LVRC Holdings LLC v. Brekka
- Court
- Court of Appeals for the Ninth Circuit (Federal circuit court)
- Decided
- 2009
- Citation
- 581 F.3d 1127 (9th Cir. 2009)
- Standard applied
- CFAA § 1030(a)(2), (a)(4) — “without authorization”
What the court held
An employee who is permitted to use his employer's computer does not access it “without authorization” under the CFAA by e-mailing company documents to himself for his own later use, and does not “exceed authorized access” where he was entitled to obtain those documents. Whether access is authorised turns on the employer's own decision to grant or revoke it, not on the employee's disloyal state of mind. Summary judgment for the defendant was affirmed.
Why
Starting from the statutory text, the court found nothing in the CFAA supporting the view that authorisation ceases the moment an employee resolves to act against the employer's interest. It read the two phrases as complementary: a person acting “without authorization” has no permission at all, while one who “exceeds authorized access” has limited permission and goes beyond it. It declined to import a state-law duty of loyalty into a federal computer-crime statute.
Our reading — not the court’s words
Why this matters in practice
Brekka is the origin of the narrow reading that Van Buren later adopted for the whole country, and it drew the line where digital-forensics evidence can actually be found: in the access-control configuration, not the insider's motive. For an examiner it means the useful artefacts in a departing-employee case are the permission grants, the account status at the time of access, and the date access was revoked. The corollary is that a copy made on the last day of lawful employment may be a trade-secret or contract problem and not a CFAA violation at all.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · departing employee · authorization · duty of loyalty
Cited 263times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on computer-crime statutes
- Van Buren v. United StatesSupreme Court of the United States · 2021A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by ob…
- United States v. RodriguezCourt of Appeals for the Eleventh Circuit · 2010A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-busin…
- United States v. Nosal (Nosal I)Court of Appeals for the Ninth Circuit · 2012“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on…
- WEC Carolina Energy Solutions LLC v. MillerCourt of Appeals for the Fourth Circuit · 2012An employee “exceeds authorized access” only when he has approval to access a computer but uses that access to obtain or alter information falling outside the b…
- Facebook, Inc. v. Power Ventures, Inc.Court of Appeals for the Ninth Circuit · 2016A social-aggregation service that accessed a platform's user data with the users' consent did not violate the CFAA while it had the platform's implied permissio…
- Sewell v. BernardinCourt of Appeals for the Second Circuit · 2015Addressing a question of first impression in the circuit, the court held that the CFAA and Stored Communications Act limitations periods run from discovery of t…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.