RulesofCivilProcedure.com Civil Procedure · Every State

Tex. Civ. Prac. & Rem. Code §§ 143.001, 143.002; Tex. Penal Code ch. 33

Harmful access by computer in Texas — chapter 143, and why it beats the federal statute

A claim in Texas district and county courts · Last verified August 26, 2026

Chapter 143 is two sentences long and does more work than its length suggests. It converts a violation of the computer crimes chapter of the Penal Code into a civil claim, adds mandatory attorney's fees, and imposes no minimum loss — which is the whole reason to plead it beside the federal Computer Fraud and Abuse Act.

It is the standard claim in a departing-employee case, and increasingly in a domestic one.

What the claim is

Someone accessed your computer, network, system or accounts without your permission, knowingly or intentionally, and it caused you or your property harm.

Where the right comes from

CPRC § 143.001, which piggybacks on Penal Code chapter 33.

What a plaintiff has to prove

Section 143.001(a): "A person who is injured or whose property has been injured as a result of a violation under Chapter 33, Penal Code, has a civil cause of action if the conduct constituting the violation was committed knowingly or intentionally."

Three elements:

  1. Injury to the person or the person's property;
  2. Resulting from a violation of Penal Code chapter 33; and
  3. Conduct committed knowingly or intentionally.

The predicate offence is usually breach of computer security under Penal Code § 33.02, which is committed by knowingly accessing a computer, computer network or computer system without the effective consent of the owner. Chapter 33 also reaches online impersonation, unauthorised use of identifying information, and tampering with data.

No criminal charge is required. The plaintiff proves the elements of the offence in the civil case.

Almost every contested chapter 143 case is an argument about authorisation, and the two recurring patterns are these.

The departing employee. Someone with valid credentials downloads the customer list, copies the files, or wipes the laptop on the way out. The defence is that they had a password and were allowed to use it. The answer is that consent is bounded by its purpose — permission to use a system for the employer's business is not permission to take its data for a competitor. A written computer use policy is what makes this argument work, and its absence is what makes it hard.

The former partner. Someone logs into an email account, a phone, a cloud backup or a social media account after the relationship ends. Shared passwords during the relationship are the defence, and the question is whether consent survived it.

How long you have to file

Section 143.001(b): suit must be brought "before the earlier of the fifth anniversary of the date of the last act in the course of the conduct constituting a violation under Chapter 33, Penal Code, or the second anniversary of the date the claimant first discovered or had reasonable opportunity to discover the violation."

A two-year discovery period inside a five-year outer limit. Two consequences follow.

Intrusions are often found late, and the discovery rule is written into the statute rather than argued for — which is unusual in Texas, where the discovery rule is a narrow exception.

The five-year limit is absolute. An intrusion discovered in year five is time-barred immediately, whatever the discovery date. The clock runs from the last act in the course of the conduct, so a continuing intrusion keeps resetting the outer limit while it continues.

What has to happen before you file

Nothing. As a practical matter, forensic preservation is the first step — the logs, the device images, the access records — because chapter 33 turns on what was accessed, when, and by whom.

What the claim pays

Section 143.002: "A person who establishes a cause of action under this chapter is entitled to:

  1. actual damages; and
  2. reasonable attorney's fees and costs."

"Is entitled to" is mandatory language. The fee award is not discretionary, and it runs one way, to the claimant.

Actual damages cover the cost of investigation and remediation, the value of what was taken or destroyed, lost business, and the cost of restoring systems and data.

No statutory damages, and no exemplary damages under the chapter — though chapter 41 exemplary damages are available on a companion tort claim where malice is proved.

Against the federal statute

The Computer Fraud and Abuse Act, 18 U.S.C. § 1030, is the parallel federal claim, and plaintiffs routinely plead both. The differences favour chapter 143 on most facts.

CPRC ch. 143CFAA
Loss thresholdNone$5,000 in one year, for most claims
Attorney's feesMandatoryNot provided
Deadline5 years / 2 from discovery2 years from discovery
ForumState courtFederal question jurisdiction

The loss threshold is the practical difference. A snooping spouse, a copied contact list or an account takeover may cause real harm without $5,000 in quantifiable loss, and the federal claim fails where the state claim does not.

The federal claim keeps two advantages: it supports removal to federal court, and it reaches conduct across state lines without an argument about which state's computer statute applies.

Who can be sued

The person who accessed the system. Their employer, where the access was within the course and scope of employment — which is how a competitor becomes a defendant when it hires away an employee who brought files.

A person who conspired in the access, through civil conspiracy, which carries the underlying claim's limitations period.

What it is usually pleaded with

Chapter 143 rarely travels alone, and its fee provision is often the reason a case is economically viable at all:

Common defenses

  • Effective consent — the defendant was an authorised user, or the plaintiff shared the password.
  • Access within the scope of the permission granted.
  • No knowing or intentional conduct — the access was accidental or automated.
  • No injury to the person or their property.
  • Limitations, on either the two-year discovery period or the five-year outer limit.

What people get wrong

You do not need $5,000 in loss. That is the federal threshold. Chapter 143 has none.

Fees are mandatory. A claimant who establishes the cause of action is entitled to reasonable attorney's fees and costs.

Credentials are not a defence by themselves. Authorisation is bounded by its purpose, and exceeding it can violate chapter 33.

The deadline is the earlier of the two periods. Discovering an intrusion at year four and eleven months leaves a month, not two years.

No criminal case is required. The civil claim proves the offence on its own.

Where it came from

Texas enacted its computer crimes chapter in 1985 and added the civil remedy in 1989, well before most states had either. The structure — a civil claim keyed to a criminal chapter — kept the civil side current automatically, because every expansion of Penal Code chapter 33 widens chapter 143 without amending it.

The fee provision is what made the claim useful. Computer intrusions produce diffuse harm: the data was copied, not destroyed, and the loss is in what the defendant can now do with it. Damages in those cases are often smaller than the forensic work needed to prove them, and without a fee award the claim would not be worth bringing.

Its practical importance has grown as employment has become portable. The claim that began as a remedy against hackers is now, in most Texas cases, a remedy against the person who used to work there.

Common questions

How long do I have to sue for unauthorised computer access in Texas?

The earlier of five years from the last act or two years from when you discovered, or had reasonable opportunity to discover, the violation.

Do I need to prove $5,000 in damages?

No. That is the federal CFAA threshold. Chapter 143 has no dollar threshold.

Are attorney's fees recoverable?

Yes, and they are mandatory. A claimant who establishes the claim is entitled to reasonable fees and costs.

Can I sue an employee who had a valid password?

Yes, if the access exceeded what the permission covered. Consent is bounded by its purpose.

Do I need a criminal conviction first?

No. The civil case proves the Penal Code violation on its own.

Can I sue an ex who logged into my email?

Yes, if the access was without your effective consent and caused you or your property injury.

Where these rules live

How this page is sourced. The statutory language quoted here is reproduced from the official text at Tex. Civ. Prac. & Rem. Code §§ 143.001, 143.002; Tex. Penal Code ch. 33. Court decisions are named for what they hold, not quoted from any commentary. The procedural rules referred to are reproduced verbatim on their own pages on this site. Everything else is original writing. Last verified August 26, 2026.
This page explains what the law says. It is legal information, not legal advice, and it cannot tell you whether you have a claim. Filing deadlines are short, several of the prerequisites below cannot be cured once missed, and the law in your circuit may differ — if the outcome matters, talk to a lawyer.