Law / Belgium

Code pénal, Livre II, articles 524 à 527, accès non autorisé dans un système informatique

Code pénal Livre II, arts. 524-527 (accès non autorisé dans un système informatique), inséré par la loi du 29 février 2024 introduisant le livre II du Code pénal; peines fixées au Livre Ier, art. 36 et 38

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force 15 days, effective 1 September 2026.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not access or remain in a computer system knowing you are not authorised to do so.
  • Do not exceed your own access rights to a computer system with a fraudulent intent or an intent to harm.
  • Do not retrieve data, use a third party's system, or cause any damage in the course of an unauthorised access; doing so raises the offence to the aggravated tier.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Six months to three years' imprisonment for unauthorised access under Article 524 or 525 (peine de niveau 2), rising to three to five years where the offender also retrieves data, uses the system, or causes damage under Article 526 (peine de niveau 3); attempt is punished the same as the completed offence under Article 527.

Penalty structure

Corporate-liability cap for the base offence (peine de niveau 2, Book I Article 38): a legal person faces a fine of more than 20,000 to 360,000 euros. A natural person instead faces imprisonment of six months to three years at this level (Book I Article 36), with no equivalent monetary cap. The aggravated offence (Article 526) reaches peine de niveau 3, raising the corporate fine to more than 360,000 to 600,000 euros and the natural-person term to three to five years.

Rule
Fixed only
As of
6 September 2026
Currency
EUR
Fixed cap
360,000

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Belgium's new Penal Code Book II criminalises accessing or remaining in a computer system without authorisation (Article 524, external access) and, separately, exceeding one's own access rights with fraudulent intent or intent to harm (Article 525, internal access), each punished at sentencing level 2. The offence is aggravated to level 3 under Article 526 where the offender also retrieves the system's data, uses a third party's system, or causes any damage.

Attempt is punished the same as the completed offence (Article 527), and possessing or supplying a device designed to enable the offence (Article 528) or inciting its commission (Article 529) are separate offences; knowingly holding or disclosing data obtained through the offence is a further offence under Article 530. The provision replaces Article 550bis of the 1867 Penal Code, which had criminalised the same conduct in materially the same terms since 13 February 2001.

Article 524 turns on the actor knowingly lacking authorisation to access the system; its text does not add a separate requirement that a technical security measure be defeated.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Belgian Official Gazette, consolidated text of the Law of 29 February 2024 introducing Book II of the Penal Code

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2026. Publisher's page: https://www.ejustice.just.fgov.be/eli/loi/2024/02/29/2024002088/justel

Back to the example  ·  Lint your app