Law / Frameworks / NIST AI RMF / Map
NIST AI RMF, MapMAP 4.1
Approaches for mapping AI technology and legal risks of its components – including the use of third-party data or software – are in place, followed, and documented, as are risks of infringement of a third party’s intellectual property or other rights.NIST AI Risk Management Framework, version 1.0, January 2023 (NIST AI 100-1), MAP 4.1
We read each law below as bearing on this control. That does not mean the control, done well, meets the law: what each law asks is on its own page. Corpus as of .
- 381
- laws
- 224
- places
- 4
- with court rulings behind them
- 10
- not yet in force
The same ground elsewhere linked through the kinds of duty both controls are mapped from
- NIST AI 600-1GAI-RISK-10 Intellectual Property
- NIST AI 600-1GAI-RISK-12 Value Chain and Component Integration
- OWASP LLM Top 10LLM03:2026 Excessive Agency
- OWASP Agentic Top 10ASI03 Identity and Privilege Abuse
- MIT mitigations3.2 Data Governance
- MIT mitigations2.1 Model & Infrastructure Security
- NIST Privacy FrameworkPR.AC-P1 Identities and credentials are issued, managed, verified, revoked, and audited for...
- NIST Privacy FrameworkPR.AC-P4 Access permissions and authorizations are managed, incorporating the principles of...
A law in force is unmarked; the rest wear their state: not yet in force
Computer misuse
222 laws, 201 places| Place | Law | What it asks, as read here |
|---|---|---|
| Penal Code, Part Twelve, Chapter One (Cyber Crimes and Punishment) |
Do not access a computer, program, or data belonging to someone else without authorization; the Penal Code's wording carries no exception for a public, unauthenticated page, and no reported case construes the term. |
|
| Alabama Digital Crime Act, Computer Tampering |
Because exceeding authorization of use is defined as using access you do have to obtain or alter information you are not entitled to obtain or alter, do not use a login or other legitimate access to a computer, computer system, or network to take or alter data beyond what you are authorized to take or alter. |
|
| Criminal mischief in the fourth degree, unauthorized computer access |
Do not knowingly access a computer, computer system, program, or network without a right, or a reasonable belief of a right, to do so, even where the access causes no further harm. |
|
| Criminal use of a computer |
Do not access, or exceed authorized access to, a computer, computer system, program, or network you have no right, or no reasonable belief of a right, to use. Do not use unauthorized access to obtain information concerning a person, another person's proprietary information, or information the source makes available to the public only for a fee. |
|
| Theft of services, unauthorized use of a computer system |
Do not obtain the use of another person's computer time, computer system, program, or network with reckless disregard that the use is unauthorized. |
|
| Code pénal, atteintes aux systèmes de traitement automatisé de données |
Do not access or remain in an automated data-processing system without authorization, whether or not the system is protected by a technical measure. Do not create, distribute, or possess tools or data intended to commit these offences, or use data obtained through them. |
|
| Penal Code, Attacks on Information Systems |
Do not access all or part of an information system by defeating a security measure, without authorization, when the result is serious. Do not intercept non-public data transmissions to, from, or within an information system without authorization. |
|
| Penal Code, Unauthorised Access to an Information System |
Do not access, without authorisation, all or part of an information system of which you are not the holder. Do not defeat a security measure or access a conditional-access ('protegido') service to reach a system without authorisation, which draws a substantially heavier penalty. |
|
| Electronic Crimes Act, 2013, access and interference |
Do not intentionally access, or download, copy or extract data from, an electronic system or network without a lawful excuse or justification. |
|
| Código Penal, art. 153 bis, unauthorized access to a restricted computer system or data |
Do not access a computer system or data of restricted access without due authorization, or by exceeding the authorization held. |
Show the other 212 laws
| Computer tampering (Arizona's computer-misuse statute) |
Do not access an Arizona-connected computer, computer system, or network without authority or in excess of your authorization; paragraph 8 criminalizes bare unauthorized access even without any intent to defraud, damage, or disrupt. Do not access a computer, computer system, or network operated by the state, a political subdivision, a health care provider, or a clinical laboratory to obtain information required by law to be kept confidential or records that are not public records. |
|
| Computer fraud |
Do not access, or cause to be accessed, a computer, computer system, or computer network to devise or execute a scheme to defraud or extort, or to obtain money, property, or a service through a false or fraudulent intent, representation, or promise. |
|
| Computer trespass |
Do not intentionally and without authorization access, alter, delete, damage, destroy, or disrupt a computer, computer system, computer network, computer program, or data. |
|
| Unlawful interference with access to computers; unlawful use or access of computers |
Do not knowingly and without authorization use, access, attempt to access, or cause access to be gained to a computer, system, network, telecommunications device, telecommunications service, or information service. |
|
| Criminal Code, unauthorised computer access and illegal appropriation of data |
Do not penetrate a computer, computer system or network without permission arising from law, contract or other legitimate basis; reading a public, unauthenticated page has not been held to fall within this prohibition, since the offence also requires that the access negligently cause destruction, alteration, damage or copying of data or other material harm. Do not intercept or appropriate computer data that is not intended for general use, without permission under law, contract or other legitimate basis, for the purpose of using it or making it available to others; data a service makes available for general, public use falls outside a plain reading of this provision. |
|
| Criminal Code Act 1995 (Cth), Part 10.7, Unauthorised Access to Restricted Data |
Do not cause access to, or modification of, data held in a computer where that data is restricted by an access control system and you are not entitled to cause the access, knowing the access is unauthorised. |
|
| StGB Sections 118a and 126a to 126c, Computer-Misuse Offenses |
Do not overcome a computer system's specific security measure to gain access, if your purpose is to obtain personal data protected by a secrecy interest, or to use the accessed data or system to harm another, per StGB Section 118a. |
|
| Criminal Code, unauthorised access, illegal interception, and system interference |
Do not intentionally access a computer system, or any part of it, without the right to do so or by violating its security measures, with intent to seize the data stored there or for personal purposes. Do not intentionally intercept, by technical means, computer data not intended for general use that is transmitted to, from, or within a computer system, without the right to do so. |
|
| Computer Misuse Act 2003, unauthorised access, modification and interception offences |
Do not cause a computer to perform any function to secure access to a program or data without being entitled to control that access or having the consent of someone who is. Do not modify computer material, intercept a computer service, or obstruct the use of a computer without authority. |
|
| Cyber Security Act, 2026, unauthorised access to a computer system |
Do not gain illegal entry into a computer, digital device, computer system, or computer network, and do not assist another person to do so; a higher penalty applies where the entry is for the purpose of committing an offence, and a further higher penalty applies where the entry results in the theft, destruction, or alteration of information, or in an AI agent generating new data through that access. |
|
| Computer Misuse Act, illegal access |
Do not gain access to a computer system, cause a programme to execute, or copy, move, alter, or erase data, knowingly or recklessly and without lawful excuse or justification. |
|
| Criminal Code, Crimes Against Computer Security |
Do not access a computer system or the information it holds by defeating or circumventing a protection or security measure, whether for gain or where doing so negligently causes substantial harm. Do not copy, intercept, or otherwise unlawfully acquire computer information causing substantial harm, even without defeating a protection measure. |
|
| Code pénal, Livre II, articles 524 à 527, accès non autorisé dans un système informatique |
Do not access or remain in a computer system knowing you are not authorised to do so. Do not exceed your own access rights to a computer system with a fraudulent intent or an intent to harm. +1 more |
|
| Cybercrime Act, illegal access to a computer system |
Do not access a computer system of another person without authorisation, in excess of authorisation, or by infringing a security measure, and do not continue to exceed authorised access once it is withdrawn. |
|
| Loi n°2017-20 portant Code du Numérique en République du Bénin, Livre VI (cybercriminalité), atteintes aux réseaux et systèmes d'information |
Do not access, or remain present in, a computer system without right; the penalty escalates where the access or presence is aggravated by fraudulent intent, exceeds an authorized level of access, results in data being suppressed or modified, or is committed in violation of the system's security measures. Do not intercept, divulge, use, alter, or misappropriate computer data during its non-public transmission to, from, or within a computer system. |
|
| Computer Misuse Act 1996, unauthorised access and modification offences |
Do not cause a computer to perform any function to secure access to a program or data without being entitled to control that access or having the consent of someone who is, and knowing the access is unauthorised. |
|
| Information, Communications and Media Act of Bhutan 2018, unauthorized access and tampering with computer systems |
Do not access a computer, computer system, network, or computer, content, or traffic data without authorization; unauthorized access is a felony of the fourth degree regardless of resulting damage, and the person is liable to pay court-determined compensation to the victim. |
|
| Código Penal, Alteración, Acceso y Uso Indebido de Datos Informáticos |
Do not appropriate, access, use, modify, suppress, or disable data stored on a computer or other computer medium without authorization, where doing so harms the data's owner. |
|
| Cybercrime and Computer Related Crimes Act, 2018 (Act No. 18 of 2018) |
Do not access, or attempt to access, all or part of a computer or computer system knowing the access is unauthorised, and do not cause a computer system to perform a function as a result of such unauthorised access. Do not secure or intend to secure access to a computer system for the purpose of obtaining a computer service, and do not intercept a function of or data within a computer system, without authorisation or beyond the authorisation given. |
|
| Penal Code Art. 154-A, Invasion of a Computing Device |
Do not invade a computing device, connected to a network or not, to obtain, alter, or destroy data or information without the device user's authorization, or to install a vulnerability to obtain an unlawful advantage. |
|
| Computer Misuse Act, unauthorised access to computer material |
Do not cause a computer to perform a function for the purpose of securing access to a program or data without authority, meaning without the entitlement to control that access and without the consent of a person who holds that entitlement. |
|
| Criminal Code (Nakazatelen kodeks), Art. 319a, Unauthorized Access to an Information System |
Do not unlawfully access an information system or a part of it; a non-immaterial unauthorized access carries imprisonment of up to six years under Article 319a(1), rising with aggravating circumstances. |
|
| Loi n°025-2018/AN du 31 mai 2018 portant Code pénal, computer and data systems offenses (Livre VII, Titre I, Chapitre 1) |
Do not access, or remain present in, a computer system without right; a heavier penalty applies where the access or continued presence results in data being suppressed, modified, or altered. Do not intercept a non-public data transmission to, from, or inside a computer system without right. +1 more |
|
| Cybercrime Law, Unauthorised Access to a Computer System |
Do not access a computer system without legal permission or authorization from its owner or another rights holder, and do not produce, sell, distribute, or introduce a device, program, or code intended to produce that unauthorised access. |
|
| Comprehensive Computer Data Access and Fraud Act (unauthorized access, broader than the federal without-authorization test) |
Do not continue accessing a California site, or circumvent a technical block, after the operator has sent a cease-and-desist notice (Facebook v. Power Ventures, 9th Cir. 2016; Craigslist v. 3Taps, N.D. Cal. 2013). |
|
| Criminal Code, offences in the information technology sector |
Do not fraudulently access or maintain access to a computer system located in Cambodia, including to copy, alter, or delete data from it. |
|
| Loi n°2010/012 du 21 décembre 2010 relative à la cybersécurité et à la cybercriminalité au Cameroun, articles 68-69 (accès frauduleux) |
Do not fraudulently access or remain within all or part of an electronic-communications network or information system, or transmit, damage, or cause a serious disruption or interruption of its functioning. Do not access, without right and in violation of a security measure, all or part of a network, information system, or terminal equipment connected to another information system, in order to obtain information or data. |
|
| Criminal Code, unauthorized use of a computer |
Do not obtain a computer service, or cause a function of a computer system to be intercepted, fraudulently and without colour of right. |
|
| Code Pénal, unauthorised access to and interference with a computer system |
Do not access, or attempt to access, a computer system by fraudulent means, and do not fraudulently remain in, hinder, falsify, or introduce data into one. |
|
| Ley 21.459, art. 2, acceso ilícito a un sistema informático |
Do not defeat a technical barrier or technological security measure (a login, a paywall, an access token) to reach a computer system without authorization; doing so is a criminal offence regardless of what is then done with the data. |
|
| Criminal Law, Arts. 285-286 (unauthorized computer intrusion and system destruction) |
Do not intrude into a computer system to obtain its data, or exercise illegal control over it, where the conduct is serious (Art. 285). |
|
| Código Penal, Acceso Abusivo a un Sistema Informático |
Do not access a computer system, whether or not it is protected by a security measure, without authorization or beyond what the system's owner agreed to, and do not remain in it against the will of the person entitled to exclude you. |
|
| Penal Code, unauthorized access to an information system |
Do not access, or attempt to access, any part of an information system without authorization. Do not remain, or attempt to remain, within an information system once access is no longer authorized. +1 more |
|
| Código Penal, artículo 231, Espionaje informático |
Do not use a computerized manipulation to appropriate, copy, or transmit information of economic or commercial value without the authorization of the system's owner or the party responsible for it. |
|
| Kazneni zakon, Computer Crime Chapter (Arts. 266-273) |
Do not access a computer system, part of one, or computer data in Croatia without authorisation; unauthorised access alone is a criminal offence, rising from up to two years' imprisonment to up to three years where the system or data belongs to a government body, the Constitutional Court, an international organisation Croatia belongs to, a local or regional government unit, a public institution, or a company of special public interest. Do not interfere with the operation of a computer system, damage, alter, delete, destroy or conceal another person's computer data or programs, or intercept a non-public transmission of computer data, without authorisation; each is a separate criminal offence carrying up to three years' imprisonment. |
|
| Código Penal (Ley 151/2022), offenses against telecommunications and ICT security |
Do not access or use an information system, storage device, software, or database without due authorization, for the purpose of appropriating, using, disclosing, or disseminating the information it stores, transmits, or captures. Do not violate an established computer-security measure to use information technology media in a way that affects the confidentiality, integrity, or availability of digital assets. |
|
| Attacks against Information Systems Law, Articles 3, 4, 7, 11-12 (Illegal Access, System Interference, Tools, Corporate Liability) |
Do not access the whole or part of an information system intentionally and without right by violating a security measure. |
|
| Convention on Cybercrime Ratifying Law, Article 2 (Illegal Access) |
Do not access the whole or part of a computer system intentionally and without right, per Article 2 of the Council of Europe Convention on Cybercrime as given force in Cyprus by Law 22(III)/2004. |
|
| Criminal Code Section 230, Unauthorized Access to a Computer System |
Do not overcome a security measure to gain access to a computer system or part of it in the Czech Republic, and do not use, delete, alter, forge, insert or transmit data, or otherwise interfere with a computer system's software or hardware, without authorization. |
|
| Cybercrime Act, unauthorized access to an information system |
Do not access, or attempt to access, all or part of an information system without the operator's authorization, and do not remain fraudulently within one once inside. |
|
| Delaware Computer Crime (unauthorized access, with a private civil right of action) |
Do not access a Delaware-connected computer system knowing you lack authorization to do so; an openly served page carries no obvious authorization barrier, but this statute's own text does not resolve the question for a public page. |
|
| Digital Code, Book IV: Unauthorized Access to a Computer System |
Do not access, or maintain access to, all or part of a computer system without authorization and with fraudulent intent. Do not exceed your lawful access authority over a computer system with fraudulent intent or intent to harm. +1 more |
|
| Straffeloven Section 263, Unauthorized Access to a Data System |
Do not obtain access to a data system, or to data intended for use in one, without the right to do so, including by defeating an access control while scraping. |
|
| Digital Code, Book VI: Fraudulent Access to Information Systems |
Do not access or attempt to access an information system, or a part of one, without authorization. Do not remain, or attempt to remain, within an information system after having fraudulently entered it. |
|
| Ley No. 53-07 sobre Crímenes y Delitos de Alta Tecnología, Acceso Ilícito |
Do not access an electronic, computer, telematic, or telecommunications system, or exceed an authorization to access one, using or not using another's identity. |
|
| COIP, acceso no consentido a un sistema informático |
Do not access, in whole or in part, a computer, telematic, or telecommunications system without authorization, or remain inside it against the will of the person with the legitimate right, to exploit the access, modify a web portal, divert data or voice traffic, or offer the system's services to third parties without paying the legitimate provider. |
|
| COIP, interceptación ilegal de datos |
Do not intercept, listen to, divert, record, or observe a computer datum, signal, or data transmission without a prior judicial order and for the purpose of obtaining registered or available information. |
|
| COIP, revelación ilegal de base de datos |
Do not reveal information registered in a file, archive, database, or similar medium, obtained through or directed at a computer, telematic or telecommunications system, for your own or a third party's benefit, in a way that breaches a person's secrecy, privacy or intimacy. |
|
| Law No. 175 of 2018 on Anti-Cyber and Information Technology Crimes |
Do not access, or remain present in, a restricted website, private account, or information system without authorization; if that access results in copying, altering, or republishing data, a higher penalty applies. Do not exceed the scope of access rights that were legally granted to you on a website, private account, or information system. |
|
| Ley de Propiedad Intelectual, elusión de medidas tecnológicas efectivas |
Do not evade an effective technological measure controlling access to a protected work, and do not make, import, distribute or offer a technology or device designed to do so, absent authorization. |
|
| Ley Especial contra los Delitos Informáticos y Conexos, acceso indebido a sistemas informáticos |
Do not access, intercept or use a computer system without authorization, or by exceeding the authorization you were granted. |
|
| Penal Code of the State of Eritrea, Unauthorized Use of a Computer from a date not yet set |
Do not obtain an unauthorized computer service, intercept a function of a computer system, or alter, destroy, or interfere with data in a computer system, without authorization. |
|
| Karistusseadustik (Penal Code) Section 217, Illegal Obtaining of Access to a Computer System |
Do not eliminate or avoid a technical means of protection, such as authentication, to obtain access to a computer system; Section 217 does not reach access to a system that carries no such protective measure. |
|
| Computer Crime and Cybercrime Act, 2022, Illegal Access |
Do not access the whole or any part of a computer system without lawful excuse or justification; logging into a system you are not entitled to use is itself an offence under this Act, even before any security measure is defeated. Do not infringe a security measure to obtain computer data once inside a system, which raises the penalty for the access itself. |
|
| Computer Crime Proclamation |
Do not secure access to the whole or any part of a computer system, computer data, or network without authorization or in excess of authorization, whether or not the system is publicly accessible. Do not intercept non-public computer data or a data-processing service without authorization. |
|
| Rikoslaki Chapter 38, Tietomurto and törkeä tietomurto (Computer Break-in and Aggravated Computer Break-in) |
Do not gain access to a computer system, or a separately protected part of one, by using an access code that does not belong to you or by otherwise breaking a protective measure, and do not use a special technical device to obtain data from such a system without hacking into it, under Rikoslaki 38 luku 8 sec. |
|
| Code pénal STAD Offenses, Unauthorized Access to and Interference with Automated Data Processing Systems |
Do not defeat an access control, password, or other security measure to reach a French computer system; reading a public, unauthenticated page without doing so has not itself been held to violate Article 323-1. |
|
| Loi n°027/2023, infractions et sanctions informatiques |
Do not access or remain in a computer system without authorization, whether or not the system is protected by a technical measure, and do not exceed an access you were granted. Do not hinder the operation of a computer system, or fraudulently introduce, alter, delete, or extract the data it holds. +1 more |
|
| Information and Communications Act, 2009, Computer Misuse and Cyber Crime part |
Do not cause a computer system to perform any function to secure access to a program or data without the right or permission of the person who controls that system. Do not intercept, or cause to be intercepted, any function of or data within a computer system without the consent of both the sender and the intended recipient of the data, or a statutory power to do so. |
|
| Criminal Code, unauthorised access and interference with computer data and systems |
Do not access a computer system, or copy, alter, or output data from it, without authorisation from the person who holds the right to grant that access. |
|
| Georgia Computer Systems Protection Act, computer theft, trespass, invasion of privacy, forgery, password disclosure from a date not yet set |
Do not use a Georgia-connected computer or computer network in a manner that exceeds the right or permission its owner granted; ordinary access to a page that grants and denies no specific permission at all does not, on the statute's own text, become use 'without authority.' Do not take, delete, alter, or interfere with computer data, programs, or operation without authority; doing so with the required intent is computer theft or computer trespass regardless of whether the access was automated. +1 more |
|
| Ausspaehen, Abfangen und Manipulation von Daten (Computer Misuse and Data Interference) |
Do not gain access to data that is specially secured against unauthorised access by overcoming that security measure. Do not intercept non-public data transmissions or a computer's electromagnetic emissions using technical means. +1 more |
|
| Cybersecurity Act, Unlawful Access |
Do not, without lawful authority, retrieve a person's subscriber information or intercept traffic data or content data. |
|
| Electronic Transactions Act, Cyber Offences |
Do not access or intercept an electronic record without authority or permission, whether or not the record sits behind a login. Do not cause a computer to perform any function to secure access to a programme or electronic record without authority. +1 more |
|
| Penal Code Article 370C (370Γ), Violation of Computer Data and Program Secrets |
Do not copy, record, use, or disclose to a third party computer data or programs that constitute a state, scientific, professional, or business secret, where the lawful holder treats them as secret from a justified interest, without right. |
|
| Penal Code Article 370D (370Δ), Access to an Information System in Breach of a Prohibition or Security Measure |
Do not access all or part of an information system, or data transmitted over a telecommunications system, by violating a prohibition or a security measure the lawful holder has put in place. |
|
| Electronic Crimes Act, 2013, unauthorised access and interference |
Do not gain access to, or download, copy or extract data from, an electronic system or network without the permission of its owner or the person in charge of it. |
|
| Código Penal, Decreto 17-73, Arts. 274 'A' a 274 'G' (Delitos Informáticos) |
Do not, without authorization, use another's computerized records, or enter by any means their data bank or electronic archives (art. 274 'F'); whether reading a public, unauthenticated page counts as unauthorized use or entry has not been tested by a Guatemalan court. |
|
| Loi n° L/2016/037/AN portant Cybersécurité et Protection des Données à Caractère Personnel, titre relatif aux infractions informatiques (cybercriminalité) |
Do not access, or continue to access, a computer system without right; a heavier penalty applies where the access hinders the system's operation. Do not fraudulently intercept data. |
|
| Cybercrime Act 2018, unauthorised access to a computer system |
Do not access a computer system without authorisation under the Cybercrime Act 2018; the located sources do not establish how Guyanese courts would read this against a public, unauthenticated page. |
|
| Hawaii Computer Crime Law, Part IX (unauthorized computer access, computer fraud, computer damage) |
Accessing a computer, computer system, or computer network connected to Hawaii without the permission of its owner or rightful user, or in excess of the permission granted, is unauthorized access under this statute; ordinary automated retrieval of a public, unauthenticated page has not been tested against this definition by a Hawaii court. |
|
| Código Penal, seguridad de las redes y de los sistemas informáticos |
Do not access a computer system, in whole or in part, by infringing a security measure established to prevent it, without authorization. |
|
| Büntető Törvénykönyv (Criminal Code), Sections 423-424, Violation of Information Systems or Data |
Do not log into, or remain logged into, an information system by violating or circumventing a technical measure safeguarding it; unauthorized access is a criminal offense under Btk. Section 423(1) regardless of whether any data is altered. |
|
| Almenn hegningarlög nr. 19/1940, Art. 229, Unauthorized Access to Computer-Stored Data |
Do not obtain access to another's data or programs stored in computer-readable form without authorization, including by defeating a security measure, under Almenn hegningarlög Article 229. |
|
| Computer crime (unauthorized access, use, or alteration) |
Do not knowingly access, attempt to access, or use an Idaho-connected computer, computer system, or network, or its software, program, documentation, or data, without authorization; subsection (3) reaches this as a misdemeanor even without any further intent to defraud, damage, or disrupt. Do not knowingly access or use a computer, system, or network with intent to defraud, to obtain money, property, or services by false pretenses, or to commit theft, and do not knowingly and without authorization alter, damage, or destroy a computer, system, network, or the software, program, documentation, or data it contains; either is a felony under subsections (1) and (2). |
|
| Information Technology Act, Unauthorized Access and Computer-Related Offences |
Do not access, or secure access to, a computer, computer system or computer network, or download, copy or extract data from it, without the permission of its owner or the person in charge of it. |
|
| Indiana Computer Trespass, lack of owner's consent |
Do not access an Indiana-connected computer system or network without the owner's consent; the statute does not say whether serving a page openly is consent to an ordinary request for it, and an owner's express refusal, such as a written demand to stop or a block, leaves later access without consent. |
|
| Criminal Code (KUHP), Article 332, unauthorised access to a computer or electronic system, as reworded by Law No. 1 of 2026 |
Do not access another person's computer or electronic system without right or unlawfully, or access any computer or electronic system without right or unlawfully in order to obtain electronic information or documents from it. |
|
| Criminal Justice (Offences Relating to Information Systems) Act 2017 |
Do not intentionally access an information system by infringing a security measure, without lawful authority or reasonable excuse (s. 2). |
|
| Computers Law, unlawful penetration of computer material |
Do not connect with, communicate with, or operate a computer or its material without authorization; doing so to commit a further offence under another law raises the maximum term to five years. |
|
| Codice Penale Art. 615-ter, Unauthorized Access to a Computer or Telematic System |
Do not access, or remain within after being excluded, a computer or telematic system protected by security measures without the right-holder's consent. |
|
| Cybercrimes Act, 2015, unauthorised access to computer program or data |
Do not knowingly obtain, for yourself or another person, access to any program or data held in a computer unless you are entitled to control that access or have the consent of a person who is so entitled. |
|
| Act on Prohibition of Unauthorized Computer Access, prohibition of unauthorized access |
Do not operate a computer connected to a telecommunications line, where it carries an access control feature, by inputting another person's identification code, or by inputting other information or a command designed to evade that feature, without the access administrator's or the authorized user's permission. |
|
| Cybercrime Law, Unauthorized Access to Information Systems |
Do not access a website, information network, information system, or information technology means, in whole or in part, without authorization or in excess of an authorization granted. Do not use a program or program command to disable, alter, damage, or gain unauthorized access to an information system, and do not intercept or capture data transmitted through one. |
|
| Unlawful acts concerning computers (Kansas's computer-crime statute) |
Do not knowingly access, or attempt to access, a Kansas-connected computer, computer system, social networking website, computer network, or computer software, program, documentation, data, or property without authorization; paragraph (a)(5) criminalizes bare unauthorized access or an attempt at it alone, even without any intent to defraud, damage, or exceed authorization. |
|
| Penal Code, unauthorized access to information |
Do not intentionally access legally protected information on an electronic medium without authorization where doing so causes significant harm; the offence is not confined to defeating a technical access control. |
|
| Penal Code, unlawful distribution of restricted electronic information resources |
Do not unlawfully distribute an electronic information resource containing citizens' personal data, or other information restricted by law or by its owner, once obtained. |
|
| Kentucky Unlawful Access to a Computer |
Do not access, cause to be accessed, or attempt to access a Kentucky-connected computer, computer system, computer network, or the data or software on one, without the effective consent of the owner. Do not receive, conceal, or use data or property known to have been obtained through a violation of this statute; doing so is a separate felony. |
|
| Computer Misuse and Cybercrimes Act, 2018, unauthorised access |
Do not gain access to a computer system by infringing a security measure, knowing the access is unauthorised, including to copy, transfer or output data from it. |
|
| Cybercrime Act 2021, unauthorised access from a date not yet set |
Do not access a computer program or computer data held in a computer system unless you are entitled to control that kind of access, or have the consent of a person who is so entitled. |
|
| Electronic Transactions Law, Unauthorised Access to an Electronic Data Processing System |
Do not illegitimately log in to an electronic data processing system, prevent access to it, damage it, or obtain credit-card or other electronic-card numbers from it to steal funds. |
|
| Criminal Code, unauthorized access to computer information |
Do not gain unauthorized access to another person's protected computer information, electronic documents, information system, or telecommunications network, including by defeating an access control, where doing so destroys, blocks, or modifies data or disrupts a processing device. |
|
| Penal Code, Illegal Access to a Computer System |
Do not defeat a special protection system to access a computer system with intent to obtain commercial, financial or privately held data. |
|
| Krimināllikums Sections 241, 243, 244, Automated Data Processing System Offences |
Do not breach an automated data processing system's protective means, access it without permission, or use rights granted to another person to access it, where doing so causes substantial harm; whether an ordinary, unauthenticated page with no such protective means falls outside the without-permission ground is untested. |
|
| Law No. 81/2018 on Electronic Transactions and Personal Data, Illegal Access to an Information System and Related IT-System Offences |
Do not fraudulently access, enter, or remain in an information system, or a part of it, that you are not authorized to access. |
|
| Penal Code Act, 2010, Misuse of Property of Another |
Do not extract information from a computer or electronic storage device owned by another person where you have no reasonable cause to believe the owner would allow that extraction. |
|
| Cybercrime Act of 2025 from a date not yet set |
Do not access a computer system without authorization; the Act's own text does not confirm how authorization is read for a public, unauthenticated web page. Do not use illegally intercepted data, commit online fraud, or commit identity theft using a computer system. |
|
| Law No. 5 of 2022 on Combating Cybercrimes, unauthorised access and system interference |
Do not breach a website's or information system's protection measures to access it without authorization, in whole or in part. Do not delete, alter, disclose, or copy data, or disable or deface a system, once inside it without authorization. +1 more |
|
| Strafgesetzbuch Art. 118a, Illegal Access to a Computer System |
Do not gain access to a computer system, or part of one, in Liechtenstein that you may not use, or may not use alone, by overcoming a specific security precaution, for the purpose of obtaining personal data protected by a confidentiality interest or of inflicting a disadvantage on another person. |
|
| Criminal Code Arts. 196-198 and 198-1, Computer Misuse and Unauthorised Access Offenses |
Do not connect to an information system in Lithuania, or a part of it, by breaching its security measures; unauthorized connection risks criminal liability of up to two years' imprisonment under Criminal Code Art. 198-1(1). Do not unlawfully connect to an information system of strategic significance for national security or great significance for state governance, the economy or the financial system, or a part of it; that risks up to three years' imprisonment under Art. 198-1(2). Do not destroy, damage, delete, alter, or otherwise restrict the use of electronic data on a system in Lithuania without authorization, or disrupt the system's operation; that risks up to two years' imprisonment under Criminal Code Arts. 196 and 197, and up to six years where it reaches many systems or a system of strategic or great significance, uses another person's personal data, or causes great damage. Do not unlawfully observe, intercept, acquire, hold, or disseminate non-public electronic data; that risks up to four years' imprisonment under Art. 198, and up to six years for such data of strategic or great significance. |
|
| Louisiana Computer Tampering, unauthorized access and exceeding authorization |
Do not access, or cause to be accessed, a Louisiana-connected computer, computer system, or computer network without the authorization of its owner, including access that intentionally exceeds the scope of authorization you were given. If a computer's owner has issued a confidential or proprietary access code, do not use a code issued to someone else; doing so creates a rebuttable presumption that your access was unauthorized or exceeded authorization. +1 more |
|
| Code penal, Computer Misuse Offences (Unauthorized Access, Interference, Data Introduction, Devices, Attempt, Association) |
Do not fraudulently access or remain in all or part of an automated data-processing or transmission system located in Luxembourg. Do not intentionally interfere with, falsify, or introduce, suppress, alter or intercept data in an automated data-processing or transmission system, to the prejudice of another person's rights. |
|
| Law No. 2014-006, fraudulent access to an information system |
Do not access, or remain connected to, all or part of an information system intentionally and without a legitimate excuse or justification. |
|
| Aggravated criminal invasion of computer privacy |
Do not intentionally make an unauthorized copy of a computer program, software, or information from a Maine-connected computer resource, knowing you are not authorized to do so; this reaches unauthorized bulk copying even without any resulting damage. |
|
| Criminal invasion of computer privacy |
Do not intentionally access a Maine-connected computer resource while knowing you are not authorized to do so; the statute states a bare authorization test with no separate requirement of malicious intent, deception, or resulting damage. |
|
| Electronic Transactions and Cyber Security Act, 2016, unauthorized access to data |
Do not access, intercept, or interfere with data without authority or permission to do so, or beyond the access you are authorized for. |
|
| Computer Crimes Act 1997, unauthorised access to computer material |
Do not cause a computer to perform a function to secure access to a program or data where that access is unauthorised and you know it to be unauthorised. |
|
| Loi n° 2019-056, accès et maintien frauduleux à un système d'information |
Do not access, or attempt to access, an information system by an irregular mode of penetration, and do not remain, or attempt to remain, in an information system once access to it is irregular. |
|
| Criminal Code Article 337C, Unlawful Access to, or Use of, Information |
Confirm you have authorisation from whoever is entitled to control access to a computer, data, or software before accessing, copying, or extracting it in Malta; acting without such authorisation under Article 337C of the Criminal Code is a criminal offence whether or not a login otherwise protects the resource. |
|
| Maryland Unauthorized Access to Computers, with a civil private right of action |
Do not access, or exceed authorized access to, a Maryland-connected computer network, system, or database intentionally and without authorization; the statute defines access but never authorization, so whether an unrestricted public page counts as authorized is unsettled rather than resolved by its text. |
|
| Unauthorized access to a computer system; penalties |
Do not access a computer system without authorization, and stop accessing it once you know your access is no longer authorized. |
|
| Loi n° 2016-007, accès non autorisé à un système informatique |
Do not access, or attempt to access, all or part of a computer system intentionally and without right. Do not remain connected to all or part of a computer system after accessing it without right. |
|
| Cybersecurity and Cybercrime Act 2021, unauthorised access offences |
Do not gain unauthorised access to any program or data held in a computer system, that is, access you are not entitled to control and have not been authorised to make. |
|
| Código Penal Federal, Unauthorised Access to Computer Systems and Equipment (Arts. 211 bis 1 to 211 bis 7) |
Do not modify, destroy, cause the loss of, learn of, or copy information in a computer system or equipment that is protected by a security mechanism, without authorisation to access it. |
|
| Ley Federal del Derecho de Autor, Technological Protection Measures and Circumvention (Arts. 114 Bis, 232 Bis) |
Do not circumvent, or supply a device, mechanism, product, component, or system designed, marketed, or predominantly used to circumvent, a technological protection measure that controls access to a copyrighted work. |
|
| Fraudulent Access to Computers, Computer Systems, and Computer Networks Act |
Do not access, or cause access to, a computer, computer system, or computer network without authorization or by exceeding authorization granted, to acquire, alter, damage, delete, or destroy data or property, or to use the system's services (MCL 752.795). Do not access or cause access to a computer, computer system, or computer network to devise or execute a scheme to defraud or to obtain money, property, or a service by false pretense (MCL 752.794). |
|
| Mississippi Computer Crimes and Identity Theft Act, core offenses |
Do not defraud, deny an authorized user access, disable or damage equipment, or destroy, insert, modify, copy, use, or take intellectual property without consent, by means that fall outside proper means (independent invention, lawful reverse engineering, license or authority of the owner, public observation, or published literature). |
|
| Tampering with computer data, computer equipment, and computer users |
Do not access a Missouri-connected computer, computer system, or computer network without authorization or without reasonable grounds to believe you have authorization. Do not modify, destroy, disclose, or take computer data, programs, or supporting documentation, or a password or other access-control information, without authorization. +1 more |
|
| Criminal Code, Illegal Access to a Computer System |
Do not access a computer system without authorization under law or contract, or beyond the limits of an authorization, including to use, administer, or control it or to conduct research or another operation in it. |
|
| Code Pénal Arts. 389-1 to 389-9, Unauthorized Access, System Interference and Data Damage |
Do not fraudulently access or remain within all or part of a Monaco information system. Do not fraudulently hinder or alter the functioning of an information system, or introduce, damage, erase, alter, delete, extract, hold, reproduce, transmit or render inaccessible computer data within one, in the course of an automated crawl. |
|
| Criminal Code of Montenegro, Unauthorised Access to a Computer System |
Do not access a computer system, in whole or in part, without authorisation. Do not defeat a computer system's protection measures, and do not access without authorisation a computer system of significance to a state authority, local-government authority, or another institution exercising public powers; either raises the offence's maximum penalty. +2 more |
|
| Electronic Transactions Law, Computer Misuse Contraventions |
Do not access all or part of a computer system or computer network by violating its security measures, with intent to obtain data or another dishonest intent. Do not intercept, by technical means, private data transmissions to, from, or within a computer system or network. |
|
| Electronic Transactions Law, unauthorized interference and interception offences |
Do not dishonestly hack, modify, alter, destroy, or steal another person's electronic record, electronic data message, or computer programme. Do not intercept a communication within a computer network, or give any person access to the contents of a communication, without the permission of both the originator and the addressee. |
|
| Cybercrime Act 2015, illegal access to a protected computer |
Do not access the whole or part of a protected computer, meaning one connected to the Republic's security, defence, or international relations, a confidential law-enforcement source, communications, public-utility, or public-key infrastructure, or public safety and essential emergency services, without a lawful excuse. Do not obtain electronic data that is specially protected against unauthorised access and not meant for you. |
|
| Electronic Transactions Act, 2063, unauthorised access to computer materials |
Do not use a computer to access a programme, information, or data without the authorisation of its owner or the person responsible for it, or in a manner contrary to the terms of an authorisation given. |
|
| Wetboek van Strafrecht, art. 138ab, Computervredebreuk (Computer Trespass) |
Do not access an automated work by breaching a security measure, a technical intervention, false signals or a false key, or a false identity; reading a public, unauthenticated page without defeating any access control has not itself been held to violate this article. After any access gained that way, do not copy, tap, or record the data stored on, processed by, or transferred through that system. |
|
| Unlawful acts regarding computers, private action and enforcement |
Do not knowingly, willfully and without authorization modify, damage, destroy, disclose, use, transfer, conceal, take, retain, copy, or obtain or attempt to obtain access to data, a program, equipment, or a computer, system or network connected to Nevada. |
|
| New Hampshire Computer Crime Statute |
Do not knowingly access, or cause to be accessed, a computer or computer network you know you are not authorized to access. Do not knowingly make an unauthorized display, use, disclosure, or copy of data obtained through such access, even after collection; this can reach how you later use or share data taken beyond the scope of any authorization. |
|
| Computer Crimes Act, unauthorized computer use |
Do not knowingly, willfully and without authorization, or in excess of an authorization obtained, access, use, take, transfer, conceal, obtain, copy or retain possession of a computer, computer network, or computer property or service connected to New Mexico; a violation is graded by the dollar value of the resulting damage, from a petty misdemeanor at two hundred fifty dollars or less up to a second degree felony above twenty thousand dollars. |
|
| New York Computer Trespass, notice-based revocation and circumvention presumption |
Do not continue accessing a New York-connected system, or circumvent a technical security measure, after the operator has given you actual notice, including a cease-and-desist letter, that your access is unwanted; this statute treats notice alone as sufficient to convert continued access into unauthorized access, without needing a technical block. |
|
| Crimes Act 1961, Accessing a Computer System Without Authorisation |
Do not intentionally access, directly or indirectly, a computer system without authorisation, knowing or being reckless as to whether you are authorised to access it. |
|
| Ley No. 1042, interference with and damage to computer systems, as reformed by Ley No. 1219 |
Do not violate a computer system's security to destroy, alter, duplicate, or damage the data, processes, or their integrity, availability, or confidentiality. |
|
| Ley No. 1042, unauthorized access to computer systems |
Do not access, intercept, or use a computer system without authorization or in excess of the authorization granted. |
|
| Loi n° 2019-33, accès illégal et maintien frauduleux |
Do not access, or remain present in, a computer system intentionally and without right; reading a page that is public and unauthenticated has not been shown to violate this test. |
|
| Cybercrimes (Prohibition, Prevention, etc.) Act, 2015, unlawful access to a computer |
Do not intentionally access a computer system or network without authorisation for a fraudulent purpose in order to obtain data vital to national security. |
|
| North Carolina Computer-Related Crime Act (unauthorized access and computer trespass) |
Do not use a North Carolina computer or computer network without the owner's authorization, or beyond the scope of authorization granted, to remove, disable, or alter data, cause a malfunction, damage property, or make an unauthorized copy of computer data, programs, or software. Do not access a computer, including a government computer, without authorization to defraud or to obtain property or services by false pretenses; accessing a government computer without authorization for any other purpose carries heightened felony exposure. |
|
| Computer fraud and computer crime |
Do not gain or attempt to gain access to, alter, damage, modify, copy, disclose, take possession of, or destroy a North Dakota-connected computer, computer system, or computer network in excess of the authorization you were given or without authorization at all; unlike some other states' statutes, no fraud, malice, or deception is required for this to be a class A misdemeanor. |
|
| Criminal Code, Computer and Information Offences |
Do not intrude into a computer network in the fields of state administration, national defence construction, or advanced science and technology; this offence does not, on its own text, reach crawling an ordinary public, non-governmental website. |
|
| Law on the Protection of Computer Software, Prohibited Acts and Supervision |
Do not copy, adapt, sell, or telecast a software, or destroy or remove a technical protection device on it, without the copyright holder's permission, outside the three listed permission-free cases (education, a law-enforcement investigation, or software already distributed free of charge). |
|
| Criminal Code, Damage and Unauthorized Entry into a Computer System |
Do not enter another's computer or system without authorization with intent to exploit its data or programs for unlawful gain or to cause damage, or to transmit data reached without authorization. Do not intercept, by technical means, a non-public transmission of computer data to, from, or within a computer system. |
|
| Penal Code, Unauthorised Access to a Computer System |
Do not gain access to a computer system or part of it by breaching a protection measure or by another unauthorised method. |
|
| Cybercrime Combat Law, unauthorized access to a website or information system |
Do not access, or remain on, a website, information system, or information-technology means in Oman without right, in excess of authorized access, or after becoming aware the access is unauthorized; a spurious raise costs a developer one read, so this is flagged even though the Law's text does not on its face require defeating a technical security measure to reach a public, unauthenticated page. |
|
| Prevention of Electronic Crimes Act 2016, unauthorized access and interference offences |
Do not access an information system or data in Pakistan that is not available to the general public without authorization, or in violation of the terms and conditions of an authorization already granted; unauthorized access is a criminal offence under section 3 of the Prevention of Electronic Crimes Act 2016, and a more heavily punished one under section 6 where the system is critical infrastructure. |
|
| Penal Code, unauthorized computer access |
Do not access a computer, computer system, or computer network without authorization, meaning without the permission of, or in excess of the permission granted by, its owner, lessor, or rightful user. |
|
| Código Penal, Delitos contra la Seguridad Informática |
Do not improperly enter or use a database, network or computer system. Do not improperly seize, copy, use or modify data in transit or held in a database or computer system, or interfere with, intercept, obstruct or prevent its transmission. |
|
| Código Penal, arts. 146 b y 174 b, introducidos por la Ley N° 4439/2011, acceso indebido a datos y a sistemas informáticos |
Do not access a computer system, or its components, using your own or another person's identity, or by exceeding an authorization. Do not circumvent a security measure to obtain data that is specially protected against unauthorized access; ordinary access to unprotected, publicly available data falls outside this narrower offence. |
|
| Unlawful use of computer and other computer crimes (hacking and similar offenses) |
Do not intentionally access or exceed authorization to access a computer, computer network, database, or World Wide Web site without authorization, or in doing so alter, interfere with the operation of, damage, or destroy it; bare unauthorized access is itself an offense here. |
|
| Decreto Legislativo 1700, illicit trafficking of computer data (art. 12-A of Ley 30096) |
Do not possess, buy, receive, sell, exchange, facilitate, or traffic computer data, access credentials, or personal databases that you know or have reason to presume were obtained without the titleholder's consent or through a security breach or a computer offense. |
|
| Ley 30096, unauthorized access and data/system integrity offenses |
Do not access a computer system, in whole or in part, without authorization or beyond what you are authorized to access; defeating a security measure to do so draws a higher penalty tier. Do not intercept non-public computer data transmissions without authorization. |
|
| Cybercrime Prevention Act of 2012, Illegal Access, Interception, and Data Interference |
Do not access the whole or any part of a computer system without right, intercept a non-public transmission of computer data without right, or intentionally or recklessly alter, damage, delete, or deteriorate computer data without right. |
|
| Kodeks karny, Unauthorized Access to Information and Computer-Misuse Offenses |
Do not bypass or circumvent an electronic, technical, magnetic, IT, or other special security measure to access data or an IT system not intended for you; unauthorized access under Kodeks karny Art. 267 carries a fine, restriction of liberty, or imprisonment up to 2 years. |
|
| Lei do Cibercrime Article 6, Illegal Access to a Computer System |
Do not access a computer system located in Portugal without legal permission or authorization from its owner or another rights holder, including by circumventing a security control. |
|
| Cybercrime Prevention Law, unauthorised access |
Do not intentionally and illegally access, exceed authorised access to, or knowingly continue accessing a Qatar-based website, information system, or information network once aware the access is unauthorised; a violation reaching a system belonging to a state authority or affiliated corporation carries a doubled penalty. Do not unlawfully capture, intercept, or spy on traffic data or data being transmitted through an information network while crawling or collecting it. |
|
| Law on Combating Cybercrime, Unauthorised Access, Interference and Fraudulent Copying of Data |
Do not access or attempt to access, without authorization, all or part of an information system. Do not remain or attempt to remain connected, without authorization, to an information system. +1 more |
|
| Rhode Island Computer Crime chapter, unauthorized access and computer trespass |
Do not access a Rhode Island-connected computer, system, or network without the owner's permission, or beyond the scope of permission actually granted; this chapter's without-authority standard reaches exceeding permission as well as having none. |
|
| Cod penal, Art. 360-366, Infracțiuni contra siguranței și integrității sistemelor și datelor informatice (Offences Against the Security and Integrity of Computer Systems and Data) |
Do not access a computer system in Romania without a right to do so; the penalty rises where the access is for the purpose of obtaining data and rises further where the system's access is technically restricted to certain users, per Cod penal art. 360. Do not intercept, alter, or disrupt computer data or a computer system's functioning, and do not transfer data out of a computer system without authorization, per Cod penal arts. 361-364. |
|
| Criminal Code Article 272, Unauthorized Access to Computer Information |
Do not access computer information protected by Russian law without authorization in a way that destroys, blocks, modifies, or copies it, under Criminal Code Article 272; a version of this offense committed for gain, by a group, or causing grave consequences carries escalating fines up to 500,000 rubles and imprisonment up to 7 years. |
|
| Criminal Code Article 274, Violation of Rules for Operating Computer-Information Storage, Processing or Transmission Systems |
Do not violate the operating rules for protected computer-information systems or telecommunications-network access rules in a way that destroys, blocks, modifies, or copies information and causes significant damage, under Criminal Code Article 274. |
|
| Criminal Code Article 274.1, Unlawful Impact on Critical Information Infrastructure |
Do not create, distribute, or use malicious computer programs, or gain unauthorized access to protected information, aimed at Russia's critical information infrastructure, under Criminal Code Article 274.1; a version committed by a group or causing grave consequences carries imprisonment up to 10 years. |
|
| Law on Prevention and Punishment of Cybercrimes, unauthorized access |
Do not access computer or computer system data without the consent of a person entitled to give it, without being entitled to control or access it yourself, or by accessing another person's computer system without authorization. |
|
| Electronic Crimes Act, illegal access and related computer-misuse offences |
Do not access a computer system, or any part of it, without lawful excuse or justification, including to copy, transfer or output data from it. Do not access a computer system the Minister has designated as restricted; a heavier penalty applies where access to a restricted system occurs in the course of another offence under this Act. |
|
| Computer Misuse Act, unauthorized access, interception and modification |
Do not cause a computer system to perform a function to secure access to, or to intercept, a program, data, or computer service, without authority. |
|
| Crimes Act 2013, computer-access and interference offences |
Do not access, directly or indirectly, the whole or part of an electronic system without authorisation, or while reckless as to whether access is authorised, whether or not the underlying data is later used for crawling or training. Do not log into or remain logged into, or continue to access, an electronic system without lawful excuse or in excess of a lawful excuse. +2 more |
|
| Computer Crimes Law, Unlawful Access to Computer or Telematics Systems |
Do not unlawfully enter, or remain against the will of the party entitled to exclude you in, a computer or telematics system protected by a security measure, under Criminal Code art. 182-bis. |
|
| Loi n° 2008-11 du 25 janvier 2008 sur la Cybercriminalité, unauthorized computer-system access (Penal Code arts. 431-8 to 431-9) |
Do not access, or attempt to access, all or part of a computer system by fraudulent means, and do not maintain a fraudulent presence in one once inside. |
|
| Criminal Code, Offences Against the Security of Computer Data |
Do not access a computer, computer network, or electronic data processing system by circumventing a protection measure, without authorisation. Do not use, record, or further distribute data obtained by circumventing a protection measure without authorisation. |
|
| Cybercrimes and other Related Crimes Act, 2021, unauthorised access to a computer system |
Do not cause a computer system to perform a function with intent to secure access to computer data you are not entitled to access and have no consent to access. |
|
| Cyber Security and Crime Act, 2021, unauthorised access |
Do not cause a computer system to perform a function to gain access to a computer system, program, or data without authorisation, including by exceeding the level of access a person entitled to grant it has consented to. |
|
| Computer Misuse Act, Unauthorised Access to Computer Material |
Do not cause a computer to perform any function for the purpose of securing access to a program or data without authority, meaning without being entitled to control that access and without the consent of a person who is so entitled. |
|
| Trestný zákon, Unauthorized Access to a Computer System and Related Offences |
Do not overcome a security measure to gain access to a computer system or part of it without authorization. Do not intercept a non-public transmission of computer data to, from, or within a computer system without authorization. |
|
| Kazenski zakonik (KZ-1, Criminal Code), Art. 221, Napad na informacijski sistem (Attack on an Information System) |
Do not enter or break into an information system without authorization, and do not intercept data without authorization during its non-public transmission into or out of an information system. |
|
| Telecommunications Act 2009, Unauthorised-Access and Interception Offences |
Do not access telecommunications facilities by infringing a security measure, with the intent of obtaining telecommunications data. Do not intercept, by technical means, a transmission that is not intended for you and not intended for public reception. |
|
| Cybercrimes Act, unlawful access and unlawful interception of data |
Do not unlawfully and intentionally access a computer system or data storage medium. Do not unlawfully and intentionally intercept data, or possess data known or reasonably suspected to have been unlawfully intercepted, without a satisfactory exculpatory account. |
|
| South Carolina Computer Crime Act |
Do not access, or cause to be accessed, a computer, computer system, or computer network without authorization to devise a scheme to defraud, obtain money or property by false pretenses, commit another crime, or to alter, damage, destroy, or modify data, programs, or software, or to introduce a computer contaminant. Do not engage in computer hacking, defined to include accessing a computer without express or implied authorization, using a port scanner or probe without permission, or using a computer, computer system, or computer network in a manner that exceeds any right or permission its owner granted; this is a separate misdemeanor offense regardless of any financial gain or loss. |
|
| South Dakota Unlawful Use of a Computer System, Software, or Data |
Do not access, or exceed authorized access to, a South Dakota-connected computer system, software, or data without the consent of the owner; this chapter turns on consent rather than on a technical access barrier, so it reaches ordinary unauthenticated automated access as well as authenticated access. Do not copy or obtain information from a computer system, compromise its security controls, or use or disclose access codes or passwords, without the owner's consent; violating this is a Class 6 felony. |
|
| Information and Communications Network Act, Article 48 (network intrusion and anti-circumvention) |
Do not access an information and communications network without authorization, or beyond the scope of granted authorization, to collect data. |
|
| National Communication Act, 2012, confidentiality and unauthorised interception of communications |
Do not break into, eavesdrop on, illegally monitor, or hack into a communication or a communication network without authorisation from the National Communication Authority, the Attorney General, the Director of Public Prosecutions, or a court. |
|
| Penal Code Act, 2008, computer and electronic related offences |
Do not gain access to, destroy, alter, copy, transfer, or interfere with data, a programme, or a system held in a computer or computer network without authority from its owner. |
|
| Código Penal Article 197 bis, Unauthorized Access to an Information System |
Do not circumvent a technical security measure, such as authentication, to access an information system without authorization; Article 197 bis does not reach access to a page that carries no such measure. |
|
| Computer Crime Act, unauthorised access, modification and dealing with unlawfully obtained data from a date not yet set |
Do not secure access to a computer or to information held in it without lawful authority; the test does not turn on defeating a technical control, so relying on a page being public and unauthenticated is not itself a defence and has not been tested by a Sri Lankan court. Do not buy, receive, retain, download, upload, or copy information known or believed to have been obtained from a computer without lawful authority by someone else. |
|
| Law by Decree No. 10 of 2018 on Cybercrime, Unauthorised Access and Computer Interference |
Do not access a website, system, network, or means of information technology without authorisation, or continue accessing it after learning the access is unauthorised, or exceed the scope of authorised access (art. 4(1)). Do not receive, record, intercept, or wiretap data sent through the network without authorisation (art. 7). |
|
| Wetboek van Strafrecht, Hacking and Denial of Access (arts. 187b-187c) |
Do not gain access to a computer system, or part of one, without authorization; access counts as unauthorized if it was obtained by breaking through security, a technical intervention, false signals or a false key, or by assuming a false identity. If access to a system was unlawfully obtained, do not go on to copy, intercept, or record the data it holds, use its processing capacity for your own or another's benefit, or pivot through it to a third party's system. |
|
| Brottsbalken 4 kap. 9 c §, Unauthorized Computer Access (Dataintrång) |
Do not unlawfully gain access to, alter, delete, block, or register information intended for automated processing in Sweden, or seriously disturb or hinder the use of such information by another similar unlawful means. |
|
| Swiss Criminal Code, Unauthorised Access to and Interference with Data Processing Systems |
Do not defeat a security measure to obtain unauthorised access to a data processing system, knowing the access is unauthorised. Do not obtain specially secured data not intended for you for your own or another's unlawful gain, and do not alter, delete or render unusable data stored or transmitted electronically without authority. |
|
| Criminal Code, Offenses Against Computer Security |
Do not access another's computer or related equipment by entering someone else's password, defeating a technical protective measure, or exploiting a system vulnerability without cause; each is a separate ground for criminal exposure under Article 358. |
|
| Criminal Code, illegal access, modification, sabotage and unlawful possession of computer information |
An app must not gain access to a computer system, network or machine media by violating its security system, modify computer information or introduce deliberately false information into it, disable or destroy a computer system or its data, or unlawfully copy, seize or intercept information transmitted through a computer system. |
|
| Cybercrimes Act, 2015, unauthorised access and interference offences |
Do not intentionally and unlawfully access, remain in, or interfere with a computer system, or intercept a non-public transmission, without the operator's authorisation. |
|
| Tennessee Personal and Commercial Computer Act, implicit consent for anonymous access |
Do not intentionally access a Tennessee-connected computer, computer system, or network without authorization; the statute defines authorization as any form of consent, and its implicit-consent clause applies to networks operated to allow anonymous access. |
|
| Texas Breach of Computer Security, effective-consent and posted-prohibition offenses |
Accessing a Texas-connected computer, computer network, or computer system without the effective consent of the owner is a criminal offense regardless of your intent (Tex. Penal Code § 33.02(a)). |
|
| Act on Computer Crime, unauthorized access and interception |
Do not access a Thai computer system or computer data protected by a security measure not intended for your use. Do not disclose another person's security measures, or intercept another person's computer data by electronic or any other means, in a manner likely to cause injury or that is not for public benefit. |
|
| Loi n° 2018-026, accès et maintien frauduleux à un système informatique |
Do not access, or remain present in, a computer system without right, including a system reached over the internet. |
|
| Computer Crimes Act 2003, unauthorised access |
Do not access a computer system without lawful excuse; the offence does not require defeating a security measure, so whether reading a public, unauthenticated page falls within 'without lawful excuse' has not been tested by a Tongan court. Do not access a computer tied to security, defence, communications, banking, public-utility, transport, or public-safety infrastructure; this carries a materially higher penalty and applies where the accused knew or ought reasonably to have known of that use. |
|
| Computer Misuse Act 2000, Unauthorised Access |
Do not cause a computer to perform a function to secure access to a program or data knowingly and without authority; authority turns on the consent of the person entitled to control access, not on whether a technical security measure was defeated. |
|
| Decree-Law on Cybercrime, unauthorised access |
Do not access, or remain in, a computer system, in whole or in part, without authorization. Do not exceed the limits of any access right that has been granted to you. |
|
| Turkish Penal Code, Information System Crimes |
Do not enter, or continue to unlawfully remain within, the whole or part of a computer system located in Turkey without authorisation. |
|
| Criminal Code, malicious programs |
Do not create, use, or distribute a computer program intended to disrupt the normal operation of a computer, subscriber device, computer program, information system, or information-telecommunication network, and do not unlawfully destroy, block, reformat, or copy information protected by Turkmen law that is stored on an electronic medium or passing through such a network; a higher penalty applies where the target is a national information source, the national information system, or a critical information-communication infrastructure object. |
|
| Criminal Code, unlawful access to an information system |
Do not access information stored on electronic media, an information system, or an information-telecommunication network that is protected by Turkmen law, without authorization to do so, where the access substantially violates the rights of a person or the protected interests of society or the state; a higher penalty applies where the source accessed is a national information source or a critical information-communication infrastructure object. |
|
| Tuvalu Telecommunications Corporation Act 1993, offences and penalties |
Do not intercept, disclose, alter, or interfere with a message or the telecommunications apparatus carrying it, and do not operate a competing telecommunications service without the Corporation's authorisation. |
|
| Federal Decree-Law on Combating Rumours and Cybercrime, hacking offences |
Do not access, or remain on, a website, information system, computer, or information network without authorization, in violation of a licence, or illegally. |
|
| Unauthorised Access to Computer Material |
Do not cause a computer to perform a function intended to secure access to a program or data, knowing that access is unauthorised because you are not entitled to control that kind of access and do not have the consent of someone who is. |
|
| Computer Fraud and Abuse Act (unauthorized access and the gates-based authorization test) |
Do not continue accessing a site, or circumvent a technical block, after the operator has sent an individualized notice revoking your access (Facebook v. Power Ventures, 9th Cir. 2016). |
|
| Digital Millennium Copyright Act, anti-circumvention provisions |
Do not circumvent a technological measure that controls access to a copyrighted work in order to collect it. |
|
| Virgin Islands Computer Crimes Act, unauthorized access and computer trespass |
Whether or not you have authority to use or access a computer or computer network, do not do so with intent to disable or alter data or programs, cause a malfunction, effect an unauthorized transfer of funds, injure property, make an unauthorized copy of computer data, or forge e-mail header or routing information to send unsolicited bulk e-mail. |
|
| Código Penal arts. 297 bis, 297 ter, 297 quater, 358 quater, and 358 quinquies, computer-offence provisions inserted by Ley N° 20.327 |
Do not access, intercept, disclose, sell, or transfer another's information held on a digital medium by computer or telematic means without authorization and without just cause. Do not access, appropriate, use, or modify a third party's confidential data held on a digital medium without the holder's authorization, and do not disclose, reveal, or transfer such data to a third party. |
|
| Cybercrime Act 2021, computer-access and interference offences |
Do not access the whole or part of a computer system by infringing a security measure, whether or not the underlying data is later used for crawling or training, unless entitled to access it or the owner has consented. Do not intercept a non-public transmission of computer data to, from or within a computer system, or the electromagnetic emission of such a system, without lawful excuse. |
|
| Unauthorised access to a protected computer or telematic system (Legge N. DXXXI, arts. 158 ter-158 quater) |
Do not access, or remain connected to, a Vatican City State computer or telematic system that is protected by a security measure, without the right to do so or against the will of the party entitled to exclude you. |
|
| Ley Especial contra los Delitos Informáticos, unauthorized access and sabotage of systems (Arts. 6-11) |
Do not access, intercept, interfere with, or use a computer system without authorization or in excess of the authorization obtained. |
|
| Law on Cybersecurity, unauthorized access prohibition |
Do not illegally access a telecom network, the Internet, a computer network, an information system, or a database belonging to another person. |
|
| West Virginia Computer Crime and Abuse Act |
Do not knowingly, willfully, and without authorization access or cause to be accessed a computer or computer network with intent to obtain computer services; this is a misdemeanor punishable by a $200 to $1,000 fine, up to one year in county jail, or both. |
|
| Crimes against computer users (bare without-authorization test) |
Do not access a Wyoming-connected computer, computer system, or computer network without authorization; this statute has no malicious-intent or deceptive-means gate, so a bare unauthorized access can fit its elements even without resulting damage or disruption. |
|
| Cyber Crimes Act, 2025, unauthorised access to computer system and data |
Do not infringe a security measure to access or monitor a computer system, or any part of one, belonging to another person without lawful authority or in excess of authority. |
|
| Cyber and Data Protection Act, Insertion of Computer-Misuse Offences into the Criminal Law Code |
Do not access data, a computer programme, or a computer system if you know or suspect you must obtain prior authority to access it and have not obtained that authority. Do not intercept a private data transmission, overcome or circumvent a protective security measure, or acquire data within or transmitted to or from a computer system without lawful authority. |
Database right
73 laws, 73 places| Place | Law | What it asks, as read here |
|---|---|---|
| Copyright Law, Sui Generis Database Producers Rights |
Do not extract or reuse the whole or a substantial part of a database's content, evaluated qualitatively or quantitatively, without the authorisation of the database's producer. Do not repeatedly and systematically extract or reuse insubstantial parts of a database's content where doing so conflicts with the database's normal exploitation or unreasonably harms the producer's legitimate interests. |
|
| Ordonnance n° 03-05, protection des bases de données |
Do not reproduce a database whose choice or arrangement of contents is an original creation without the rightsholder's authorization; Algeria has no sui generis database right, so an unoriginal, purely factual database is not itself protected. Do not rely on the private-use exception for a digital-form reproduction of a database; that exception expressly excludes it. |
|
| Copyright Law, sui generis database right |
Do not extract or re-utilise the whole or a substantial qualitative or quantitative part of another party's database without the database maker's authorisation, unless the extraction or re-utilisation is of an insubstantial part by a lawful user of a database made available to the public. |
|
| UrhG Sections 76c to 76e, Sui Generis Database Right |
Do not extract or re-utilize the whole, or a substantial part, of a database that required a substantial investment to compile, verify, or present, without the producer's authorization, per UrhG Section 76d. Do not repeatedly and systematically extract or re-utilize insubstantial parts of such a database where this conflicts with its normal exploitation or unreasonably prejudices the producer's legitimate interests, per UrhG Section 76d. |
|
| Law on Legal Protection of Compilations of Data, sui generis database right |
Extracting or repeatedly using the whole or an essential part of a database that was prepared, verified, or compiled with essential investment requires the producer's permission, whatever the source of the data it contains. Obtaining a protected compilation of data by cracking, directly or indirectly, the technical security measures protecting it is illegal use, even where the compilation is also copyright protected. |
|
| Copyright Act 1998, compilation and database protection |
Do not reproduce or commercially deal in a substantial part of a database or compilation that is original by reason of the selection, co-ordination or arrangement of its contents, without the compiler's authorisation. |
|
| Copyright Law, Database Compilation Protection |
An app scraping a database from a Bahraini source may freely take the underlying facts or data themselves, but copying the compiler's creative selection or arrangement of that database's contents is copyright infringement if done without authorization. |
|
| Copyright Act, 2023, database protection |
Do not reproduce or extract a database that reflects the compiler's own intellectual expression without the rightsholder's permission or a Rules-specified exception; Bangladesh has not enacted a text-and-data-mining exception, so training a model on such a database rests only on whatever the unlocated implementing Rules for the Act's general reproduction exception may allow. |
|
| Law on Copyright and Related Rights, Database Right and Software Exceptions |
Do not copy, reproduce, or otherwise use a protected database's compilation structure, or another copyrighted work it contains, beyond archival copying or another free-use ground this Law recognizes, without the rightsholder's authorization. This Law has no text-and-data-mining exception or opt-out mechanism, so a training use resting on none of the Law's free-use grounds needs the rightsholder's authorization. |
|
| Loi n°2005-30 relative à la protection du droit d'auteur et des droits voisins, exclusion des nouvelles du jour et protection des bases de données comme compilations |
Treat a database compiled through the selection, coordination, or arrangement of its contents as a protected work: do not reproduce all or a substantial part of it without the rights holder's authorization, even though the underlying facts and data are not themselves protected. |
Show the other 63 laws
| Copyright and Designs Act 2004, database right |
Do not extract or re-utilise all or a substantial part of the contents of a database that reflects substantial investment in obtaining, verifying or presenting its contents, without the database right owner's authorisation, unless a statutory exception applies. |
|
| Law on Copyright and Related Rights, Rights of Database Producers |
Do not reproduce, distribute, make available to the public, or otherwise communicate the whole or a substantial part of a database whose making required a qualitatively or quantitatively substantial investment, without the producer's authorization. Do not repeatedly and systematically extract or reuse insubstantial parts of such a database if doing so conflicts with the database's normal use or unreasonably prejudices the producer's legitimate interests, even though a single insubstantial extraction is free. |
|
| Copyright and Neighbouring Rights Act, 2000 (Cap. 68:02), Database Protection |
Treat a database compiled through the selection, coordination, or arrangement of its contents as a protected literary work: do not reproduce the whole or a substantial part of it without the rights holder's authorisation, even though the underlying facts and data are not themselves protected. Do not rely on the Act's private-reproduction exception to copy the whole or a substantial part of a database; that exception does not extend to a database. |
|
| Copyright Law, Database Compilation Right |
Do not reproduce, translate, adapt, reorganize, distribute, or communicate to the public a database whose selection, organization, or arrangement of content is an intellectual creation, without the rightsholder's authorization. |
|
| Loi n°048-2019/AN du 12 novembre 2019 portant protection de la propriété littéraire et artistique, database and news exceptions |
Treat a database compiled through the selection or arrangement of its contents as a protected work: do not reproduce all or a substantial part of it without the rights holder's authorization, even for otherwise-permitted private use. Rely only on the Law's enumerated exceptions rather than a general fair-use or text-and-data-mining defense when quoting, analyzing, or reproducing a protected work: a short quotation or analysis, a press review, or current-events reporting, each requiring clear credit to the author and source, and none framed as covering AI training. |
|
| Law No. 1/021 of December 30, 2005 on the Protection of Copyright and Related Rights, database and facts exclusions |
Treat a database compiled through the selection or arrangement of its contents as a protected work: do not reproduce all or a substantial part of it without the rights holder's authorization, even for otherwise-permitted private use. Rely only on the Law's enumerated exceptions rather than a general fair-use or text-and-data-mining defense when quoting, analyzing, or reproducing a protected work: a quotation compatible with fair practice, a press review, or current-events reporting, each requiring source and author credit, and none framed as covering AI training. |
|
| Loi n°2000/011 du 19 décembre 2000 relative au droit d'auteur et aux droits voisins, article 4(2)(b) (protection des bases de données) |
Treat a database compiled through an original selection, coordination, or arrangement of its contents as a protected composite work: do not exploit the whole or a substantial part of it by reproduction, representation, transformation, or distribution without the rights holder's authorization, even though the underlying facts and data are not themselves protected. |
|
| Copyright (Cayman Islands) Order 2015, database and compilation copyright |
Do not reproduce or commercially deal in a substantial part of a database or compilation protected as a literary work under the extended Copyright, Designs and Patents Act 1988 without the compiler's authorisation. |
|
| Ley sobre Derechos de Autor y Derechos Conexos, artículo 8, protección de bases de datos |
Do not reproduce the original selection or arrangement of a Costa Rican database compilation without the rightsholder's authorization; Costa Rican law protects a database only as a compilation, so it does not by itself bar extracting the underlying data. |
|
| Autorský zákon Sections 88-94, Sui Generis Database Right |
Do not extract or re-utilize the whole, or a qualitatively or quantitatively substantial part, of a database made with a substantial investment by another person in the Czech Republic without the maker's authorization, and do not repeatedly and systematically extract insubstantial parts in a way that conflicts with the database's normal exploitation or unreasonably harms the maker's legitimate interests. |
|
| Copyright and Neighboring Rights Act, database compilation protection |
Treat a database compiled through the choice, coordination or arrangement of its contents as a protected work: do not reproduce all or a substantial part of that arrangement without the rights holder's authorization. |
|
| Ophavsretsloven Section 71, Sui Generis Database Right |
Do not reproduce or make available to the public the whole, or a substantial part, of a catalogue, table, database or similar compilation resulting from a substantial investment, without the maker's authorization, for 15 years from the year it was made or first made available. |
|
| Copyright Act 2003, database and compilation protection |
Do not reproduce the whole or a substantial part of a database that is original by reason of the selection or arrangement of its contents, in digital form, without the copyright owner's authorisation; the private-use, personal-purpose reproduction exception does not reach that reproduction. |
|
| Law No. 82 of 2002 on the Protection of Intellectual Property Rights, Copyright and Database Chapter (Book Three) |
Treat a database compiled through the selection or arrangement of its contents as copyright-protected: do not reproduce or copy all or a substantial part of a database, in whole or in part, without the rights holder's authorization, even after the database has been published. |
|
| Autoriõiguse seadus (Copyright Act) Chapter VIII-1, Sui Generis Right of a Maker of a Database |
Do not extract or re-utilise the whole, or a substantial part evaluated qualitatively or quantitatively, of a database reflecting a substantial investment by its maker, absent authorization or a statutory exception, per Copyright Act Section 75-4. |
|
| Copyright and Neighbouring Rights Protection Proclamation, Database Protection |
Do not reproduce a database whose selection or arrangement of contents is an original creation without the rightsholder's authorization; Ethiopia has no sui generis database right, so an unoriginal, purely factual database is not itself protected on that basis. Do not rely on the personal-reproduction exception to copy the whole or a substantial part of a database in digital form; that exception does not extend to a database. |
|
| Database Directive, Sui Generis Right and Lawful-User Exceptions |
Do not extract or re-utilize the whole or a substantial part, evaluated qualitatively or quantitatively, of an EU database's contents without the maker's authorization, where the maker shows a substantial investment in obtaining, verifying, or presenting that content. Do not repeatedly and systematically extract or re-utilize insubstantial parts of a database's contents where doing so conflicts with the database's normal exploitation or unreasonably prejudices the maker's legitimate interests, even where no single extraction takes a substantial part. +1 more |
|
| Tekijanoikeuslaki Section 49, Sui Generis Database and Collection Producer Right |
Do not reproduce or make available to the public the whole, or a qualitatively or quantitatively substantial part, of a list, database, or similarly compiled work made by another with substantial investment, without the maker's authorization, for 15 years from completion or first publication, under Tekijanoikeuslaki 49 sec. |
|
| CPI Sui Generis Database Right, Producer's Right to Prohibit Extraction and Reutilization |
Do not extract or reutilize a qualitatively or quantitatively substantial part of a French database's content without the producer's authorization, where the producer shows a substantial investment in constituting, verifying, or presenting that content. Repeated or systematic extraction or reutilization of insubstantial parts can still infringe where it amounts, in its cumulative effect, to extracting or reutilizing a substantial part. |
|
| Loi n°1/87, protection des recueils et compilations |
Do not reproduce a collection or database whose choice or arrangement of contents is an original intellectual creation without the rightsholder's authorization; Gabon has no sui generis database right, so an unoriginal, purely factual collection is not itself protected. |
|
| Copyright and Related Rights, database producer right |
Do not extract or re-use the whole, or a qualitatively or quantitatively significant part, of a database's contents without the database producer's authorisation. Do not repeatedly or systematically extract or re-use insignificant parts of a database if doing so conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests. |
|
| Schutz des Datenbankherstellers (Sui Generis Database Right) |
Do not reproduce, distribute, or publicly communicate a database, or a substantial part of it, without the database maker's authorisation. Do not repeatedly and systematically extract insubstantial parts of a database in a way that conflicts with its normal exploitation or unreasonably prejudices the maker's legitimate interests. |
|
| Copyright Act, Database Protection |
Do not reproduce a database whose selection or arrangement of contents is an original intellectual creation without the rightsholder's authorization; Ghana has no sui generis database right, so an unoriginal, purely factual database is not itself protected on that basis. Do not rely on the personal-use exception to copy the whole or a substantial part of a database in digital form; that exception does not extend to a database. |
|
| Ley de Derecho de Autor y Derechos Conexos, Decreto 33-98 (compilations, databases, and technological measures) |
Do not circumvent a technological measure that controls access to a protected work, and do not manufacture, import, or traffic in a device or service designed mainly to do so. No text-and-data-mining exception exists in Guatemalan copyright law; reproducing a protected compilation's own original selection or arrangement to build a training dataset has no statutory carve-out and needs the rightsholder's authorization or a fair-use-style limitation. |
|
| Loi portant protection de la propriété littéraire et artistique, articles 9 et 22 (bases de données) |
Do not reproduce all or a substantial part of a database whose selection, coordination or arrangement of contents makes it an intellectual creation without the rightsholder's authorisation; the private-copy exception does not cover it. Do not rely on a text-and-data-mining exception or a sui generis database right when copying Guinean databases; the law provides neither, so protection turns on the originality of the selection or arrangement alone. |
|
| Szjt. Section 84/A, Sui Generis Database Producer's Right |
Obtain the database producer's consent before extracting or re-utilizing the whole or a substantial part of a database's contents, per Szjt. Section 84/A(1), where obtaining, verifying, or presenting that database's contents required substantial investment. Do not repeatedly and systematically extract or re-utilize even an insignificant part of such a database if doing so conflicts with its normal exploitation or unreasonably prejudices the producer's legitimate interests, per Szjt. Section 84/A(3). |
|
| Höfundalög nr. 73/1972, Art. 50, Sui Generis Database Producer Right |
Do not repeatedly and systematically extract or re-utilise an insubstantial part of a protected Icelandic database if doing so conflicts with its normal exploitation or unreasonably prejudices the producer's legitimate interests, under Höfundalög Article 50. Do not reproduce or make available the whole or a substantial part of a protected database without the producer's authorization within the 15-year protection term. |
|
| Law No. 3 of 1971 on Copyright, as amended by CPA Order No. 83, compilation protection and reproduction right (Arts. 2, 3, 8, 45) |
Do not reproduce, in any manner or form including onto a digital or electronic storage medium, a protected work, including a compilation of data, without the written permission of the author or the author's successors. |
|
| Copyright and Related Rights Act 2000, Database Right |
Do not extract or re-utilise all or a substantial part of the contents of a database in which a substantial investment (financial, human or technical) has been made in obtaining, verifying or presenting its contents, without the database right owner's authorisation (s. 321(1)-(2)). |
|
| Legge sul Diritto d'Autore Artt. 102-bis and 102-ter, Sui Generis Database Right |
Do not extract or re-utilize the whole or a substantial part of a database's content without the database maker's authorization, for the fifteen years (renewable on a substantial new investment) following the database's completion or first making-available. |
|
| Autortiesību likums Chapter IX, Sui Generis Database Right |
Do not extract (permanently or temporarily transfer to another medium) or re-utilize (make available to the public) the whole, or a qualitatively or quantitatively substantial part, of a database that reflects a substantial investment by its maker, absent authorization or a statutory exception, per Article 57. Do not repeatedly and systematically extract or re-utilize insubstantial parts of such a database in a way that conflicts with its normal use or unreasonably prejudices the maker's legitimate interests, per Article 57(4). |
|
| Liberia Intellectual Property Act, 2016, database compilation and private-copy exclusion (§§ 9.3, 9.4, 9.10) |
Treat a database compiled through the selection or arrangement of its contents as a protected work; do not reproduce the whole or a substantial part of it without the rights holder's authorization, even where the reproduction would otherwise qualify as a permitted private copy. Do not rely on a text-and-data-mining or general research exception when reproducing a protected work or database for training or analysis purposes; the Act states none. |
|
| Urheberrechtsgesetz, Sui Generis Database Right |
Do not extract or re-utilize the whole, or a qualitatively or quantitatively substantial part, of the contents of a database whose producer made a substantial investment in obtaining, verifying, or presenting those contents, without the producer's authorization. Do not repeatedly and systematically extract or re-utilize insubstantial parts of such a database's contents in a manner that conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests. |
|
| Loi du 18 avril 2001 sur les droits d'auteur, Sui Generis Database Right (Art. 67) |
Do not extract or reuse the whole, or a substantial part evaluated qualitatively or quantitatively, of the contents of a database protected under this article without the producer's authorization. Do not repeatedly and systematically extract or reuse insubstantial parts of a database's contents where doing so conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests. |
|
| Copyright Act Article 25, Sui Generis Right in Respect of Databases |
Extracting or re-utilizing the whole or a substantial part of a database's contents without the maker's consent risks infringing the sui generis database right, independent of any copyright in the database's contents (Art. 25). |
|
| Ley Federal del Derecho de Autor, Database Compilation and Non-Original Database Protection (Arts. 107 to 110) |
Do not reproduce, translate, adapt, reorder, distribute, or publicly communicate a protected database's selection or arrangement, or a non-original database within its 5-year exclusive-use period, without the rightsholder's authorisation. |
|
| Copyright and Neighbouring Rights Law, Sui Generis Database Right |
Before extracting or re-utilizing the whole, or a substantial part, of a database a Moldovan producer made a substantial investment in compiling, obtain the producer's authorization, unless a research, private-use, security, or judicial-proceeding exception applies. Do not repeatedly and systematically extract or re-utilize insubstantial parts of such a database in a way that conflicts with its normal exploitation or unreasonably prejudices the producer's legitimate interests. |
|
| Law on Copyright, database protection and reproduction restriction |
An app that scrapes, systematically uploads, or otherwise extracts a database created in Mongolia must act consistently with the rights and legitimate interests of the person who created it, and any reproduction of the works or information the database compiles needs a lawful basis under the Law, because the database's creator or rights holder holds the exclusive right to distribute copies of it. |
|
| Law on Copyright and Related Rights, Rights of Makers of Databases |
Do not reproduce, distribute, rent, or make available to the public the entire contents of a database, or a qualitatively or quantitatively substantial part of it, without the maker's authorisation. Do not repeatedly and systematically extract or reuse qualitatively or quantitatively insubstantial parts of a database where doing so conflicts with the database's normal exploitation or unreasonably prejudices the maker's legitimate interests. |
|
| Law No. 2-00 on Copyright and Related Rights, Database and Reproduction Provisions |
Do not reproduce all or part of a database in digital form without the rights holder's authorization, even for a personal or non-commercial use; the private-use exception does not reach a digital-form database. Rely only on the Law's enumerated exceptions (quotation, teaching, judicial and administrative use, library archiving, and similar narrow purposes) rather than a general fair-use or text-and-data-mining defense; none of them addresses training an AI model on copyrighted content or a compiled database. |
|
| Copyright Law, compilation protection with no sui generis database right from a date not yet set |
Reproducing the whole or a substantial part of a database in digital form requires the right holder's authorization; it is not covered by the Law's personal-use exception. |
|
| Copyright Act, 2059, database compilation protection and digital reproduction limit |
Do not reproduce a collection of works, or a data set or database, that is original in its presentation, collection, or expression, without the author's or copyright owner's authorisation; Nepal has no sui generis database right, so protection turns on this originality test rather than on investment alone. Do not reproduce a significant portion of a database through digital transmission where doing so would be prejudicial to the economic right of the author or the copyright owner. |
|
| Databankenwet, Sui Generis Database Right |
Do not extract or re-utilize the whole or a substantial part of a database's contents without the producer's authorization, and do not repeatedly and systematically extract or re-utilize insubstantial parts in a way that conflicts with the database's normal exploitation or unreasonably prejudices the producer. |
|
| Ley No. 312, protection of compilations and databases |
Do not reproduce the whole, or an important part, of a protected compilation or database in digital form without the rights holder's authorization; the personal-use privilege does not cover it. When reproducing a fragment of a protected work under the quotation right, limit the reproduction to what the citation, analysis, comment, or criticism justifies, and name the source and the author. |
|
| Law on Copyright and Related Rights, Rights of the Database Maker |
Do not extract or re-utilize the whole or a substantial part, evaluated qualitatively or quantitatively, of the contents of a database without the database maker's permission. Do not repeatedly and systematically extract or re-utilize insubstantial parts of a database's contents in a manner contrary to its normal exploitation, or in a way that unreasonably prejudices the database maker's legitimate interests. |
|
| Copyright Act, Sui Generis Database Right |
Do not extract or reuse all or a substantial part of a database's contents without the producer's authorisation where the database resulted from a substantial investment in collecting, checking or presenting its contents. Do not repeatedly or systematically extract or reuse immaterial parts of such a database in a way that harms its normal use or unreasonably prejudices the producer's legitimate interests. |
|
| Ley N° 1328/1998, art. 4, numeral 14, bases de datos como compilación |
Do not rely on the personal-copying exception to justify copying a database or a compilation of data; that exception does not reach either. |
|
| Decreto Legislativo 822, protection of compilations and databases |
Do not rely on the personal-use copying privilege to justify copying a database or compilation of data; that privilege does not reach it. |
|
| Ustawa o ochronie baz danych, Sui Generis Database Right |
Get the producer's authorization before extracting or reusing a substantial part, by quality or quantity, of a protected database's contents; the right runs 15 years from the database's completion or first public availability. Do not repeatedly and systematically extract or reuse even an insubstantial part of a database in a way that conflicts with its normal exploitation or unreasonably prejudices the producer's legitimate interests. |
|
| Sui Generis Database Right, Decreto-Lei n.º 122/2000 |
Do not extract or re-use, for direct or indirect commercial purposes, a substantial part of a database protected by Portugal's sui generis database right or database copyright without the maker's or author's authorization. |
|
| Civil Code Part IV, Database Maker's Exclusive Right |
Do not extract materials from a database that required substantial financial, material, or organizational outlay to create, or reuse those materials, without the rightholder's permission, where the database is Russian-made or otherwise covered by Civil Code Article 1336; a database of at least 10,000 independent elements is presumed to meet the substantial-outlay threshold, and extraction covers transferring its whole content or a substantial part onto another medium by any technical means, which reaches automated bulk scraping. |
|
| Copyright Act 1998, compilation-only protection of collections and databases |
Do not reproduce a collection of works or of data, including a database, whose selection, coordination, or arrangement is original, without the authorisation of the collection's author or other copyright owner, unless a specific exception such as quotation or news reporting applies. |
|
| Decreto-Lei n.º 02/2017, protecção de compilações e exclusão das notícias do dia |
Do not reproduce a compilation, anthology, or systematic collection whose choice or arrangement of contents is itself an intellectual creation, without the rightsholder's authorization; Sao Tome and Principe has no sui generis database right, so an unoriginal, purely factual collection of data is not itself protected against reproduction. |
|
| Law on Copyright and Related Rights, Right of the Database Producer |
Do not extract or re-utilise the whole or a substantial part, in quantitative or qualitative terms, of a database's contents without the database producer's authorisation. Do not systematically extract or re-utilise insubstantial parts of a database's contents where doing so conflicts with the database's normal exploitation or unreasonably prejudices the producer's legitimate interests. |
|
| Copyright Act, Arts. 91-98 (database producer's right) |
Do not reproduce, distribute, broadcast, or transmit all or a substantial part of a database another party made a substantial investment to build, verify, or present. |
|
| TRLPI Articles 133 to 137, Sui Generis Database Right |
Do not extract or reuse the whole, or a substantial part evaluated qualitatively or quantitatively, of a database that reflects a substantial investment by its maker, absent authorization or a statutory exception, per TRLPI Article 133. |
|
| Copyright Act, Computer-Readable Databases as Compilations |
Do not reproduce a computer-readable database whose selection or arrangement of contents is original, without the compiler's authorization. |
|
| Upphovsrättslagen 49 §, Sui Generis Database Right (Katalogskydd) |
Do not extract or make copies of a substantial part of a database compiled by, or resulting from a substantial investment of, a person or business connected to Sweden without authorization, for fifteen years from the database's completion. |
|
| Copyright Act 1997, Protection of Collections and Databases |
Do not reproduce the whole or a substantial part of a collection of works or of data that is original by its selection, coordination, or arrangement, without the copyright owner's authorization. |
|
| Law on Intellectual and Artistic Works, Database Producer Right |
Do not transfer a substantial part or all of the content of a database that reflects a substantial investment by its producer to another medium, or distribute, sell, rent, or communicate that content to the public, without the database producer's permission, for fifteen years from the database's disclosure. |
|
| Copyright Law, Sui Generis Database Right |
Do not extract or re-utilise, without the database maker's authorization, the whole or a substantial part of the contents of a database whose maker made a qualitatively or quantitatively significant investment in obtaining, verifying or presenting those contents. |
|
| Database Right |
Do not extract or re-utilise all or a substantial part of the contents of a UK database protected by database right without the maker's consent. |
|
| Ley sobre el Derecho de Autor, compilations and databases (Art. 3) |
Providing public access to a database of protected works over a telecommunication network requires the rightholder's authorization. |
Copyright and text and data mining (TDM)
68 laws, 66 places| Place | Law | What it asks, as read here |
|---|---|---|
| UrhG Section 42h, Text-and-Data-Mining Exception |
For any other text-and-data-mining use, do not reproduce a work if the rightsholder has expressly reserved their rights in an adequately signaled, and for online works machine-readable, manner, per UrhG Section 42h(6). |
|
| Copyright and Related Rights Law, database exclusion and enforcement remedies |
Do not eliminate a technical protection measure applied to a work or database without the right holder's permission. |
|
| Copyright Law, Quotation Exception |
An app training a model or otherwise reproducing text scraped from a Bahraini source may reproduce only a brief section of a legally published work, for a legitimate purpose and no more than the extent that purpose requires, and must mention the source and the author's name where the source indicates them. |
|
| Copyright Act, fair dealing exceptions |
Characterise text-and-data-mining as research or private study, and weigh the extent copied, the purpose, and the effect on the work's market, before relying on fair dealing rather than a licence. |
|
| Code de droit économique, article XI.190, 20°, exception de fouille de textes et de données |
Do not reproduce a work made accessible in a lawful manner for text-and-data-mining purposes if the rightsholder has expressly reserved that use in an appropriate manner. For a work made available online, treat only a machine-readable reservation as an appropriate one. |
|
| Law on Copyright and Related Rights, Content Limitations (No Text-and-Data-Mining Exception) |
Do not reproduce, distribute, make available, or otherwise exploit a copyrighted work, including for training a model on it, without a transfer of the relevant right or a license, because the Law recognizes no general text-and-data-mining or fair-use exception beyond its closed list of specific limitations. |
|
| Copyright and Neighbouring Rights Act (ZAPSP), Arts. 26e, 26zh and 26k, Text-and-Data-Mining Exception for Crawling and Training |
Honor an express, machine-readable rights reservation before relying on the general text-and-data-mining exception to reproduce or extract a lawfully accessed work, per ZAPSP Article 26e(4). |
|
| Copyright Law, reproduction right and limited exceptions |
Get the right-holder's authorization before reproducing a Cambodian copyrighted work, including through automated collection, unless the citation exception applies. |
|
| Copyright (Cayman Islands) Order 2015, text and data analysis exception |
Limit a copy made under the extended section 29A text-and-data-analysis exception to non-commercial research carried out by a person with lawful access to the work, and do not transfer the copy or use it for any other purpose. |
|
| Copyright Law, Article 24 (closed list of exceptions, no text-and-data-mining item) |
Treat use of copyrighted material beyond personal study, brief quotation, or the other listed exceptions as needing the rightholder's permission. |
Show the other 58 laws
| Copyright Act, Exclusive Reproduction Right, No Text and Data Mining Exception |
Obtain the author's authorization before reproducing a copyrighted work by any means, including temporary electronic storage during crawling, since no text-and-data-mining exception applies. Do not rely on the quotation, teaching, or private-copy exceptions to reproduce copyrighted text at scale for model training; they are narrow and conditioned on non-commercial, limited use. |
|
| Copyright Act 2013, economic rights, computer program copying, and technological protection measures |
Do not copy, reproduce, or communicate to the public a substantial part of a copyrighted work without the owner's authorisation, unless a section 14 to 25 exception applies, such as the section 22 exception for a single copy or adaptation of a computer program made to use it for the purpose it was obtained, for archival purposes, or to replace a lost or destroyed copy. |
|
| Zakon o autorskom pravu i srodnim pravima, Text and Data Mining Exceptions (Arts. 187-188) |
Before using the general text-and-data-mining exception to reproduce a copyrighted work, database or computer program found online in Croatia for AI training, check whether the rightsholder has reserved their rights through a machine-readable signal such as metadata; if they have, the exception does not cover your use. |
|
| Intellectual Property and Related Rights Law, Article 25 (Text and Data Mining Exception) |
Do not train on or mine a work whose rightholder has reserved the use through a machine-readable or other appropriate means. |
|
| Autorský zákon Sections 39c-39d, Text and Data Mining Exception for Automated Analysis |
Honor a rightholder's express, suitably given reservation, including a machine-readable reservation on a work made available online, before relying on the general text-and-data-mining exception to mine that work in the Czech Republic. |
|
| Ophavsretsloven Sections 11b-11c, Text and Data Mining Exception |
Do not extract from, or make copies of, a work you have lawful access to for commercial text and data mining, including AI training, where the rights holder has expressly reserved that use in an appropriate manner such as a machine-readable opt-out. |
|
| Copyright Act 2003, temporary reproduction and quotation exceptions |
A temporary reproduction of a work made in the process of a digital transmission, by a person entitled to make it, does not itself infringe copyright, but an act of automated reproduction that falls outside that exception and outside the quotation and current-events exceptions requires the copyright owner's authorisation. |
|
| Ley No. 65-00 sobre Derecho de Autor, Limitaciones y Excepciones |
Do not reproduce or transform a substantial part of a copyrighted work, including for training a model on scraped text, outside the law's quotation, teaching-reproduction, or press-review and news-of-the-day exceptions, without the rights holder's authorization. |
|
| Código Ingenios, uso justo y minería de textos |
Text and data mining outside that library, archive, or museum context, such as mining text scraped from the open web for model training, is not covered by this exception and needs another lawful basis. |
|
| DSM Directive, Article 4 (text-and-data-mining exception and rights reservation) |
Check for machine-readable rights reservations (robots directives, metadata, terms) before mining or training on EU-accessible content Skip or license content whose rights holder has opted out +1 more |
|
| Copyright Act 1999, Fair Dealing and Criminal Liability for Infringement from a date not yet set |
Making for sale or hire, importing other than for private and domestic use, or possessing in the course of a business with a view to committing an infringing act, an object that is and that you know or ought reasonably to know is an infringing copy of a copyright work is an offence. |
|
| Tekijanoikeuslaki Section 13b, Text-and-Data-Mining Reproduction Exception |
Honor an author's express and appropriate reservation of the text-and-data-mining reproduction right before reproducing their work for that purpose under Tekijanoikeuslaki 13 b sec (1 mom.), unless you are a research organization or cultural heritage institution mining for scientific research under 13 b sec (2 mom.), which cannot be overridden by contract or technical measures. |
|
| Copyright and Related Rights, no text-and-data-mining exception |
This law carries no text-and-data-mining exception; obtain the rightsholder's authorisation or a licence before reproducing copyrighted text or data from a Georgian source for AI training or data mining, unless a general exception such as the quotation exception genuinely fits the use. |
|
| Text und Data Mining (General Text and Data Mining Exception) |
Do not disregard a rightsholder's machine-readable reservation of rights over a work accessible online; a reservation made only in natural language is not effective. |
|
| Text und Data Mining fuer Zwecke der wissenschaftlichen Forschung (Text and Data Mining for Scientific Research) |
Stop making a reproduction available to others once the joint research or quality verification it was shared for has concluded. Do not undermine measures a rightsholder takes to protect the security and integrity of its networks and databases. |
|
| Copyright Act, 2011, quotation, temporary reproduction and compilation copyright from a date not yet set |
Obtain a licence, or rely on the fair-dealing quotation exception, before reproducing a copyright-protected Grenadian work at scale for model training, since the Act has no text-and-data-mining exception. Where relying on the quotation exception, keep the reproduction to a short part compatible with fair dealing, not exceeding the extent justified by the purpose, and give the source and the author's name. |
|
| Ley del Derecho de Autor, sin excepción de minería de textos y datos, protección de compilaciones |
Do not reproduce a protected work, or a collection of works or of data original in its selection, coordination or arrangement, beyond the narrow personal-use, library-preservation or teaching exceptions this law states. |
|
| Szjt. Section 35/A, Text and Data Mining Exception |
Reproduce a work for text-and-data mining, including AI training, only where you have lawful access to it and the rightsholder has not objected in advance in an appropriate, machine-readable manner for online content, per Szjt. Section 35/A(1). |
|
| Copyright Act, No Text-and-Data-Mining Exception, Database Compilations, and Technological Protection Measures |
Get the rights holder's authorisation before reproducing or reusing copyrighted material, including a copyrighted database or compilation, to train an AI model; the fair-dealing exceptions do not name text-and-data-mining or AI training as a covered purpose. Do not circumvent an effective technological protection measure applied to a work with the intention of infringing a right the Act confers. |
|
| Copyright Law, reproduction right and research exception |
Get the rights holder's permission before reproducing a copyrighted work in Indonesia, including through automated collection, unless the narrow research and criticism exception applies. |
|
| Electronic Commerce Law, Copyright in Digital Works Chapter |
Do not copy, perform, distribute, supply or publish a copyrighted electronic data message without the author's permission. |
|
| Legge sul Diritto d'Autore Artt. 70-ter and 70-quater, Text-and-Data-Mining Exceptions |
Honour an express reservation of rights by the rightholder over the works or database used: Article 70-quater's general TDM permission, which art. 70-septies extends to AI training, does not apply where the rightholder has expressly reserved the use. |
|
| Law on Intellectual Property, Copyright Exceptions and Data Compilations |
Do not rely on the fair-use exception where reproduction is obtained by circumventing a technological protection measure or removing rights-management information. |
|
| Autortiesību likums Article 21.1, Text and Data Mining Exception (Scraping and AI Training) |
Honor a rights holder's explicit, machine-readable opt-out before relying on the general text-and-data-mining exception to reproduce a lawfully accessible work, per Article 21.1(3). |
|
| Copyright Order, 1989, Absence of a Text-and-Data-Mining Exception or Database Right |
Obtain a licence from the rights holder before reproducing copyrighted literary, artistic or scientific expression at scale for AI-training purposes; bare facts and data are not protected and may be collected without one. Do not rely on a text-and-data-mining exception, because none exists in this Order; any large-scale automated reproduction of protected expression must fit within the ordinary free-use exceptions in section 9 or be licensed. |
|
| Law No. 9 of 1968, protected works and collections |
Do not reproduce, translate, or republish a protected literary, artistic, or scientific work without the author's written or electronic permission; Libya has no separate database right, so an unoriginal collection or compilation is protected only to the extent its individual contents are. |
|
| Urheberrechtsgesetz Art. 22, Privileged Uses |
Do not reproduce a copyrighted work outside the closed list of privileged uses (personal use, non-commercial teaching or scientific research illustration, or specified non-commercial digital reproduction) without the rightsholder's authorization. There is no text-and-data-mining exception or machine-readable opt-out mechanism under this Act; obtain the rightsholder's authorization for bulk reproduction of copyrighted text for commercial purposes such as AI model training, unless a privileged use applies. |
|
| Copyright and Related Rights Act, quotation and informational-purpose exceptions |
Do not reproduce more than a short part of a published work as a quotation unless the reproduction is compatible with fair practice and does not exceed what the purpose justifies, and always indicate the source and the author's name. Do not rely on the quotation exception, the informational-purpose exception, or the personal-use reproduction exception to justify scraping and reproducing a full copyrighted work, or the whole or a substantial part of a database, for training a model; the Act creates no text-and-data-mining exception and expressly excludes database reproduction from the personal-use exception. |
|
| Copyright Act 2014, limitations on economic rights and offences |
Do not reproduce, adapt or communicate a substantial part of a copyrighted work to the public beyond the narrow private-use, quotation, research, teaching, library, or current-events exceptions in sections 16 to 22. There is no text-and-data-mining exception; training on scraped copyrighted text must fit within one of the existing narrow exceptions, most plausibly the section 19 ground for scientific research or teaching illustration, or risk criminal liability under section 56. |
|
| Law on Copyright, quotation and news free-use exceptions |
An app training a model on, or reproducing, Mongolian copyrighted text can rely only on the Law's general free-use grounds (quoting for news, research, training, or criticism, or a library's own search database), each conditioned on naming the author and source, a non-profit purpose, a fair-use extent, and no market harm to the original work, because Mongolia has not enacted a text-and-data-mining-specific exception; a use outside those grounds needs the right holder's consent. |
|
| Copyright Law, reproduction exceptions and computer programme adaptation from a date not yet set |
Reproducing a work beyond the Law's named exceptions (personal use excluding a whole or substantial database or book, quotation with attribution, teaching purposes, current-events reporting) requires the right holder's authorization. |
|
| Copyright and Neighbouring Rights Protection Act 6 of 1994, Fair Dealing and Compilation Protection |
Confirm that any reproduction of a literary or musical work stays within what section 15's fair dealing exceptions actually allow (research or private study, criticism or review, or reporting a current event) before scraping, storing, or redistributing that content at scale. Do not rely on a text-and-data-mining-specific exception or a machine-readable opt-out signal to justify training on Namibian-sourced copyrighted text, since the Act provides neither; any such use has to fit within the general fair dealing exceptions in section 15. |
|
| Auteurswet, artt. 15n and 15o, Text and Data Mining Exceptions |
Any other miner with lawful access may do the same only where the rightsholder has not expressly reserved the right in an appropriate way, including by machine-readable means on a work made available online; check for such a reservation before mining. |
|
| Copyright Law, Computer Program Protection and Use-Without-Permission Exceptions |
Do not copy, adapt, or otherwise use a copyrighted work, including a computer program, beyond the nine listed permission-free cases (personal or family use, library or archive preservation, school education, state management, press introduction, quotation, free performance, public-place copying, and Braille or sound recording for the blind). |
|
| Law on Copyright and Related Rights, General Exceptions and Quotation |
Obtain the rights holder's permission before reproducing a work beyond the enumerated exceptions; a computer program is excluded from this part of the law entirely. No text-and-data-mining-specific exception or machine-readable opt-out exists; a use exceeding the enumerated purposes needs the rights holder's permission. |
|
| Law on Copyright and Neighboring Rights, exceptions and absence of a text-and-data-mining exception |
Do not rely on the Law's Article 20 free-uses list (quotation for clarification or criticism, personal or educational use, or a single lawfully-owned computer-program copy) to reproduce Omani-copyrighted text for training an AI or machine-learning model; none of them reaches that use, and the Law has no text-and-data-mining exception. |
|
| Copyright Ordinance 1962, closed enumerated fair dealing exceptions |
Do not rely on a general fair use or text-and-data-mining exception to reproduce or train on copyrighted literary, dramatic, musical or artistic works gathered from Pakistan; section 57 of the Copyright Ordinance 1962 permits reproduction only for a closed list of purposes, none of which is text or data mining. |
|
| Copyright and Neighbouring Rights Act 2000, Exceptions to Copyright and Enforcement |
Do not reproduce, adapt, or otherwise use a substantial part of a protected literary or artistic work, including text from a published article, beyond what the private-use, quotation, teaching, reprographic, or informatory-purposes exceptions in this Act allow, without the author's or copyright owner's authorization. Do not reproduce a substantial part of a database in digital form under the private-use exception; reproducing a database beyond what another exception allows requires the rightholder's authorization. |
|
| Ley N° 1328/1998, arts. 8, 40 y 41, límites y excepciones al derecho de autor |
When quoting or reproducing a lawfully disclosed work under either exception, name the author and the source and stay within what fair practice and the exception's own purpose justify. |
|
| Intellectual Property Code, Fair Use of a Copyrighted Work |
Weigh the purpose and character of a use of a copyrighted work, the nature of the work, the amount used, and the effect on the work's market before relying on fair use to reproduce it for training data or aggregation. |
|
| Ustawa o prawie autorskim i prawach pokrewnych, Text-and-Data-Mining Exceptions |
Honor a rightsholder's express opt-out from the general text-and-data-mining exception; for a work made available so that anyone can access it at a time and place of their choosing, that opt-out is valid only when expressed in a machine-readable format together with metadata. Rely on the unconditional research text-and-data-mining exception, which no opt-out can defeat, only where you are a cultural-heritage institution or a covered higher-education or research body acting without a direct or indirect financial-gain purpose, and only while you keep the mined reproductions under access controls limited to authorized persons. |
|
| CDADC Text and Data Mining Exception |
Check whether the rights holder of a legally accessible work has expressly reserved it against text and data mining through a machine-readable means, such as optical reading of content made available online, before mining it for that purpose, unless mining it as a research organization or cultural-heritage institution for scientific research. |
|
| Copyright Protection Law, exceptions to copyright |
A reproduction or adaptation of a protected work for automated collection or model training must fit within the Law's narrow permitted-use list (personal use, non-profit teaching illustration, or adapting a lawfully-held copy of a computer program); Qatar has no text-and-data-mining exception, so bulk ingestion of copyrighted text for training does not fit these categories and requires the author's authorisation. |
|
| Legea nr. 8/1996 privind dreptul de autor și drepturile conexe, art. 36^1-36^2, Text and Data Mining Exceptions, inserted by Legea nr. 69/2022 |
Do not reproduce or extract text and data from a lawfully accessible work online for text-and-data-mining purposes if the rights holder has reserved that use through machine-readable means or another adequate method, per Legea nr. 8/1996 art. 36^2. |
|
| Copyright Act, 2003, fair dealing and compilation copyright |
Where relying on fair dealing to reproduce a Vincentian literary, dramatic, musical or artistic work at scale for research or model training, confine the use to the research-or-private-study or criticism-review-reporting grounds, give a sufficient acknowledgement except when reporting current events, and weigh the four fairness factors in section 52, since the Act has no text-and-data-mining exception for scraping-derived training data. Do not treat a written table or compilation as free of copyright merely because it is a compilation of data; it is protected like any other literary work only where it is original, and the Act confers no sui generis right over the underlying data itself. |
|
| Copyright Law (2026), circumventing technical protection measures |
Do not circumvent, without justification, a technical protection measure that a rights holder uses to protect its rights in a work, performance, sound recording or broadcast programme; the offence carries imprisonment of up to one year and a fine of up to one million riyals, or either, without prejudice to any heavier penalty under another law. |
|
| Copyright Law (2026), copying to develop artificial intelligence products and algorithms |
Copy a work in Saudi Arabia to develop artificial intelligence products or algorithms only where the work was lawfully published, the copy was lawfully acquired and the copying goes no further than that purpose needs, and keep records of the type, source, purpose and date of each use to give to a competent authority hearing a dispute. Do not republish, distribute, make available or unnecessarily embed a work used for AI development in a final product without the rights holder's permission unless the work is in the public domain, and do not use it in a purely commercial framework unless the use is non-essential to the work or does not affect its normal exploitation. |
|
| Autorský zákon, TDM Exception |
Do not reproduce a lawfully accessible work for text-and-data-mining purposes if the rightsholder has expressly reserved that use. |
|
| RDL 24/2021 Article 67, Text and Data Mining Exception |
Honor an express, machine-readable rights reservation before relying on the general text-and-data-mining exception to reproduce a legitimately accessible work, per RDL 24/2021 art. 67.3. |
|
| Upphovsrättslagen 15 a-15 c §§, Text and Data Mining Exception |
Honor an author's appropriate, including machine-readable, reservation of the text-and-data-mining right before relying on the general exception in Upphovsrättslagen 15 a § to reproduce a work. Do not retain a copy made under the text-and-data-mining exception longer than necessary for the mining purpose, and do not use it for another purpose. |
|
| Copyright Act, fair use of a work |
Test a collection or training use of another's copyrighted work against Article 65's fair-use factors (purpose and character, nature of the work, proportion used, and market effect) case by case; there is no separate text-and-data-mining exception or opt-out mechanism to rely on instead. |
|
| Criminal Code, infringement of copyright and related rights |
An app must not use, copy, store, transport or transfer a copyrighted work or phonogram without the copyright holder's authorization where doing so causes major damage; no scientific-research, quotation or text-and-data-mining exception has been identified for this offense. |
|
| Copyright Act, fair-use exception and absence of a text-and-data-mining exception |
Reproducing or adapting more than a normal, non-prejudicial extract of another party's copyrighted work, including to train a model, needs a Section 32 to 35 exception or a licence, because Thai copyright law has no dedicated text-and-data-mining exception for automated bulk extraction. |
|
| Copyright and Related Rights Code, Reproduction Right and Counterfeiting |
Do not reproduce, communicate to the public, or otherwise use a protected work, including a compilation or database that is itself an intellectual creation, without the author's authorisation, unless a free-use exception in article 129 applies. |
|
| Copyright Ordinance, infringement penalties |
Reproducing, distributing, publicly exhibiting, or importing a copy of a copyrighted work without the rights holder's consent risks liability under this Ordinance, which provides no exception for text-and-data-mining, research, or other automated reproduction. |
|
| Text and Data Mining for Non-Commercial Research |
Obtain a licence or the rights holder's consent before crawling third-party websites to collect data for commercial AI model training, since the non-commercial-research text-and-data-mining exception does not cover commercial use. Do not transfer a copy made under the non-commercial-research exception to anyone else, or use it for any purpose beyond that research, without the copyright owner's authorisation. |
|
| Ley N° 9.739 arts. 44-45, illicit-reproduction rule and free-use exceptions for quotation and news |
Do not reproduce, distribute, communicate, or make a copyrighted work available to the public without the author's consent, unless a free-use exception applies. |
|
| Copyright and related rights by reference to Italian law (Legge N. CXCVII) |
Do not reproduce the Pope's image, voice, speeches, or writings, or the published texts of Holy See or Vatican City State laws and official acts, without regard to the copyright and personality-right protections this law states for them. Do not photograph or otherwise reproduce Vatican City State's protected cultural property unless you are the institution that holds custody of it. |
Personal data
9 laws, 9 places| Place | Law | What it asks, as read here |
|---|---|---|
| Código Penal, Violación de Datos Personales |
Do not obtain, compile, extract, or use personal data contained in a file, archive, or database without the controller's authorization, even for data found on a public web page. |
|
| Data Protection Act, No. 1 of 2023, application to processing of personal data from a date not yet set |
Once in force, establish a lawful basis, ordinarily the data subject's consent, before collecting or processing personal data from Grenada, including through crawling or scraping. |
|
| Personal Data Protection Law, scraped personal data |
Have a lawful basis under Article 20 before collecting or otherwise processing the personal data of an individual in Indonesia, including data collected from a public website; the Act carries no basis keyed to the data already being public. |
|
| Personal Data Protection Law, Reach Over Scraped Public Personal Data |
A scraper collecting the personal data of a person in Moldova from a public, unauthenticated page must still establish an art. 6 lawful basis, such as consent or a legitimate interest that respects the person's rights, for the collection and any later use, including training a model. |
|
| Personal Data Protection Law, reach over scraped public personal data |
A scraper collecting the personal data of an individual in Oman from a public page must confirm the data was made public in a manner not contrary to the Personal Data Protection Law before treating it as outside the Law's scope under Art. 3(j); a biometric identifier such as a faceprint or voiceprint derived from publicly posted photographs, video, or audio requires a Ministry permit under Art. 5 regardless of the recording's public availability. |
|
| Data Privacy Act of 2012, Application to Scraped Public Personal Data |
An app scraping the publicly available personal data of an individual in the Philippines must still identify a lawful basis for processing that data under the Data Privacy Act; the data's public availability does not by itself supply the data subject's consent or any other lawful basis. |
|
| Rhode Island Data Transparency and Privacy Protection Act, publicly available information exemption |
Do not treat personal data scraped from an aggregator, people-search site, or re-hosted directory as publicly available under RIDTPPA; the exemption has no prong for a third party's unrestricted disclosure of someone else's data. |
|
| Personal Data Protection Act, 2022, application to processing of personal data |
Register with the Personal Data Protection Commission and have a lawful basis before collecting or processing personal data through a crawler or data pipeline, whether or not the data was publicly accessible online. |
|
| Law on Personal Data, publicly available personal data |
An app scraping personal data from a publicly accessible Uzbek source must still meet the Law on Personal Data's general lawful-basis and consent requirements unless the data qualifies as publicly available personal data under Art. 29, meaning data the subject has made freely accessible or that is not subject to a confidentiality requirement. |
Unfair competition
4 laws, 4 places| Place | Law | What it asks, as read here |
|---|---|---|
| Anti-Unfair Competition Law, 2025 revision, Article 13 (data scraping and technical circumvention clause) |
Do not obtain or use data lawfully held by another business operator by fraud, coercion, or by evading or destroying that operator's technical access controls. |
|
| Electronic Commerce Law, Trade Secrets Chapter |
Do not illegally acquire, or disclose to a third party, a trade or economic secret in an electronic environment. |
|
| Unfair Competition Prevention and Trade Secret Protection Act, Art. 2(1) items ka and pa (data misappropriation and general catch-all) |
Do not acquire data by theft, fraud, unauthorized access, or other wrongful means, or use or disclose data acquired that way. Do not use, disclose, or provide to a third party, beyond a contractual access limit and for wrongful profit or to harm the data holder, data you accessed under that limit. +1 more |
|
| Unfair Competition Act, Exploitation of Another Person's Market-Ready Work Product |
Do not take over and exploit, through a technical reproduction process, another person's market-ready work product without a reasonable effort of your own. |
AI training data
2 laws, 2 places| Place | Law | What it asks, as read here |
|---|---|---|
| AI Act, Article 53 (obligations for providers of general-purpose AI models) |
Adopt and follow a copyright policy that respects TDM opt-outs |
|
| Law on Artificial Intelligence, copyright and training data |
Do not train an AI model on a published work if the author or rightsholder has posted a prohibition against it in machine-readable form. |
AI prohibited practices
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Law on Artificial Intelligence, prohibited practices |
Do not collect, process, or use data to develop, train, test, or operate an AI system in violation of Vietnam's data, personal data protection, intellectual property, or cybersecurity law. |
Contract terms of service (ToS)
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| Copyright Law (2026), licence terms for software, applications and databases |
Follow the licence terms that accompany software, applications and databases in Saudi Arabia, including terms that appear electronically on download, installation or use; a user who agrees to them is bound unless they are contrary to public order or morals. |
Crawl signals
1 law, 1 place| Place | Law | What it asks, as read here |
|---|---|---|
| AI Training Data Transparency Act (AB 2013) |
State whether those datasets include copyrighted, trademarked, or patented data, and whether they include personal information. |
Full text of the NIST AI Risk Management Framework, public domain (a US government work). Every control of the framework.