Legal Cyber Academy
Case law repository

United States v. Rodriguez

Court
Court of Appeals for the Eleventh Circuit (Federal circuit court)
Decided
2010
Citation
628 F.3d 1258 (11th Cir. 2010)
Standard applied
CFAA § 1030(a)(2)(B) — “exceeds authorized access” read to cover policy breach
Other dispositionComputer-crime statutes
Read the full opinion628 F.3d 1258 (11th Cir. 2010) · full text on CourtListener

What the court held

A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-business reasons, in breach of an agency policy prohibiting access without a business reason. The Act does not require proof that the information was used to further another crime or for financial gain, and the conviction was affirmed.

Why

The agency's policy limited access to business purposes and had been communicated through mandatory training, posted notices, a daily screen banner and annual acknowledgement forms, and the employee admitted accessing records for non-business reasons. On that record the court treated the policy as defining the scope of authorisation, and rejected the argument that the statute's text imported any additional use or gain element.

Our reading — not the court’s words

Why this matters in practice

Rodriguez is the clearest statement of the broad, policy-based reading of “exceeds authorized access” that prevailed in several circuits before Van Buren, and it is included precisely because Van Buren displaced it. Anyone relying on a pre-2021 CFAA case has to ask which side of the split it came from, and this is the paradigm of the losing side. The facts are worth keeping in mind for a different reason: the same conduct may still be a state computer-crime offence, a privacy-statute violation, or a firing, and the CFAA was never the only exposure.

This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.

Additional detail

Tags: CFAA · insider lookup · computer-use policy · superseded by Van Buren

Cited 177times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.

Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.