Law / Austria

StGB Sections 118a and 126a to 126c, Computer-Misuse Offenses

StGB Sec. 118a, 126a-126c, BGBl. Nr. 60/1974 as amended

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 October 2002.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not overcome a computer system's specific security measure to gain access, if your purpose is to obtain personal data protected by a secrecy interest, or to use the accessed data or system to harm another, per StGB Section 118a.
  • Do not alter, delete, suppress, or render unusable data over which you lack sole authority, in a way that damages another, per StGB Section 126a.
  • Do not seriously disrupt a computer system's functioning by entering or transmitting data, per StGB Section 126b.
  • Do not create, acquire, distribute, or possess a program, device, password, or access code built or adapted to commit these offenses, per StGB Section 126c.

If you get it wrong

Criminal exposureYes

Criminal exposure note

StGB Section 118a: imprisonment up to two years for the base offense (up to three years if the system is a critical-infrastructure component, up to five years if committed within a criminal organization against critical infrastructure). Prosecution proceeds only on the victim's authorization (Section 118a(3)). Section 126a: imprisonment up to six months or a fine up to 360 daily rates for the base offense; up to two years where the damage exceeds EUR 5,000; up to three years where many computer systems are affected using a purpose-built tool; six months to five years where the damage exceeds EUR 300,000, critical infrastructure is affected, or the act is committed within a criminal organization. Section 126b carries the identical tiered structure for disrupting a system's functioning. Section 126c: imprisonment up to six months or a fine up to 360 daily rates for creating, acquiring, or distributing a purpose-built tool with intent that it be used for one of these offenses; up to two years where the tool is used in relation to Section 118a, 119, or 119a, or to an aggravated form of Section 126a or 126b.

Who enforces it

Enforcement body

Ordinary criminal courts, on public prosecution for Sections 126a to 126c and on the victim's authorization for Section 118a.

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 118a punishes anyone who gains access to a computer system, or part of one, by overcoming a specific security measure, with intent either to obtain personal data whose secrecy is protected or to cause harm through the accessed data or system; prosecution requires the victim's authorization. Section 126a punishes altering, deleting, rendering unusable, or suppressing data over which the offender lacks sole authority, where this damages another.

Section 126b punishes seriously disrupting a computer system's functioning by entering or transmitting data. Section 126c punishes creating, acquiring, distributing, or possessing a program, device, password, or access code built or adapted for committing these offenses, with intent that it be so used. None of the four turns on whether the targeted content was publicly viewable; each turns on overcoming a technical or legal barrier to access, or on the tool's built purpose.

When LexLint raises it

  • crawls_web

Read the law

Austrian Federal Law Gazette (Rechtsinformationssystem, RIS), consolidated text of the Strafgesetzbuch

Back to the example  ·  Lint your app