Van Buren v. United States
- Court
- Supreme Court of the United States (U.S. Supreme Court)
- Decided
- 2021
- Citation
- 593 U.S. 374 (2021)
- Standard applied
- CFAA, 18 U.S.C. § 1030(a)(2) — “exceeds authorized access”
What the court held
A person “exceeds authorized access” under the Computer Fraud and Abuse Act only by accessing files, folders or databases that are off limits to him — not by obtaining, for an improper purpose, information he was otherwise entitled to reach. The Court reversed the conviction of a police sergeant who ran a licence-plate search he was authorised to run but did so for payment.
Why
The Court read both CFAA clauses consistently as a gates-up-or-down inquiry: either one may access a system or an area within it, or one may not. Reading “without authorization” as a gates question while making “exceeds authorized access” turn on the circumstances would be inconsistent with the design and structure of subsection (a)(2). The Court expressly left open whether the inquiry turns only on technological limits or also on limits in contracts and policies.
“Under Van Buren’s reading, liability under both clauses stems from a gates-up-or-down inquiry—one either can or cannot access a computer system, and one either can or cannot access certain areas within the system.”
Our reading — not the court’s words
Why this matters in practice
Van Buren retired a decade of circuit law that had let employers and prosecutors convert a terms-of-service or policy breach into a federal computer crime, and it changed what a CFAA investigation has to establish: entitlement to reach the data, not the motive for reaching it. An examiner asked to support a CFAA claim should expect the decisive evidence to be access-control configuration and provisioning records rather than the insider's intent. What the Court reserved — whether contractual as opposed to code-based limits can set the gate — is still where the litigation is.
This paragraph is Legal Cyber Academy’s editorial assessment of the decision’s practical importance. The court said none of it. For what the court actually said, read the opinion.
Additional detail
Tags: CFAA · exceeds authorized access · insider misuse
Cited 286times in CourtListener’s corpus at the time this entry was compiled. Treat it as a rough measure of influence, not of correctness.
Other decisions on computer-crime statutes
- LVRC Holdings LLC v. BrekkaCourt of Appeals for the Ninth Circuit · 2009An employee who is permitted to use his employer's computer does not access it “without authorization” under the CFAA by e-mailing company documents to himself…
- United States v. RodriguezCourt of Appeals for the Eleventh Circuit · 2010A Social Security Administration employee exceeded his authorised access under the CFAA when he looked up the personal details of seventeen people for non-busin…
- United States v. Nosal (Nosal I)Court of Appeals for the Ninth Circuit · 2012“Exceeds authorized access” in the CFAA is limited to violations of restrictions on access to information, and does not extend to violations of restrictions on…
- WEC Carolina Energy Solutions LLC v. MillerCourt of Appeals for the Fourth Circuit · 2012An employee “exceeds authorized access” only when he has approval to access a computer but uses that access to obtain or alter information falling outside the b…
- Facebook, Inc. v. Power Ventures, Inc.Court of Appeals for the Ninth Circuit · 2016A social-aggregation service that accessed a platform's user data with the users' consent did not violate the CFAA while it had the platform's implied permissio…
- Sewell v. BernardinCourt of Appeals for the Second Circuit · 2015Addressing a question of first impression in the circuit, the court held that the CFAA and Stored Communications Act limitations periods run from discovery of t…
Summarised from the opinion as retrieved from CourtListener. Reference material, not legal advice. Back to the repository.