Law / Poland

Kodeks karny, Unauthorized Access to Information and Computer-Misuse Offenses

Ustawa z dnia 6 czerwca 1997 r. Kodeks karny (Dz.U. 1997 nr 88 poz. 553, tekst jednolity), art. 267-269c

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not bypass or circumvent an electronic, technical, magnetic, IT, or other special security measure to access data or an IT system not intended for you; unauthorized access under Kodeks karny Art. 267 carries a fine, restriction of liberty, or imprisonment up to 2 years.
  • Do not produce, obtain, sell, or supply a device, computer program, password, or access code adapted to commit an Art. 267, 268a, 269, or 269a offense; doing so is a separate offense under Art. 269b carrying imprisonment up to 5 years, unless you act solely to secure a system or to develop a securing method.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Art. 267(1)-(2): fine, restriction of liberty, or imprisonment up to 2 years for unauthorized access to information or to an IT system. Art. 268(1)-(2): fine, restriction of liberty, or imprisonment up to 2 years for destroying, damaging, deleting, or altering a record of significant information, rising to imprisonment up to 3 years where the record is on an IT data carrier; Art. 268(3) raises this to imprisonment from 3 months to 5 years where the act causes significant property damage. Art. 268a(1)-(2): imprisonment up to 3 years for destroying, damaging, deleting, altering, or hindering access to IT data or disrupting its automated processing, rising to imprisonment from 3 months to 5 years for significant property damage. Art. 269(1)-(2): imprisonment from 6 months to 8 years for the same conduct against IT data of special significance for national defense, communications security, or government or local-government functioning. Art. 269a: imprisonment from 3 months to 5 years for materially disrupting an IT system's or network's operation. Art. 269b(1): imprisonment from 3 months to 5 years for producing, obtaining, selling, or supplying a device, program, password, or access code adapted to commit the listed offenses; Art. 269b(1a) exempts a person acting solely to secure a system or develop a securing method. Prosecution of Arts. 267 and 268 requires the victim's motion (wniosek) under Arts. 267(5) and 268(4); Arts. 268a, 269, 269a, and 269b are prosecuted without one.

What it reaches

Obligation class

Access restriction, Prohibition

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 267 criminalizes obtaining unauthorized access to information not intended for the accessor by opening a sealed letter, connecting to a telecommunications network, or bypassing or circumventing an electronic, magnetic, IT, or other special safeguard protecting it, and separately criminalizes unauthorized access to the whole or part of an IT system, planting or using an eavesdropping, visual, or other device or software to obtain information, and disclosing information obtained that way.

Article 268 and 268a criminalize destroying, damaging, deleting, or altering a record of significant information or IT data, or hindering a person's or a system's ability to use it. Article 269 raises the penalty where the IT data affects national defense, communications security, or government or local-government functioning.

Article 269a criminalizes materially disrupting an IT system's or network's operation through unauthorized transmission, destruction, deletion, damage, hindrance, or alteration of data.

Article 269b criminalizes producing, obtaining, selling, or making available a device or computer program adapted to commit the offenses in Articles 165(1)(4), 267(1) to (3), 268a, 269, 269a, 270, or 270a, or a password, access code, or other data enabling unauthorized access to an IT system or network, with an exemption at Article 269b(1a) for a person acting solely to secure a system or to develop a securing method.

When LexLint raises it

  • crawls_web

Read the law

Dziennik Ustaw, consolidated text of the Kodeks karny, Kancelaria Sejmu edition

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived September 5, 2026. Publisher's page: https://isap.sejm.gov.pl/isap.nsf/download.xsp/WDU19970880553/U/D19970553Lj.pdf

Back to the example  ·  Lint your app