Privacy Law Library

Computer Fraud and Abuse Act

CFAA

Data security · Other

The CFAA is an anti-hacking law, included here because section 1030(a)(2) protects the confidentiality of information on computers, including financial records, consumer reports, and information on any protected computer. It is the main federal basis for prosecuting data theft and gives victims of unauthorized access a civil remedy.

Where
Federal
Citation
18 U.S.C. 1030
Status
In force
In force since
1984-10-12
Last amended
2020-10-20
Enforced by
U.S. Department of Justice (criminal); private civil actions by persons suffering damage or loss
People can sue
Limited
Penalties
Criminal fines and imprisonment scaled by offense; civil actions for compensatory damages and injunctive relief if a statutory harm threshold (e.g., $5,000 in loss) is met.
Applies to
  • Any person who accesses a protected computer without authorization or exceeds authorized access

Practices it requires

  • Do not intentionally access a protected computer without authorization, or exceed authorized access, and thereby obtain information.18 U.S.C. 1030(a)(2)(C)
  • Do not obtain financial institution records or consumer reporting agency files through unauthorized access.18 U.S.C. 1030(a)(2)(A)
  • Do not traffic in passwords or similar access information with intent to defraud.18 U.S.C. 1030(a)(6)

Other duties

  • Persons suffering damage or loss may sue within two years if a listed harm factor is met.18 U.S.C. 1030(g)

Sources

Checked against these sources on 2026-09-25 by research agent (Claude), primary sources.

Unverified: 1030(a)(6) wording was not re-read | effective_date is the enactment date of Pub. L. 98-473

Research reference, not legal advice.