Law / Honduras

Código Penal, seguridad de las redes y de los sistemas informáticos

Decreto No. 130-2017, Código Penal, arts. 398-405 (Seguridad de las Redes y de los Sistemas Informáticos)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 10 November 2019.

A computer misuse rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Do not access a computer system, in whole or in part, by infringing a security measure established to prevent it, without authorization.
  • Do not introduce, delete, alter or suppress computer data, or disable a computer system's operation, without authorization.
  • Reading a public, unauthenticated page that defeats no access control has not itself been held to violate this offence.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Six to eighteen months' imprisonment, or a fine of 100 to 200 day-fines, for unauthorized access to a computer system by infringing a security measure (art. 398). One to two years' imprisonment, or a fine of up to 300 day-fines, for unauthorized introduction, deletion, alteration or suppression of computer data, and one to three years' imprisonment, or a fine of up to 400 day-fines, for disabling a system's operation (art. 399). Six months to one year's imprisonment, or a fine of up to 200 day-fines, for the device-abuse offence (art. 400); the same range, or a fine of up to 300 day-fines, for technology-facilitated identity theft (art. 401). Every penalty in this title is increased by a third for critical-infrastructure or grave-economic-damage aggravations (arts. 398, 399) and again by a third, with professional disqualification (absolute disqualification for a public official), where the offender is the system's administrator or an authorized user, or belongs to an organized criminal group (art. 402). A legal person responsible for one of these offences faces three to five years' suspension of its specific activities and a fine of 300 to 500 day-fines (art. 403). Each day-fine is worth not less than twenty Lempiras (L.20) nor more than five thousand Lempiras (L.5,000), set by the court according to the convicted person's economic situation (art. 53).

Penalty structure

Article 398's fine is 100 to 200 day-fines; article 53 fixes each day-fine's value between L.20 and L.5,000, set by the sentencing court from the convicted person's economic situation. fixed_cap and minimum are the arithmetic extremes (200 x L.5,000 and 100 x L.20) for the unauthorized-access offence specifically; the damage offence in article 399 carries a wider day-fine range (up to 400 days) not captured by this single block.

Rule
Fixed only
As of
5 September 2026
Minimum
2,000
Currency
HNL
Fixed cap
1,000,000

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 398 punishes with six to eighteen months' imprisonment or a fine of 100 to 200 day-fines whoever, infringing the security measures established to prevent it, accesses all or part of a computer system without authorization, with the penalty increased by a third where the system concerns critical community infrastructure.

Article 399 punishes unauthorized introduction, deletion, deterioration, alteration, suppression or serious disabling of computer data with one to two years' imprisonment or a fine of 100 to 300 day-fines, and unauthorized disabling of a computer system's operation with one to three years' imprisonment or a fine of 100 to 400 day-fines, with both penalties increased by a third where the conduct causes grave economic damage or affects critical community infrastructure.

Article 400 punishes manufacturing, importing, selling, facilitating or obtaining devices, software, passwords or access codes intended for committing these offences with six months to one year's imprisonment or a fine of 100 to 200 day-fines, and article 401 punishes identity theft carried out through information and communication technology with fraudulent intent with the same six-months-to-one-year imprisonment range or a fine of 100 to 300 day-fines.

Article 402 raises every penalty in this title by a third where the offender is responsible for or authorized to access the system, or belongs to an organized criminal group, and adds professional disqualification, with absolute disqualification for a public official. Article 403 punishes a legal person responsible for one of these offences with three to five years' suspension of its specific activities and a fine of 300 to 500 day-fines.

Article 404 gives Honduran courts jurisdiction over these offences when committed in Honduras against a system located abroad, or against a system located in Honduras from abroad. Because the article 398 offence turns on infringing a security measure, accessing a public, unauthenticated page that defeats no access control falls outside a plain reading of the provision.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Código Penal, Decreto 130-2017, full text as published in La Gaceta No. 34,940, Tribunal Superior de Cuentas legal library

Back to the example  ·  Lint your app