Definition

A criminal-law concept describing conduct, procedure, or legal consequence defined by governing offense or rule elements. It applies only when the legally specified conditions for its use or enforcement are satisfied. It does not apply where required elements or conditions are absent. It materially affects charging, adjudication, detention, or sanction decisions in practice. The concept is generally stable, though elements and penalties may be revised over time.

Principle

Principle
Protecting confidentiality and lawful control of information; unauthorized access to data occurs when technical or procedural protections are bypassed and no lawful permission exists to view or acquire the data.

Demonstration

Demonstration
An attacker performs SQL injection against a web application to export customer records, or an employee copies a restricted database export to a personal device without permission.

Misapplication

Misapplication
Treating any access to non-sensitive metadata or data cached temporarily as illicit; assuming encryption always converts access into authorization status without context.

Consequence

Consequence
Correctly classifying data access as unauthorized triggers data breach response, potential notice obligations, privacy remedies for affected individuals, and criminal or civil liability for the actor.

Reversal

Reversal
Authorized data access: reading, copying, or exporting data under valid consent, policy authorization, or legal process acknowledged by the data controller.

Boundary

Boundary
Covers acts against data confidentiality and exfiltration irrespective of physical location; excludes use of freely published or explicitly shared data, and legitimate discovery or compliance processes.

Semantic Tension

Semantic Tension
Overlaps with network access and system tampering when those actions are the means to obtain data; contrasted with computer fraud when deception or financial loss is the central element.

Synthesis

Synthesis
Unauthorized access to data is the specific infraction of obtaining or interacting with information held by a system without the controller’s permission, undermining privacy and data governance obligations.