Ausspaehen, Abfangen und Manipulation von Daten (Computer Misuse and Data Interference)
Strafgesetzbuch (StGB), §§ 202a, 202b, 202c, 202d, 303a, 303b
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not gain access to data that is specially secured against unauthorised access by overcoming that security measure.
- Do not intercept non-public data transmissions or a computer's electromagnetic emissions using technical means.
- Do not produce, obtain, sell, or distribute passwords, security codes, or software designed to commit these offences.
- Do not obtain, pass on, or distribute data that another person has unlawfully obtained, for enrichment or to cause harm.
- Do not unlawfully delete, suppress, render unusable, or alter data.
- Do not substantially disrupt a data-processing operation of essential significance to another person, business, or public authority.
- Reading a public, unauthenticated page without defeating any access-security measure has not itself been held to violate these provisions.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Section 202a: imprisonment up to 3 years or a fine. Section 202b: imprisonment up to 2 years or a fine, subsidiary to a more severely punished provision. Section 202c: imprisonment up to 2 years or a fine. Section 202d: imprisonment up to 3 years or a fine. Section 303a: imprisonment up to 2 years or a fine; attempt is punishable. Section 303b: imprisonment up to 3 years or a fine, rising to up to 5 years where the processing affects an outside business, undertaking or public authority, and to imprisonment of 6 months to 10 years in especially serious cases (large-scale financial loss, commercial or gang commission, or impairment of essential public supply or national security).
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 202a punishes, with imprisonment of up to three years or a fine, unlawfully obtaining access, for oneself or another, to data that is not intended for oneself and is specially secured against unauthorised access, by overcoming that access security.
Section 202b punishes, with imprisonment of up to two years or a fine, unlawfully obtaining such data for oneself or another using technical means from a non-public data transmission or from a data-processing installation's electromagnetic emissions, unless a more severe provision applies.
Section 202c punishes, with imprisonment of up to two years or a fine, preparing such an offence by producing, obtaining, selling, supplying, distributing or otherwise making accessible passwords or other security codes enabling access to such data, or computer programs designed to commit such an offence.
Section 202d punishes, with imprisonment of up to three years or a fine, obtaining, passing on, distributing or otherwise making accessible data that is not generally accessible and that another person obtained through an unlawful act, in order to enrich oneself or a third party or to harm another, with an exemption for acts performed exclusively in fulfilment of lawful official or professional duties.
Section 303a punishes, with imprisonment of up to two years or a fine, unlawfully deleting, suppressing, rendering unusable or altering data, and the attempt is itself punishable.
Section 303b punishes substantially disrupting a data-processing operation of essential significance to another through such conduct, with imprisonment of up to three years or a fine, rising to up to five years where the data processing is of essential significance to an outside business, undertaking or public authority, and, in especially serious cases, to imprisonment of six months to ten years, a category the statute names as including causing a loss of great magnitude, acting commercially or as a member of a gang formed for repeated computer sabotage, or impairing the population's supply of essential goods or services or the Federal Republic's security.
Because section 202a's offence turns on overcoming an access-security measure, a scraper reading a public, unauthenticated page without defeating any technical access control falls outside a plain reading of the provision.
When LexLint raises it
crawls_webtrains_models
Read the law
official consolidated Strafgesetzbuch text, gesetze-im-internet.de