Cybercrime Directive, Articles 2(d) and 3 to 12 (offenses against information systems, penalties and jurisdiction)
Directive 2013/40/EU, Arts. 2(d), 3-12
In force since .
A computer misuse rule binding public and private bodies.
- Obligation class
- Access restriction, Prohibition
As of .
What it requires
- This Directive is addressed to the Member States (Article 19), which had to bring into force the measures necessary to comply with it by (Article 16(1)), so a service meets these rules through each Member State's criminal law; Denmark is not bound by it (recital 32).
- Do not intentionally access, without right, the whole or any part of an information system by infringing a security measure; Member States must make this a criminal offense, at least for cases which are not minor (Article 3). Without right means not authorized by the owner or another right holder of the system or of part of it, or not permitted under national law (Article 2, point (d)).
- Do not intentionally and without right seriously hinder or interrupt the functioning of an information system by inputting computer data, or by transmitting, damaging, deleting, deteriorating, altering or suppressing such data, or by rendering such data inaccessible; Member States must make this a criminal offense, at least for cases which are not minor (Article 4).
- Do not intentionally and without right delete, damage, deteriorate, alter or suppress computer data on an information system, or render such data inaccessible; Member States must make this a criminal offense, at least for cases which are not minor (Article 5).
- Do not intentionally and without right intercept, by technical means, non-public transmissions of computer data to, from or within an information system, including electromagnetic emissions from an information system carrying such data; Member States must make this a criminal offense, at least for cases which are not minor (Article 6).
- Do not, without right and with the intention that it be used to commit an offense under Articles 3 to 6, produce, sell, procure for use, import, distribute or otherwise make available a computer program designed or adapted primarily for committing one of those offenses, or a computer password, access code or similar data by which the whole or any part of an information system can be accessed; Member States must make this a criminal offense, at least for cases which are not minor (Article 7).
- Do not incite, aid or abet an offense under Articles 3 to 7, or attempt one under Articles 4 and 5; Member States must make each of these punishable as a criminal offense (Article 8).
- The offenses reach a legal person as well as an individual: Member States must ensure that a legal person can be held liable where an offense was committed for its benefit by a person with a leading position in it (Article 10(1)), or by a person under its authority because a leading person failed to supervise or control (Article 10(2)).
- Member States must establish jurisdiction over these offenses where one is committed in whole or in part within their territory (Article 12(1), point (a)), and in doing so must ensure that they have jurisdiction where the offender commits it while physically present on their territory, whether or not the offense is against an information system there, and where the offense is against an information system on their territory, whether or not the offender is physically present there (Article 12(2)).
If you get it wrong
Criminal exposureYes
Criminal exposure note
Article 9(2) requires Member States to provide a maximum term of imprisonment of at least two years for the offenses in Articles 3 to 7, at least for cases which are not minor. Article 9(3) requires a maximum of at least three years for the offenses in Articles 4 and 5, when committed intentionally, where a significant number of information systems have been affected through the use of a tool referred to in Article 7 designed or adapted primarily for that purpose. Article 9(4) requires a maximum of at least five years for those offenses where they are committed within the framework of a criminal organization, as defined in Framework Decision 2008/841/JHA, cause serious damage or are committed against a critical infrastructure information system. These are minimums for the maximum term that each Member State's own law must provide.
Who enforces it
Enforcement body
Each Member State, through the national criminal law that implements the Directive, over which Article 12(1) requires it to establish jurisdiction where the offense is committed in whole or in part within its territory, or by one of its nationals, at least in cases where the act is an offense where it was committed.
What this law does
Article 16(1) required Member States to bring into force the laws, regulations and administrative provisions necessary to comply with the Directive by . Recital 32 records that Denmark is not taking part in the adoption of the Directive and is not bound by it or subject to its application.
Article 2, point (d), defines without right as conduct, including access, interference or interception, that is not authorized by the owner or by another right holder of the system or of part of it, or not permitted under national law.
Article 3 requires Member States to make intentional access without right to the whole or any part of an information system punishable as a criminal offense where it is committed by infringing a security measure, at least for cases which are not minor.
Article 4 requires Member States to make seriously hindering or interrupting the functioning of an information system by inputting computer data, by transmitting, damaging, deleting, deteriorating, altering or suppressing such data, or by rendering such data inaccessible, intentionally and without right, punishable as a criminal offense, at least for cases which are not minor.
Article 5 requires Member States to make deleting, damaging, deteriorating, altering or suppressing computer data on an information system, or rendering such data inaccessible, intentionally and without right, punishable as a criminal offense, at least for cases which are not minor.
Article 6 requires Member States to make intercepting, by technical means, non-public transmissions of computer data to, from or within an information system, intentionally and without right, punishable as a criminal offense, at least for cases which are not minor.
Article 7 requires Member States to make the intentional production, sale, procurement for use, import, distribution or other making available of a computer program designed or adapted primarily for committing an offense under Articles 3 to 6, or of a computer password, access code or similar data by which an information system can be accessed, without right and with the intention that it be used to commit one of those offenses, punishable as a criminal offense, at least for cases which are not minor.
Article 8 requires Member States to make incitement, aiding and abetting an offense under Articles 3 to 7 punishable as a criminal offense, and to do the same for an attempt to commit an offense under Articles 4 and 5.
Article 9(2) requires Member States to provide a maximum term of imprisonment of at least two years for the offenses in Articles 3 to 7, at least for cases which are not minor. Article 9(3) requires a maximum term of at least three years for the offenses in Articles 4 and 5, when committed intentionally, where a significant number of information systems have been affected through the use of a tool referred to in Article 7 designed or adapted primarily for that purpose.
Article 9(4) requires a maximum term of at least five years for the offenses in Articles 4 and 5 where they are committed within the framework of a criminal organization, as defined in Framework Decision 2008/841/JHA, cause serious damage, or are committed against a critical infrastructure information system.
Article 10(1) requires Member States to ensure that legal persons can be held liable for the offenses in Articles 3 to 8 committed for their benefit by any person, acting individually or as part of a body of the legal person, who has a leading position within it based on a power of representation, an authority to take decisions on its behalf or an authority to exercise control within it.
Article 10(2) extends that liability to cases where a lack of supervision or control by such a person has allowed a person under its authority to commit one of those offenses for the benefit of the legal person.
When establishing jurisdiction over an offense committed in whole or in part within its territory, Article 12(2) requires a Member State to ensure that it has jurisdiction where the offender commits the offense when physically present on its territory, whether or not the offense is against an information system on its territory, or where the offense is against an information system on its territory, whether or not the offender is physically present there.
Recital 11 leaves it to each Member State to determine under its national law and practice what constitutes a minor case. Recital 17 states that contractual obligations or agreements to restrict access to information systems by way of a user policy or terms of service should not incur criminal liability where the access under such circumstances would be deemed unauthorized and thus would constitute the sole basis for criminal proceedings.
When LexLint raises it
When your app profile says your app crawls the web or trains models.