Law / Monaco

Code Penal Arts. 389-1 to 389-9, Unauthorized Access, System Interference and Data Damage

Code penal art. 389-1 a 389-9 (Titre II, Chapitre II, Section IV, Des delits relatifs aux systemes d'information), crees par la loi n. 1.435 du 8 novembre 2016 relative a la lutte contre la criminalite technologique

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force since 18 November 2016.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not fraudulently access or remain within all or part of a Monaco information system.
  • Do not fraudulently hinder or alter the functioning of an information system, or introduce, damage, erase, alter, delete, extract, hold, reproduce, transmit or render inaccessible computer data within one, in the course of an automated crawl.
  • Do not produce, hold, or supply a tool, device, password or access code principally designed to commit these offences, other than for authorized testing, research, or protecting an information system.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Article 389-1 (fraudulent access to or remaining within a system): two years' imprisonment and the chiffre 3 fine (9,000 to 18,000 euros), which may be doubled depending on the circumstances. Article 389-2 (hindering or altering a system's functioning), Article 389-3 (data damage), Article 389-4 (using damaged data), and Article 389-7 (data forgery): five years and the chiffre 4 fine (18,000 to 90,000 euros) each. Article 389-5 (technical interception of non-public data transmissions): three years and the chiffre 4 fine. Article 389-6 (producing or supplying tools to commit these offences): the penalty for the underlying offence or the most severely punished one. Article 389-8 (computer fraud causing financial harm for unlawful economic benefit): five years and the chiffre 4 fine, whose maximum may be raised to the amount of the profit realised. Article 389-9 (organized-group participation): the penalty for the offence itself or the most severely punished one. Article 389-11 sets the fine for a legal person at up to 1,000,000 euros.

Penalty structure

Chiffre 3 (Article 389-1's base fine): 9,000 to 18,000 euros, which Article 389-1 itself allows to be doubled depending on the circumstances. Chiffre 4 (the fine for Articles 389-2, 389-3, 389-4, 389-5, 389-7 and 389-8): 18,000 to 90,000 euros; Article 389-8's chiffre 4 maximum may additionally be raised to the amount of the profit realised, and a legal person's fine under Article 389-11 is set at up to 1,000,000 euros rather than the natural-person figures above.

Rule
Fixed only
As of
6 September 2026
Minimum
9,000
Currency
EUR
Fixed cap
90,000

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 389-1 punishes fraudulently accessing or remaining within all or part of an information system with two years' imprisonment and the fine under Code penal article 26 chiffre 3, which may be doubled depending on the circumstances. Article 389-2 punishes fraudulently hindering or altering the functioning of all or part of an information system with five years' imprisonment and the chiffre 4 fine.

Article 389-3 punishes fraudulently introducing, damaging, erasing, deteriorating, modifying, altering, deleting, extracting, holding, reproducing, transmitting or rendering inaccessible computer data, or acting to modify or suppress its processing or transmission mode, with five years and the chiffre 4 fine; Article 389-4 punishes knowingly using data so damaged, erased, deteriorated, modified or altered with the same penalty.

Article 389-5 punishes technically intercepting non-public data transmissions to, from or within an information system, including electromagnetic emissions carrying such data, with three years and the chiffre 4 fine.

Article 389-6 punishes fraudulently producing, importing, holding, offering, transferring, disseminating, obtaining for use, or making available a device, tool, or password or access code principally designed or adapted to commit the offences at Articles 389-1 to 389-5, with the penalty for the underlying offence or the most severely punished one, subject to an exemption for authorized testing, research, or protection of an information system.

Article 389-7 punishes fraudulently introducing, altering, erasing or deleting computer data to produce inauthentic data with intent that it be relied on as authentic, with five years and the chiffre 4 fine. Article 389-8 punishes fraudulently causing financial harm to another through data manipulation or system interference with intent to obtain an unlawful economic benefit, with five years' imprisonment and the chiffre 4 fine, whose maximum may be raised to the amount of the profit realised.

Article 389-9 punishes participating in an organized group or agreement formed to prepare, commit, facilitate, or receive the proceeds of one or more of the offences at Articles 389-1 to 389-8 with the penalty for the offence itself or the most severely punished one. Article 389-11 sets the fine for a legal person at up to 1,000,000 euros.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Official consolidated Code penal text, legimonaco.mc

Back to the example  ·  Lint your app