Shield Public Safety Training · Police Technology Case Law Center

Van Buren v. United States

593 U.S. 374 (2021)

The Supreme Court decision narrowing the Computer Fraud and Abuse Act's "exceeds authorized access" clause—holding that a user does not violate the CFAA merely by obtaining information for an improper purpose when the user is otherwise entitled to access that information.

CourtSupreme Court of the United States
DecisionJune 3, 2021
Majority OpinionJustice Barrett
Vote6–3
DissentJustice Thomas, joined by Chief Justice Roberts and Justice Alito
DefendantNathan Van Buren, former Georgia police sergeant
DatabaseLaw-enforcement license-plate database
ConductSearch performed for personal / corrupt purpose using valid credentials
StatuteComputer Fraud and Abuse Act, 18 U.S.C. § 1030
Core HoldingImproper purpose alone does not constitute "exceeding authorized access"
ResultEleventh Circuit reversed and case remanded
Last ReviewedAugust 10, 2026

Executive Summary

The Case in One Paragraph

Nathan Van Buren, a Georgia police sergeant, had valid credentials allowing him to access a law-enforcement database and retrieve license-plate information for legitimate police purposes. During an FBI sting, Van Buren agreed to run a license plate for Andrew Albo in exchange for approximately $5,000. The search violated department policy because Van Buren used the database for a personal, non-law-enforcement purpose. Federal prosecutors charged him under the Computer Fraud and Abuse Act (CFAA), arguing that he had "exceeded authorized access." The Supreme Court rejected that interpretation. Because Van Buren was authorized to enter the database and retrieve the type of license-plate record at issue, he did not exceed authorized access merely because he retrieved the information for an improper purpose. The CFAA's "exceeds authorized access" clause instead applies when a user is authorized to access a computer but enters files, folders, databases, accounts, or other areas that are off limits to that user.

Van Buren v. United States is a statutory computer-crime decision, not a Fourth Amendment search case. Yet it is highly relevant to public-safety technology because it defines the federal criminal boundary between misusing data one is allowed to access and accessing data one is not allowed to access.

The distinction is particularly important for law enforcement. Officers, dispatchers, analysts, corrections employees, records personnel, contractors, and other public-safety users often have legitimate credentials to sensitive databases. An employee who looks up a neighbor, former partner, celebrity, or acquaintance for an improper personal reason may commit a serious policy violation and may violate other criminal or civil laws. But after Van Buren, that improper purpose alone does not establish an "exceeds authorized access" CFAA violation when the employee was technically and substantively authorized to retrieve that category of information.

Conversely, an authorized user who enters another user's account, a restricted database, a prohibited folder, or another computational area to which the user's access does not extend may still fall within the CFAA.

Core Rule A person "exceeds authorized access" under the CFAA when the person has authorization to access a computer but obtains information from a part of the computer—such as a file, folder, database, or account—that the person is not entitled to access. The statute does not criminalize obtaining information the person is otherwise entitled to access merely because the person acts for an improper purpose.

Key Holdings at a Glance

Access, Not Motive The CFAA asks whether the user could access the information, not why the user wanted it.
Policy Violation Alone Is Not Enough Violating an employer's acceptable-use rule does not by itself establish "exceeds authorized access."
Restricted Areas Still Matter Accessing a file, account, database, or other computer area outside the user's authorization may violate the CFAA.
Valid Credentials Can Still Produce a CFAA Violation A user may be authorized into the system generally but unauthorized to enter particular areas.
Ordinary Computer Use Informed the Court The majority rejected an interpretation that could make routine violations of workplace or website rules federal crimes.
Other Laws Still Apply Van Buren does not immunize bribery, privacy violations, records misuse, misconduct, or other offenses.

Facts

Van Buren served as a police sergeant in Georgia. During his duties he became acquainted with Andrew Albo, whom department leadership considered volatile.

Van Buren later approached Albo for a personal loan. Albo secretly recorded the request and reported it to local law enforcement, claiming that Van Buren was attempting to extract money from him.

The recording reached the FBI, which developed an undercover operation to determine how far Van Buren would go in exchange for money.

Under the FBI plan, Albo asked Van Buren to run a license plate supposedly belonging to a woman Albo had met at a strip club. Albo said he wanted to determine whether she was an undercover police officer. In exchange for the database search, Albo would pay Van Buren approximately $5,000.

Van Buren used his patrol-car computer, logged into the law-enforcement database using his own valid credentials, and ran the FBI-created plate.

There was no dispute that department policy prohibited the search. Van Buren had been trained that the database could not be used for personal purposes.

The question was whether violating that use restriction also violated the CFAA.

The Computer Fraud and Abuse Act

The relevant CFAA provision, 18 U.S.C. § 1030(a)(2), imposes liability on a person who intentionally accesses a computer without authorization or exceeds authorized access and thereby obtains protected information.

The statute separately defines "exceeds authorized access." The Supreme Court focused on that statutory definition rather than on the ordinary-language intuition that Van Buren obviously had acted "without authorization" in a colloquial sense.

The statutory distinction is between:

CategoryMeaning
Without authorizationUser has no permission to access the computer or system at all.
Exceeds authorized accessUser may enter the computer but obtains information located in an area to which that user's authorized access does not extend.
Statutory Focus The CFAA is principally an access-control statute. It is not a federal code of ethics for every improper use of information obtained through an authorized computer account.

The "Gates-Up-or-Down" Framework

The majority described the statute as reflecting a "gates-up-or-down" approach to authorization.

Computer systems commonly separate information into areas: accounts, databases, files, folders, records, or applications. A user may be authorized to enter some and prohibited from entering others.

If the gate to the relevant information is down for the user—meaning the user is entitled to access that information—the CFAA's "exceeds authorized access" clause is not violated merely because the user has a bad motive.

If the gate is up—meaning that area is off limits to the user—the user may exceed authorized access by entering it.

Public-Safety Example An employee who is permitted to query a statewide vehicle database but runs a plate for personal curiosity may violate policy without violating Van Buren's interpretation of the CFAA. An employee who uses credentials or technical methods to enter a restricted intelligence database that the employee is not permitted to access presents a materially different CFAA question.

Purpose Restrictions Are Different From Access Restrictions

Van Buren's department allowed him to retrieve license-plate information, but only for law-enforcement purposes.

The Government argued that authorization therefore depended on purpose: the same query was authorized when done for police work and unauthorized when done for money or personal reasons.

The Supreme Court rejected that purpose-based construction of "exceeds authorized access."

The Court concluded that the statutory definition focuses on whether the user is entitled to obtain the information through the computer—not whether external rules permit the user to obtain it for the particular reason motivating the search.

Do Not Misstate Van Buren Van Buren does not say purpose restrictions are meaningless. They can support discipline, termination, decertification, privacy claims, state-law charges, corruption charges, database sanctions, and other consequences. The case says only that improper purpose does not, standing alone, satisfy the CFAA's "exceeds authorized access" language.

Justice Barrett's Majority Opinion

Justice Barrett's opinion relied heavily on statutory text, structure, and the technical meaning of computer "access."

The Word "So"

The key statutory phrase refers to information the user is not "entitled so to obtain." The majority read "so" as referring back to the manner of obtaining the information through authorized computer access.

Access Has a Technical Meaning

In computing, access refers to entering a system or a particular part of a system. That technical meaning reinforced a division between areas a user may enter and areas the user may not.

Congress Removed Purpose Language

Earlier statutory language had referred more explicitly to improper purposes. Congress later removed that language, which the majority viewed as cutting against the Government's purpose-based interpretation.

Avoiding Extraordinary Breadth

The majority also noted the sweeping consequences of the Government's interpretation. If violating a computer-use policy were enough, employees could potentially commit federal crimes by reading news or sending personal email on work computers contrary to workplace rules.

Likewise, ordinary Internet users might face CFAA liability for violating website terms of service.

Majority's Bottom Line Van Buren was allowed to enter the database and obtain license-plate information. His corrupt reason for doing so did not convert that otherwise permitted access into "exceed[ing] authorized access" under § 1030.

Justice Thomas's Dissent

Justice Thomas, joined by Chief Justice Roberts and Justice Alito, read the statute more broadly.

The dissent drew on traditional property and agency concepts. A person may receive limited permission to use another's property for a particular purpose, yet exceed that permission when using the property for something else.

The dissent illustrated the idea with a valet: permission to drive a customer's vehicle to park it does not authorize taking the vehicle for a personal joyride.

Applying that principle to Van Buren, the dissent viewed his database authorization as limited to law-enforcement purposes. Because the corrupt plate search fell outside that permitted use, the dissent concluded that he exceeded authorized access.

Doctrinal Divide The majority treats authorization primarily as a question of which computer areas a user may enter. The dissent treats authorization more like limited consent that can depend on the purpose for which the information is obtained.

Law-Enforcement Databases After Van Buren

Van Buren has direct operational implications for police and corrections agencies because government databases frequently contain highly sensitive information.

Improper Personal Queries

Running a plate, criminal-history record, employee file, jail record, or investigative database query for personal reasons may remain serious misconduct even if the employee is technically authorized to retrieve that category of record.

Restricted Databases

If an employee accesses an application, user account, case file, intelligence repository, or other system area to which the employee's permissions do not extend, the CFAA remains potentially applicable.

Credential Sharing

Using another employee's credentials or circumventing role-based permissions can create a substantially different authorization analysis from Van Buren's use of his own valid credentials.

After-Hours or Off-Duty Access

Time-based restrictions may be operationally significant, but whether they create an access boundary under the CFAA depends on how authorization is structured. Agencies should not rely solely on policy wording when technical access controls can clearly define permissions.

Agency Design Lesson If an agency considers certain records genuinely off limits to particular users, enforce that distinction through role-based access control, permissions, segmentation, or other technical mechanisms rather than relying only on an acceptable-use policy.

Policy Violations Still Matter

Van Buren is sometimes misunderstood as giving employees a federal "right" to misuse databases so long as their password works.

It does no such thing.

An improper database query may implicate:

  • department policy;
  • state criminal statutes;
  • official misconduct laws;
  • bribery or corruption offenses;
  • privacy statutes;
  • DMV or criminal-justice database rules;
  • CJIS access requirements;
  • employment discipline;
  • civil liability;
  • professional licensing or certification;
  • collective-bargaining provisions; and
  • evidentiary or disclosure obligations.
Training Message The correct lesson is not "personal database searches are legal." The correct lesson is "improper purpose alone is not the same thing as exceeding authorized access under this particular federal statute."

Civil CFAA Implications

The CFAA also contains a civil cause of action for qualifying persons who suffer specified damage or loss from conduct involving a statutory violation.

Because Van Buren interprets the statutory phrase "exceeds authorized access," its narrow construction affects both criminal prosecutions and civil CFAA litigation using that language.

Employers therefore cannot automatically convert every breach of a computer-use policy, confidentiality rule, or business-purpose restriction into a federal CFAA claim.

Other civil theories—contract, trade secret, privacy, fiduciary duty, tort, or state computer-crime statutes—may still apply depending on the facts.

Current DOJ CFAA Charging Policy

The Department of Justice revised its CFAA charging policy after Van Buren.

Current Justice Manual guidance directs federal prosecutors not to bring "exceeds authorized access" cases based merely on contracts, terms of service, or employee-use policies when the defendant was otherwise permitted to access the relevant computer area.

The policy instead focuses on situations in which a computer is divided into areas—such as files, folders, user accounts, or databases—and the defendant knowingly accesses an area to which authorized access does not extend.

DOJ also directs prosecutors to decline CFAA prosecution when available evidence shows that the defendant's conduct consisted of and was intended as good-faith security research.

Current Federal Enforcement Approach Federal CFAA charging policy now tracks Van Buren's distinction between misuse of authorized access and entry into information or areas the defendant was not authorized to access.
Policy Is Not Statutory Immunity DOJ charging policy guides federal prosecutors. It does not amend the statute, bind state prosecutors, or eliminate other criminal and civil theories.

Van Buren, AI, and Database Access

AI changes how authorized users interact with restricted data systems.

AI Agents With User Credentials

An AI assistant may act through an employee's authenticated account. Agencies must define whether the AI can access only data the employee may access and whether automated actions are attributable, logged, and reviewable.

Cross-System Retrieval

A user may be authorized to access Database A but not Database B. An AI system that automatically pulls information from both can blur the access boundary unless permissions are technically enforced.

Prompt-Induced Overreach

A user may ask an AI system for information the user is not entitled to retrieve. If the agent circumvents role-based restrictions or accesses prohibited data stores, the issue is closer to Van Buren's "gates-up" category than ordinary misuse of authorized information.

Training and Retrieval-Augmented Generation

Agencies may allow models to retrieve protected law-enforcement records while generating answers. Permissions should follow the underlying user's authorization and should prevent the model from exposing information from repositories the user cannot directly access.

Auditability

AI-generated answers can obscure which databases were queried. Audit logs should record the user, model, source system, query, retrieved records, and output.

AI Governance Rule Design AI access around computational permissions, not merely policy instructions. Van Buren makes the technical boundary between accessible and prohibited information especially important.

Technology in 2026

Van Buren is increasingly important as agencies consolidate information into shared cloud platforms, data lakes, federated search systems, and AI-assisted investigative tools.

Role-Based Access Control

Modern systems can assign granular permissions by role, unit, case, classification, jurisdiction, or data type. Those controls can create clearer access boundaries than broad written policies alone.

Zero-Trust Architecture

Modern security models increasingly authenticate and authorize each request rather than assuming that a user inside a network may access everything. That architecture aligns closely with Van Buren's focus on specific areas of permitted and prohibited access.

Data Lakes and Federated Search

A single search interface may query multiple repositories. Agencies should know whether the interface filters results according to the user's underlying permissions or exposes records the user could not otherwise access.

AI Agents Can Cross Boundaries Silently

Agentic systems may call APIs, databases, and tools automatically. Poorly configured permissions can allow the software to reach information beyond the user's authorization without the user understanding how the data was obtained.

Internal Misuse Remains a Governance Risk

Even when misuse does not satisfy the CFAA after Van Buren, unauthorized personal queries can cause serious privacy harms, undermine investigations, expose confidential informants, and create agency liability.

2026 Risk Do not rely on policy language alone to protect highly sensitive systems. Use technical permissions to enforce true access boundaries, maintain detailed audit logs, and investigate improper use under every applicable criminal, administrative, privacy, and employment framework—not just the CFAA.

Practical Guidance for Law Enforcement and Corrections Agencies

1. Separate Access Controls From Use Policies

Define which data a user technically may access and separately define permissible reasons for using it.

2. Use Role-Based Permissions

If an employee should never see a class of records, do not rely solely on a policy telling the employee not to look.

3. Audit Sensitive Queries

Maintain searchable logs of plate checks, criminal-history queries, intelligence searches, jail records, employee records, and other sensitive access.

4. Create Automated Misuse Alerts

Flag unusual patterns such as searches involving relatives, celebrities, co-workers, neighbors, or records unrelated to assigned duties—while validating alerts before taking action.

5. Maintain Clear Administrative Rules

Van Buren narrows federal CFAA liability but does not reduce the importance of strong policy prohibitions against curiosity searches and personal use.

6. Identify Alternative Criminal Statutes

Agency counsel should know applicable state computer-crime, privacy, official-misconduct, bribery, records, and database-specific statutes.

7. Control Credential Sharing

Prohibit shared credentials and use multifactor authentication where appropriate.

8. Apply Least Privilege

Users should have only the database permissions necessary for their roles.

9. Govern AI and API Access

AI agents, integrations, and automated workflows should inherit and enforce the same or stricter permissions as the human user.

10. Preserve Audit Evidence

When misuse is suspected, preserve authentication logs, query history, device data, session records, policy acknowledgments, communications, and any AI-system logs.

Database Misuse Investigation Checklist

QuestionWhy It Matters
Was the user authorized to enter the computer system?Separates "without authorization" from insider-access cases.
Was the user authorized to access the specific database?Central Van Buren question.
Was the user authorized to access the specific account, file, or record?Granular permissions can determine CFAA exposure.
Did the user use valid credentials?Relevant but not necessarily dispositive.
Was the violation only one of purpose?Improper motive alone does not establish "exceeds authorized access."
Was a technical restriction bypassed?Strong evidence of unauthorized area access.
Were another person's credentials used?May materially alter authorization analysis.
What written policies applied?Still relevant to discipline, intent, notice, and other laws.
What audit logs exist?Establishes what systems and records were accessed.
Were AI agents or APIs involved?Automated systems may have crossed access boundaries.
What other criminal statutes apply?Van Buren addresses only a specific CFAA theory.
What privacy or employment consequences apply?Misuse can remain serious even without CFAA liability.

Litigation Checklist for Agency Counsel and Prosecutors

  1. Map the computer architecture. Identify systems, databases, accounts, folders, and permission levels.
  2. Identify the defendant's exact authorization.
  3. Separate purpose restrictions from access restrictions.
  4. Determine whether any technical barrier or permission boundary was crossed.
  5. Preserve authentication and query logs.
  6. Identify whether valid or borrowed credentials were used.
  7. Review current DOJ CFAA policy in federal cases.
  8. Evaluate state computer-crime and privacy statutes.
  9. Analyze bribery, corruption, records, and official-misconduct theories independently.
  10. For AI-assisted access, determine which system actually retrieved each record.
  11. Preserve role assignments and permission configurations as they existed at the relevant time.
  12. Do not characterize an improper motive as unauthorized access without proving the access boundary Van Buren requires.

Frequently Asked Questions

What did Van Buren v. United States hold?

The Supreme Court held that a person does not "exceed authorized access" under the CFAA merely by obtaining information for an improper purpose when the person is otherwise entitled to access that information.

What did Van Buren actually do?

He used valid police credentials to run a license plate in a law-enforcement database for Andrew Albo during an FBI sting in exchange for approximately $5,000.

Was the database search permitted by department policy?

No. Van Buren had been trained that the database could be used only for legitimate law-enforcement purposes. His conduct plainly violated policy.

Why wasn't that enough for the CFAA?

Because the Court interpreted "exceeds authorized access" as focusing on whether Van Buren was entitled to obtain the information through the computer, not whether he had a proper reason for obtaining it.

Does Van Buren protect employees who misuse confidential information?

No. It narrows one CFAA theory. Other federal laws, state laws, privacy rules, employment policies, professional standards, and civil causes of action may still apply.

Can an employee violate the CFAA using valid credentials?

Yes. If the credentials permit access to the computer generally but the employee enters a file, account, database, or other area that is off limits, the "exceeds authorized access" clause may still apply.

Are terms-of-service violations CFAA crimes?

Van Buren strongly rejects using ordinary purpose or use restrictions as the basis for "exceeds authorized access" liability. Current DOJ policy likewise states that prosecutors will not bring such cases based solely on general contractual or terms-of-service restrictions.

What is the "gates-up-or-down" approach?

It is shorthand for the Court's access-based framework: a user either has permission to enter a particular computer area or does not. The CFAA focuses on crossing that access boundary rather than on the user's subjective purpose.

Why does this matter for police databases?

Agencies should distinguish between employees who misuse records they are entitled to query and employees who access systems or records outside their permission level. Both may be misconduct, but the federal CFAA analysis differs.

How does Van Buren affect AI systems?

AI agents can make access boundaries less visible. Agencies should use technical controls so automated tools cannot retrieve information beyond the user's authorized repositories, and should log every system the AI accesses.

Primary Authorities and Current Federal Guidance

Van Buren v. United States, 593 U.S. 374 (2021)
Official Supreme Court opinion.
Read the official Van Buren opinion
18 U.S.C. § 1030 — Fraud and related activity in connection with computers
Current federal statutory text.
Review current 18 U.S.C. § 1030
U.S. Department of Justice — Justice Manual § 9-48.000
Current federal CFAA charging policy, including guidance after Van Buren and treatment of good-faith security research.
Review current DOJ CFAA charging policy

Final Assessment

Van Buren draws a clear line between access and misuse. That distinction is especially important in public safety, where employees often have legitimate access to systems containing extraordinary quantities of sensitive information.

The Court did not minimize Van Buren's misconduct. It held that Congress did not use the CFAA's "exceeds authorized access" provision to criminalize every improper purpose for which an authorized user retrieves information.

That statutory limit should influence system design. If agencies need certain information to be truly inaccessible to particular employees, technical permissions should enforce that boundary. Written policy remains essential for conduct regulation, but policy and access control serve different functions.

The distinction becomes even more important as AI agents and federated systems act across multiple databases. Agencies must know not merely what a user is told not to do, but what the system actually allows the user—and the user's software—to access.

Shield Practice Rule Treat database misuse and unauthorized access as separate questions. Enforce sensitive data boundaries through role-based technical controls, audit every query, preserve access logs, and investigate personal or corrupt use under all applicable policy, privacy, criminal, and employment frameworks. For CFAA analysis, ask whether the user actually crossed a computer-access boundary—not simply whether the user had an improper purpose.

Shield Public Safety Training · Police Technology Case Law Center

This monograph is provided for training and general informational purposes. It is not legal advice and does not replace review of the complete opinions, subsequent history, current statutory text, controlling jurisdictional authority, agency policy, or consultation with agency counsel.

© 2026 Shield Public Safety Training. All rights reserved. Reviewed August 10, 2026.