Legal Cyber Academy
Case law repository

Van Buren v. United States

Court
Supreme Court of the United States (U.S. Supreme Court)
Decided
2021
Citation
593 U.S. 374 (2021)
Standard applied
CFAA, 18 U.S.C. § 1030(a)(2) — “exceeds authorized access”
Other dispositionComputer-crime statutes
Read the full opinion593 U.S. 374 (2021) · full text on CourtListener

What the court held

A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by obtaining, for an improper purpose, information he was otherwise entitled to reach. The Court reversed the conviction of a police sergeant who ran a licence-plate search he was authorised to run but did so for payment.

Why

The Court read both CFAA clauses consistently as a gates-up-or-down inquiry: either one may access a system or an area within it, or one may not. Reading “without authorization” as a gates question while making “exceeds authorized access” turn on the circumstances would be inconsistent with the design and structure of subsection (a)(2). The Court expressly left open whether the inquiry turns only on technological limits or also on limits in contracts and policies.

Under Van Buren’s reading, liability under both clauses stems from a gates-up-or-down inquiry—one either can or cannot access a computer system, and one either can or cannot access certain areas within the system.
Van Buren v. United States, 593 U.S. 374 (2021)

Our reading — not the court’s words

Why this matters in practice

Van Buren retired a decade of circuit law that had let employers and prosecutors convert a terms-of-service or policy breach into a federal computer crime, and it changed what a CFAA investigation has to establish: entitlement to reach the data, not the motive for reaching it. An examiner asked to support a CFAA claim should expect the decisive evidence to be access-control configuration and provisioning records rather than the insider's intent. What the Court reserved — whether contractual as opposed to code-based limits can set the gate — is still where the litigation is.

This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.

Additional detail

Tags: CFAA · exceeds authorized access · insider misuse

Cited 286times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.

Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.