Law / Uruguay

Código Penal arts. 297 bis, 297 ter, 297 quater, 358 quater, and 358 quinquies, computer-offence provisions inserted by Ley N° 20.327

Ley N° 20.327, de 25 de septiembre de 2024, arts. 6 y 8, Código Penal arts. 297 bis, 297 ter, 297 quater, 358 quinquies

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

In force.

A computer misuse rule binding public and private bodies.

As of 5 September 2026.

What it requires

  • Do not access, intercept, disclose, sell, or transfer another's information held on a digital medium by computer or telematic means without authorization and without just cause.
  • Reading a public, unauthenticated page without defeating any access control has not itself been held to violate these provisions.
  • Do not access, appropriate, use, or modify a third party's confidential data held on a digital medium without the holder's authorization, and do not disclose, reveal, or transfer such data to a third party.
  • Do not destroy, alter, or render unusable data or computer systems belonging to another without authorization.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Unauthorized access, illicit interception, and computer damage (Código Penal arts. 297 bis, 297 ter, and 358 quater) each carry six to twenty-four months' imprisonment. Appropriating or modifying a third party's confidential data (art. 297 quater, first paragraph) carries the same six-to-twenty-four-month range, rising to one to four years' imprisonment where the data is disclosed, revealed, or transferred to a third party (art. 297 quater, second paragraph), a range aggravated further where the data is personal data protected under Ley N° 18.331.

What it reaches

Obligation class

Access restriction, Security

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Article 297 bis (acceso ilícito a datos informáticos) punishes with six to twenty-four months' imprisonment anyone who, by computer or telematic means, without authorization and without just cause, accesses, interferes with, discloses, sells, or transfers another's information held on a digital medium; because the offence's trigger is acting without authorization, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

Article 297 ter punishes unauthorized interception of non-public data transmissions with the same six-to-twenty-four-month range.

Article 297 quater (vulneración de datos) punishes, with the same six-to-twenty-four-month range, accessing, appropriating, using, or modifying a third party's confidential data held on a digital or other medium without the holder's authorization, and separately punishes disclosing, revealing, or transferring such data to a third party with one to four years' imprisonment, aggravated where the data are personal data protected under Ley N° 18.331.

Article 358 quater (daño informático) punishes destroying, altering, or rendering unusable data or computer systems without authorization and with intent to cause harm with six to twenty-four months' imprisonment. Article 358 quinquies (abuso de los dispositivos) punishes producing, acquiring, importing, marketing, or supplying to a third party a program, system, or access credential unequivocally intended for committing an offence, with the same six-to-twenty-four-month range.

When LexLint raises it

  • crawls_web
  • trains_models

Read the law

Official text of Ley N° 20.327 inserting these articles into the Código Penal
Centro de Información Oficial (IMPO), Uruguay's official legislative database

Back to the example  ·  Lint your app