Cybercrime Prevention Law, unauthorised access
Law No. 14 of 2014 (Cybercrime Prevention Law), arts. 2-4
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not intentionally and illegally access, exceed authorised access to, or knowingly continue accessing a Qatar-based website, information system, or information network once aware the access is unauthorised; a violation reaching a system belonging to a state authority or affiliated corporation carries a doubled penalty.
- Do not unlawfully capture, intercept, or spy on traffic data or data being transmitted through an information network while crawling or collecting it.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Article 3's general unauthorised-access offence carries imprisonment of up to three years and a fine of up to QAR 500,000, doubled on aggravating grounds; article 2's parallel offence against a state-affiliated system carries the same base penalty and doubling; article 4's interception offence carries a lower ceiling of two years and QAR 100,000.
Penalty structure
Article 3 (general unauthorised access, exceeding authorised access, or continued access once known unauthorised) and article 2 (unauthorised access to a state-affiliated system) each carry imprisonment of up to three years and a fine of up to QAR 500,000, doubled to up to six years and QAR 1,000,000 where the access results in acquiring, disclosing, destroying, transferring, or republishing data. Article 4's separate interception offence carries a lower ceiling of imprisonment up to two years and a fine of up to QAR 100,000.
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- QAR
- Fixed cap
- 1,000,000
What it reaches
Obligation class
Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 3 punishes any person who intentionally and illegally accesses a website, information system, information network, or information technology technique, exceeds authorised access, or knowingly continues to visit or access it once aware the access is unauthorised, with imprisonment of up to three years and a fine of up to QAR 500,000, doubled where the access results in acquiring, disclosing, destroying, or republishing data.
Article 2 imposes the same base penalty, doubled on the same grounds, for unlawful access specifically to a website or information system belonging to a state authority, body, entity, or affiliated corporation. Article 4 separately punishes unlawfully capturing, intercepting, or spying on traffic data or data in transit through an information network or technology technique, with a lower ceiling of two years and QAR 100,000. The Law does not define 'unauthorised' by reference to a technical access control.
When LexLint raises it
crawls_webtrains_models
Read the law
official unofficial-translation text published by the Communications Regulatory Authority (CRA)