Crimes Act 1961, Accessing a Computer System Without Authorisation
Crimes Act 1961 (NZ), No 43, s. 252
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 October 2003.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not intentionally access, directly or indirectly, a computer system without authorisation, knowing or being reckless as to whether you are authorised to access it.
- Accessing a public, unauthenticated page has not itself been held to violate this section, since the offence does not extend to a person authorised to access a system who merely uses that access for an unintended purpose.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Under s. 252(1), a fixed maximum of 2 years imprisonment on conviction; the section states no accompanying fine.
Who enforces it
Enforcement body
New Zealand Police, prosecuted by the Crown
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Makes it an offence, punishable by up to 2 years imprisonment, to intentionally access, directly or indirectly, any computer system without authorisation, knowing or being reckless as to the lack of authorisation.
The section expressly does not apply to a person who is authorised to access a computer system but does so for a different purpose than the one for which access was given, which leaves open whether accessing a public, unauthenticated page (for which no authorisation was ever required) falls within the offence at all; no reported New Zealand decision has tested a scraping fact pattern under this section.
When LexLint raises it
crawls_webtrains_models
Read the law
official consolidated Act text, New Zealand Legislation