Computer Crime and Cybercrime Act, 2022, Illegal Access
Computer Crime and Cybercrime Act, 2022 (Act No. 6 of 2022), s. 3 (Illegal Access)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force since 4 March 2022.
A computer misuse rule binding public and private bodies.
As of 6 September 2026.
What it requires
- Do not access the whole or any part of a computer system without lawful excuse or justification; logging into a system you are not entitled to use is itself an offence under this Act, even before any security measure is defeated.
- Do not infringe a security measure to obtain computer data once inside a system, which raises the penalty for the access itself.
If you get it wrong
Criminal exposureYes
Criminal exposure note
Section 3(1): a fine of up to E300,000 or imprisonment of up to three years, or both, for accessing a computer system without lawful excuse or justification. Section 3(2) raises this to a fine of up to E500,000 or imprisonment of up to five years, or both, where the access also infringes a security measure to obtain computer data.
Penalty structure
Section 3(1)'s base offence (access without lawful excuse or justification, no security measure infringed) caps at a fine of E300,000 or imprisonment of three years, or both. Section 3(2)'s aggravated offence (access that also infringes a security measure to obtain data) caps at a fine of E500,000 or imprisonment of five years, or both; the fixed_cap recorded here is the higher, aggravated-tier amount.
- Rule
- Fixed only
- As of
- 6 September 2026
- Currency
- SZL
- Fixed cap
- 500,000
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 3(1) makes it an offence, without needing to defeat any security measure, for a person to intentionally access the whole or any part of a computer system "without lawful excuse or justification," carrying a fine of up to E300,000 or imprisonment of up to three years, or both; "access" is defined at s. 2, in relation to this section only, as "logging into a computer system," so a plain reading does not reach merely retrieving a public, unauthenticated page without logging in.
Section 3(2) raises the penalty to a fine of up to E500,000 or imprisonment of up to five years, or both, where the person accessing under subsection (1) also infringes a security measure with intent to obtain computer data.
When LexLint raises it
crawls_webtrains_models
Read the law
Computer Crime and Cybercrime Act
2022, official Government Gazette Extraordinary text hosted by the Eswatini Communications Commission (ESCCOM)