'Without right' in Article 2(d). The definition concerns a general principle of criminal
law and aims to avoid criminal liability for a person acting either as permitted under
national law or with the authorisation of the owner or of another right holder of the
information system or part of it.
Specific criminal offences are defined, namely:
Illegal access to information systems as such (Article 3);
Illegal system interference (Article 4) which includes any illegal access to an
information system causing its functioning to be seriously hindered or interrupted;
Illegal data interference (Article 5) which refers to any unlawful interference with
computer data as such impairing its integrity or availability;
Illegal interception (Article 6) of non-public transmissions of computer data and
electromagnetic emissions from an information system carrying such data;
Illegal provision of tools used for committing the mentioned offences (Article 7). In
this context, such tools could be a computer programme as well as a computer
password or any other data allowing access to an information system.
In addition, the Directive extends criminal liability to incitement, aiding and abetting by
natural and/or legal persons to commit and their attempt to commit the offences mentioned
above (Article 8). While inciting, aiding and abetting cover all the offences referred to in
Articles 3 – 7, the attempt refers only to Articles 4 and 5.
Minimum levels of maximum penalties for offences referred to in the Directive are provided
for in Article 9:
As a baseline, a maximum penalty of imprisonment of at least 2 years is set for all the
offences except for the ones under Article 8 (Article 9(2)).
At least 3 years of imprisonment as a maximum penalty apply to offences under
Articles 4 and 5 where a significant number of information systems has been affected
(generally referred to as botnet offences; Article 9(3).
At least 5 years of imprisonment as a maximum penalty are required for offences
under Articles 4 and 5 committed by a criminal organisation (Article 9(4)(a)), causing
serious damage (Article 9(4)(b)) or committed against a critical infrastructure
information system (Article 9(4)(c)).
Whenever an offence under Articles 4 and 5 is committed in the context of misuse of
personal data of another person, Member States should ensure that it may be
considered as aggravating circumstances unless those circumstances are already
covered by another offence (Article 9(5)).
The subsequent Articles set up minimum conditions for the liability of legal persons (Article
10) and provide an exemplary list of possible sanctions against them (Article 11).
Recognising that the offences mentioned above can be committed (in the sense of 'executed')
in a place where the offender actually acts while their effects on the targeted information
system might take place somewhere else, Article 12 provides for obligations to establish
jurisdiction differentiating between:
the place where the offender is physically present when committing the offence,
the location of the targeted information system,
4