Computer Misuse Act 2003, unauthorised access, modification and interception offences
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 16 June 2003.
A computer misuse rule binding public and private bodies.
As of 7 September 2026.
What it requires
- Do not cause a computer to perform any function to secure access to a program or data without being entitled to control that access or having the consent of someone who is.
- Do not modify computer material, intercept a computer service, or obstruct the use of a computer without authority.
- Treat a computer used for security, defence, banking, financial services, public utilities, public transport, or public-safety systems as carrying enhanced criminal exposure for unauthorised access.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Unauthorised access (section 3) is punishable on summary conviction by a fine not exceeding five thousand dollars or imprisonment not exceeding six months, rising to ten thousand dollars or one year for a repeat conviction, and to twenty thousand dollars or three years where damage results. Unauthorised modification (section 5) carries the same tiers as section 3. Unauthorised use or interception of a computer service, and unauthorised obstruction (sections 6-7), carry a fine not exceeding ten thousand dollars or three years' imprisonment, rising to twenty thousand dollars or three to five years for a repeat conviction, and to fifty thousand dollars or five years where damage results. Unauthorised disclosure of an access code (section 8) carries a fine not exceeding ten thousand dollars or three years, rising to twenty thousand dollars or five years for a repeat conviction. Access to a protected computer under section 9 is liable on conviction to a fine not exceeding one hundred thousand dollars or imprisonment not exceeding twenty years.
Penalty structure
Section 9's enhanced-punishment tier for a protected computer caps a fine at one hundred thousand dollars (twenty years' imprisonment); the base offences in sections 3 and 5-8 carry lower tiered caps ranging from five thousand to fifty thousand dollars depending on the offence, repeat conviction, and whether damage resulted.
- Rule
- Fixed only
- As of
- 7 September 2026
- Currency
- BSD
- Fixed cap
- 100,000
Who enforces it
Enforcement body
Royal Bahamas Police Force
What it reaches
Obligation class
Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 3 makes it an offence for any person, without authority, knowingly to cause a computer to perform a function for the purpose of securing access to a program or data, whether or not the act was directed at any particular program, data, or computer. Access is unauthorised if the person is not entitled to control access of that kind and lacks consent from someone who is, so authorisation, not the technical means of access, is what the Act tests.
Sections 5 to 8 separately criminalise unauthorised modification of computer material, unauthorised use or interception of a computer service, unauthorised obstruction of a computer's use, and unauthorised disclosure of an access code.
Section 9 imposes enhanced punishment where the computer accessed is a protected computer used for security, defence, confidential law-enforcement sources, banking, financial services, public utilities, public transport, public key infrastructure, or public-safety systems. The Act applies whatever the offender's nationality where either the accused or the computer, program or data was in The Bahamas at the material time.
When LexLint raises it
crawls_webtrains_models
Read the law
Computer Misuse Act, Chapter 107A, Statute Law of The Bahamas