Criminal Code, Crimes Against Computer Security
Criminal Code No. 275-Z of 9 July 1999, arts. 349, 350, 352, 354 and 355 (as amended to 2023)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 January 2001.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not access a computer system or the information it holds by defeating or circumventing a protection or security measure, whether for gain or where doing so negligently causes substantial harm.
- Do not copy, intercept, or otherwise unlawfully acquire computer information causing substantial harm, even without defeating a protection measure.
- Do not develop, use, distribute, or sell a program or device known to be intended for defeating a protection system or for unauthorized access to, or destruction, blocking, or modification of, computer information.
- Reading a public, unauthenticated page without defeating any access control or security measure has not itself been shown to violate these articles.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Article 349(1): a fine, disqualification from certain positions or activity, arrest, restriction of freedom for up to two years, or deprivation of freedom for up to two years; article 349(2): restriction of freedom for up to five years or deprivation of freedom for up to seven years where the conduct negligently causes a crash, accident, casualties, or other grave consequences. Article 352(1) (unlawful acquisition of computer information): a fine, disqualification, arrest, restriction of freedom for up to three years, or deprivation of freedom for up to two years. Article 354(1) (malicious software or devices): a fine, arrest, restriction of freedom for up to three years, or deprivation of freedom for the same term.
What it reaches
Obligation class
Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 349(1) punishes unauthorized access to computer information accompanied by a breach of a protection system, committed for gain or negligently causing substantial harm, with a fine, disqualification from certain positions or activity, arrest, restriction of freedom for up to two years, or deprivation of freedom for the same term; article 349(2) raises the penalty to restriction of freedom for up to five years or deprivation of freedom for up to seven years where the same conduct negligently causes a crash, accident, casualties, or other grave consequences.
Article 352(1) separately punishes intentional unauthorized copying, interception, or other unlawful acquisition of computer information causing substantial harm, without requiring a breach of a protection system, at up to three years' restriction of freedom or two years' deprivation of freedom.
Article 354 punishes developing, using, distributing, or selling a computer program or device known to be intended for defeating a protection system or for unauthorized access, destruction, blocking, or modification of computer information, and article 355 punishes a person with lawful access who negligently breaches computer-system operating rules and thereby causes substantial harm.
Because articles 349(1) and 352(1) require a breach of a protection system, a corrupt purpose, or a resulting harm, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of these provisions.
When LexLint raises it
crawls_webtrains_models