the parallel case Reddit filed against SerpApi, Perplexity, Oxylabs, and AWMProxy in the Southern District of New York in October 2025, which raises an overlapping SearchGuard-circumvention theory under a different judge, in a different circuit’s persuasive orbit. SerpApi is still defending that case on its own footing, with its own motion to dismiss pending there.
A bot-detection layer that stops scrapers isn’t automatically a copyright fence. Courts are starting to draw that line explicitly.
What Still Hasn’t Changed
A dismissed DMCA claim isn’t a blanket legal opinion. A few things are true at the same time.
SearchGuard still runs. Solving it at scale still means handling a live bot-detection layer, not a legal argument. Google can still refile a narrower complaint focused on Knowledge Panel images within its 21-day window, provided it can plead the actual license terms this time. If that amended claim survives, it would apply only to results carrying a licensed image, not to the general practice of pulling organic listings.
Terms of Service and contract claims sit outside the DMCA entirely, and a terms-of-service gate can still create separate exposure even where copyright law doesn’t reach. This decision resolved a copyright-access question specific to Section 1201. It said nothing about breach of contract, trespass to chattels, or state-law unfair competition theories, all of which showed up in the earlier, still-unresolved Reddit litigation over the same underlying scraping methods. Anyone reading this ruling as a general green light for scraping any search engine, or any site, is reading it too broadly.
For a team currently paying for a scraping API to reach Google’s results, none of this changes the build-versus-buy math on its own. A vendor that already handles SearchGuard, CAPTCHA-solving, and IP rotation still has to keep handling all three tomorrow, regardless of which way this case goes. What the ruling does change is the liability conversation. Before July 20, a platform’s DMCA theory against scraping-as-a-service was untested at this scale. Now there’s a reasoned order on the record holding that theory fails wherever the underlying page carries nothing copyrighted. That’s useful context for any team weighing whether to build a Google-scraping pipeline in-house, rent access from an API vendor, or bring in a partner who already tracks cases like this one as part of the job.
What a production Google-data pipeline actually returns, once the anti-bot layer is handled, looks like structured, comparable fields rather than raw HTML:
// Illustrative shape only, not a captured Google response
{
"query": "best running shoes 2026",
"organic_results": [
{"position": 1, "title": "2026 Running Shoe Guide", "domain": "runnersworld.com"}
],
"knowledge_panel": {
"title": "Nike Pegasus 41",
"contains_licensed_image": true
},
"shopping_results": [
{"title": "Nike Air Zoom Pegasus 41", "price": "139.99", "seller": "nike.com"}
]
}
That’s the layer DataFlirt’s search-engine data work targets: handling the bot-detection fight, then delivering fields a pricing or SEO team can actually query, instead of a results page they still have to parse by hand.
Why Businesses Scrape Google Search Results in the First Place
None of this changes why the demand exists. Google’s results feed a handful of recurring business needs, over and over:
- Rank tracking across large keyword sets, refreshed daily instead of manually
- Competitive pricing and ad intelligence pulled from Google Shopping listings
- Local pack and Maps visibility tracking for multi-location brands
- SERP-feature research: Knowledge Panels, People Also Ask, featured snippets
- Structured, licensable AI training data drawn from public search results
SearchGuard’s challenge-response flow: how Google separates human browsers from automated queries, and where Google alleged SerpApi’s workaround intercepted the process.
Legal outcomes here turn on facts specific to this case, not general rules for scraping. For how copyright, contract, and CFAA exposure generally apply, see DataFlirt’s is web crawling legal breakdown.
Next Steps
Choose DataFlirt if:
- Google Search, Shopping, or Maps data needs to land as clean JSON, CSV, or a live API, not raw HTML you still have to parse.
- Handling a bot-detection layer like SearchGuard, Cloudflare, or Akamai is a real, ongoing requirement, not a one-time script.
- There’s no in-house data engineering team to keep a Google-scraping pipeline running through the next anti-bot update.
- The engagement should be consultative: a partner who flags legal risk honestly, instead of a vendor who stays quiet until there’s a subpoena.
Look elsewhere if:
- DataFlirt runs on cloud infrastructure and third-party proxy vendors rather than owning infrastructure in-house. That’s true of nearly every provider in this space, so it isn’t a differentiator against alternatives, but it’s worth knowing if in-house infra ownership is a hard requirement.
Most projects are scoped within 48 hours. Talk to DataFlirt about a compliant, custom-built Google search data pipeline.


