Law note · Florida
Florida Computer-Related Crime Act (dual without-authorization and exceeding-authorization prongs)
What it asks of an app
- Do not assume Florida's exceeding-authorization prong is read as narrowly as the federal Computer Fraud and Abuse Act (CFAA)'s; Van Buren construes only the federal statute and no Florida decision has extended its reasoning here.
- Defeating an access control exposes you to a civil remedy under section 815.06(5)(a) available to the computer's owner or lessee, in addition to criminal liability.
When LexLint raises it
crawls_web
What we found
Section 815.06(2) provides that a person commits an offense if he or she willfully, knowingly, and without authorization or exceeding authorization accesses or causes access to any computer, computer system, computer network, or electronic device with knowledge that such access is unauthorized or the manner of use exceeds authorization, among other prohibited acts such as denial of service, destruction of data, and introduction of malware.
Unlike a single-prong without authorization statute, section 815.06 explicitly names both prongs the Computer Fraud and Abuse Act (CFAA) is built on, the exact wording Van Buren v. United States (593 U.S. 374, 2021) narrowed for the federal statute; that holding construes the federal CFAA and does not bind a Florida court's reading of its own statute, so Florida's exceeding-authorization prong is not automatically read narrowly simply because the federal one now is.
Section 815.06(5)(a) also creates a civil remedy for the owner or lessee of the computer harmed by a violation. No Florida appellate decision squarely addresses public-page scraping under this section. The section originates in ch. 78-92 (1978), but the exceeding-authorization prong quoted above was not yet present as of the 2018 codification; it was added by section 40 of ch. 2019-167, so this document dates the section to that amendment's commencement rather than to the 1978 original.