Prestel

Daily Tech History: August 29, 1990 — The UK’s Computer Misuse Act Takes Effect

Vintage 1990s-era computer, evoking the era of the UK's Computer Misuse Act

On August 29, 1990, the United Kingdom’s Computer Misuse Act came into force, becoming one of the first laws anywhere in the world written specifically to criminalize hacking. It had received Royal Assent two months earlier, on June 29, but this was the day it actually took effect and started governing what counted as a computer crime.

The law existed because of an embarrassing gap earlier in the decade. In 1984, two hackers, Robert Schifreen and Stephen Gold, talked their way into British Telecom’s Prestel network — at one point even poking around in the private mailbox of Prince Philip, the Duke of Edinburgh. When they were eventually caught and prosecuted, the case (R v Gold & Schifreen) fell apart on appeal, because Britain simply had no law that treated unauthorized computer access as a crime; prosecutors had tried to stretch old forgery statutes to fit, and the House of Lords wasn’t buying it. Parliament responded with the Computer Misuse Act, which created three specific offenses: unauthorized access to computer material, unauthorized access with intent to commit a further crime, and unauthorized modification of computer material.

More than three decades later, the Act is still on the books and still the primary UK statute prosecutors reach for in hacking cases, though it’s been amended over the years and remains a point of debate — security researchers have long argued its broad wording makes it risky to do legitimate penetration testing or vulnerability disclosure without careful legal footing. Love it or criticize it, it set an early template that plenty of other countries’ computer crime laws would later echo.

Source: Wikipedia — Computer Misuse Act 1990 and Computer History Museum — This Day in History

Daily Tech History is a running series looking back at notable moments in technology on this date.