Law / France

Code penal STAD Offenses, Unauthorized Access to and Interference with Automated Data Processing Systems

Code penal, art. 323-1 a 323-8 (Chapitre III, Des atteintes aux systemes de traitement automatise de donnees)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not defeat an access control, password, or other security measure to reach a French computer system; reading a public, unauthenticated page without doing so has not itself been held to violate Article 323-1.
  • Do not impair, falsify, corrupt, or delete data on a French computer system in the course of an automated crawl, which Articles 323-2 and 323-3 punish separately from unauthorized access itself, with a higher penalty where the system is a State personal-data system.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 323-1 (fraudulent access to or remaining within a system): five years' imprisonment, though the base tier is three years and EUR 100,000, rising where access causes the deletion or alteration of the data held. Article 323-2 (impairing or falsifying a system's functioning) and Article 323-3 (fraudulently introducing, extracting, holding, reproducing, transmitting, deleting or altering data): five years' imprisonment and a fine of EUR 150,000 each, rising to seven years and EUR 300,000 where the system targeted is a State-operated system processing personal data. Article 323-4 punishes conspiring to prepare any of these offenses with the same penalty as the offense itself, or the most severe if several are contemplated, rising to ten years and EUR 300,000 where committed by an organized group (Article 323-4-1). Article 323-7 punishes an attempt with the same penalties as the completed offense. Article 323-6 exposes a corporate defendant to the fine under Code penal Article 131-38 (which multiplies the individual fine by five) plus the additional penalties listed in Article 131-39, including up to a five-year prohibition on issuing checks and publication of the judgment.

Penalty structure

Article 323-1's base tier for fraudulent access to or remaining within an automated data processing system: three years' imprisonment and a fine of EUR 100,000. The chapter's other offenses carry higher fixed caps: Articles 323-2 and 323-3 (impairing a system's functioning, or introducing, extracting or altering its data) each carry EUR 150,000 and five years, rising to EUR 300,000 and seven years where the system targeted is a State-operated personal-data system; Article 323-4-1 raises an organized-group offense to EUR 300,000 and ten years.

Rule
Fixed only
As of
6 September 2026
Currency
EUR
Fixed cap
100,000

Who enforces it

Enforcement body

French criminal courts (tribunaux correctionnels), on prosecution by the public prosecutor (parquet); no dedicated regulator enforces this chapter.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 323-1 punishes fraudulently accessing or remaining within all or part of an automated data processing system with three years' imprisonment and a fine of EUR 100,000.

Article 323-2 punishes impairing or falsifying the functioning of such a system, and Article 323-3 punishes fraudulently introducing, extracting, holding, reproducing, transmitting, deleting or altering data within one, each with five years' imprisonment and a fine of EUR 150,000, rising to seven years and EUR 300,000 where the targeted system is a State-operated system processing personal data.

Article 323-1's own penalty rises in the same pattern where the access results in the deletion or alteration of data held in the system. Because the base Article 323-1 offense requires infringing a security measure to gain access, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

Article 323-3-1 separately punishes possessing or supplying a tool or program designed to commit these offenses, Article 323-4 punishes conspiring to commit them, and Article 323-7 punishes an attempt with the same penalties as the completed offense. Article 323-8 exempts measures carried out by authorized state intelligence services for protecting national security interests abroad.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

official consolidated Code penal text, Legifrance (read through an archived capture of the official page
the live Legifrance page returns a Cloudflare challenge)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.legifrance.gouv.fr/codes/id/LEGISCTA000006149839

Back to the example  ·  Lint your app