Criminal Justice (Offences Relating to Information Systems) Act 2017
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 12 June 2017.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not intentionally access an information system by infringing a security measure, without lawful authority or reasonable excuse (s. 2).
- Do not intentionally hinder or interrupt an information system, or delete, damage, alter, suppress or intercept data on it, without lawful authority (ss. 3-5).
- Do not produce, distribute or make available a computer programme, password, code or similar data designed for committing any of the section 2 to 5 offences (s. 6).
- Reading a public, unauthenticated page without defeating any access control has not itself been held to violate section 2.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Offences under ss. 2, 4, 5 or 6: on summary conviction, a class A fine or imprisonment up to 12 months, or both; on conviction on indictment, a fine or imprisonment up to 5 years, or both. An offence under s. 3 (interference with an information system) carries the same summary tier but up to 10 years on indictment (s. 8(1)-(2)).
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 2 makes it an offence to intentionally access an information system without lawful authority or reasonable excuse by infringing a security measure. Sections 3 and 4 separately criminalise intentionally hindering or interrupting the functioning of an information system, or intentionally deleting, damaging, altering or suppressing data on it, without lawful authority.
Section 5 criminalises intentionally intercepting a non-public transmission of data to, from or within an information system, without lawful authority. Section 6 criminalises producing, selling, procuring, importing, distributing or otherwise making available a computer programme, password, code or similar data designed for committing any of the section 2 to 5 offences.
Because section 2's trigger is infringing a security measure, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of that offence; no reported Irish case has tested the point. The Act repealed the earlier, narrower 'unauthorised accessing of data' offence at section 5 of the Criminal Damage Act 1991, which had rested on operating a computer with intent to access data rather than on defeating a security measure.
When LexLint raises it
crawls_webtrains_models