Criminal Code Act 1995 (Cth), Part 10.7, Unauthorised Access to Restricted Data
Criminal Code Act 1995 (Cth), Schedule (the Criminal Code), Part 10.7, ss. 476.2, 478.1
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 21 December 2001.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not cause access to, or modification of, data held in a computer where that data is restricted by an access control system and you are not entitled to cause the access, knowing the access is unauthorised.
- Reading a public, unauthenticated page without defeating any access control has not itself been held to violate this section.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A fixed maximum of 2 years imprisonment on conviction under s. 478.1(1); the text of this provision states no accompanying fine.
Who enforces it
Enforcement body
Australian Federal Police, prosecuted by the Commonwealth Director of Public Prosecutions
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 478.1 makes it an offence, punishable by up to 2 years imprisonment, to cause unauthorised access to, or modification of, restricted data, meaning data held in a computer to which access is restricted by an access control system, intending to cause the access or modification and knowing it is unauthorised.
Access is unauthorised under section 476.2 only if the person is not entitled to cause it, so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the offence, and no reported Australian case has tested a scraping fact pattern under this Part.
When LexLint raises it
crawls_webtrains_models
Read the law
official consolidated Act text, Federal Register of Legislation