Cod penal, Art. 360-366, Infracțiuni contra siguranței și integrității sistemelor și datelor informatice (Offences Against the Security and Integrity of Computer Systems and Data)
Codul penal (Legea nr. 286/2009), art. 360-366
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 February 2014.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not access a computer system in Romania without a right to do so; the penalty rises where the access is for the purpose of obtaining data and rises further where the system's access is technically restricted to certain users, per Cod penal art. 360.
- Do not intercept, alter, or disrupt computer data or a computer system's functioning, and do not transfer data out of a computer system without authorization, per Cod penal arts. 361-364.
- Do not produce, distribute, or possess a device, program, password, or access code intended to commit one of these offences, per Cod penal art. 365.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Unauthorized access to a computer system carries 3 months to 3 years' imprisonment or a fine, rising to 6 months to 5 years where the access was for obtaining data and to 2 to 7 years where the system was access-restricted (art. 360). Illegal interception, data-integrity alteration, and unauthorized data transfer each carry 1 to 5 years (arts. 361, 362, 364); disrupting a system's functioning carries 2 to 7 years (art. 363); dealing in an access-defeating device, program, password or code carries 6 months to 3 years' imprisonment or a fine, and possession for that purpose carries 3 months to 2 years' imprisonment or a fine (art. 365); attempt is punishable (art. 366).
What it reaches
Obligation class
Access restriction
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Unauthorized access to a computer system is punishable by 3 months to 3 years' imprisonment or a fine, rising to 6 months to 5 years where the access aimed at obtaining data and to 2 to 7 years where the system's access was technically restricted to certain categories of users, per art. 360.
Illegal interception of a non-public data transmission, alteration of the integrity of computer data, and unauthorized transfer of data from a computer system each carry 1 to 5 years' imprisonment, per arts. 361, 362 and 364. Disrupting a computer system's functioning carries 2 to 7 years, per art. 363.
Producing, importing, distributing or making available a device, program, password or access code for the purpose of committing one of these offences carries 6 months to 3 years' imprisonment or a fine, and mere possession of one of these items for that purpose carries 3 months to 2 years' imprisonment or a fine, per art. 365; an attempt at any of these offences is itself punishable, per art. 366.
When LexLint raises it
crawls_web