Law / Georgia

Criminal Code, unauthorised access and interference with computer data and systems

Criminal Code of Georgia, Chapter XXXV (Cybercrime), Arts. 284-286

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 1 June 2000.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not access a computer system, or copy, alter, or output data from it, without authorisation from the person who holds the right to grant that access.
  • Whether reading a public, unauthenticated page without registration or login falls within this offence is unsettled under Georgian law; treat a target that is a critical information system subject as carrying materially higher exposure.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Articles 284 and 286 carry a base tier of a fine, corrective labour up to two years, or imprisonment for the same term; Article 285's base tier adds imprisonment up to three years. Each article's aggravated tier (group, official position, repetition, or substantial damage) reaches imprisonment of two to five years (Art. 284), three to six years (Art. 285), or three to five years (Art. 286); each article's critical-information-system-subject tier reaches imprisonment of three to six years (Art. 284), four to seven years (Art. 285), or four to seven years (Art. 286).

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 284 punishes unauthorised access to a computer system by a fine or corrective labour of up to two years, or imprisonment for the same term, rising to imprisonment of two to five years for access committed by a group, using an official position, repeatedly, or resulting in substantial damage (over GEL 2,000), and to imprisonment of three to six years where the target is a critical information system subject.

Article 285 punishes unauthorised making, purchase, storage, sale, or dissemination of software, a password, an access code, or similar data for the purpose of committing a Chapter XXXV offence, by a fine or corrective labour of up to two years and/or imprisonment of up to three years, rising to three to six years for the aggravating circumstances listed above and to four to seven years against a critical information system subject.

Article 286 punishes unauthorised damage, deletion, modification, or concealment of computer data by a fine or corrective labour of up to two years and/or imprisonment for the same term, rising through the same aggravating tiers to three to five years and, against a critical information system subject, four to seven years.

The chapter's own note defines 'unauthorised' as illegal access or use, including where the right holder has not directly or indirectly transferred the right, without requiring that a technical security measure be defeated; because of that, and because no reported Georgian case addresses the point, whether reading a public, unauthenticated page without registration or login falls within these offences is unsettled rather than settled either way.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Criminal Code of Georgia, official consolidated text, Legislative Herald of Georgia (Matsne)

Back to the example  ·  Lint your app