OCTOBER TERM, 2020 · DECIDED JUNE 3, 2021 · 6–3

593 U.S. ____ · No. 19-783 · Argued November 30, 2020

Share

Van Buren v. United States

Reversed and remandedFinal ruling
computer fraudcybercrimeemployee computer usecriminal lawinternet regulation

Opinion of the Court by Justice Barrett, joined by Justices Breyer, Sotomayor, Kagan, Gorsuch, and Kavanaugh

The Supreme Court ruled that a police officer who used a law enforcement database for personal gain did not violate the federal computer fraud law, because he had valid credentials to access that database and was not entering any area of the system that was off-limits to him.

The decision significantly narrows the Computer Fraud and Abuse Act, holding that the law punishes people who break into parts of a computer system they have no permission to enter — not employees who misuse access they legitimately have.

How it got here: Van Buren was convicted in federal trial court and sentenced to 18 months; the Eleventh Circuit affirmed; the Supreme Court agreed to hear the case to resolve a circuit split over the CFAA's scope.

The Case in Depth

What happened

Nathan Van Buren was a Georgia police sergeant who agreed to run a license-plate search through a restricted law enforcement database in exchange for roughly $5,000 — unaware that the request was part of an FBI sting. He used his own valid login credentials to perform the search, but his department's policy allowed such queries only for legitimate law enforcement purposes. He was convicted of a felony under the Computer Fraud and Abuse Act and sentenced to 18 months in prison.

The question before the Court

Does a police officer commit a federal computer fraud crime when he uses a work computer to access a law enforcement database — using his own valid credentials — but retrieves information for an unauthorized personal purpose rather than a legitimate law enforcement reason?

The Court's answer

No — using a work computer for an unauthorized personal purpose does not, by itself, violate the Computer Fraud and Abuse Act. The law's "exceeds authorized access" clause only covers employees who enter areas of a computer system they have no permission to access at all — a restricted database, a locked folder, a prohibited part of the system. Van Buren had full permission to query the license-plate database; he simply used it for the wrong reason, and the statute does not reach that.

The Court read the statute's key phrase — "not entitled so to obtain" — as a reference back to information one has no right to retrieve through one's authorized computer, not as a catch-all for any policy or contract that limits why or how someone may use a computer. An employee who is permitted to access a file or database does not commit a federal crime simply because he accesses it for an improper purpose.

Curious how the Court got there? See the step-by-step legal reasoning →

Why it matters

Workers who send a personal email, read the news, or pay bills on a work computer — violating a common workplace computer-use policy — cannot be criminally prosecuted under the federal computer fraud law based on that conduct alone. The ruling also prevents websites and online services from using the CFAA to turn ordinary violations of their terms of service into federal crimes.

What changes now

The Eleventh Circuit's judgment is reversed and Van Buren's CFAA conviction cannot stand. The case is sent back for further proceedings consistent with the Court's ruling. More broadly, the decision resolves a long-running circuit split about the scope of the CFAA's "exceeds authorized access" clause, limiting the law's reach nationwide. The Court left open one question: whether the access inquiry turns solely on technical, code-based barriers or also on restrictions set by contracts and workplace policies.

What this does not decide

The Court explicitly declined to decide whether the "gates-up-or-down" test looks only at technical, code-based barriers to computer access or also considers restrictions imposed by contracts or employer policies. That question — and its implications for a wide range of workplace and online settings — remains unresolved.

Concurrences and dissents

Dissent — Justice Thomas

Justice Thomas argued that entitlements to use property have always been circumstance-specific — a valet may park your car but cannot joyride in it. Van Buren lacked a law enforcement purpose, so the condition that gave him the right to access the database was absent; he was simply not entitled to retrieve that information when he did. Thomas also argued that the 1986 amendment to the CFAA broadened the statute by replacing the narrow word 'purpose' with the broader phrase 'not entitled,' and that policy worries about over-criminalization do not justify rewriting statutory text.

How the Court got there

The legal reasoning, step by step

  1. The CFAA makes it a crime to 'exceed authorized access,' which the statute defines as accessing a computer 'with authorization' and then obtaining information 'that the accesser is not entitled so to obtain.' The Court treated the word 'so' — a term of reference pointing back to a previously stated manner of obtaining information — as the key to the statute's meaning.
  2. The only manner of obtaining information already described in the definition is using a computer one is authorized to access. So 'not entitled so to obtain' means information one has no right to retrieve through one's authorized computer — i.e., areas of the system one simply cannot enter, like a forbidden folder or a restricted database. Purpose for accessing permitted areas is irrelevant under this reading.
  3. The Court rejected the government's broader interpretation, which would have made 'so' a hook for any restriction — in a workplace policy, a website's terms of service, or a private contract — on the circumstances under which a user may retrieve information. The Court found nothing in the text supporting that reading, and it would give 'so' an untethered reach inconsistent with how the word ordinarily functions in statutes.
  4. The statute's structure reinforced the narrower view. The two CFAA clauses — 'without authorization' (targeting outsiders who break into a computer) and 'exceeds authorized access' (targeting insiders who enter areas of a computer they cannot enter) — work consistently under Van Buren's gates-up-or-down approach. The government's reading would treat the two clauses differently without any textual justification.
  5. The civil-liability provisions of the CFAA define compensable 'damage' and 'loss' as technological harms like corrupted or impaired data — the kind of harm caused by hacking, not by an employee misusing information he was permitted to access. Those narrow definitions fit a scheme designed to fight hacking but are ill suited to the information-misuse conduct the government was trying to reach here.
  6. The government's reading would criminalize a breathtaking range of ordinary workplace computer activity — sending a personal email on a work device, checking the news — for the millions of employees who work under common computer-use policies. The Court found this sweeping consequence a strong indicator that the government's interpretation of the statute was implausible.

Doctrinal impact

Laws and provisions at issue

Computer Fraud and Abuse Act § 1030(a)(2)

Federal law making it a crime to intentionally access a computer without authorization or exceed authorized access to obtain information.

18 U.S.C. § 1030(e)(6)

The CFAA's definition of 'exceeds authorized access' — the key phrase the Court interpreted in this case.

Cases affected by this decision

Distinguishes Musacchio v. United States (577 U.S. 237)

The earlier case's description of the CFAA was passing dicta that did not address or resolve the scope of 'exceeds authorized access.'

Supreme Court Opinion

Ask GovernmentReporter about this case

Ask anything about the majority, concurrences, or dissents.

Van Buren v. United States | SCOTUS Reporter