← All Cases Coverage by Bryan K. Randolph · BrynoDC

Van Buren v. United States

No. 19-783 SCOTUS · Decided Decided SCOTUS
Argued: Nov 30, 2020 Decided: Jun 3, 2021


The Facts

Van Buren had proper credentials to access the state's law enforcement database as part of his official duties. He used those credentials to look up a person at the request of an FBI informant who paid him for the information. The government charged him under the CFAA provision making it a crime to 'exceed authorized access' to a computer. Van Buren argued he was authorized to access the database; he just accessed it for an improper purpose.

The Application

History

Van Buren had legitimate authorization to access the license plate database as part of his official duties, so under the Court's gates-up-or-down framework, the gate to that data remained up for him. He was entitled to reach that information, even if his purpose in doing so, selling a woman's address to an FBI informant for money, was improper and unauthorized. The Court held that exceeds authorized access refers only to unauthorized access to data itself, not unauthorized purposes or misuse of authorized access, because the CFAA cannot extend to every employee who violates workplace rules or terms of service. Since Van Buren's gate was open, his conviction could not rest on exceeding authorized access under this narrowed interpretation.

The Conclusion

**The Supreme Court reversed Van Buren's conviction 6-3, narrowing the CFAA significantly.** An employee or official who has legitimate authorization to access a computer system does not violate the CFAA merely by using that access for an unauthorized purpose, foreclosing prosecution of millions of routine computer users who violate terms of service or use access for personal benefit.

CourtSupreme Court of the United States
Filed -
CL StatusActive
View on CourtListener →

No circuit court data for this case.

Cert Granted -
StatusActive
Filed (CL) -
View on CourtListener →
SCOTUS TMR-1fe6bbe8 May 14, 2026

Case Analysis

Overview

Georgia police sergeant Nathan Van Buren used his authorized access to a government license plate database to look up a woman's address in exchange for money, at the request of someone who turned out to be an FBI informant. He was convicted under the Computer Fraud and Abuse Act for 'exceeding authorized access'; the Supreme Court reversed 6-3, holding that the CFAA covers only those who access data they have no right to obtain, not those who misuse data they are legitimately permitted to access.

Facts

Van Buren had proper credentials to access the state's law enforcement database as part of his official duties. He used those credentials to look up a person at the request of an FBI informant who paid him for the information. The government charged him under the CFAA provision making it a crime to 'exceed authorized access' to a computer. Van Buren argued he was authorized to access the database; he just accessed it for an improper purpose.

Issue

Whether a person who is authorized to access information in a computer system 'exceeds authorized access' under the Computer Fraud and Abuse Act when that person uses their legitimate access to obtain information for a purpose the computer owner has not sanctioned.

Rule

The CFAA provision covering those who 'exceed authorized access' applies to individuals who access parts of a computer system they are not entitled to access at all, not to those who access information they are entitled to access but use it for an improper purpose. The 'gates-up-or-down' framework focuses on whether the person had authorization to reach the data in question, not on whether the purpose of the access was proper.

Analysis

Van Buren had legitimate authorization to access the license plate database as part of his official duties, so under the Court's gates-up-or-down framework, the gate to that data remained 'up' for him. He was entitled to reach that information, even if his purpose in doing so (selling a woman's address to an FBI informant for money) was improper and unauthorized. The Court held that 'exceeds authorized access' refers only to unauthorized access to data itself, not unauthorized purposes or misuse of authorized access, because the CFAA cannot extend to every employee who violates workplace rules or terms of service. Since Van Buren's gate was open, his conviction could not rest on 'exceeding authorized access' under this narrowed interpretation.

Conclusion

**The Supreme Court reversed Van Buren's conviction 6-3, narrowing the CFAA significantly.** An employee or official who has legitimate authorization to access a computer system does not violate the CFAA merely by using that access for an unauthorized purpose, foreclosing prosecution of millions of routine computer users who violate terms of service or use access for personal benefit.

Notes

OT2020. Added via SCOTUS bulk import 2026-05-14

Subscribe on Substack ↗

This tracker is maintained by BrynoDC and is free because readers fund it. Support