United States of America (R on the Application of) v Bow Street Magistrates' Court; Ex parte Government of the United States of America

[1999] UKHL 31

Case details

Case citations
[1999] UKHL 31
Court
House of Lords
Judgment date
5 August 1999
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Criminal law Extradition Computer misuse
Keywords
unauthorised computer access insider access authority to access data computer misuse extradition crime conspiracy habeas corpus judicial review data access permissions
Outcome
appeal allowed unanimously (5–0); discharge quashed and matter remitted to the magistrate
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

An employee or other authorised user commits the unauthorised-access offence where the user intentionally accesses actual data which falls outside the authority granted, while knowing that the access is unauthorised. Authority to access other data of the same kind does not suffice.

Under sections 1 and 17 of the Computer Misuse Act 1990, the relevant distinctions are between kinds of access, such as viewing, copying and altering, and between the particular programs or data covered by the authority. The offence is not confined to external hacking.

Section 15 also makes offences under sections 2 and 3, and the specified related conspiracies and attempts, extraditable through an existing extradition order which covers any other offence satisfying its conditions.

Factual background

The United States sought Mr Allison's extradition for an alleged conspiracy with an American Express employee. The employee could technically access all customer accounts, but her authority extended only to accounts assigned to her. Information obtained from other accounts was allegedly used to forge cards and steal money.

The Bow Street magistrate committed Mr Allison on one charge but discharged him on two charges alleging conspiracy to secure unauthorised access with intent to commit theft and forgery. Mr Allison challenged whether the alleged offences were extradition crimes. The United States challenged the discharge of the first two charges.

The Divisional Court, Kennedy LJ and Blofeld J., dismissed both challenges in [1999] Q.B. 847. The United States appealed. The principal issues were whether section 15 of the Computer Misuse Act 1990 made the alleged computer offences extraditable and whether an employee with access to some data acts without authority when accessing particular data outside the limits of her employment.

Held

  1. Appeal allowed unanimously. Lord Hobhouse of Woodborough delivered the leading speech. Lord Steyn, Lord Hutton, Lord Saville of Newdigate and Lord Millett agreed with his reasoning. The order of the Divisional Court was set aside, the magistrate's discharge of Mr Allison on the first and second proposed charges was quashed, and the matter was remitted to the magistrate.

  2. Per Lord Hobhouse, section 15 of the Computer Misuse Act 1990 makes offences under sections 2 and 3, together with the specified conspiracies and attempts, extraditable for the purposes of an Order in Council made under section 2 of the Extradition Act 1870. No amendment to the treaty or the 1976 Order was required. Article III covered not only the offences listed in its Schedule but also any other offence satisfying its conditions. The habeas corpus proceedings therefore rightly failed.

  3. Per Lord Hobhouse, section 17(2) of the Computer Misuse Act 1990 defines distinct kinds of access, including altering, copying, using and obtaining output. Section 17(5) correspondingly requires attention to authority for the kind of access in question. Its two cumulative requirements identify the two sources of authority: the user may personally be entitled to authorise the access, or may have consent from someone so entitled.

  4. The word “control” in section 17(5) means the entitlement to authorise or forbid access. It does not mean physical capacity to operate the computer. Authority must extend both to the relevant kind of access and to the actual program or data accessed. Authority to access one item does not authorise access to another item merely because both are data of the same kind.

  5. On the evidence, the employee intentionally caused the computer to provide data which she knew she was not authorised to access. Her conduct fell within section 1(1). Section 1 is not confined to external hacking or conduct affecting an abstract authorised level within a computer system. It includes an insider who knowingly exceeds clearly defined limits upon access to particular programs or data.

  6. The result in D.P.P. v Bignell [1998] Cr.App.R. 1 was probably correct because the authorised computer operator had not exceeded his authority. Its broader statements concerning control, levels of access and the confinement of the Act to hacking introduced glosses absent from the statutory language. Those statements were unnecessary to that decision and had misled the magistrate and the Divisional Court.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Appellate history

  1. House of Lords: In [1999] UKHL 31, unanimously allowed the United States' appeal, set aside the Divisional Court's order, quashed the magistrate's discharge on the first and second proposed charges, and remitted the matter to the magistrate.

  2. Divisional Court of the Queen's Bench Division: Kennedy LJ and Blofeld J. dismissed both Mr Allison's habeas corpus proceedings and the United States' judicial review proceedings in [1999] Q.B. 847, but certified a question of law of general public importance.

  3. Bow Street Magistrates' Court: Committed Mr Allison on the third proposed charge but declined to commit him on the first and second charges.

Lower court decision

Judgment appealed:
[1999] QB 847
Outcome:
appeal allowed unanimously (5–0); discharge quashed and matter remitted to the magistrate

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.