Ley 30096, unauthorized access and data/system integrity offenses
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 22 October 2013.
A computer misuse rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not access a computer system, in whole or in part, without authorization or beyond what you are authorized to access; defeating a security measure to do so draws a higher penalty tier.
- Do not damage, introduce, delete, deteriorate, alter, suppress, or make inaccessible another party's computer data.
- Do not disable a computer system, impede access to it, or hinder or prevent its operation or the provision of its services.
- Do not intercept non-public computer data transmissions without authorization.
- Do not design, sell, distribute, or obtain a tool, password, or access code specifically to commit one of these offenses.
- Expect a sentencing enhancement of up to one-third above the legal maximum where an offense under this Law is committed using artificial intelligence or a similar technology.
- Conduct under articles 2, 3, 4, or 10 carried out to run an authorized test or other authorized procedure to protect computer systems is exempt from criminal liability.
If you get it wrong
Criminal exposureYes
Private right of actionNo
Criminal exposure note
Article 2: one to four years' imprisonment and 30 to 90 day-fines for unauthorized access; three to six years and 80 to 120 day-fines where a security measure is defeated. Articles 3, 4, and 7: three to six years' imprisonment and 80 to 120 day-fines. Article 11 raises any of these sentences by up to one-third above the legal maximum on an aggravating circumstance, including an offense committed using artificial intelligence or a similar technology.
Who enforces it
Enforcement body
Ministerio Público (Peru's Public Prosecutor's Office) and the Poder Judicial, through ordinary criminal prosecution
What it reaches
Obligation class
Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 2 punishes deliberately and illegitimately accessing all or part of a computer system, or exceeding authorized access, with one to four years' imprisonment and thirty to ninety day-fines; the penalty rises to three to six years' imprisonment and eighty to one hundred twenty day-fines where the agent defeats a security measure to gain access.
Article 3 punishes deliberately and illegitimately damaging, introducing, deleting, deteriorating, altering, suppressing, or making inaccessible computer data, and article 4 punishes deliberately and illegitimately disabling a computer system in whole or in part, impeding access to it, or hindering its operation or the provision of its services, each with three to six years' imprisonment and eighty to one hundred twenty day-fines.
Article 7 punishes deliberately and illegitimately intercepting non-public computer data transmissions to, from, or within a computer system. Article 10 punishes fabricating, designing, developing, selling, facilitating, distributing, importing, or obtaining a mechanism, program, device, password, access code, or other computer data specifically designed to commit one of the Law's offenses.
Article 11 raises the sentence by up to one-third above the legal maximum for any of these offenses where an aggravating circumstance applies, including, since Ley 32314 (29 April 2025), where the agent commits the offense using artificial intelligence or a similar or analogous technology. Article 12 exempts from criminal liability conduct described in articles 2, 3, 4, or 10 undertaken to carry out an authorized test or other authorized procedure to protect computer systems.
When LexLint raises it
crawls_webtrains_models
Read the law
consolidated text of Ley 30096
Ley de Delitos Informáticos, as republished by LP Derecho (Pasión por el Derecho), a Peruvian legal publisher