What it means
The statute at the centre of this is extremely broad. It was written long before the modern web and turns on the idea of exceeding authorised access, which prosecutors have at times read to cover ordinary rule-breaking such as sharing a password or collecting data from a public page against a site's terms.
Aaron's Law would replace that elastic language with something closer to getting past a technical barrier. The reform was introduced in Congress in 2013 and has been put forward again in later sessions.
Each attempt has stalled rather than passed, so anyone assessing exposure should check the current wording of the statute and the decided cases rather than assume the reform is in force. The debate itself, though, has already changed how carefully companies write their own access policies.
A finance or business audience should care for an unglamorous reason, which is that internal policy becomes legal risk. If breaching an acceptable use policy can be charged as a crime, then every vague line in a staff handbook is a potential trigger and every data-collection script a vendor runs on your behalf is a question for the risk register.
Narrowing the statute would push most of that back into employment and contract law, where it is normally handled. The practical angle shows up in three places.
Due diligence on any business whose data comes from scraping or from third-party portals needs to test how that access was authorised and whether the terms permit commercial use. Offboarding matters too, because an ex-employee still holding live credentials is a problem for both sides, as is an employee who keeps using a system after permission has been withdrawn.
There is also a plain governance point that survives whatever happens to the bill. Write access rules that say what is actually required, review them, and log who was granted what, because a clear authorisation trail protects the organisation either way.
Treat vague policy wording as a cost to be fixed rather than as harmless small print.
In practice
Real-world examples.
Example
A fintech lender is acquiring a credit-scoring start-up whose model depends on data collected from public web pages. The buyer's diligence team asks how that collection was authorised and whether any source's terms prohibited automated access. The answer drives both the price and the indemnity wording in the purchase agreement.
Example
An investment firm discovers that a departed analyst still has working credentials to a market data portal two months after leaving. Access is cut the same day, the vendor is notified, and the incident prompts a standing control that links system access removal to the payroll leavers report.
Example
A research team wants to download a data provider's full dataset rather than query it page by page, which the provider's terms forbid. Legal advises negotiating a bulk licence instead, because relying on an aggressive reading of the terms creates a risk out of all proportion to the saving.
Case study
Seen in the real world.
Larkspur Analytics is a fictional market-data business used purely as an illustration. It sold industry pricing benchmarks assembled largely from automated collection of competitor websites, and it had grown quickly on the strength of that data.
When a larger group offered to buy it, the diligence team asked a simple question that nobody at Larkspur had documented, which was what authorised the collection of each source. Several sources had terms that prohibited automated access and commercial redistribution, and roughly a quarter of the benchmark coverage traced back to those sources.
The offer fell from an $18,000,000 headline to $14,000,000, with part of the balance held in escrow until the affected feeds were replaced with licensed data. The illustrative point is that the legal uncertainty behind Aaron's Law is not an abstract debate, because it shows up as a discount on a real valuation.
Watch out
Common mistakes.
- Assuming Aaron's Law is settled law, when it is a proposed amendment that has been introduced more than once without being enacted.
- Treating a website's terms of service as a technicality, when access rules can carry consequences well beyond a civil dispute.
- Leaving credentials active after someone leaves, which creates exposure for the former employee and for the organisation at the same time.
Questions
People also ask.
What would the reform actually change?
It would narrow the definition of unauthorised access so that policy and terms-of-service breaches are not automatically treated as federal computer crimes.
Who was it named after?
Aaron Swartz, a programmer and open-access activist who was being prosecuted under the statute at the time of his death in 2013.
What should a finance team do about it?
Document how every external data feed is authorised, tie access removal to the leavers process, and raise unlicensed scraping as a diligence and risk-register item.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
