Model Local Law: Municipal Automated Data Access Program
A sample New York local law for establishing a paid program for automated access to public municipal website data. Drafted with two versions — cost-recovery and revenue — each followed by plain-language commentary for officials who have never read a local law.
This document is a legislative drafting template prepared for policy research and discussion. It is not legal advice and does not create an attorney-client relationship. It has not been reviewed by any municipal attorney, COOG, or court. Every statutory citation must be verified against official McKinney's consolidated laws or the NY Senate legislative database before introduction — several key NY statutes (POL §§ 84–89, MHRL § 10, Statute of Local Governments) could not be directly fetched from primary sources during the underlying research and were reconstructed from widely-cited secondary authority S-011, S-012, S-013. A municipality must consult its own attorney, seek a COOG advisory opinion S-015, S-206, and complete the Legal Review Checklist at the end before adopting any version.
All bracketed items (e.g., [MUNICIPALITY], [DEPARTMENT], dollar figures, dates) are placeholders. Every S-NNN citation refers to a source in sources/sources.yaml.
How to Use This Document
This package contains two draft versions of a sample local law for a paid automated (bot) access program for public municipal website data.
- Version A (Cost-Recovery Model) — fees limited to documented actual cost of providing automated access. Structured to fit within the existing FOIL fee framework S-011, S-202 and federal cost-recovery precedent (FOIA S-001, S-201, PACER S-008, S-204, S-205). Lower legal risk.
- Version B (Revenue Model) — fees above pure cost recovery to fund broader digital infrastructure. Relies on a broader home-rule argument S-002, S-012 with explicit legislative findings. Higher legal risk. If counsel is uncertain, adopt Version A.
Both versions share most sections. Where Version B differs, it is clearly marked. After each major section, italic commentary explains the section in plain language for officials who have never read a local law.
Version A — Cost-Recovery Model Local Law
§ A-1. Title
A Local Law establishing a Municipal Automated Data Access Program for the [CITY/TOWN/VILLAGE] of [MUNICIPALITY]
Commentary: Every NY local law has a title that identifies the subject. The title is what appears in the local law filing with the NY Department of State and in the municipality's code book. Keep it short and descriptive.
§ A-2. Legislative Findings and Statement of Purpose
WHEREAS, the [CITY/TOWN/VILLAGE] of [MUNICIPALITY] (hereinafter “the Municipality”) operates a public website at [URL] through which it publishes government information, records, notices, agendas, budgets, permits, and other public data for the benefit of residents and the public; and
WHEREAS, the Municipality's website is digital property of the local government, maintained and operated as an extension of its governmental facilities and the transaction of its business, consistent with NY Constitution Article IX, § 2(c)(ii)(3) (“the transaction of its business”) and § 2(c)(ii)(6) (“the acquisition, care, management and use of its … property”) S-002; and
WHEREAS, automated software programs commonly known as “bots,” “crawlers,” or “scrapers” increasingly access the Municipality's website at high volume and machine speed, consuming server capacity, bandwidth, and infrastructure resources that are also needed to serve human residents; and
WHEREAS, industry research indicates that bots account for approximately fifty-three percent (53%) of web activity and “bad bots” alone approximately forty percent (40%) S-116; and
WHEREAS, uncontrolled automated access degrades website performance for human residents, increases infrastructure costs, and creates security risks S-114, S-116; and
WHEREAS, the New York Freedom of Information Law (FOIL), Public Officers Law §§ 84–89, guarantees the public's right to request and obtain copies of government records through a formal request-and-response process with statutory fee caps, and the Municipality is fully committed to preserving and never replacing that statutory right S-011, S-202; and
WHEREAS, a bot crawling a public website that has already published information is accessing already-public material and is not, by that act alone, making a formal FOIL request within the meaning of Public Officers Law §§ 86–89, which govern a request-and-response process for agency records S-011; and
WHEREAS, the Municipality desires to establish a voluntary, alternative, premium channel for structured automated access to its public data — through a registered, key-based, rate-limited API — that supplements, and does not replace, free public website access and free FOIL access; and
WHEREAS, charging commercial users of high-volume automated access a fee limited to the actual, documented cost of providing that access is consistent with the cost-recovery standard that governs government records-access fees under FOIL S-011, S-202, federal FOIA S-001, S-201, the federal PACER system S-008, S-204, S-205, and the E-Government Act of 2002 S-016; and
WHEREAS, providing free or reduced-fee access to residents, news media, academic researchers, and public-interest users is consistent with the differential fee structure of federal FOIA S-001, S-201 and PACER's discretionary exemptions S-204, S-205, and is necessary to protect the public-access floor that FOIL and the First Amendment require S-011, S-001; and
WHEREAS, fee revenue shall be dedicated solely to the costs of operating the program and to civic technology improvements that benefit all residents, and shall not be diverted to unrelated general government purposes, consistent with the lesson of National Veterans Legal Services Program v. United States, where PACER fees were found unlawfully diverted to costs unrelated to the electronic access system S-009, S-010; and
WHEREAS, the Municipality has consulted, or will consult prior to adoption, with the NY Committee on Open Government (COOG) regarding the proposed program's consistency with FOIL S-015, S-206;
NOW, THEREFORE, be it enacted by the [Governing Body] of the [CITY/TOWN/VILLAGE] of [MUNICIPALITY] as follows:
The finding that a bot crawling a public website is not making a FOIL request is supported by the statutory text S-011 but untested in NY courts S-011, S-015. Municipal counsel must confirm this and seek a COOG advisory opinion before adoption.
Commentary: The “WHEREAS” clauses are the legislature's explanation of the problem and the intent. Courts and the public read these to understand why the law was passed. They are not legally operative (the operative rules are in the sections that follow) but they matter if the law is ever challenged — a court will ask whether the legislature had a legitimate purpose. This section establishes that the purpose is traffic management and cost recovery, not revenue generation, and that FOIL is preserved.
§ A-3. Definitions
For purposes of this Local Law, the following terms shall have the meanings set forth below:
(a) “Automated Access” means access to the Municipality's public website or data API by a software program that sends HTTP requests automatically without a human directing each request, including web crawlers, spiders, scrapers, and API clients. The HTTP standards themselves recognize automated user agents, including “spiders (web-traversing robots), command-line tools, [and] billboard screens” as user agents S-102.
(b) “Bot” means any software program that performs Automated Access. Bots include search engine crawlers (e.g., Googlebot), commercial scrapers, AI training crawlers, and API clients S-102, S-116.
(c) “Crawler” or “Spider” means a Bot that begins at one web page, follows links to other pages, and recursively traverses the website S-101.
(d) “API” (Application Programming Interface) means a structured endpoint, or set of endpoints, through which computer programs may request and receive data from the Municipality in a machine-readable format (typically JSON), as distinguished from a human-readable web page. The W3C Data on the Web Best Practices recognize APIs as a standard access method S-301, and the federal Project Open Data schema distinguishes API access (accessURL) from file download (downloadURL) S-304.
(e) “API Key” means a unique identifier issued by the Municipality to a registered Requester, included in each API request to identify and authenticate the Requester and to apply the Requester's assigned access tier, rate limits, and quota S-106.
(f) “News Media Requester” means a Requester that is a news organization or journalist whose primary purpose is to publish news to the public, mirroring FOIA's “news media” category, 5 U.S.C. § 552(a)(4)(A)(ii)(II) S-001, S-201.
(g) “Academic or Research Requester” means a Requester affiliated with an educational or scientific institution whose primary purpose is academic research or scholarly publication, not commercial use, mirroring FOIA's “educational or scientific institution” category S-001, S-201.
(h) “Public-Interest Requester” means a Requester that is a non-profit organization, government agency, or individual whose use is likely to contribute significantly to public understanding of government operations and is not primarily commercial, modeled on FOIA's public-interest waiver, 5 U.S.C. § 552(a)(4)(A)(iii) S-001, S-201.
(i) “Commercial Requester” means a Requester whose primary purpose is to use, resell, or commercialize the data, including data brokers, real-estate platforms, AI training operations, and any entity deriving revenue from the data. This mirrors FOIA's “commercial use” category, 5 U.S.C. § 552(a)(4)(A)(ii)(I) S-001, S-201.
(j) “Resident Requester” means a Requester who is a natural person residing within the Municipality accessing data for personal, non-commercial purposes.
(k) “Requester” means any person or entity that registers for and accesses the API under this Local Law. “Person” is defined consistent with FOIL's “any person” standard S-011.
(l) “FOIL” means the New York Freedom of Information Law, Public Officers Law Article 6, §§ 84–89 S-011, S-202.
(m) “FOIL Request” means a formal, written request for existing agency records submitted pursuant to Public Officers Law § 86, triggering the statutory response deadlines, fee caps, and appeal rights of §§ 87–89 S-011, S-202.
(n) “Rate Limit” means a rule capping the number of API requests a Requester may send in a defined time window (e.g., requests per second, per minute, or per month), enforced by the API gateway, with excess requests rejected (typically HTTP 429 “Too Many Requests”) S-114, S-120.
(o) “Quota” means a limit on the total number of API requests a Requester may make in a billing period (e.g., per month), distinct from a Rate Limit, which governs speed S-120.
(p) “Program” means the Municipal Automated Data Access Program established by this Local Law.
(q) “Program Administrator” means the [DEPARTMENT] (e.g., Department of Information Technology, Office of the Clerk, or other designated department) responsible for administering the Program.
(r) “Machine-Readable Format” means a data format that a computer can parse automatically without human interpretation, including CSV, JSON, XML, and GeoJSON, as distinguished from PDF or styled HTML, consistent with W3C Best Practice 12 S-301.
(s) “Metadata” means descriptive information about a dataset, including at minimum the title, description, publisher, contact point, last-modified date, update frequency, license, and access level, consistent with the DCAT-US schema required fields S-304 and W3C Best Practices 1–2 S-301.
(t) “robots.txt” means the text file, governed by RFC 9309, placed at the root of the Municipality's website that provides advisory guidance to crawlers. RFC 9309 explicitly states that its rules “are not a form of access authorization” S-101.
(u) “Personally Identifiable Information” or “PII” means information that identifies a specific individual, including but not limited to name, address, telephone number, email address, Social Security number, date of birth, driver's license number, financial account numbers, and medical information.
(v) “TOS” (Terms of Service) means the published terms and conditions governing use of the Program's API, which each Requester accepts as a condition of registration, as further specified in § A-8.
Commentary: Definitions are the foundation of any local law — every term used later must be defined here to avoid ambiguity. The tiered requester categories (Commercial, Resident, News Media, Academic, Public-Interest) are modeled directly on federal FOIA's three-category structure S-001, S-201 so the fee differentials in § A-6 and § A-7 have a defensible legal basis.
§ A-4. Authority
This Local Law is enacted pursuant to the following authority:
(a) New York Constitution Article IX, § 2(c)(i): Every local government has the power to adopt local laws not inconsistent with the constitution or any general law relating to its property, affairs, or government S-002.
(b) New York Constitution Article IX, § 2(c)(ii)(3): Power to adopt local laws relating to “the transaction of its business” S-002.
(c) New York Constitution Article IX, § 2(c)(ii)(6): Power to adopt local laws relating to “the acquisition, care, management and use of its highways, roads, streets, avenues and property” S-002. The Municipality's website and data infrastructure are “property” of the local government within the meaning of this provision.
(d) New York Constitution Article IX, § 3(c): Rights, powers, privileges, and immunities granted to local governments by Article IX shall be liberally construed in favor of the local government S-002.
(e) New York Municipal Home Rule Law § 10(1)(i): Power to adopt local laws relating to the property, affairs, or government of the municipality S-012.
(f) New York Municipal Home Rule Law § 10(1)(ii)(a)(3) and (6): Power to adopt local laws relating to “the transaction of [its] business” and “the acquisition, care, management and use of its … property” S-012.
(g) New York Statute of Local Governments: Grants local governments powers of local legislation and administration, which may only be repealed or diminished by re-enactment in two consecutive calendar years S-013.
(h) New York Public Officers Law §§ 84–89 (FOIL): The Municipality's obligations under FOIL, including the public's right to request records, the statutory fee caps, and the appeal process, are preserved in full and are not modified, limited, or replaced by this Local Law. This Local Law creates an additional, voluntary access channel; it does not alter the FOIL floor S-011, S-202.
The specific statutory text of MHRL § 10 and the Statute of Local Governments could not be directly verified against primary sources S-012, S-013. The citations are well-established in NY municipal law but must be confirmed against official McKinney's before introduction.
Commentary: The Authority section is the legal “power source” for the law — a local law without stated legal basis can be challenged as ultra vires. This section cites the NY Constitution's home rule provisions, MHRL § 10, and explicitly preserves FOIL — the most important legal anchor, because the program must never be read as overriding state open-records law.
§ A-5. Program Establishment
(a) Establishment. There is hereby established the Municipal Automated Data Access Program (the “Program”), to be administered by the [DEPARTMENT] (the “Program Administrator”).
(b) Purpose. The Program provides a voluntary, registered, key-based, rate-limited API through which Requesters may obtain the Municipality's public data in machine-readable formats, as an alternative to (a) informal scraping of the Municipality's public website and (b) formal FOIL requests. The Program does not replace, restrict, or condition free public access to the Municipality's website by human users, and does not replace, restrict, or condition the public's right to submit FOIL requests under Public Officers Law §§ 86–89 S-011, S-202.
(c) Scope. The Program applies to public data that the Municipality has already published or has determined to publish through the Program's API. The Program does not create any new obligation to publish data that is not already public, and does not remove any data from the Municipality's free public website.
(d) Data Inventory Prerequisite. No fee shall be charged under this Program until the Program Administrator has completed a data inventory of the Municipality's public datasets, classified each dataset as public, restricted-public, or non-public (consistent with the DCAT-US accessLevel field S-304), and published a data catalog with metadata meeting the minimum fields specified in § A-9. This prerequisite ensures that the Program charges for clean, structured, well-documented data — not for messy, unstructured web pages — consistent with the W3C Data on the Web Best Practices S-301 and the phased implementation roadmap recommended in the underlying research.
(e) Free Public Access Preserved. The Municipality shall continue to publish all data available through the Program's API on its free public website in a human-readable form, and shall continue to accept and process FOIL requests for all records subject to FOIL at the statutory fee rates set forth in Public Officers Law § 87(1)(b)(iii) (not to exceed $0.25 per page for paper copies up to 9 × 14 inches) and § 87(1)(c) (actual cost of reproduction for electronic records, excluding search time and administrative costs) S-011, S-202. No person shall be required to use the Program or to pay any Program fee in order to obtain public records.
Commentary: This section creates the program and names who runs it. The critical legal design choices here are: (1) the program is voluntary and alternative, not mandatory — no one is forced to use it; (2) free public website access and free FOIL access both continue unchanged; and (3) fees can only be charged once the data is actually clean and structured, so the municipality is charging for a real service (structured API delivery), not for clicking on a web page.
§ A-6. Access Tiers
The Program shall offer the following access tiers. Tier assignment shall be based on the Requester's declared and verified purpose, consistent with the differential fee structure of federal FOIA S-001, S-201 and the discretionary exemption model of PACER S-204, S-205.
(a) Free Tier — Resident, News Media, Academic, and Public-Interest Requesters.
- Resident Requesters, News Media Requesters, Academic or Research Requesters, and Public-Interest Requesters shall receive API access at no charge, subject to the rate limits and quotas specified in the Fee Schedule (§ A-7) and the Technical Standards (§ A-8).
- “Free” means $0.00 in Program fees. It does not mean the Requester is exempt from the Program's registration, API key, acceptable use, or rate-limit requirements. All Requesters using the API must register and receive an API key, consistent with the US Census Bureau's free-key model S-108.
- The Municipality shall not condition Free Tier access on any payment, subscription, or fee waiver application for these categories. Verification of category (e.g., proof of residency, press credentials, academic affiliation) may be required but shall not be structured so as to deter or delay access.
(b) Always-Free Content. The following categories of data shall be available at no charge to all Requesters (including Commercial Requesters) within the Free Tier rate limits, regardless of requester category, analogous to PACER's always-free court opinions S-204:
- Meeting agendas and minutes;
- Public notices and legal notices;
- Budgets and annual financial reports;
- Press releases;
- The data catalog itself (metadata); and
- Any dataset that federal FOIA requires be made available “without charge, license, or registration requirement” in bulk downloadable form, 5 U.S.C. § 552(e)(3)(A) S-001, to the extent a NY municipality is voluntarily aligning with that federal standard.
(c) Paid Tier — Commercial Requesters.
- Commercial Requesters shall pay the fees set forth in the Fee Schedule (§ A-7) for API access exceeding the Free Tier rate limits.
- A Commercial Requester that wishes to access Always-Free Content (§ A-6(b)) at a volume exceeding the Free Tier rate limits must register for the Paid Tier and pay the applicable subscription or metered fee for that volume.
(d) Bulk Data Tier. The Program Administrator may offer bulk data downloads (complete dataset files) to any Requester, priced pursuant to § A-7. Bulk data shall be offered in a machine-readable format (CSV, JSON, XML, or GeoJSON) consistent with W3C Best Practice 17 (“Provide bulk download”) S-301 and the DCAT-US downloadURL field S-304.
(e) Human Website Access Not Affected. No tier, fee, registration, or rate limit established by this Program shall apply to a human being accessing the Municipality's public website through a standard web browser for personal reading, consistent with the FOIL public-access floor S-011 and the First Amendment presumption of public access to government information S-001.
Whether differential pricing that charges Commercial Requesters while providing free access to other categories survives rational-basis review in the municipal context is untested. Federal FOIA's three-tier structure has never been successfully challenged S-001, S-201. Counsel should confirm tier definitions are rationally related to cost recovery and public-access protection and do not discriminate based on speech content.
Commentary: This section sets up the tiers — who pays and who does not. The design mirrors federal FOIA, which has charged commercial users more than news and academic users for decades without being successfully challenged S-001. The “Always-Free Content” list makes clear that core democratic records are never paywalled within free-tier limits. The most important line is (e): a human reading the website in a browser is never charged.
§ A-7. Fee Schedule (Cost-Recovery)
(a) Cost-Recovery Standard. All fees established under this Program shall be limited to the actual, documented cost of providing automated access through the API, consistent with the cost-recovery standards of:
- NY FOIL, Public Officers Law § 87(1)(c), which defines “actual cost of reproduction” for electronic records as including only (i) the hourly salary of the lowest-paid employee with necessary skill, (ii) the actual cost of storage media, and (iii) the actual cost of outside professional services, and which excludes search time and administrative costs S-011, S-202;
- Federal FOIA, 5 U.S.C. § 552(a)(4)(A)(iv), which limits fees to “the direct costs of search, duplication, or review” S-001, S-201;
- The federal PACER system, whose fees are set to “reimburse the costs” of the electronic access system S-205, S-210; and
- The E-Government Act of 2002, which requires that electronic access fees be “reasonably necessary” to reimburse system costs S-016, as construed in National Veterans Legal Services Program v. United States S-009, S-010.
(b) Cost Components. The Program Administrator shall, before setting any fee, document the following actual cost components of providing automated API access:
- Infrastructure costs: API gateway, CDN, WAF, bot management, and hosting costs attributable to the Program (e.g., AWS API Gateway at $1.00/million HTTP requests or $3.50/million REST requests S-121; Cloudflare Pro at $20–25/month S-110; AWS WAF Bot Control at $10/month + per-request fees S-115; Kong Gateway OSS at no software cost but with hosting cost S-106);
- Bandwidth costs: Data transfer costs attributable to API traffic (e.g., AWS data transfer out at approximately $0.09/GB S-121);
- Staff time for Program administration: Account management, billing, user verification, rate-limit configuration, and incident response, calculated at the hourly salary of the lowest-paid employee with the necessary skill, consistent with the FOIL “actual cost” standard S-202;
- Logging and audit infrastructure: Costs of maintaining request logs, audit trails, and usage reports S-106, S-120; and
- Outside professional services: Any outside vendor cost for setup, maintenance, or security assessment, to the extent the Municipality's own IT resources are inadequate, consistent with the FOIL “actual cost” standard S-202.
(c) Fee Schedule. The Program Administrator shall set and publish a fee schedule that recovers no more than the documented actual cost under § A-7(b). The following schedule is a model; the Program Administrator shall adjust the dollar amounts based on the Municipality's documented costs and shall publish the cost analysis supporting each fee:
| Tier | Subscription Fee | Rate Limit | Monthly Quota | Per-Request Fee (beyond quota) |
|---|---|---|---|---|
| Free (Resident, News, Academic, Public-Interest) | $0 | 10 requests/sec | 10,000 requests/month | N/A (Free Tier capped at quota) |
| Commercial — Small | $50/month | 100 requests/sec | 1,000,000 requests/month | $0.005/request |
| Commercial — Standard | $250/month | 500 requests/sec | 10,000,000 requests/month | $0.005/request |
| Commercial — Enterprise | Negotiated annual license | Custom | Custom | Per agreement |
| Bulk Data (any Requester) | Per-dataset, at actual cost of preparation + storage media | N/A | N/A | N/A |
- The per-request fee of $0.005 is a placeholder calibrated below PACER's $0.10/page S-204, S-205 on the rationale that a single API request returns a structured record, not a scanned page, and the marginal cost of serving an API request is lower than PACER's per-page cost. The Program Administrator shall replace this figure with the Municipality's actual per-request cost, documented pursuant to § A-7(b).
- The Commercial subscription fees ($50/month, $250/month) are placeholders calibrated to cover the documented infrastructure and administrative cost of serving a commercial-tier Requester, and shall be adjusted to actual cost. The economic research estimated that a small/medium NY municipality should expect $500–$75,000/year in gross revenue from such a program, with net revenue likely $0–$40,000/year after program costs — enough to fund infrastructure, not to balance a budget.
- Bulk Data pricing shall not exceed the actual cost of preparing the bulk file (staff time at the lowest-paid-employee rate, consistent with FOIL S-202) plus the actual cost of storage media if physical media is provided. If the bulk file is delivered electronically, the fee shall not exceed the actual cost of electronic transmission and storage.
(d) Fee Limitations.
- No fee shall be charged to any Requester if the cost of processing the payment equals or exceeds the fee, consistent with federal FOIA, 5 U.S.C. § 552(a)(4)(A)(iv)(I) S-001, S-201.
- No advance payment shall be required unless the estimated fee exceeds $250 or the Requester has previously failed to pay, consistent with federal FOIA, 5 U.S.C. § 552(a)(4)(A)(v) S-001, S-201.
- The first 10,000 API requests per month shall be free for all Requesters, including Commercial Requesters, analogous to PACER's $30/quarter waiver (under which 75% of PACER users pay nothing) S-204, S-205 and federal FOIA's first-100-pages-free provision S-001, S-201.
- Fees shall be reviewed annually and adjusted to reflect actual costs. Any fee reduction or increase shall be published with an updated cost analysis.
(e) Revenue Dedication. All revenue collected under this Program shall be deposited in a dedicated fund to be known as the “[MUNICIPALITY] Data Access and Civic Technology Fund,” and shall be used solely for:
- The costs of operating and maintaining the Program (infrastructure, staff, logging, audit);
- Improvements to the Municipality's public website performance and accessibility;
- Expansion of the Municipality's open data catalog and machine-readable data publication; and
- Tools and systems that improve FOIL response efficiency.
Revenue shall not be transferred to the general fund or used for purposes unrelated to the Program or civic technology, consistent with the lesson of National Veterans Legal Services Program v. United States, where PACER fees were found unlawful because revenue was diverted to costs unrelated to the electronic access system S-009, S-010, S-016.
Whether the FOIL “actual cost of reproduction” standard S-202 applies to a voluntary API program (as opposed to a FOIL request) is open. This Local Law takes the conservative position that the cost-recovery ceiling applies by analogy. If counsel concludes FOIL does not apply to the voluntary API, Version B may be considered. Either way, fees must be tied to documented cost to survive a PACER-style challenge S-009, S-010.
Commentary: This is the most legally sensitive section. Every dollar figure must be backed by a real cost calculation. The research found that PACER was sued and forced to refund $100 million because its fees exceeded cost and revenue was diverted S-009, S-010. This section prevents that by requiring documented cost, dedicating revenue, and building in a free allowance so low-volume users never pay.
§ A-8. Technical Standards
(a) Registration and API Keys.
- Every Requester using the Program's API shall register and receive an API Key before making requests, consistent with the US Census Bureau API model S-108.
- Registration shall require: the Requester's name and contact information; the Requester's category (Resident, News Media, Academic, Public-Interest, or Commercial); a declared purpose; and, for Commercial Requesters, the business entity name and a description of the commercial use.
- Registration shall be through a click-through or click-to-accept agreement (not a passive browsewrap), in which the Requester affirmatively accepts the TOS. Click-through acceptance provides a stronger contractual basis than passive posting, consistent with the distinction between “clickwrap” and “browsewrap” agreements recognized in Facebook, Inc. v. Power Ventures and related case law S-007.
- The Program Administrator may revoke or suspend an API Key for violation of the TOS, exceeding rate limits after notice, or misrepresentation of requester category, pursuant to § A-11.
(b) Rate Limits and Quotas.
- The Program Administrator shall enforce Rate Limits and Quotas per tier as specified in the Fee Schedule (§ A-7), using an API gateway (e.g., Kong S-106, S-120, AWS API Gateway S-121, or equivalent).
- The API gateway shall return HTTP 429 “Too Many Requests” with
RateLimit-Limit,RateLimit-Remaining, andRateLimit-Resetheaders when a Rate Limit is exceeded, consistent with Kong's Rate Limiting plugin behavior S-120. - Rate Limits shall be enforced by API Key (authenticated consumer) where the Requester is authenticated, and by IP address where the Requester is unauthenticated, consistent with Kong's key-auth and IP-based limiting modes S-106, S-120, S-114.
(c) robots.txt. The Municipality shall maintain a robots.txt file at the root of its public website, consistent with RFC 9309 S-101. The Municipality acknowledges that robots.txt is advisory only and “not a form of access authorization” S-101, and shall not rely on robots.txt as the sole enforcement mechanism for the Program. Enforcement shall be primarily technical (API gateway, rate limiting, WAF rules), consistent with the lesson of Facebook v. Power Ventures that technical access controls provide stronger enforcement grounds than passive TOS posting S-007.
(d) Bot Management. The Municipality shall implement bot management infrastructure (e.g., Cloudflare Bot Fight Mode S-103, S-110, AWS WAF Bot Control S-104, S-115, or equivalent) to identify automated traffic, challenge suspicious requests, and protect the origin server from overload. Bot detection is probabilistic and produces false positives and false negatives S-122; the Program Administrator shall configure bot management conservatively to avoid blocking legitimate human users, including accessibility tools and search engine crawlers, which shall be whitelisted as “Verified bots” where the platform supports it S-122.
(e) Acceptable Use (TOS). The TOS shall prohibit, at minimum:
- Accessing the API without a valid API Key;
- Exceeding assigned Rate Limits or Quotas;
- Circumventing technical access controls (API Key validation, IP-based blocks, WAF rules), which may constitute a violation of the Computer Fraud and Abuse Act, 18 U.S.C. § 1030, as construed in Van Buren v. United States (accessing off-limits files or circumventing affirmative technical barriers) S-006, S-014 and Facebook v. Power Ventures (circumventing IP blocks after notice) S-007;
- Reselling or redistributing API access credentials;
- Using the API to attempt to access non-public data or data outside the Requester's authorized scope;
- Using the data in violation of applicable privacy law, including the Driver's Privacy Protection Act, 18 U.S.C. § 2721 S-203, FERPA, 20 U.S.C. § 1232g S-310, and HIPAA; and
- Any use that violates applicable federal, state, or local law.
(f) Logging and Audit. The Program Administrator shall log every API request with, at minimum: timestamp, client IP, API Key / consumer ID, endpoint, response status, response size, and rate-limit headers, consistent with Kong logging capabilities S-106 and AWS WAF logging S-115. Logs shall be retained for a minimum of [ONE (1) YEAR] and shall be available for audit pursuant to § A-13.
(g) Service Availability. The Program is offered on a best-effort basis. The Municipality does not guarantee uninterrupted API availability and shall not be liable for damages resulting from API downtime, except to the extent required by law. The Municipality shall publish an API status page and shall use reasonable efforts to provide advance notice of scheduled maintenance.
Whether a municipal website's TOS is enforceable against a scraper of public government data is unresolved S-003, S-004, S-007. Technical enforcement (API keys, rate limits, WAF) provides the primary enforcement; the TOS provides the contractual and notice basis. The CFAA may apply to circumvention of technical controls on a government computer S-014, but after Van Buren covers only accessing off-limits files S-006. Counsel should confirm the enforcement strategy with IT and, if a scraper circumvents technical controls after notice, consult the DA or US Attorney regarding CFAA referral.
Commentary: This section turns legal rules into technical requirements. Key choices: (1) require click-through registration, not passive TOS, because click-through is more likely enforceable; (2) enforce primarily through technology (API keys, rate limits, WAF), not lawsuits, because case law says technical controls are stronger S-007; (3) log everything for audit; and (4) whitelist search engines and accessibility tools so bot management doesn't break Google or screen readers.
§ A-9. Data Standards
(a) Machine-Readable Formats. All data served through the Program's API shall be published in a machine-readable format, consistent with W3C Best Practice 12 (“Use machine-readable standardized data formats”) S-301. Acceptable formats include:
- CSV for tabular data (budgets, permit lists, assessment rolls) S-301;
- JSON for nested or relational data and for API responses S-301, S-304;
- XML for integration with legacy government systems S-304; and
- GeoJSON for geographic data (parcels, roads, zoning districts) S-304.
PDF shall not be used as the primary format for any data served through the API, consistent with the W3C's distinction between formats “that can be read and edited by humans” and formats that are “machine-readable” S-301.
(b) Metadata. Every dataset served through the Program shall be described by metadata meeting, at minimum, the required fields of the DCAT-US (Project Open Data) schema v1.1 S-304:
title— human-readable dataset name;description— what the data is;publisher— the Municipality;contactPoint— name and email of the data steward;modified— last-modified date in ISO 8601 format (YYYY-MM-DD) S-309;identifier— unique, stable dataset identifier;accessLevel—public,restricted public, ornon-publicS-304;license— the terms of use for the data;accrualPeriodicity— update frequency in ISO 8601 repeating duration (e.g.,R/P1Dfor daily,R/P1Yfor annual) S-304; anddistribution— the files or API endpoints through which the data is available, withaccessURL,downloadURL,format, andmediaTypeS-304.
The Municipality may adopt the full DCAT-US schema or the W3C DCAT v3 vocabulary S-302 as its metadata standard. The Municipality shall embed schema.org Dataset JSON-LD markup on dataset landing pages to enable discovery via search engines, consistent with schema.org's Dataset type S-303.
(c) Data Schema and Field Standards.
- Dates shall be expressed in ISO 8601 format (
YYYY-MM-DDfor dates;YYYY-MM-DDThh:mm:ssZfor date-times) S-309, consistent with W3C Best Practice 13 (“Use locale-neutral data representations”) S-301 and the DCAT-USmodifiedandtemporalfield requirements S-304. - Currency shall be stored as raw decimal numbers with no currency symbol, no thousands separators, and no text (e.g.,
1234.56, not$1,234.56), consistent with the W3C locale-neutral example S-301. A separatecurrencyfield with an ISO 4217 code (e.g.,USD) may be included. - Addresses shall be split into components (
street_number,street_name,unit,city,state,zip), not stored as a single combined string. - Field names shall use a consistent naming convention (e.g.,
snake_case), documented in the dataset's data dictionary, linked via the DCAT-USdescribedByfield S-304. - Controlled vocabularies shall be used for categorical fields (e.g., permit type, department code, status), consistent with W3C Best Practice 15 S-301.
(d) Update Cadence. Each dataset's update frequency shall be published in its metadata (accrualPeriodicity) S-304 and shall be met. The modified date shall be updated each time the dataset changes. Stale data destroys the value of the API and the justification for any fee S-301.
(e) Data Catalog. The Municipality shall publish a machine-readable data catalog (a data.json file consistent with DCAT-US S-304, or a CKAN catalog S-306, or a Socrata catalog as used by data.ny.gov S-308 and NYC Open Data S-208) listing all datasets available through the Program. The catalog shall be the public face of the Program and shall be accessible without registration.
(f) API Documentation. The Program Administrator shall publish complete API documentation, including: available endpoints, request parameters, response formats, sample responses, authentication requirements, and rate limits, consistent with W3C Best Practice 25 (“Provide complete documentation for your API”) S-301. The US Census API User Guide S-108 is a model of clear government API documentation.
(g) Bulk Download. The Municipality shall offer bulk download of complete datasets in machine-readable format, consistent with W3C Best Practice 17 (“Provide bulk download”) S-301 and the DCAT-US downloadURL field S-304. Bulk download is the FOIL-friendly alternative: a Requester who wants a complete dataset can download it directly rather than filing a FOIL request or running a high-volume crawler.
Commentary: This section is what makes the program worth paying for. If the data is messy PDFs, no commercial user will pay for API access. If it is clean CSV/JSON with stable field names, ISO 8601 dates, published update cadence, and a documented schema, the API saves a commercial user the expensive labor of scraping and cleaning — and that saved labor is the value the fee recovers S-301, S-304.
§ A-10. Exemptions and Privacy
(a) FOIL Exemptions Preserved. No data that is exempt from disclosure under Public Officers Law § 87(2) shall be made available through the Program S-011, S-202. This includes, without limitation:
- Records that would endanger the life or safety of any person (§ 87(2)(a)) S-011;
- Records that would constitute an unwarranted invasion of personal privacy (§ 87(2)(b)) S-011; and
- Records specifically exempted by other federal or state law S-011.
(b) Personally Identifiable Information. The Program shall not serve PII through the API. PII shall be redacted at the field level before publication, consistent with the W3C warning that “combining data from multiple sources may allow inadvertent identification of individuals” S-301. Common redactions include:
- Removal of Social Security numbers, driver's license numbers, bank account numbers, and medical record numbers from all datasets;
- Replacement of personal names with roles where the individual's identity is not the public interest;
- Truncation or removal of residential addresses for records where the address is a person's home (not a business); and
- Testing for re-identification risk (the “mosaic effect”) before publication, recognizing that a dataset removing names but retaining ZIP code + birth date + gender can re-identify approximately 87% of the US population S-301.
(c) DPPA Compliance. No motor vehicle record containing personal information regulated by the Driver's Privacy Protection Act, 18 U.S.C. § 2721, shall be made available through the Program except for a permissible use enumerated in § 2721(b) and subject to the resale/redisclosure recordkeeping requirements of § 2721(c) S-203. The Program's TOS shall require Commercial Requesters receiving any DPPA-permissible data to maintain the 5-year recipient audit trail required by § 2721(c) S-203.
(d) FERPA Compliance. No student education record protected by the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, shall be made available through the Program without parent or eligible-student consent, except as permitted by FERPA's exceptions S-310. Directory information (name, address, dates of attendance) may be published only if the school district has given the public notice required by 34 C.F.R. § 99.37, and the Program Administrator shall consult the school district's FERPA policy before publishing any directory information, recognizing that combining directory information with other data can re-create a protected education record S-310.
(e) HIPAA Compliance. No individually identifiable health information protected by HIPAA (45 C.F.R. Parts 160 and 164) shall be made available through the Program. Even where the Municipality is not a HIPAA covered entity, health information shall be treated as exempt under FOIL § 87(2)(b) (personal privacy) S-011. (NOTE: The HIPAA Privacy Rule regulatory text was not independently fetched in the underlying research; the general principle — do not publish identifiable health information — is well-established and reinforced by the W3C privacy guidance S-301. Specific HIPAA compliance questions should be reviewed by counsel.)
(f) Data Classification Before Publication. No dataset shall be published through the Program until it has been classified as public (not restricted public or non-public) using the DCAT-US accessLevel field S-304, and the classification has been reviewed by the municipal attorney or clerk. When in doubt, a dataset shall be marked restricted public and withheld pending legal review, consistent with the principle that it is easier to add a dataset later than to recall one that exposed private information S-301.
(g) Records Not Encrypted. Any electronic record provided through the Program shall not be encrypted, consistent with Public Officers Law § 87(5)(a), which prohibits agencies from providing records in encrypted computer format S-011, S-202. (API access is not “encryption” of the data; the data itself shall be provided in a readable format.)
Commentary: Privacy is the biggest liability risk. Publishing the wrong field can violate FOIL, DPPA, FERPA, or HIPAA. This section requires a classification step before publication, mirrors the DCAT-US three-level access classification S-304, and bars the most sensitive categories outright. The “when in doubt, withhold” rule is the safe default.
§ A-11. Enforcement
(a) Technical Enforcement. The primary enforcement mechanism for this Program shall be technical, not legal, consistent with the lesson of Facebook v. Power Ventures that affirmative technical barriers (IP blocks, API key revocation, WAF rules) provide stronger enforcement grounds than passive TOS posting S-007. Technical enforcement measures shall include:
- Rate-limit enforcement: Excess requests are rejected (HTTP 429) S-120;
- API Key revocation: A Requester that violates the TOS may have its API Key suspended or revoked, cutting off access S-106;
- IP-based blocking: A client that circumvents API Key requirements or repeatedly violates rate limits may be blocked at the IP level by the WAF or API gateway S-114, S-115;
- Bot management challenges: Suspicious automated traffic may be challenged (CAPTCHA, JavaScript challenge) by the bot management layer S-103, S-116; and
- Honeypot detection: Hidden URLs that no human would request but a crawler would may be used to identify and block non-registered bots.
(b) TOS Enforcement. A Requester that violates the TOS (§ A-8(e)) is subject to:
- Written notice of the violation and an opportunity to cure within [TEN (10) BUSINESS DAYS];
- Suspension of the API Key for a defined period if the violation is not cured;
- Revocation of the API Key for repeated or serious violations;
- Billing for unauthorized usage at the Commercial Tier rate, if a Requester misrepresents its category to obtain Free Tier access;
- Termination of any bulk data license; and
- Referral to law enforcement if the violation involves circumvention of technical access controls (which may implicate the CFAA, 18 U.S.C. § 1030 S-014, as construed in Van Buren S-006 and Power Ventures S-007) or violation of privacy law (DPPA S-203, FERPA S-310, HIPAA).
(c) Unregistered Scraping. A bot that accesses the Municipality's public website without registering for the Program is not, by that act alone, violating this Local Law — the public website remains open to all, and FOIL rights are preserved S-011. However:
- Unregistered automated traffic is subject to the Municipality's bot management and rate-limiting infrastructure (§ A-8(c), (d)), which may challenge, throttle, or block it to protect server capacity for human users;
- A bot that circumvents affirmative technical access controls (API Key validation, IP blocks, WAF rules) after notice may be subject to CFAA referral S-006, S-007, S-014; and
- The Municipality may publish a robots.txt file advising crawlers of preferred access paths S-101, but acknowledges that robots.txt is advisory only and not a form of access authorization S-101.
(d) No Liability for Good-Faith Technical Enforcement. The Municipality and its officials shall not be liable for good-faith technical enforcement actions (rate limiting, IP blocking, bot challenges) that inadvertently block or delay a legitimate user, including false positives from bot detection, recognizing that bot detection is probabilistic and produces false positives and false negatives S-122. The Program Administrator shall provide a dispute resolution process for users who believe they were incorrectly blocked.
Whether municipal TOS are enforceable against scrapers, and whether the CFAA applies to circumvention of technical controls on a municipal website, are unresolved S-003, S-004, S-006, S-007, S-014. No court has ruled on TOS enforcement against scrapers of government websites. Enforcement should be primarily technical; legal enforcement reserved for clear circumvention of affirmative technical barriers after notice, on the Power Ventures model S-007.
Commentary: Enforcement is mostly technical (the software blocks you), not legal (the municipality sues you). This is deliberate: case law says technical controls are enforceable, passive TOS are not S-007. Lawsuits and CFAA referrals are reserved for serious cases where a scraper circumvented actual technical barriers after being told to stop.
§ A-12. Appeals and FOIL Preservation
(a) FOIL Rights Fully Preserved. Nothing in this Local Law shall be construed to:
- Replace, limit, restrict, or condition any person's right to submit a FOIL request pursuant to Public Officers Law §§ 86–89 S-011, S-202;
- Authorize the Municipality to charge more than FOIL permits for records obtained through the FOIL process (i.e., not more than $0.25 per page for paper copies up to 9 × 14 inches under § 87(1)(b)(iii), and not more than the actual cost of reproduction for electronic records under § 87(1)(c), excluding search time and administrative costs) S-011, S-202;
- Require any person to use the Program or to pay any Program fee in order to obtain public records;
- Refuse a FOIL request on the basis that the requester is an automated system or bot — FOIL applies to “any person” S-011; or
- Eliminate or reduce free public access to the Municipality's website by human users through a standard web browser.
(b) FOIL Is an Alternative, Not a Replacement. The Program is a voluntary, alternative, premium channel for structured automated access. A Requester who does not wish to pay Program fees may, at any time, submit a FOIL request for the same records and receive them at the statutory FOIL fee rates S-011, S-202. The Municipality shall process all FOIL requests under the FOIL statute, not under this Program.
(c) Program Appeals. A Requester whose API Key is suspended or revoked, whose tier classification is disputed, or who is otherwise aggrieved by a decision of the Program Administrator may appeal to the [Governing Body or designated appeals officer] within [THIRTY (30) DAYS] of the decision. The appeal shall be decided within [THIRTY (30) DAYS] of receipt. This appeal process is separate from and does not affect the Requester's FOIL appeal rights under Public Officers Law § 89(1)(a) S-011.
(d) No FOIL Fee for FOIL Requests Fulfilled Through the API. If a Requester submits a formal FOIL request and the Municipality chooses to fulfill it by providing API access to the requested records, the Municipality may not charge Program fees for that fulfillment — the FOIL fee caps apply S-011, S-202.
The finding that the Program does not replace FOIL is the legal cornerstone. If a court finds the Program effectively replaces FOIL (e.g., by making FOIL so difficult that the paid API is the only practical channel), the Program could be struck down as conflicting with FOIL S-011. The Municipality must ensure FOIL remains a real, usable, free alternative. The Program's economic value depends on the convenience premium — Requesters pay because the API is more convenient than FOIL, not because FOIL is unavailable S-202.
Commentary: This is the single most important section for legal survival. If a court finds the program effectively replaces FOIL, the whole law falls. The section says, in five ways, that FOIL is untouched: you can still file FOIL requests, FOIL fees apply, no one is required to use the program, and the municipality cannot refuse a FOIL request because the requester is a bot.
§ A-13. Reporting and Transparency
(a) Annual Report. The Program Administrator shall publish an annual report, not later than [MARCH 1] of each year, covering the prior calendar year. The report shall include:
- Revenue: Total fees collected, broken down by tier;
- Costs: Total Program costs, broken down by category (infrastructure, bandwidth, staff, logging, outside services), consistent with the cost components of § A-7(b);
- Net revenue or deficit: Revenue minus costs;
- Usage: Number of registered Requesters by category; total API requests by tier; top datasets by request volume; bulk data downloads;
- Fund balance: Balance of the Data Access and Civic Technology Fund (§ A-7(e)) and expenditures from it;
- Cost-to-fee analysis: A comparison of documented actual cost to fees charged, demonstrating that fees do not exceed cost (for Version A) or documenting the surplus and its dedicated use (for Version B);
- FOIL impact: Number of FOIL requests received during the year, and an assessment of whether the Program has increased, decreased, or not affected FOIL request volume — the “cost-shift” risk identified in the economic research;
- Privacy incidents: Any incident in which exempt or PII data was inadvertently served through the API, the response, and corrective action;
- Enforcement actions: Number of API Key suspensions, revocations, IP blocks, and any CFAA or law enforcement referrals;
- Data catalog status: Number of datasets published, number classified as public/restricted/non-public, and any datasets added or removed during the year; and
- Bot traffic analysis: Summary of bot traffic to the Municipality's website (volume, percentage of total traffic, top bot categories), consistent with Cloudflare or AWS WAF analytics S-122, S-115.
(b) Public Availability. The annual report shall be published on the Municipality's website in a machine-readable format (consistent with § A-9) and shall be submitted to the [Governing Body]. The report itself shall be a FOIL-releasable record S-011.
(c) Independent Audit. The Municipality shall commission an independent audit of the Program's cost-to-fee analysis not less than once every [THREE (3) YEARS], to verify that fees do not exceed documented cost (Version A) or that surplus is properly dedicated (Version B). The audit shall be published with the annual report.
(d) COOG Consultation. The Program Administrator shall, not less than once every [THREE (3) YEARS], consult with the NY Committee on Open Government (COOG) S-015, S-206 regarding the Program's consistency with FOIL and shall publish any COOG advisory opinion received.
Commentary: Transparency is what prevents the PACER problem. PACER was sued because fees exceeded cost and surplus was diverted S-009, S-010. This section requires an annual public report, independent audit every three years, and periodic COOG consultation. If fees are tied to cost and the accounting is public, the program is defensible.
§ A-14. Severability
If any clause, sentence, paragraph, section, or provision of this Local Law is adjudged by any court of competent jurisdiction to be invalid, such judgment shall not affect, impair, or invalidate the remainder thereof, but shall be confined in its operation to the clause, sentence, paragraph, section, or provision directly involved in the controversy in which such judgment shall have been rendered.
Commentary: Standard NY local law severability clause. If a court strikes down one part (e.g., the fee for a specific tier), the rest of the law survives.
§ A-15. Effective Date
This Local Law shall take effect [SIXTY (60) DAYS] after filing with the New York Secretary of State pursuant to Municipal Home Rule Law § 27 S-012, except that no fee shall be charged under § A-7 until the Program Administrator has (a) completed the data inventory required by § A-5(d), (b) published the cost analysis required by § A-7(b), and (c) published the fee schedule required by § A-7(c).
Commentary: NY local laws take effect after filing with the Secretary of State. This law adds a gate: no fees until the data is inventoried, costs documented, and fee schedule published — preventing the municipality from charging before the program is ready.
Version B — Revenue Model Local Law
Version B is identical to Version A except as modified below. Sections not reproduced here are unchanged from Version A. Modified sections are marked [MODIFIED — VERSION B].
Version B sets fees above pure cost recovery. This carries higher legal risk because the FOIL “actual cost” standard S-011, S-202, federal FOIA “direct costs” cap S-001, S-201, and PACER “reasonably necessary” standard S-009, S-016 all point toward a cost-recovery ceiling, and the PACER litigation established that diverted surplus is unlawful S-009, S-010. Version B relies on the theory that the Program is not a FOIL request-response process and therefore FOIL fee caps do not apply; instead, the Municipality exercises home rule authority to sell a premium voluntary service. This theory is plausible but untested. Municipal counsel must complete the Legal Review Checklist before adopting Version B.
When to choose which version
| Criterion | Version A — Cost-Recovery | Version B — Revenue Model |
|---|---|---|
| Legal risk | Lower — fits within existing FOIL fee framework S-011, S-202 and federal cost-recovery precedent. | Higher — relies on broader home-rule argument S-002, S-012; FOIL fee-cap applicability is open. |
| Fee ceiling | Documented actual cost only. | Actual cost plus a margin of up to 50% to fund civic technology. |
| Revenue use | Dedicated to Program costs and civic-tech improvements. | Same dedication, broader civic-tech purposes (digital accessibility, broadband, digital equity). |
| Commercial subscription (Small) | $50/month | $100/month |
| Commercial subscription (Standard) | $250/month | $500/month |
| Per-request fee (Commercial) | $0.005/request | $0.01/request |
| If counsel is uncertain | Adopt this version. | Do not adopt. Adopt Version A instead. |
Commentary: The safest path is Version A. Version B doubles the commercial fees and adds a margin above cost, betting that courts will treat the premium API as a voluntary user fee, not a FOIL copy fee. The risk is that a court disagrees and applies the FOIL cost ceiling. The safeguards — revenue dedication, transparency, audit, COOG consultation — are designed to make the program defensible. But this is genuinely uncertain law.
Switch to the “Version B — Modified Sections” tab to read the three sections that differ from Version A: § B-2 (Legislative Findings), § B-7 (Fee Schedule), and § B-13 (Reporting and Transparency). All other sections (Title, Definitions, Authority, Program Establishment, Access Tiers, Technical Standards, Data Standards, Exemptions and Privacy, Enforcement, Appeals and FOIL Preservation, Severability, and Effective Date) are identical to Version A.
Legal Review Checklist
Before adopting either version of this Local Law, the municipality's attorney must answer the following questions. These are drawn from the “Open Legal Questions” section of the legal landscape research and from the “Legal Review Required” flags throughout this document. A “No” or “Uncertain” answer on a critical question means the ordinance should not be adopted until the question is resolved.
Critical Questions (Must Answer Before Adoption)
1. Does a bot crawling a public municipal website constitute a “FOIL request”?
- Status: No NY court has ruled. Statutory text suggests no S-011.
- Action: Seek a COOG advisory opinion S-015, S-206. If COOG opines that bot crawling is a FOIL request, fees must comply with FOIL caps and Version B is not viable.
- ☐ Resolved ☐ Unresolved
2. Does FOIL preempt a municipal automated-access fee program?
- Status: Likely no (Program supplements FOIL), but untested S-011.
- Action: Seek a COOG advisory opinion. Confirm FOIL is preserved in practice.
- ☐ Resolved ☐ Unresolved
3. Can a municipality legally enforce website TOS against scrapers?
- Status: No court has ruled. Technical enforcement is stronger than legal S-003, S-004, S-007.
- Action: Confirm enforcement is primarily technical. Reserve legal enforcement for circumvention of technical barriers after notice S-006, S-007, S-014.
- ☐ Resolved ☐ Unresolved
4. Does First Amendment public-forum doctrine apply to municipal website access?
- Status: No court has characterized a municipal website as a public forum S-001.
- Action: Confirm tiers are based on requester category, not speech content, and are rationally related to cost recovery S-001, S-201.
- ☐ Resolved ☐ Unresolved
5. Have the exact statutory texts of POL §§ 86–89, MHRL § 10, and the Statute of Local Governments been verified?
- Status: Could not be fetched from primary sources S-011, S-012, S-013.
- Action: Verify every citation against official McKinney's before introduction.
- ☐ Resolved ☐ Unresolved
6. (Version B only) Does the Municipality have authority to charge above cost?
- Status: FOIL, FOIA, and PACER standards point toward cost recovery S-001, S-009, S-011, S-016, S-201, S-202. Version B's theory is plausible but untested.
- Action: Obtain a written legal opinion. If uncertain, adopt Version A.
- ☐ Resolved ☐ Unresolved ☐ N/A (adopting Version A)
7. (Version B only) Is revenue dedication to civic technology sufficiently “related to the system”?
- Status: PACER court found diversion unlawful S-009, S-010, S-016. Version B's dedication is broader but related.
- Action: Confirm each surplus expenditure category is defensibly related to the Program or digital government services.
- ☐ Resolved ☐ Unresolved ☐ N/A (adopting Version A)
Important Questions (Should Answer Before Adoption)
8. What specific COOG advisory opinions address electronic records, bulk data, and automated requests?
- Status: The COOG database requires interactive search; specific opinion numbers were not retrieved S-015, S-206.
- Action: Search the COOG advisory opinion database at dos.ny.gov/coog for opinions on (a) electronic records fees, (b) bulk data access, (c) automated requests, and (d) whether passive website access is distinct from FOIL requests. Cite any relevant opinions in the legislative findings.
- ☐ Resolved ☐ Unresolved
9. Have any NY municipalities attempted paid automated-access programs, and were they legally challenged?
- Status: No specific examples were found in the research S-008.
- Action: Research whether any NY municipality (or any US municipality) has enacted a similar program and whether it was challenged. Contact the NY Conference of Mayors, the Association of Towns, and the NY Committee on Open Government.
- ☐ Resolved ☐ Unresolved
10. Can a municipal robots.txt be cited as legally binding terms of access?
- Status: Untested. RFC 9309 states robots.txt rules “are not a form of access authorization” S-101.
- Action: Do not rely on robots.txt as a legal enforcement mechanism. Use it as advisory guidance only. Enforcement is technical (§ A-8, § A-11).
- ☐ Resolved ☐ Unresolved
11. What is the rational-basis standard for differential commercial vs. nonprofit fees in the municipal context?
- Status: Federal FOIA's tiered structure has not been challenged on equal-protection grounds S-001, S-201, but no court has applied the analysis to a municipal program.
- Action: Confirm that the tier definitions are rationally related to cost recovery and public-access protection (legitimate government interests) and do not discriminate based on the content of the requester's speech.
- ☐ Resolved ☐ Unresolved
12. Does the CFAA apply to state/local government websites, and if so, what does Van Buren permit?
- Status: The CFAA covers government computers (18 U.S.C. § 1030(e)(2)(B)) S-014. After Van Buren, the CFAA covers accessing off-limits files, not mere TOS violations S-006. Circumventing technical access controls (API registration, IP blocks) is more likely to trigger the CFAA than TOS violations.
- Action: Confirm the enforcement strategy with the District Attorney or US Attorney. Reserve CFAA referral for clear circumvention of affirmative technical barriers after notice (Power Ventures model) S-007.
- ☐ Resolved ☐ Unresolved
Recommended Actions Before Adoption
- Seek a COOG advisory opinion on the proposed Program before introduction S-015, S-206.
- Conduct a privacy review of every dataset proposed for the API, using the DCAT-US
accessLevelclassification S-304 and consulting counsel on FOIL exemptions S-011, DPPA S-203, FERPA S-310, and HIPAA. - Instrument the municipal website to measure actual bot traffic volume and cost before setting fees S-122. Replace placeholder fee figures with documented costs.
- Engage journalists, open-government advocates, and the local business community before adoption to address the “paywalling public records” risk.
- Confirm the Municipality's web hosting model and whether the Program can be implemented without modifying the civic CMS S-123.
- Verify whether the Municipality's existing open-data platform (CKAN S-306, Socrata S-308, S-208) supports API keys, rate limiting, and metered billing, or whether new infrastructure (Kong S-106, AWS API Gateway S-121) is needed. (Socrata metered-billing capabilities need verification S-214.)
Sources Cited
All sources are logged in sources/sources.yaml. Key sources cited in this ordinance:
- S-001 / S-201 — FOIA, 5 U.S.C. § 552: Three-tier fee structure; direct-costs cap; public-interest waiver; bulk-access-free provision.
- S-002 — NY Constitution Art. IX: Home rule authority (§§ 2(c)(i), 2(c)(ii)(3), 2(c)(ii)(6), 3(c)).
- S-003 / S-004 / S-005 — hiQ Labs v. LinkedIn: Scraping public data likely lawful.
- S-006 — Van Buren v. United States: CFAA narrowed; TOS violations not criminal.
- S-007 — Facebook v. Power Ventures: Circumventing technical barriers after notice may violate CFAA.
- S-008 / S-204 / S-205 / S-210 — PACER: $0.10/page fee; $30/quarter waiver; discretionary exemptions; cost-recovery framing.
- S-009 / S-010 / S-016 — Nat'l Veterans Legal Services v. US / E-Government Act: PACER fees unlawfully diverted; fees must be tied to system cost.
- S-011 / S-202 — NY FOIL (POL §§ 84–89): FOIL framework, fee caps, public-access floor.
- S-012 / S-013 — MHRL § 10 / Statute of Local Governments: Statutory home rule authority.
- S-014 — CFAA, 18 U.S.C. § 1030: Applicability to government computers.
- S-015 / S-206 — COOG: Authoritative FOIL advisory body.
- S-101 — RFC 9309: robots.txt advisory only.
- S-102 — RFC 9110: HTTP defines bots as user agents.
- S-103 / S-110 / S-122 — Cloudflare: Bot management tiers, pricing, bot scores.
- S-104 / S-105 / S-115 — AWS WAF: Bot Control, AI traffic monetization, pricing.
- S-106 / S-120 — Kong Gateway: API gateway auth, rate limiting, logging.
- S-108 — US Census API: Free-key registration model.
- S-114 — NGINX: Rate limiting.
- S-116 — Imperva: Bots = 53% of web traffic.
- S-121 — AWS API Gateway: Pricing.
- S-123 — Granicus: Civic CMS vendor.
- S-203 — DPPA: DMV record restrictions; § 2721(e) allows administrative fee.
- S-207 / S-208 — data.gov / NYC Open Data: Free open-data precedent.
- S-301 — W3C Data on the Web Best Practices: BP 12, 13, 17, 23, 25.
- S-302 / S-304 — W3C DCAT / DCAT-US: Metadata schema; accessLevel classification.
- S-303 — Schema.org Dataset; S-306 — CKAN; S-308 — data.ny.gov; S-309 — ISO 8601; S-310 — FERPA.
No new sources were added to sources.yaml. Where a needed source did not exist, the text flags it as “needs source” or “needs verification.”
End of Model Ordinance. This document is a sample legislative drafting template prepared for policy research. It is not legal advice. Every statutory citation must be verified against official sources. A municipality must consult its own attorney, seek a COOG advisory opinion, and complete the Legal Review Checklist before adopting any version of this law.