# Unauthorized Person

> Unauthorized Person means any individual accessing data or performing activities without required assignment or express authorization.

**Term:** Unauthorized Person  
**Last updated:** 2026-07-29

## Definition

## What Unauthorized Person Means in a Contract

An Unauthorized Person is a defined term used across commercial, technology, and employment agreements to describe anyone who acts, accesses, or interferes with something covered by the contract without holding the required assignment, credential, or express consent. The concept exists to draw a clear boundary between people who are entitled to touch confidential information, systems, funds, or premises and those who are not, so that any crossing of that boundary can be identified, reported, and remedied under agreed procedures.

The term rarely stands alone. It is almost always tied to obligations elsewhere in the agreement, such as confidentiality clauses, data security schedules, or access control provisions. When a party promises to prevent access by an Unauthorized Person, that promise only has teeth if the contract also explains who counts as authorized, how authorization is granted, and what evidence proves it.

In practice, this definition helps allocate risk. If a data breach or unauthorized disclosure occurs, the first question is often whether the person involved fell inside or outside the authorized group. A precise definition removes ambiguity from that inquiry and supports faster incident response.

## How Unauthorized Person Is Defined or Measured

Most definitions hinge on two elements: the absence of a formal assignment or role, and the absence of express permission from the party who controls the resource in question. Contracts typically measure authorization against an internal record, such as an access control list, a signed [authorization letter](https://www.genieai.co/en-us/template-type/authorization-letter), or a role assigned under an [assignment agreement](https://www.genieai.co/en-us/template-type/assignment-agreement). If a name or role is not on that record, the individual is treated as unauthorized regardless of their intentions.

Some agreements measure authorization dynamically, meaning that a person who was once authorized becomes unauthorized the moment their role ends, their credentials are revoked, or a project concludes. Others tie the status to a specific document, such as a [certificate of authorization](https://www.genieai.co/en-us/template-type/certificate-of-authorization), which must remain valid and unexpired.

- Lack of an assigned role or job function covering the activity
- Absence of written or system-based permission
- Expired, revoked, or never-granted access credentials
- Actions taken outside the scope of an existing authorization

## Where Unauthorized Person Appears in Agreements

The term appears frequently in data protection schedules, confidentiality clauses, and IT security policies. It is a common feature of a [data processing agreement](https://www.genieai.co/en-us/template-type/data-processing-agreement), where the processor must warrant that no Unauthorized Person will access personal data, and in a [data protection addendum](https://www.genieai.co/en-us/template-type/data-protection-addendum) attached to a wider commercial contract.

It also surfaces in employment and assignment documents, where a company wants to ensure that only employees with a specific assignment can access certain files, funds, or client accounts. Physical security clauses in construction, real estate, and facilities contracts use the term to restrict entry to sites or restricted areas.

Industries handling sensitive information, including healthcare, finance, and technology, rely heavily on this term within incident response and breach notification provisions, since regulators and counterparties expect a clear account of who touched affected systems.

## Why the Exact Wording Matters

Vague drafting around this term creates real risk. If a contract simply says access must be limited to authorized personnel without defining how authorization is granted or evidenced, disputes can arise over whether a contractor, subcontractor, or former employee was actually unauthorized at the relevant time. Precise wording closes that gap by linking the term to a verifiable source of truth, such as a maintained access list or a written assignment.

The exact wording also determines liability. A party that must prevent access by an Unauthorized Person is judged against that specific standard, so courts or arbitrators applying the law governing the contract will look closely at how the term was defined when assessing whether a breach occurred.

## Drafting Considerations

Drafters should specify how authorization is created, evidenced, and withdrawn, ideally by cross-referencing a related document such as an [authorization form](https://www.genieai.co/en-us/template-type/authorization-form) or an internal access policy. The definition should also state whether authorization is role-based, individual-based, or time-limited, since each approach changes how quickly the status of a person can shift from authorized to unauthorized.

It is also wise to align this term with obligations found in a [data breach response policy](https://www.genieai.co/en-us/template-type/data-breach-response-policy) or notification procedure, so that any incident involving an Unauthorized Person triggers a clear, pre-agreed response rather than an ad hoc negotiation. Consistency across related documents reduces interpretive disputes later.

Finally, parties should consider carve-outs for emergency access, auditors, or regulators who may need temporary entry without being treated as unauthorized, and should ensure the definition is broad enough to cover both digital and physical access where relevant.

## Context

### Relevant circumstances

- Appointing a representative to act on an organization's behalf in a specific project or deal.
- Establishing roles and responsibilities in staffing or partnership situations.
- Outlining authority in decision-making instances within an organization.

### Relevant sectors

- Legal Services
- Information Technology
- Financial Services
- Real Estate
- Healthcare

## Relevant contract types

- [Authorization Letter](https://www.genieai.co/en-us/template-type/authorization-letter)
- [Assignment Agreement](https://www.genieai.co/en-us/template-type/assignment-agreement)
- [Certificate of Authorization](https://www.genieai.co/en-us/template-type/certificate-of-authorization)

---

This is the Markdown representation of [https://www.genieai.co/en-us/define/unauthorized-person](https://www.genieai.co/en-us/define/unauthorized-person), provided for AI agents and crawlers. The HTML page is canonical. See [/llms.txt](https://www.genieai.co/llms.txt) for the full content map.
