United States v. Nosal (Nosal I)
- Court
- Court of Appeals for the Ninth Circuit (Federal circuit court)
- Decided
- 2012
- Citation
- 676 F.3d 854 (9th Cir. 2012) (en banc)
- Standard applied
- CFAA § 1030(a)(4) — “exceeds authorized access”
What the court held
“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on its use. Because the defendant's accomplices had permission to access the employer's database and to obtain the information in it, the CFAA counts failed and their dismissal was affirmed.
Why
The court read “entitled” in the statutory definition as a synonym for “authorized,” so the phrase refers to data one is not permitted to reach rather than data one may reach but must not misuse. It stressed that a single statutory definition governs every use of the phrase across § 1030, so a use-based reading would make every breach of a private computer-use policy a federal crime given how broadly “protected computer” is defined. Ambiguity in a criminal statute had to be resolved against that result.
“we hold that “exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and not restrictions on its use.”
Our reading — not the court’s words
Why this matters in practice
Nosal I is the opinion that framed the debate Van Buren resolved, and the access-versus-use distinction it drew is still the practical question in any insider case. Its warning about the consequences of a use-based reading — that terms-of-service breaches would become crimes — is why the narrow reading prevailed. Note the limit of the win: the underlying conduct in Nosal remained exposed to trade-secret liability, and later proceedings in the same case addressed password sharing after authorisation had been revoked.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · access versus use · en banc · computer-use policy
Cited 147times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on computer-crime statutes
- Van Buren v. United StatesSupreme Court of the United States · 2021A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by ob…
- LVRC Holdings LLC v. BrekkaCourt of Appeals for the Ninth Circuit · 2009An employee who is permitted to use his employer's computer does not access it “without authorization” under the CFAA by e-mailing company documents to himself…
- United States v. RodriguezCourt of Appeals for the Eleventh Circuit · 2010A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-busin…
- WEC Carolina Energy Solutions LLC v. MillerCourt of Appeals for the Fourth Circuit · 2012An employee “exceeds authorized access” only when he has approval to access a computer but uses that access to obtain or alter information falling outside the b…
- Facebook, Inc. v. Power Ventures, Inc.Court of Appeals for the Ninth Circuit · 2016A social-aggregation service that accessed a platform's user data with the users' consent did not violate the CFAA while it had the platform's implied permissio…
- Sewell v. BernardinCourt of Appeals for the Second Circuit · 2015Addressing a question of first impression in the circuit, the court held that the CFAA and Stored Communications Act limitations periods run from discovery of t…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.