From: Law.com/Corporate Counsel

By Andrew M. Hinkes

As businesses rely upon computer technology to store valuable, protected data, they have also been forced to trust their employees who access that data. Although many state and federal statutes exist to punish employees who misappropriate confidential or trade secret-protected information, there is a split among federal circuit courts as to whether employees who have access to employer computer systems violate the Computer Fraud and Abuse Act when they misappropriate employer information they are permitted to access and use that information to damage their employer.

In  U.S. v. Nosal, 676 F.3d 854 (9th Cir. 2012), the U.S. Court of Appeals for the Ninth Circuit joined the majority of federal circuit courts in holding that when an employer has given employees access to its systems, employees do not “exceed authorized access” as defined by the CFAA, when those employees misappropriate information from those systems. The Eleventh Circuit takes the opposite, minority approach, interpreting the CFAA to make criminal unauthorized use of employer information. This minority position allows employer policies to determine whether an employee act violates federal law.

The CFAA, enacted in 1984, is showing its age. The law was originally intended to punish computer hacking but the rapid advance in technology and today’s ubiquitous use of computers is pushing courts to awkwardly apply the CFAA’s legal framework to present-day problems.

Most violations of the CFAA require a potential violator to exceed authorized access on a computer system, which is defined in 18 U.S.C. 1030(e)(6) as “to access a computer with authorization and to use such access to obtain or alter information in the computer that the accesser is not entitled so to obtain or alter.” To violate the statute, must one simply access information to which they are not entitled? Or does the violation occur when the obtained — perhaps legitimately — information is used in an unauthorized manner?

In  Nosal, the U.S. charged Nosal under the CFAA for aiding and abetting other employees to use their legitimately issued credentials to access their employer’s system and obtain information later used to damage the employer. The issue was whether “exceeds authorized access” should refer to a person who is authorized to access certain systems but accesses unauthorized data, or a person with authorized access to the computer system, but who is limited to in the use to which he can put the data by employer policy or contract.

The Ninth Circuit joined the majority of federal circuits by adopting the first interpretation, holding that the phrase “exceeds authorized access” in the CFAA “is limited to violations of restrictions on access to information, and not restrictions on its use.” The court noted in its opinion that the broader reading would necessarily rely upon the employer’s definition of “authorization” to determine what is a violation and potentially render otherwise innocuous behavior to be a federal crime simply because a computer is involved. The majority set forth a variety of absurd situations which the broad reading might criminalize, such as violating the terms of service of a social networking website or accessing a website.

The Eleventh Circuit, however, adheres to the broader approach. In  U.S. v. Rodriguez , 628 F.3d 1258 (11th Cir. 2010), a case originating in Florida, the defendant used his employer’s database to look up personal acquaintances, violating his employer’s policy which prohibited employees from using its databases for non- business reasons. The Eleventh Circuit in  Rodriguez  adopted an employer policy-based, intended-use approach, which effectively allows employers to define the scope of a federal crime through their policies.

Under the narrow  Nosal  interpretation, potential liability under the CFAA depends on the person’s access. An employer who allows employees to use work computers gives them authorization to access any information they can reach without “the circumvention of technological access barriers,” such as passwords or firewalls. This allows for prosecution of insider hackers, but does not allow prosecution of misappropriators. As noted in  Nosal, “this narrower interpretation is also a more sensible reading … of a statute whose general purpose is to punish hacking … not misappropriation of trade secrets — a subject Congress has dealt with elsewhere.”

Although the broad, intended use approach still applies in Florida, employers should use caution when developing data protection strategies. Employers should both develop and enforce computer access and data-use policies. In light of the Ninth Circuit’s ruling, it would be wise to implement additional security procedures, such as password protection and restricting access to systems containing valuable data.

Although the split among circuits over the CFAA may soon be argued before the Supreme Court, Congress may act first. The Personal Data Privacy and Security Act of 2011 is currently before the Senate. The bill would amend the CFAA to eliminate civil actions for unauthorized use of a protected computer that are based solely on a violation of “a contractual obligation or agreement, such as an acceptable use policy or terms of service agreement, with an Internet service provider, Internet website, or non-government employer.” Until then, claims under the CFAA in Florida will continue to be given broad interpretation, and arguably, allow employers to define a federal criminal violation by its employee policies.

Andrew M. Hinkes is an attorney with Berger Singerman. He focuses on contract litigation, business torts, real estate-related litigation, representation of court-appointed receivers, employment-related litigation and construction litigation.