Legal Cyber Academy
Case law repository

United States v. Nosal (Nosal I)

Court
Court of Appeals for the Ninth Circuit (Federal circuit court)
Decided
2012
Citation
676 F.3d 854 (9th Cir. 2012) (en banc)
Standard applied
CFAA § 1030(a)(4) — “exceeds authorized access”
Other dispositionComputer-crime statutes
Read the full opinion676 F.3d 854 (9th Cir. 2012) (en banc) · full text on CourtListener

What the court held

“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on its use. Because the defendant's accomplices had permission to access the employer's database and to obtain the information in it, the CFAA counts failed and their dismissal was affirmed.

Why

The court read “entitled” in the statutory definition as a synonym for “authorized,” so the phrase refers to data one is not permitted to reach rather than data one may reach but must not misuse. It stressed that a single statutory definition governs every use of the phrase across § 1030, so a use-based reading would make every breach of a private computer-use policy a federal crime given how broadly “protected computer” is defined. Ambiguity in a criminal statute had to be resolved against that result.

we hold that “exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and not restrictions on its use.
United States v. Nosal (Nosal I), 676 F.3d 854 (9th Cir. 2012) (en banc)

Our reading — not the court’s words

Why this matters in practice

Nosal I is the opinion that framed the debate Van Buren resolved, and the access-versus-use distinction it drew is still the practical question in any insider case. Its warning about the consequences of a use-based reading — that terms-of-service breaches would become crimes — is why the narrow reading prevailed. Note the limit of the win: the underlying conduct in Nosal remained exposed to trade-secret liability, and later proceedings in the same case addressed password sharing after authorisation had been revoked.

This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.

Additional detail

Tags: CFAA · access versus use · en banc · computer-use policy

Cited 147times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.

Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.