Trestny zakon, Unauthorized Access to a Computer System and Related Offences
Act 300/2005 Coll. (Trestny zakon), ss. 247-247d
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 1 January 2006.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not overcome a security measure to gain access to a computer system or part of it without authorization.
- Do not interfere with a computer system's operation or with computer data within it without authorization, including by unauthorized insertion, transmission, damage, deletion, degradation, alteration, suppression, or blocking of computer data.
- Do not intercept a non-public transmission of computer data to, from, or within a computer system without authorization.
- Do not produce, import, procure, sell, exchange, distribute, or otherwise make available a device, computer program, password, access code, or similar data created to enable unauthorized access to a computer system.
- Reading a public, unauthenticated page without defeating any access control has not itself been held to violate these sections.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Section 247: imprisonment up to two years for the base offence, six months to three years where committed in a more serious manner or causing significant damage, and one to five years where causing large-scale damage or committed as a member of a dangerous grouping. Section 247a and section 247b (unauthorized interference with a system or with data): six months to three years for the base offence, one to five years for an aggravated form (significant damage, serious disruption to a public authority or court, or misuse of another's personal data to gain a third party's trust), and two to eight years where the act causes large-scale damage, causes a serious disruption of critical infrastructure, or is committed by a member of a dangerous grouping. Section 247c (unauthorized interception): up to two years for the base offence, six months to three years where committed by an employee of an electronic communications service provider, one to five years for an aggravated form, and two to eight years for the most serious form. Section 247d (production or possession of an access device): up to two years for the base offence, six months to three years where committed in a more serious manner or causing significant damage, and one to five years where causing large-scale damage or committed as a member of a dangerous grouping. None of sections 247 to 247d attaches a monetary fine.
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 247 punishes a person who overcomes a security measure and thereby obtains unauthorized access to a computer system or part of it with imprisonment of up to two years, rising to six months to three years where the act is committed in a more serious manner or causes significant damage, and to one to five years where it causes large-scale damage or is committed as a member of a dangerous grouping.
Because the offence's trigger is overcoming a security measure, reading a public, unauthenticated page without defeating any access control has not itself been held to violate this section.
Section 247a punishes unauthorized interference with a computer system's operation, section 247b unauthorized interference with computer data, section 247c unauthorized interception of non-public computer-data transmissions, and section 247d the production, import, or sale of a device, password, or access code created for unauthorized access to a computer system, each with its own escalating tiers running from six months up to eight years for the most serious forms.
When LexLint raises it
crawls_webtrains_models