High-Profile Identity Theft and Executive Data Misappropriation in California: Penal Code 530.5 PC
Under Penal Code 530.5 PC, identity theft is willfully obtaining another person's personal identifying information and using it for an unlawful purpose without that person's consent.
For an executive who holds the keys to sensitive corporate data or high-net-worth client accounts, the line between a routine business transaction and a felony can turn on a single fact: consent.
When a relationship sours or authorization is later disputed, ordinary access can be recast as theft.
What Does Penal Code 530.5 Criminalize?
Penal Code 530.5 PC reaches more conduct than most people might assume. Under CALCRIM 2040, the state must prove three things:
- First, that you willfully obtained someone else's personal identifying information.
- Second, that you willfully used that information for an unlawful purpose, such as obtaining credit, goods, services, or medical information in another's name.
- Third, that you did so without the consent of the person whose information it was.
Two features make the statute broad. It does not require that you profited or that anyone was actually harmed, since the offense is complete once the information is used for an unlawful purpose.
And under Penal Code 530.55, a person is not limited to a human being. A company, a partnership, an association, or a public entity can be the victim, which is why misusing a firm's corporate identity to open accounts or obtain services falls squarely within the law.
The statute does not stop at active misuse. It separately punishes merely acquiring or retaining someone's information with intent to defraud, and it punishes selling or transferring that information to a person who will misuse it.
For an executive, that means holding a dataset can itself draw scrutiny once fraudulent intent is alleged.
The definition of protected information is equally wide. It covers names, account numbers, passwords, and biometric data, among many other identifiers, whether the target is an individual or an entity.
How Can an Authorized Transaction Become a Felony?
This is where high-profile professionals face the sharpest risk. Executives routinely handle client account numbers, employee records, investor data, and personal financial files as part of their jobs. The trouble begins when the scope of that authorization is contested.
Consider the common flashpoints. A departing executive downloads client files, believing they are entitled to their own work product. An officer uses a company's credentials to complete a transaction that the board later calls unauthorized.
In each case, the underlying access looked routine until someone disputed it. Post-departure downloads are a particularly common flashpoint.
What an executive treats as taking their own contacts, a former employer may report as stealing protected data. Put simply, consent that felt obvious in the moment can evaporate when a business relationship ends badly.
Data misappropriation cases also frequently pair identity theft with a computer-access charge under Penal Code 502 PC, which criminalizes accessing a computer system or data without permission or beyond the scope of permission. One set of facts can therefore generate several counts at once.
What Are the Penalties?
Identity theft is a "wobbler" offense, so prosecutors may file it as a misdemeanor or a felony based on the facts and your record. As such, the sanctions available can vary significantly.
- Misdemeanors can incur up to one year in county jail and up to $1,000 in fines.
- Felonies can incur up to three years in county jail and up to $10,000 in fines.
The multiplier that often surprises executives is counting. Each separate use of protected information is its own count, so a single course of conduct can produce many charges even where there is one named victim.
A pattern of transactions can turn a manageable case into serious felony exposure quickly.
Because identity theft is a crime of moral turpitude, a conviction reaches well beyond the sentence into immigration status and professional licensing.
Courts also routinely order restitution for any losses tied to the misuse. A felony conviction carries a lifetime firearm ban as well, and because the offense turns on deceit, a conviction is the kind of finding that can jeopardize a professional license.
Where Is the Line Between Authorized Access and a Crime?
This is the question that decides most executive cases, and the answer is narrower than an investigator's first theory suggests. Two elements protect legitimate conduct: consent and unlawful purpose.
If you had permission to access the information, or you used it for a genuine business reason rather than an unlawful one, the statute is not satisfied.
Intent does the rest of the work. The law requires willful conduct, so an honest belief that you were authorized, or that the use was permitted, cuts against the charge.
These cases are built almost entirely from access logs, device images, message records, and account histories, which cuts both ways. The same data that appears to show misuse often documents the authorization and the legitimate purpose behind it.
A dispute over who owned a file or whether a transaction was approved is a civil disagreement, not automatically a felony. In short, identity theft requires an unlawful purpose carried out without consent, not merely access that someone later regretted granting.
What are the Related Laws?
When executive identity theft under Penal Code § 530.5 PC is alleged, prosecutors rarely file it in a vacuum. Because corporate data disputes usually involve networks, financial instruments, or trade secrets, several companion statutes frequently appear in the same indictment.
Here are five closely related California offenses commonly charged alongside or in place of executive identity theft:
-
Penal Code § 502 PC – Computer Access Fraud & Data Theft: Targets the act of accessing a network, system, or database without permission. While PC 530.5 addresses misuse of identity data once obtained, PC 502 criminalizes the intrusion into a technical server or the extraction of data itself.
-
Penal Code § 487 PC – Grand Theft: Applies when money, labor, or personal property worth more than $950 is taken. In corporate data disputes, prosecutors assign an objective monetary value to proprietary databases or customer rosters to pursue this as a felony alongside identity theft.
-
Penal Code § 470 PC – Forgery: Covers altering, falsifying, or signing legal or financial instruments without authorization. This is added if an executive uses another officer's digital profile or credentials to ratify contracts, approve corporate spending, or falsify corporate logs.
-
Penal Code § 518 PC – Extortion: Penalizes using an unlawful threat to compel an individual or company to hand over money or property. This surfaces if a departing executive extracts sensitive files and threatens to leak them or expose them to regulators unless a specific severance package is paid.
-
Penal Code § 503 PC – Corporate Fraud / Embezzlement: Defines the fraudulent appropriation of property by someone to whom it was originally entrusted. This charge applies when an executive who had lawful management control over company funds or data assets converts them to personal or unauthorized use.
Frequently Asked Questions (FAQs)
How can a routine business download be charged as identity theft?
The boundary between authorized data access and a felony is consent. Executives routinely handle corporate data sheets, client rosters, and investor portfolios with full authorization. However, if a professional sours their relationship with a firm or departs for a competitor, the company may claim that any downloaded information or local backups exceeded the scope of the employee's permission, recharacterizing ordinary work product extraction as identity theft.
Does a Penal Code § 530.5 PC charge require proof that someone suffered financial loss?
No. Under California law, prosecutors do not need to show that the defendant profited from the data, or that any individual or business suffered actual financial harm. The offense is legally complete the moment protected identifying data is willfully obtained and used for an unauthorized or unlawful purpose. Holding a data set with the mere intent to defraud can be sufficient to trigger a charge.
Can I be accused of identity theft if the data belongs to a corporation rather than a person?
Yes. Under Penal Code § 530.55, the legal definition of a "person" extends far beyond a human being. It explicitly encompasses corporations, partnerships, business associations, and public entities. Misusing a firm's tax ID numbers, corporate bank routing data, or encrypted business credentials to open accounts or move funds falls squarely under the identity theft statute.
How do prosecutors multiply charges in a single executive data dispute?
In white-collar data cases, prosecutors use counting to dramatically expand exposure. Each distinct use of an account number, password, or identifier can be filed as an independent, standalone count of identity theft. If a departing manager utilizes a corporate credential to complete a sequence of several transactions, they can face a long string of felony counts from a single event.
What is the relationship between identity theft and Penal Code § 502 PC?
When corporate data is allegedly taken, prosecutors almost always pair identity theft with computer access fraud under Penal Code § 502 PC. While Section 530.5 focuses on the unauthorized use of the data itself, Section 502 penalizes accessing the network, server, or software to extract that data without permission. This allows the state to pursue multiple theories of liability simultaneously from one data download.
How does a defense team beat an executive identity theft charge before court?
Defenses generally focus on establishing colorable authorization and the absence of an unlawful purpose. By compiling employment agreements, company-wide data-retention policies, internal correspondence, and client transition requests, defense counsel can show that the executive operated under a good-faith belief that their access was approved. Presenting this transaction history during the prefiling window can steer a prosecutor toward treating the matter as a civil contract dispute rather than a crime.
The Contested Client List
A wealth-management executive leaves one firm and begins working for a competitor. He takes a spreadsheet of client contact and account details, intending to service the same clients at the new shop.
The former employer reports the departure as identity theft and computer fraud, and a District Attorney files charges under Penal Code 530.5 and 502.
The defense assembles the executive's employment agreement, the firm's own policy allowing advisors to keep client relationships, the onboarding paperwork from the new firm, and messages showing several clients had asked to move with the advisor.
Because the executive had at least colorable authorization and used the data for a lawful business purpose rather than to defraud, both the consent element and the unlawful-purpose element are weakened.
Presented before charges were finalized, this record persuaded the prosecutor that the matter was a contract dispute between firms, not a crime, and the case closed without a filing.
How Are These Cases Defended, and Why Does Early Action Matter?
Strong defenses in these cases target consent and unlawful purpose, the two elements prosecutors most often assume rather than prove.
Defense counsel may show documented authorization or demonstrate that the data was used for a legitimate business purpose. Others attack intent, since a good-faith belief in permission defeats the willfulness the statute demands.
These files often overlap with grand theft and other white-collar crimes, so early framing shapes what a prosecutor ultimately charges.
For a high-profile executive, the timing is decisive. A filed charge can trigger a board inquiry and reach the industry press long before any hearing.
The window between an internal complaint and a criminal filing is the most valuable stretch of the entire matter.
During pre-filing intervention, defense counsel can present the authorization record and the business rationale directly to prosecutors and argue that the conduct was permitted rather than fraudulent.
In the right case, that work resolves the exposure quietly, protecting both the client's liberty and a reputation that a single headline can damage for years.
As such, in executive identity theft cases, the outcome usually turns on consent and intent, and the most important move is often made before the first court date, while the record can still show the access for what it was.
To ensure you have a strong defense, contact the attorneys at Eisner Gorin LLP today.

If you have one phone call from jail, call us! If you are facing criminal charges,