The information provided in this article is for educational and informational purposes only and does not constitute legal, financial, or tax advice. No attorney-client relationship is formed by reading this content. Laws and regulations vary by jurisdiction and change frequently; always consult with a qualified professional regarding your specific situation. The author and publisher assume no liability for any actions taken based on this information.
Key Facts
- Federal level: The CFAA defines “exceeds authorized access” as using authorized computer access to obtain or alter information the accesser is not entitled to obtain or alter.
- Federal level: In Van Buren v. United States, the Supreme Court held that “exceeds authorized access” turns on off-limits areas such as files, folders, or databases, not on improper motives for accessing information.
- Federal level: FOIA requires federal agencies to make responsive records promptly available under published rules when a request reasonably describes the records, subject to statutory exemptions.
- Federal level: FOIA sets a 20-day agency determination deadline and provides an appeal right “not less than 90 days” after an adverse determination.
- Federal level: The Wiretap Act generally bars intercepting wire, oral, or electronic communications, but it includes an exception for electronic communications configured to be readily accessible to the general public.
- Federal level: The Stored Communications Act makes it unlawful to intentionally access, or exceed authorization to access, communications while they are in electronic storage, with provider and user exceptions.
- National overview: ABA Model Rule 4.4 limits evidence-gathering methods that violate third-person legal rights and requires prompt notice for inadvertently sent documents or ESI.
- Federal level: FCRA generally limits when consumer reporting agencies may furnish consumer reports to specified permissible purposes and “no other.”.
- Federal level: For investigative consumer reports, FCRA requires clear written disclosure to the consumer before the report is prepared and additional disclosures about the nature and scope of the investigation when requested.
Last reviewed: May 2026. Legal rules, forms, deadlines, and procedures can change by jurisdiction, agency, and court system.
- Why “publicly available investigative research” can still trigger legal boundaries
- The CFAA turns on “exceeds authorized access,” not just on whether information seems public
- Van Buren limits the CFAA concept when the access is authorized
- A quick map of how federal laws use different “public” ideas
- FOIA as a federal records access mechanism (with statutory timing)
- The Wiretap Act focuses on interception, with an exception for public accessibility
- The Stored Communications Act targets unauthorized access to communications in electronic storage
- Ethics rules can add a rights based constraint to evidence handling
- Consumer data boundaries in investigative research FCRA permissible purposes
- Investigative consumer reports trigger FCRA disclosure duties
- Privacy and “online research” can raise questions even when sources look public
- Another related way privacy issues show up in investigations
- Bottom line the law reads “publicly available” through multiple federal lenses
- Sources
Why “publicly available investigative research” can still trigger legal boundaries
People often describe online investigations as “publicly available” research, but U.S. law treats different kinds of online activity differently. Federal statutes can focus on authorization to access computer systems, whether communications get intercepted, whether content sits in electronic storage, and whether consumer-report information gets furnished for permissible purposes.
The CFAA turns on “exceeds authorized access,” not just on whether information seems public
The Computer Fraud and Abuse Act (CFAA) uses a specific definition for “exceeds authorized access.” Under 18 U.S.C. § 1030(e)(6), that term means to access a computer with authorization and then use that access to obtain or alter information in the computer that the accesser is not entitled to obtain or alter (18 U.S.C. § 1030(e)(6)(2)&num=0&edition=prelim)).
Van Buren limits the CFAA concept when the access is authorized
A common confusion is assuming that “improper purpose” automatically makes access criminal under the CFAA. In Van Buren v. United States, the Supreme Court interpreted the CFAA definition to focus on whether the information came from “particular areas of the computer” that are “off-limits” to the person, such as “files, folders, or databases,” rather than on the person’s motives (Van Buren v. United States (19-783)).
A quick map of how federal laws use different “public” ideas
The phrase “publicly available” can mean very different things depending on the legal rule being analyzed. The table below compares the core trigger each federal framework uses in investigative settings:
| Legal framework | Key boundary it checks | What “publicly available” tends to mean in that framework |
|---|---|---|
| CFAA | Whether the person used authorized access to reach information in off-limits areas (as described in Van Buren) | Access can still be restricted by the system’s off-limits areas even if the target information may appear accessible elsewhere |
| Wiretap Act | Whether communications are intercepted and whether an express exception applies | The statute focuses on whether an electronic communication is configured to be readily accessible to the general public |
| Stored Communications Act | Whether someone intentionally accesses (without authorization or by exceeding authorization) communications while in electronic storage | The statute focuses on electronic storage access and statutory provider/user exceptions |
| FOIA | Whether a request to a federal agency is made under published rules and seeks records the statute covers | “Publicly available” arises through the federal records process, subject to exemptions |
FOIA as a federal records access mechanism (with statutory timing)
When investigators seek records from federal agencies, FOIA supplies a federal process for access to covered records. FOIA provides that “each agency” shall make requested records “promptly available to any person” when the request reasonably describes the records and is made in accordance with published rules, subject to statutory exemptions (5 U.S.C. § 552(a)(3)(A)). FOIA also requires an agency determination within “20 days” after receipt of the request (5 U.S.C. § 552(a)(6)(A)(i)) and provides an appeal right “not less than 90 days” after an adverse determination (5 U.S.C. § 552(a)(6)(A)(ii)(aa)).
The Wiretap Act focuses on interception, with an exception for public accessibility
Federal wiretap law generally prohibits intentional interception of wire, oral, or electronic communications unless a specific exception applies. One express exception says it is “not unlawful” to intercept or access an electronic communication that is “configured so that” it is “readily accessible to the general public” (18 U.S.C. § 2511(g)(i)). This exception illustrates that “public accessibility” in wiretap law depends on how the communication is configured, not simply on whether the information can be discovered through online research.
The Stored Communications Act targets unauthorized access to communications in electronic storage
Separate from wiretapping, the Stored Communications Act (SCA) addresses access to communications that sit in electronic storage. The statute makes it unlawful to intentionally access “without authorization” (or to intentionally exceed authorization) a facility through which an electronic communication service is provided, and thereby obtain or alter access to a wire or electronic communication while it is in electronic storage, unless a statutory exception applies (18 U.S.C. § 2701(a) and (c)). The SCA also includes exceptions for conduct authorized by the communications service provider and for a user with respect to that user’s communications under 18 U.S.C. § 2701(c).
Ethics rules can add a rights based constraint to evidence handling
For lawyers, ABA Model Rule 4.4 treats evidence handling as a legal-rights issue, not only as a technical access issue. Under Rule 4.4(a), a lawyer “shall not use” means or “use methods of obtaining evidence that violate the legal rights of third persons,” and under Rule 4.4(b), a lawyer who receives a document or electronically stored information (ESI) that was inadvertently sent must promptly notify the sender (ABA Model Rule 4.4).
Consumer data boundaries in investigative research FCRA permissible purposes
If an investigation uses consumer-report style information provided through consumer reporting agencies, FCRA controls when consumer reports may be furnished. Under 15 U.S.C. § 1681b(a), “any consumer reporting agency may furnish a consumer report” only under specified circumstances and “no other,” meaning permissible purposes must fit the statute’s list (15 U.S.C. § 1681b(a)).
Investigative consumer reports trigger FCRA disclosure duties
For investigative consumer reports specifically, FCRA imposes disclosure duties tied to how the consumer-report investigation gets prepared. Under 15 U.S.C. § 1681d(a), a person may not procure or cause to be prepared an investigative consumer report unless it is clearly and accurately disclosed to the consumer in a writing mailed or otherwise delivered not later than three days after the report was first requested. The statute also requires additional disclosure obligations upon the consumer’s written request, including a “complete and accurate disclosure of the nature and scope of the investigation” under 15 U.S.C. § 1681d(b) (15 U.S.C. § 1681d(a)–(b)).
Privacy and “online research” can raise questions even when sources look public
Online investigative work can raise privacy questions when personal data gets collected, republished, or repackaged through online workflows. The First File previously covered privacy concerns raised by technology in privacy concerns raised by technology.
Another related way privacy issues show up in investigations
Privacy disputes in the investigative context can also involve tools or services that aggregate personal data at scale. The First File previously discussed these privacy themes in personal information snatchers and privacy risks.
Bottom line the law reads “publicly available” through multiple federal lenses
A workable way to think about “publicly available investigative research” is that different federal rules use different gatekeeping concepts: authorized access and off-limits areas for the CFAA, interception exceptions tied to public configuration for the Wiretap Act, electronic storage access rules for the Stored Communications Act, and permissible-purpose and disclosure duties for FCRA consumer reports. Federal law controls these federal mechanisms, while additional limits can come from state law and state professional conduct rules, so state and federal coverage do not always line up.