Skip to content
Home

Computer Misuse Act 1990 (United Kingdom)

UK statute passed in 1990 to criminalise unauthorised access to computer systems, define related offences, and provide a legal framework for prosecution, interpretation, enforcement and international influence.

Overview

The Computer Misuse Act 1990 is primary United Kingdom legislation enacted to criminalise unauthorised access to computer systems and related wrongdoing. It was introduced after high-profile incidents in the 1980s exposed gaps in the criminal law that left computer intrusions effectively unpunished. The Act sets out offences relating to unauthorised access, access with intent to commit further offences, and unauthorised modification or impairment of computer material. The text of the statute and modern guidance are available from official publications and parliamentary materials such as the Act itself and Parliamentary records.

Origins and motivating cases

The legislative impetus included instances in which individuals gained access to commercial viewdata services and were able to read private messages on those systems. A prominent episode involved intrusion into a viewdata service maintained by a telecommunications provider; public accounts of that event noted access to private communications, including material relating to a member of the royal household, which highlighted the absence of appropriate criminal offences at the time (the service involved and contemporaneous case accounts). Lawmakers concluded a specific statutory response was required to deter and punish unauthorised electronic access.

Principal offences

Broadly stated, the Act criminalises several types of conduct commonly associated with hacking and malicious software. These include:

  • Unauthorised access to a computer system, program or data by bypassing security or using another person's credentials without permission;
  • Unauthorised access with intent to commit further offences such as fraud, theft or other wrongdoing;
  • Unauthorised acts intended to impair the operation of computers, or the availability, integrity or confidentiality of data, which can cover denial-of-service attacks and deliberate corruption of information;
  • Unauthorised modification of computer material, a provision used in prosecutions for distributing malware and similar tampering.

Penalties, interpretation and amendments

Penalties under the Act range from fines to custodial sentences, depending on the seriousness of the offence and the defendant's intent. Over time the courts have interpreted the statutory language and Parliament has amended the legislation to address new technologies and threats. Subsequent legislative measures and case law have refined how intent, authorisation and damage are assessed; authoritative updates and summaries of amendments can be consulted in official materials and commentary covering revisions.

Criticism, defences and security research

From its introduction the Act attracted criticism for broad drafting that risked capturing legitimate security research, authorised testing and other benign activities. Early critics argued the statute made little practical distinction between exploratory or well‑intentioned access and deliberately criminal behaviour, prompting calls for clearer statutory defences, guidance for researchers and prosecutorial discretion. Over time, legal guidance, professional standards and policy debate have sought to balance enforcement with the need for responsible vulnerability disclosure and authorised penetration testing; public policy discussions and analyses of those reforms are available elsewhere (policy discussions).

Enforcement and practical application

Investigations under the Act are typically undertaken by specialist police units and prosecutors who work with technical experts to establish whether access was unauthorised and whether intent to commit further wrongdoing or to impair systems can be proved. The Act has underpinned prosecutions involving account compromise, malware distribution and service disruption. It is also relevant to protecting personal data and systems from unauthorised intrusion; guidance on data protection and cyber security practice is published by regulatory and government bodies (data protection resources).

International influence and comparison

The structure and concepts in the Computer Misuse Act have influenced law reform in other jurisdictions. When countries reviewed or drafted computer-crime laws they often considered the UK approach as one of several models; for example, legislative debates and statutes in jurisdictions such as Canada and the Republic of Ireland referenced comparable offences and policy choices. International cooperation on cybercrime, mutual legal assistance and shared standards have further shaped how national provisions are applied in cross-border cases.

Significance

The Computer Misuse Act 1990 remains a cornerstone of UK cybercrime law. While technology and threat landscapes have changed considerably since its passage, the Act continues to provide a legal framework for addressing unauthorised access and related harms. Ongoing debate about scope, defences for legitimate security activity and the interaction with privacy and data-protection law ensures the topic remains a live area for lawmakers, practitioners and researchers.

Questions and answers

Q: Why was the Computer Misuse Act 1990 made?

A: The Computer Misuse Act 1990 was made because there were no laws against hacking, and people could hack into systems and see personal data without breaking the law.

Q: Who hacked into British Telecom's Prestel viewdata service in 1984-1985?

A: Robert Schifreen and Stephen Gold hacked into British Telecom's Prestel viewdata service in 1984-1985.

Q: Why were Robert Schifreen and Stephen Gold not prosecuted for hacking into British Telecom's Prestel viewdata service?

A: Robert Schifreen and Stephen Gold were not prosecuted for hacking into British Telecom's Prestel viewdata service because there were no laws against hacking at the time.

Q: What is the problem with not having laws against hacking?

A: The problem with not having laws against hacking is that people could hack into systems and see personal data without breaking the law.

Q: Has the Computer Misuse Act been amended since 1990?

A: Yes, the Computer Misuse Act has been amended many times since 1990 to keep it up to date.

Q: Did everyone like the Computer Misuse Act when it was made?

A: No, some people did not like the Computer Misuse Act when it was made, saying it was made too quickly and not given much thought.

Q: Does the Computer Misuse Act differentiate between people who hack for fun and people who hack to steal data or money?

A: No, the Computer Misuse Act does not make a difference between people who hack for fun and people who hack to steal data or money.

Related articles

Author

AlegsaOnline.com Computer Misuse Act 1990 (United Kingdom)

URL: https://en.alegsaonline.com/art/22320

Share

Sources