Law note · New Jersey
New Jersey Computer Criminal Activity, objective reasonable-person authorization test
What it asks of an app
- Whether your access to a New Jersey-connected system is authorized turns on an objective reasonable-person test, not on the target's after-the-fact say-so; an open, unrestricted page with no login wall or technical block tends to favor a reading of authorized access, though no New Jersey court has applied this to a scraping fact pattern.
- There is no statutory notice-based revocation mechanism here comparable to some other states' cease-and-desist rules, so do not assume a bare demand letter alone changes your authorization status under this statute specifically.
When LexLint raises it
crawls_web
What we found
A person is guilty of computer criminal activity if the person purposely or knowingly and without authorization, or in excess of authorization, accesses data, a database, computer storage medium, computer program, software, equipment, a computer, computer system, or computer network, graded as a crime of the third degree for the general access offense.
N.J. Stat. section 2C:20-23(q) defines authorization objectively: permission, authority or consent given by a person who possesses lawful authority to grant it, and an actor has authorization if a reasonable person would believe that the act was authorized.
There is no separate statutory carve-out for publicly available data and no notice-based revocation concept anywhere in the definitions section, so the operative question for an open, unauthenticated page is whether a reasonable person encountering it, with no login wall, technical block, or other denial signal, would believe access was authorized, which tends to favor treating ordinary public-page crawling as authorized absent such a signal.
No reported New Jersey case applies this reasonable-person test to a scraping or public-page fact pattern; State v. Reid, 194 N.J. 386 (2008), the only related decision located, concerns a state-constitutional subpoena question arising from a stolen-credentials fact pattern and does not resolve the authorization element itself.
Primary source
New Jersey Courts' Model Criminal Jury Charge, Computer Criminal Activity, Access (njcourts.gov), quoting the operative statutory text
cross-confirmed against the New Jersey Legislature's own statute database (lis.njleg.state.nj.us)