Law / Madagascar

Law No. 2014-006, fraudulent access to an information system

Loi n° 2014-006 sur la lutte contre la cybercriminalité, art. 3, 4 et 6 (accès et maintien frauduleux)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Do not access, or remain connected to, all or part of an information system intentionally and without a legitimate excuse or justification.
  • Whether reading a public, unauthenticated page with no login or technical barrier counts as access without a legitimate excuse or justification has not been tested by a Malagasy court.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

A fine of 100,000 to 10,000,000 Ariary for fraudulent access or continued presence alone; six months' to five years' imprisonment together with the same fine range where the access or continued presence damaged data or impeded the system (art. 6).

Penalty structure

Fine-only tier for fraudulent access or continued presence with no resulting damage; the same fine range applies together with six months' to five years' imprisonment where the conduct damaged data or impeded the system's operation.

Rule
Fixed only
As of
5 September 2026
Currency
MGA
Fixed cap
10,000,000

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 defines fraudulent access as intentionally accessing all or part of an information system without a legitimate excuse or justification, or beyond one. Article 4 defines fraudulent continued presence in the same terms, for remaining connected to or continuing to use a system.

Article 6 punishes fraudulent access or continued presence alone with a fine of 100,000 to 10,000,000 Ariary; where the access or continued presence damaged, erased, altered, or suppressed data, or impeded or altered the system's functioning, the penalty rises to six months' to five years' imprisonment together with the same fine range.

Article 3's definition of fraudulent access nowhere requires infringing a security measure or other technical protection, so its trigger, an intentional access without a legitimate excuse or justification, reads broader on its face than a standard limited to defeating one. The National Assembly adopted the law on 19 June 2014; the presidential promulgation date and Journal Officiel publication date are not confirmed in the primary text located.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Text of Loi n° 2014-006 reproduced by the Association francophone des autorités de protection des données personnelles (AFAPDP)

Back to the example  ·  Lint your app