Law / Benin

Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybercriminalité), atteintes aux réseaux et systèmes d'information

Loi n°2017-20 du 20 avril 2018, Livre VI, Atteintes aux Réseaux et Systèmes d'Information, portant Code du Numérique en République du Bénin

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 20 April 2018.

A computer misuse rule binding public and private bodies.

As of 4 September 2026.

What it requires

  • Do not access, or remain present in, a computer system without right; the penalty escalates where the access or presence is aggravated by fraudulent intent, exceeds an authorized level of access, results in data being suppressed or modified, or is committed in violation of the system's security measures.
  • Do not intercept, divulge, use, alter, or misappropriate computer data during its non-public transmission to, from, or within a computer system.
  • Do not cause an interruption of a computer system's normal operation, or damage, delete, deteriorate, alter, or suppress computer data, without right.
  • Do not produce, sell, obtain, import, or distribute a device, program, password, or access code designed to commit any of the above offenses.
  • Do not falsify computer data by introducing, modifying, altering, or erasing data stored, processed, or transmitted by a computer system.
  • A search-engine or hosting provider that wants the Code's liability exemption must not originate the content in question, must not select its recipient, must not select or modify it, and, as a host, must remove or disable access to illegal content once notified.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Base offense (Art. 507 alinéa 1, unauthorized access or continued unauthorized presence): one to five years' imprisonment and a fine of 500,000 to 1,000,000 CFA francs, or either penalty alone. The aggravated forms (alinéa 2, fraudulent intent; alinéa 3, exceeding an authorized access level with fraudulent intent or intent to harm) draw two to five years' imprisonment and a fine of 500,000 to 2,000,000 CFA francs, or either penalty alone. Where any of these three forms results in the suppression, obtaining, or modification of the system's data, or an alteration of the system's operation, the penalty just described is doubled (alinéa 4). Independently, where any of the three base forms is committed in violation of the system's own security measures, the penalty is instead ten to twenty years' imprisonment (réclusion criminelle) and a fine of 5,000,000 to 500,000,000 CFA francs (alinéa 5); this is the instrument's statutory ceiling.

Penalty structure

Art. 507 is tiered: the base offense (alinéa 1, unauthorized access or continued presence) draws 500,000 to 1,000,000 CFA francs; the aggravated forms (alinéa 2, fraudulent intent; alinéa 3, exceeding an authorized access level) draw 500,000 to 2,000,000 CFA francs; any of these three forms resulting in data suppression, obtaining, modification, or system alteration doubles the fine just described (alinéa 4, up to 4,000,000 CFA francs); and any of the three base forms committed in violation of the system's security measures instead draws 5,000,000 to 500,000,000 CFA francs (alinéa 5), the instrument's ceiling recorded here. Each tier carries a matching imprisonment range; see criminal_exposure_note.

Rule
Fixed only
As of
4 September 2026
Minimum
500,000
Currency
XOF
Fixed cap
500,000,000

Who enforces it

Enforcement body

Beninese public prosecution and the criminal courts, with the Agence Nationale de Sécurité des Systèmes d'Information (ANSSI-Bénin) responsible for overseeing information-systems security

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Benin's general computer-misuse title, part of the cybercriminality and cybersecurity Book of the Digital Code.

Article 507 punishes intentionally and without right accessing or remaining present in all or part of a computer system with one to five years' imprisonment and a fine of 500,000 to 1,000,000 CFA francs, or either penalty alone; the aggravated form committed with fraudulent intent, and exceeding an authorized level of access to a computer system, are each punished at two to five years' imprisonment and a fine of 500,000 to 2,000,000 CFA francs, or either penalty alone.

Where any of these three forms results in the suppression, obtaining, or modification of the system's data, or an alteration of the system's operation, the penalty just described is doubled; where instead any of the three is committed in violation of the system's own security measures, the offense draws a separate, harsher penalty of ten to twenty years' imprisonment (réclusion criminelle) and a fine of 5,000,000 to 500,000,000 CFA francs (Art. 507).

Article 508 separately punishes intercepting, divulging, using, altering, or misappropriating computer data during its non-public transmission; Article 509 punishes causing an interruption of a computer system's normal operation; Article 510 punishes damaging, deleting, deteriorating, altering, or suppressing computer data; Article 511 punishes producing, selling, obtaining, importing, or distributing a device, program, password, or access code designed to commit any of the above offenses; Article 512 punishes falsifying computer data by introducing, modifying, altering, or erasing it.

Two liability exemptions sit earlier in the same Book: a provider of a search engine or content index is not liable for its search results, and an online host is not liable for information stored at a user's request, each conditioned on the provider not originating the content, not selecting its recipient, and not selecting or modifying it, and on the host acting to remove or disable access to illegal content once notified (Art. 505 and 506).

The title does not define "without right" for a public, unauthenticated web page specifically, and no Beninese court decision construing these articles in that context was located.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Loi n°2017-20 portant Code du Numérique, official consolidated text as republished by Benin's Ministère de l'Économie et des Finances

Back to the example  ·  Lint your app