Law / United States /
New Jersey
New Jersey Computer Criminal Activity, objective reasonable-person authorization test
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 14 April 2003.
A computer misuse rule binding public and private bodies.
As of 29 August 2026.
What it requires
- Whether your access to a New Jersey-connected system is authorized turns on an objective reasonable-person test, not on the target's after-the-fact say-so; an open, unrestricted page with no login wall or technical block tends to favor a reading of authorized access, though no New Jersey court has applied this to a scraping fact pattern.
- There is no statutory notice-based revocation mechanism here comparable to some other states' cease-and-desist rules, so do not assume a bare demand letter alone changes your authorization status under this statute specifically.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
A person is guilty of computer criminal activity if the person purposely or knowingly and without authorization, or in excess of authorization, accesses data, a database, computer storage medium, computer program, software, equipment, a computer, computer system, or computer network, graded as a crime of the third degree for the general access offense.
N.J. Stat. section 2C:20-23(q) defines authorization objectively: permission, authority or consent given by a person who possesses lawful authority to grant it, and an actor has authorization if a reasonable person would believe that the act was authorized.
There is no separate statutory carve-out for publicly available data and no notice-based revocation concept anywhere in the definitions section, so the operative question for an open, unauthenticated page is whether a reasonable person encountering it, with no login wall, technical block, or other denial signal, would believe access was authorized, which tends to favor treating ordinary public-page crawling as authorized absent such a signal.
No reported New Jersey case applies this reasonable-person test to a scraping or public-page fact pattern; State v. Reid, 194 N.J. 386 (2008), the only related decision located, concerns a state-constitutional subpoena question arising from a stolen-credentials fact pattern and does not resolve the authorization element itself.
Section 4 of the founding act, P.L. 1984, c.184 (C.2C:20-25), was most recently revised by P.L. 2003, c.39 (effective 14 April 2003, per the NJ Division of Criminal Justice's own codification table), which expanded the offense's degree range from third to first and added the mandatory-minimum-sentence provision now at subsection g.; the objective reasonable-person authorization test in section 2C:20-23(q) is unchanged since then.
When LexLint raises it
crawls_web
Read the law
New Jersey Courts' Model Criminal Jury Charge, Computer Criminal Activity, Access (njcourts.gov), quoting the operative statutory text
cross-confirmed against the New Jersey Legislature's own statute database (lis.njleg.state.nj.us); effective_date sourced to the NJ Division of Criminal Justice's 2003 codification table (nj.gov/oag/dcj), which dates C.2C:20-23 through C.2C:20-25 to P.L. 2003, c.39, effective 2003-04-14
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.