Código Penal (Ley 151/2022), offenses against telecommunications and ICT security
Ley 151/2022, Código Penal, Título IX, Capítulo I (arts. 289-294)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 30 November 2022.
A computer misuse rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not access or use an information system, storage device, software, or database without due authorization, for the purpose of appropriating, using, disclosing, or disseminating the information it stores, transmits, or captures.
- Do not violate an established computer-security measure to use information technology media in a way that affects the confidentiality, integrity, or availability of digital assets.
- Reading a public, unauthenticated page without defeating any technical access control and without one of the specific purposes Article 290 names has not itself been held to violate these provisions.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Imprisonment ranging from six months (arts. 289, 291, 293) to five years (art. 294), or a fine denominated in cuotas (200 to 1,000 depending on the article), or both; each cuota's monetary value is fixed by the sentencing court between 10 and 200 pesos according to the convicted person's income (art. 40.2), so the fine is not a single peso amount. Article 296 allows the sanction to be doubled for grave harm or harm to a foreign or strategic system, and increased by half for an official with custody of the affected system.
What it reaches
Obligation class
Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 289 punishes violating legally established computer-security measures to use information technology media and affect the confidentiality, integrity, or availability of digital assets, with imprisonment of six months to two years or a fine of 200 to 500 cuotas, or both.
Article 290 punishes accessing or using, or letting another access or use, an information system, storage device, software, or database without due authorization, with the purpose of appropriating, using, knowing, disclosing, or disseminating the information it stores, transmits, or captures, with imprisonment of one to three years or a fine of 300 to 1,000 cuotas, or both; because the offense turns on lacking due authorization for a specific purpose rather than on defeating a technical access control, a scraper reading a public, unauthenticated page falls outside a plain reading of the provision unless it is shown to lack authorization for one of the stated purposes.
Article 291 punishes using equipment or procedures to obstruct lawful access to information systems, or scanning telecommunications and ICT services to detect security vulnerabilities, interrupt services, or obtain information about their operation or users, without authorization. Article 292 punishes any act intended to compromise the security of ICT-using systems and knowingly providing a service toward that end.
Article 293 punishes intercepting, manipulating, or interfering with an information or telematic system without authorization and with intent to cause damage, with an aggravated bracket where illegally obtained passwords or similar means are used. Article 294 punishes producing, trafficking, or introducing computer viruses or malicious code intended to disable ICT infrastructure.
Article 296 allows the sanction to be doubled where a grave harm results, an international or foreign system is affected, or a vital or strategic system is put at risk, and increased by half where the offender is an official or employee with custody of the affected system, and allows the accessory sanction of confiscation of property.
Each cuota's monetary value is fixed by the sentencing court between 10 and 200 pesos according to the convicted person's income, so the fine bracket named in each article above is not itself a single peso amount.
Cuba's separate telecommunications framework, Decreto-Ley 35/2021, and its implementing Resolución 105/2021 on cybersecurity-incident response (issued under the earlier Decreto 360/2019) impose incident-notification duties on network operators but create no distinct authorization or access regime for a third party reading data from a system.
When LexLint raises it
crawls_webtrains_models
Read the law
Official text of Ley 151/2022 (Código Penal) as published in Gaceta Oficial de la República de Cuba
Ordinaria No. 93 (1 September 2022), in an Internet Archive capture