Law / Andorra

Penal Code, Attacks on Information Systems

Codi penal, Llei 9/2005, del 21 de febrer, qualificada del Codi penal, as consolidated, art. 225 (Atacs contra els sistemes d'informació)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Do not access all or part of an information system by defeating a security measure, without authorization, when the result is serious.
  • Do not obstruct or interrupt a network or information system, or delete, damage, alter, or make inaccessible data within one, without authorization.
  • Do not intercept non-public data transmissions to, from, or within an information system without authorization.
  • Reading a public, unauthenticated page without defeating any security measure has not itself been held to violate this article.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Imprisonment from three months to three years for unauthorized access defeating a security measure, obstructing a network or system, damaging or intercepting data, or supplying tools for those offences (art. 225(1)-(5)); imprisonment from three to six years plus a fine of up to four times the damage caused where the offence is committed by an organized group, causes especially serious damage, seriously harms an essential public service or critical infrastructure, or creates a serious danger to State security (art. 225(6)).

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 225 of the qualified Penal Code punishes with imprisonment from three months to three years whoever, by any means, intentionally and without authorization, accesses all or part of an information system in violation of at least one security measure, when the result is serious; the same range of imprisonment applies to intentionally and without authorization obstructing or interrupting the operation of a network or information system, deleting, damaging, or altering data within an information system, intercepting non-public data transmissions, and producing, selling, or distributing hacking tools or access codes for those purposes.

Imprisonment of three to six years plus a fine of up to four times the damage caused applies where the conduct is committed by an organized group, causes especially serious damage, seriously harms an essential public service or critical infrastructure, or creates a serious danger to State security. Each paragraph requires defeating a security measure or acting without authorization, so reading a public, unauthenticated page does not fit a plain reading of the article.

The consolidated text carries no per-article amendment date, and its reference to essential services and critical infrastructure reflects a later revision of the article than the Code's original 2005 enactment, so no single commencement date for the article as currently worded is stated on the page.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Consolidated Catalan text of the qualified Penal Code
published by the Andorran government's official legal portal (portaljuridicandorra.ad) the portal's own consolidated version is labeled a text refós sense caràcter oficial (consolidated text without official character)

Back to the example  ·  Lint your app