Law / Qatar

Cybercrime Prevention Law, unauthorised access

Law No. 14 of 2014 (Cybercrime Prevention Law), arts. 2-4

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 6 September 2026.

What it requires

  • Do not intentionally and illegally access, exceed authorised access to, or knowingly continue accessing a Qatar-based website, information system, or information network once aware the access is unauthorised; a violation reaching a system belonging to a state authority or affiliated corporation carries a doubled penalty.
  • Do not unlawfully capture, intercept, or spy on traffic data or data being transmitted through an information network while crawling or collecting it.

If you get it wrong

Criminal exposureYes

Criminal exposure note

Article 3's general unauthorised-access offence carries imprisonment of up to three years and a fine of up to QAR 500,000, doubled on aggravating grounds; article 2's parallel offence against a state-affiliated system carries the same base penalty and doubling; article 4's interception offence carries a lower ceiling of two years and QAR 100,000.

Penalty structure

Article 3 (general unauthorised access, exceeding authorised access, or continued access once known unauthorised) and article 2 (unauthorised access to a state-affiliated system) each carry imprisonment of up to three years and a fine of up to QAR 500,000, doubled to up to six years and QAR 1,000,000 where the access results in acquiring, disclosing, destroying, transferring, or republishing data. Article 4's separate interception offence carries a lower ceiling of imprisonment up to two years and a fine of up to QAR 100,000.

Rule
Fixed only
As of
6 September 2026
Currency
QAR
Fixed cap
1,000,000

What it reaches

Obligation class

Access restriction

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 3 punishes any person who intentionally and illegally accesses a website, information system, information network, or information technology technique, exceeds authorised access, or knowingly continues to visit or access it once aware the access is unauthorised, with imprisonment of up to three years and a fine of up to QAR 500,000, doubled where the access results in acquiring, disclosing, destroying, or republishing data.

Article 2 imposes the same base penalty, doubled on the same grounds, for unlawful access specifically to a website or information system belonging to a state authority, body, entity, or affiliated corporation. Article 4 separately punishes unlawfully capturing, intercepting, or spying on traffic data or data in transit through an information network or technology technique, with a lower ceiling of two years and QAR 100,000. The Law does not define 'unauthorised' by reference to a technical access control.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

official unofficial-translation text published by the Communications Regulatory Authority (CRA)

Back to the example  ·  Lint your app