Act on Prohibition of Unauthorized Computer Access, prohibition of unauthorized access
Act on Prohibition of Unauthorized Computer Access, Act No. 128 of 1999, Arts. 2(4), 3, 11
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not operate a computer connected to a telecommunications line, where it carries an access control feature, by inputting another person's identification code, or by inputting other information or a command designed to evade that feature, without the access administrator's or the authorized user's permission.
- Reading a public, unauthenticated page that carries no access control feature to defeat has not itself been held to violate this Act.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Violating the prohibition on unauthorized computer access (Art. 3) is punished by imprisonment with work for not more than three years or a fine of not more than 1,000,000 yen (Art. 11); violating the identification-code, facilitation, storage, or impersonation provisions (Arts. 4, 6, 7, 9(3)) is punished by imprisonment with work for not more than one year or a fine of not more than 500,000 yen (Art. 12), and violating the code-supply provision (Art. 5) alone is punished by a fine of not more than 300,000 yen (Art. 13).
Penalty structure
The Art. 3 prohibition on unauthorized computer access carries the Act's highest tier: a fine of up to 1,000,000 yen or imprisonment with work for up to three years, or both (Art. 11). Lesser offences under the Act cap at 500,000 yen (Art. 12) or 300,000 yen (Art. 13).
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- JPY
- Fixed cap
- 1,000,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 2(4) defines an act of unauthorized computer access as operating a specified computer that carries an access control feature, in a way the feature restricts, by inputting via a telecommunications line another person's identification code associated with that feature, or other information or a command designed to evade the feature.
Article 3 prohibits any person from engaging in such an act; violating it is punished under Article 11 by imprisonment with work for not more than three years or a fine of not more than 1,000,000 yen. The Act also prohibits obtaining, storing, or supplying such an identification code for that purpose, and impersonating an access administrator to solicit one (Arts. 4 through 7), each punished less severely under Articles 12 and 13.
Because every prohibited act requires defeating an access control feature the target computer already carries, reading a public, unauthenticated page that carries no such feature falls outside a plain reading of the Act.
When LexLint raises it
crawls_webtrains_models
Read the law
official statute text, Japanese Law Translation portal (Ministry of Justice)