APPENDICES

5.20 Access of any kind by any person to any program held in a computer is "unauthorised" if they

are not entitled to control access of the kind in question to the program or data, or do not have the consent to access the kind of program or data in question from any person so entitled.448 The section identifies two ways in which authority may be acquired – either by being oneself the person entitled to authorise access or by being a person who has been authorised by a person entitled to authorise access. It also makes clear that the authority must relate not simply to the data or programme, but also the actual kind of access secured.449

5.21 There is some uncertainty as to whether an offence is committed under s1 by a person

who is authorised to secure access to particular computer material, or data, but does so for unauthorised purposes.450 The leading authority on this point under the Data Protection Act 1984 (now repealed) was DPP v Bignell, in which the Court held that the retrieval of information from the police national computer (PNC), by someone with the proper authority under the Computer Misuse Act 1990, but at the request of others who were to use the data for non-police purposes, was a matter for the Data Protection Act 1984 or for police disciplinary proceedings rather than the Computer Misuse Act 1990.451 However, dicta in DPP v Bignell which related to the Computer Misuse Act 1990 were disapproved in R v Bow Street Metropolitan Stipendiary Magistrate, ex p Government of the United States of America which held that the Computer Misuse Act 1990 prevented someone with the authority to access data at a particular level on a computer system from accessing other data held on the same system for improper purposes, on the basis that such access will be unauthorised access within the meaning of section 1(1).452 It therefore remains unclear as to whether a person who had authorised access to information held on a computer, for example the PNC, but accesses this information for improper purposes, for example to sell it to a journalist, would commit an offence under s1 as well as s55 of the DPA. In a number of cases involving misuse of information held on police computers, offenders have been prosecuted for misconduct in public office rather than under the 1990 Act.453

5.22 Section 2 covers unauthorised access to computer material pursuant to s1, with the intent

to commit an offence or to facilitate the commission of further offences. The basis notion is that someone guilty of an offence under s1 will have further criminal sanctions imposed on them if this is done with the intention to commit or facilitate the commission of further offences, although it is not necessary to prove that the intended further offence has actually been committed.

5.23 Further offences for the purposes of s2 are offences which have a sentence fixed by law or

where an individual found guilty of that offence would be liable for a term of imprisonment of five years or more. For example, a person will be guilty of an offence under s2 if unauthorised access to sensitive information held on a computer was obtained for the purposes of blackmailing a person to whom that information related, or where unauthorised access was obtained for the purposes of theft.

5.24 It is immaterial for the purposes of s2 whether the further offence is to be committed on the same occasion as the unauthorised access or on any future occasion and a person can s17(5)

1931

be guilty of the offences under s2 even though the facts are such that the commission of the further offence is impossible.454

5.25 Section 3 creates an offence for unauthorised modification. A person is guilty of an offence

if they do any unauthorised act in relation to a computer, knowing at the time that it is unauthorised and either: (a) they intend by doing the act to impair the operation of any computer, to prevent or hinder access to any program or data held in any computer, or to impair the operation of any such program or the reliability of such data;455 or (b) they are reckless as to whether the act will do any of these things.456

5.26 A person found guilty of this offence is liable on conviction on indictment to imprisonment for

a term not exceeding ten years and/or to a fine, or on summary conviction to imprisonment for a term not exceeding six months and/or a fine not exceeding the statutory maximum.457

5.27 Section 3A relates to the making, supplying or obtaining of articles for use in offences under

ss1 or 3. Section 3A provides that a person is guilty of an offence if a) they make, adapt, supply or offer to supply any article intending it to be used to commit, or to assist in the commission of, an offence under ss1 or 3, (b) they supply or offer to supply any article believing that it is likely to be used to commit or to assist in the commission of an offence under ss1 or 3, (c) they obtain any article with a view to its being supplied for use to commit, or to assist in the commission of, an offence under ss1 or 3. For the purposes of s3A "article" includes any program or data held in electronic form.458

5.28 There are no guideline cases on sentencing for offences under the Computer Misuse Act

  1. In the case of Delamere, an employee who sold confidential details of two bank account holders was sentenced to four months' detention.459 In the case of Lindesay a computer consultant who corrupted a website of a client company which had dismissed him was sentenced to nine months imprisonment following a guilty plea to three s3 offences.460

Section 55 Data Protection Act 1998 5.29 Section 55(1) makes it a criminal offence to knowingly or recklessly, without the consent

of the data controller, (a) obtain or disclose personal data or the information contained in personal data, or (b) procure the disclosure to another person of the information contained in personal data, subject to specified defences in s55(2). This is considered above at 4.59.

1932