 'Without right' in Article 2(d). The definition concerns a general principle of criminal law and aims to avoid criminal liability for a person acting either as permitted under national law or with the authorisation of the owner or of another right holder of the information system or part of it. Specific criminal offences are defined, namely:  Illegal access to information systems as such (Article 3);  Illegal system interference (Article 4) which includes any illegal access to an information system causing its functioning to be seriously hindered or interrupted;  Illegal data interference (Article 5) which refers to any unlawful interference with computer data as such impairing its integrity or availability;  Illegal interception (Article 6) of non-public transmissions of computer data and electromagnetic emissions from an information system carrying such data;  Illegal provision of tools used for committing the mentioned offences (Article 7). In this context, such tools could be a computer programme as well as a computer password or any other data allowing access to an information system. In addition, the Directive extends criminal liability to incitement, aiding and abetting by natural and/or legal persons to commit and their attempt to commit the offences mentioned above (Article 8). While inciting, aiding and abetting cover all the offences referred to in Articles 3 – 7, the attempt refers only to Articles 4 and 5. Minimum levels of maximum penalties for offences referred to in the Directive are provided for in Article 9:     As a baseline, a maximum penalty of imprisonment of at least 2 years is set for all the offences except for the ones under Article 8 (Article 9(2)). At least 3 years of imprisonment as a maximum penalty apply to offences under Articles 4 and 5 where a significant number of information systems has been affected (generally referred to as botnet offences; Article 9(3). At least 5 years of imprisonment as a maximum penalty are required for offences under Articles 4 and 5 committed by a criminal organisation (Article 9(4)(a)), causing serious damage (Article 9(4)(b)) or committed against a critical infrastructure information system (Article 9(4)(c)). Whenever an offence under Articles 4 and 5 is committed in the context of misuse of personal data of another person, Member States should ensure that it may be considered as aggravating circumstances unless those circumstances are already covered by another offence (Article 9(5)). The subsequent Articles set up minimum conditions for the liability of legal persons (Article 10) and provide an exemplary list of possible sanctions against them (Article 11). Recognising that the offences mentioned above can be committed (in the sense of 'executed') in a place where the offender actually acts while their effects on the targeted information system might take place somewhere else, Article 12 provides for obligations to establish jurisdiction differentiating between:   the place where the offender is physically present when committing the offence, the location of the targeted information system, 4

Select target paragraph3