Law / Panama

Código Penal, Delitos contra la Seguridad Informática

Código Penal de la República de Panamá (texto único 2010), Libro Segundo, Título VIII, Capítulo I, arts. 289-292

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Do not improperly enter or use a database, network or computer system.
  • Do not improperly seize, copy, use or modify data in transit or held in a database or computer system, or interfere with, intercept, obstruct or prevent its transmission.
  • Expect an aggravated penalty if the data belongs to a public office, a public-service institution, a bank, insurer or other financial institution, or if the conduct is committed for profit or by someone authorized to access the system.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Two to four years' imprisonment under article 289 or 290, aggravated by a third to a sixth under article 291 for data held by public offices, public-service providers, banks, insurers or financial or securities institutions, or when committed for profit, and aggravated by a sixth to a third under article 292 when committed by the person in charge of, or authorized to access, the database or system.

What it reaches

Obligation class

Access restriction, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 289 sanctions with two to four years' imprisonment anyone who improperly enters or uses a database, network or computer system.

Article 290 imposes the same two-to-four-year range on anyone who improperly seizes, copies, uses or modifies data in transit or held in a database or computer system, or who interferes with, intercepts, obstructs or prevents its transmission; neither article conditions the offence on defeating a technical security measure, so a plain reading reaches unauthorized use of a public, unauthenticated page as well as a password-protected one.

Article 291 aggravates the penalty by a third to a sixth when the conduct targets data held by a public office, a public, private or mixed institution providing a public service, or a bank, insurer or other financial or securities institution, and aggravates it further when committed for profit.

Article 292 aggravates the penalty by a sixth to a third when the offender is the person in charge of the database or system, a person authorized to access it, or someone who used privileged information to commit the offence. The consolidated text names an adoption date of 15 April 2010 for this compiled version of the Código Penal, but that date marks the compilation rather than a stated commencement day for these specific articles, so no commencement date is recorded here.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Consolidated Código Penal text (texto único 2010) reproduced by the UNODC Sherloc/CLD legislation database
sourced from the Asamblea Nacional's own Legispan record

Back to the example  ·  Lint your app