Computer Misuse Act, unauthorised access to computer material
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 21 June 2000.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not cause a computer to perform a function for the purpose of securing access to a program or data without authority, meaning without the entitlement to control that access and without the consent of a person who holds that entitlement.
- Whether reading a publicly accessible, unauthenticated page fits this section's authorisation test has not been tested in a reported Brunei decision.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
A first conviction carries a fine of up to $5,000 and imprisonment of up to 2 years, or both; a second or subsequent conviction up to $10,000 and 3 years; and, where the offence causes damage, up to $50,000 and 7 years (s. 3(1)-(2)). Section 9 substitutes a fine of up to $100,000 and imprisonment of up to 20 years where the access reached a protected computer.
Penalty structure
Section 3(1): a first conviction is fined up to $5,000 with up to 2 years' imprisonment, or both; a second or subsequent conviction up to $10,000 and 3 years. Section 3(2): where the offence causes damage, up to $50,000 and 7 years. Section 9(1): where the access reached a protected computer in the course of an offence under sections 3, 5, 6 or 7, the penalty is instead a fine of up to $100,000 and imprisonment of up to 20 years, the highest figure recorded here.
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- BND
- Fixed cap
- 100,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 3 prohibits knowingly causing a computer to perform a function for the purpose of securing access, without authority, to a program or data held in any computer, with access being without authority where the person is not entitled to control access of that kind and has no consent from someone who is.
A first conviction carries a fine of up to $5,000 and imprisonment of up to 2 years, or both, rising to $10,000 and 3 years for a second or subsequent conviction, and to $50,000 and 7 years where the offence causes damage (s. 3(2)); where access to a protected computer, one used for defence, a confidential law-enforcement source, essential infrastructure, or public safety, is obtained in the course of this or certain other offences, section 9 substitutes an enhanced penalty of up to $100,000 and 20 years.
The Act's authorisation test turns on entitlement to control access rather than on infringing a technical security measure, and no reported Brunei decision has tested whether reading a public, unauthenticated page fits it.
When LexLint raises it
crawls_webtrains_models