United States v. Rodriguez
- Court
- Court of Appeals for the Eleventh Circuit (Federal circuit court)
- Decided
- 2010
- Citation
- 628 F.3d 1258 (11th Cir. 2010)
- Standard applied
- CFAA § 1030(a)(2)(B) — “exceeds authorized access” read to cover policy breach
What the court held
A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-business reasons, in breach of an agency policy prohibiting access without a business reason. The Act does not require proof that the information was used to further another crime or for financial gain, and the conviction was affirmed.
Why
The agency's policy limited access to business purposes and had been communicated through mandatory training, posted notices, a daily screen banner and annual acknowledgement forms, and the employee admitted accessing records for non-business reasons. On that record the court treated the policy as defining the scope of authorisation, and rejected the argument that the statute's text imported any additional use or gain element.
Our reading — not the court’s words
Why this matters in practice
Rodriguez is the clearest statement of the broad, policy-based reading of “exceeds authorized access” that prevailed in several circuits before Van Buren, and it is included precisely because Van Buren displaced it. Anyone relying on a pre-2021 CFAA case has to ask which side of the split it came from, and this is the paradigm of the losing side. The facts are worth keeping in mind for a different reason: the same conduct may still be a state computer-crime offence, a privacy-statute violation, or a firing, and the CFAA was never the only exposure.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · insider lookup · computer-use policy · superseded by Van Buren
Cited 177times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on computer-crime statutes
- Van Buren v. United StatesSupreme Court of the United States · 2021A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by ob…
- LVRC Holdings LLC v. BrekkaCourt of Appeals for the Ninth Circuit · 2009An employee who is permitted to use his employer's computer does not access it “without authorization” under the CFAA by e-mailing company documents to himself…
- United States v. Nosal (Nosal I)Court of Appeals for the Ninth Circuit · 2012“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on…
- WEC Carolina Energy Solutions LLC v. MillerCourt of Appeals for the Fourth Circuit · 2012An employee “exceeds authorized access” only when he has approval to access a computer but uses that access to obtain or alter information falling outside the b…
- Facebook, Inc. v. Power Ventures, Inc.Court of Appeals for the Ninth Circuit · 2016A social-aggregation service that accessed a platform's user data with the users' consent did not violate the CFAA while it had the platform's implied permissio…
- Sewell v. BernardinCourt of Appeals for the Second Circuit · 2015Addressing a question of first impression in the circuit, the court held that the CFAA and Stored Communications Act limitations periods run from discovery of t…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.