Article 197 bis punishes access to the whole or part of an information system by circumventing the security measures established to prevent it, and the interception, by technical means, of non public transmissions of computer data, including the electromagnetic emissions of the system.
1. Whoever, by any means or procedure, circumventing the security measures established to prevent it, and without being duly authorised, accesses or facilitates to another access to the whole or a part of an information system, or remains within it against the will of the person having the legitimate right to exclude that person, shall be punished with imprisonment of six months to two years.
2. Whoever, through the use of technical devices or instruments, and without being duly authorised, intercepts non public transmissions of computer data taking place from, to or within an information system, including the electromagnetic emissions thereof, shall be punished with imprisonment of three months to two years or a fine of three to twelve months.
Working translation prepared by Société Juridique from the consolidated Spanish text published by the Official State Gazette. It has no official status: the only authoritative version is the Spanish original, available at the Official State Gazette and reproduced verbatim in our Spanish-language entry for this provision. Source: Organic Law 10/1995 of 23 November, the Spanish Criminal Code.
Existence and circumvention of security measures. Paragraph 1 requires that security measures established to prevent access be circumvented. Access to a system without a password, with credentials voluntarily handed over or through a publicly exposed interface does not satisfy that element.
Scope of the authorisation held. An employee or a service provider holding credentials of their own does not commit the offence by using them, even where that use exceeds internal policy. The dividing line is the authorisation granted and not the purpose for which it was used, and the internal documentation on access profiles is decisive.
Attribution of the access. The correlation between an internet protocol address, a session and a natural person requires technical evidence. Shared credentials, the absence of two factor authentication and the lack of a forensic examination of the terminal are habitual grounds of challenge.
Concurrence with Articles 197 and 264. Unlawful access is frequently charged together with the disclosure of secrets and with computer damage. Delimiting each provision avoids a double assessment of the same intrusion and habitually reduces the resulting penalty.
Are you under investigation or facing charges in Spain? Société Juridique acts for foreign nationals throughout Spain, with offices in Alicante and Madrid and a 24-hour custody line. +34 669 30 21 13 or enquire online.
This entry is provided for information only and does not constitute legal advice. The application of any provision depends on the circumstances of the individual case and requires examination of the case file by a qualified lawyer.