Van Buren v. United States, 593 U.S. 374 (2021) was decided by the Supreme Court of the United States on June 3, 2021 (No. 19-783). The Court reversed the Eleventh Circuit and remanded. An individual exceeds authorized access only by obtaining information from areas of a computer — files, folders, or databases — that are off-limits to him; improper motive for retrieving information he is otherwise entitled to obtain is not a CFAA violation. Justice Thomas dissented, joined by Chief Justice Roberts and Justice Alito. The Court left open whether the gates-up-or-down line is drawn by code-based restrictions alone or also by contractual and policy restrictions.
The question before the court
Does a person who is authorized to access a computer system "exceed authorized access" under 18 U.S.C. § 1030(e)(6) when he retrieves information he is permitted to retrieve but does so for a purpose forbidden by an employer policy or terms of use?
The governing rule
The Computer Fraud and Abuse Act punishes anyone who "intentionally accesses a computer without authorization or exceeds authorized access" and thereby obtains information, 18 U.S.C. § 1030(a)(2), and defines "exceeds authorized access" as "to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter," § 1030(e)(6). Because Congress supplied an explicit definition, that definition governs even where it departs from the phrase's ordinary sense. Tanzin v. Tanvir, 592 U.S. 43 (2020). The word "so" is a term of reference meaning "in the same manner as has been stated," and the only manner of obtaining information stated in § 1030(e)(6) is by using a computer one is authorized to access. "Access" carries its established technical meaning of entering a system or a part of a system, and technical terms in a statute addressing a technical subject take their specialized sense. Both clauses of § 1030(a)(2) therefore pose the same gates-up-or-down question. The Court expressly reserved whether that inquiry turns only on code-based limits or also on limits in contracts and policies.
How the court applied it
Van Buren, a Georgia police sergeant, used his own valid credentials on his patrol-car computer to run a license plate in a state law enforcement database in exchange for roughly $5,000 from an FBI informant, in plain violation of a department rule restricting the database to law enforcement purposes. The parties agreed he accessed the computer with authorization and obtained information in it; the case turned on whether he was "entitled so to obtain" it. Justice Barrett's opinion for the Court gave "so" its referential meaning, which points back to the single stated circumstance — obtaining information through a computer one may access — rather than to every workplace rule that might qualify a user's right. Structure reinforced the text. The Government read "without authorization" as a binary gate but "exceeds authorized access" as circumstance-dependent, and never explained why Congress would forbid accessing information for an improper purpose while permitting access to the machine itself for the same purpose. The CFAA's civil remedy compounded the problem: "damage" and "loss" are defined in terms of impairment to data, programs, systems, and information services — technological harms typical of hacking, not the misuse of records an employee may lawfully see. The Court also noted the practical stakes, since the Government's reading would criminalize sending a personal email or reading the news on a work computer, and would make liability turn on whether an employer happened to phrase a rule as a use restriction or an access restriction.
What the court concluded
The Court reversed the Eleventh Circuit and remanded. An individual exceeds authorized access only by obtaining information from areas of a computer — files, folders, or databases — that are off-limits to him; improper motive for retrieving information he is otherwise entitled to obtain is not a CFAA violation. Justice Thomas dissented, joined by Chief Justice Roberts and Justice Alito. The Court left open whether the gates-up-or-down line is drawn by code-based restrictions alone or also by contractual and policy restrictions.
From the opinion
- “covers those who obtain information from particular areas in the computer—such as files, folders, or databases—to which their computer access does not extend” — Opening of Justice Barrett's opinion for the Court, stating the holding
- “liability under both clauses stems from a gates-up-or-down inquiry—one either can or cannot access a computer system” — Part II.B, adopting Van Buren's structural reading of § 1030(a)(2)
- “we need not address whether this inquiry turns only on technological (or "code-based") limitations on access” — Footnote 8, reserving the boundary of the gates-up-or-down test
Why it matters for cyber conflict
Van Buren narrows the principal federal anti-hacking statute to breaches of access barriers rather than breaches of policy, which shifts CFAA exposure away from insiders who misuse data they may lawfully see and toward intruders who cross a technical boundary. For cyber-conflict practice it also means that a network's written terms of use are no substitute for enforced access controls when an operator later seeks a federal remedy.
Editorial note: this case note was drafted with AI assistance by the JLCW Research Desk, checked against the text of the opinion, and reviewed by a human editor before publication. Every quotation above is carried through from the opinion itself. See our editing policy.
Read the opinion: Van Buren v. United States on CourtListener. This note is a summary prepared by the Journal, not legal advice, and not a substitute for the opinion itself.
The scholarship behind this: Cyber Countermeasures by Private Actors
More on Private Sector · All case notes · Peer-reviewed scholarship