Loi n° 2019-056, accès et maintien frauduleux à un système d'information
Loi n° 2019-056 du 5 décembre 2019 portant répression de la cybercriminalité arts. 4-5 (accès et maintien frauduleux à un système d information)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 13 December 2019.
A computer misuse rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not access, or attempt to access, an information system by an irregular mode of penetration, and do not remain, or attempt to remain, in an information system once access to it is irregular.
- The statute does not state that unauthorized access must defeat a technical security measure, so reading a public, unauthenticated page could fall inside a broad reading of 'irregular penetration' even without circumventing any access control.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Imprisonment of two months to one year and a fine of 200,000 to 5,000,000 CFA francs, or either penalty, rising to imprisonment of two months to two years and a fine of 1,000,000 to 10,000,000 CFA francs where the access or presence results in deleting or altering data or impairing the system's operation (arts. 4-5).
Penalty structure
Base tier under articles 4 and 5 for a fraudulent access or presence that causes no further harm. The fine rises to 1,000,000-10,000,000 CFA francs, with imprisonment of two months to two years, where the access or presence results in deleting or altering data or impairing the system's operation.
- Rule
- Fixed only
- As of
- 5 September 2026
- Minimum
- 200,000
- Currency
- XOF
- Fixed cap
- 5,000,000
What it reaches
Obligation class
Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 4 punishes anyone who accesses or attempts to access, fraudulently, all or part of an information system, with imprisonment of two months to one year and a fine of 200,000 to 5,000,000 CFA francs, or either penalty, and raises the penalty to two months to two years' imprisonment and a fine of 1,000,000 to 10,000,000 CFA francs where the access results in deleting or altering data or impairing the system's operation.
Article 5 punishes fraudulently remaining or attempting to remain in all or part of an information system on the same terms.
Article 3 defines fraudulent access as any irregular mode of penetration of an automated data-processing system, a definition that does not itself require defeating a technical security measure, so whether it reaches a person who reads a public, unauthenticated page without circumventing any access control turns on how 'irregular' is construed rather than on a stated security-measure element.
When LexLint raises it
crawls_webtrains_models