info@societejuridique.com
Madrid: Paseo de la Castellana 216 8 ª Planta
Alicante: Av. Ansaldo Nº31, local 16
24h emergencies: 669 30 21 13

Social media:

Article 197 bis Spanish Criminal Code: Unlawful access to information systems and interception of data

Article 197 bis punishes access to the whole or part of an information system by circumventing the security measures established to prevent it, and the interception, by technical means, of non public transmissions of computer data, including the electromagnetic emissions of the system.

Wording of Article 197 bis of the Spanish Criminal Code

1. Whoever, by any means or procedure, circumventing the security measures established to prevent it, and without being duly authorised, accesses or facilitates to another access to the whole or a part of an information system, or remains within it against the will of the person having the legitimate right to exclude that person, shall be punished with imprisonment of six months to two years.

2. Whoever, through the use of technical devices or instruments, and without being duly authorised, intercepts non public transmissions of computer data taking place from, to or within an information system, including the electromagnetic emissions thereof, shall be punished with imprisonment of three months to two years or a fine of three to twelve months.

Working translation prepared by Société Juridique from the consolidated Spanish text published by the Official State Gazette. It has no official status: the only authoritative version is the Spanish original, available at the Official State Gazette and reproduced verbatim in our Spanish-language entry for this provision. Source: Organic Law 10/1995 of 23 November, the Spanish Criminal Code.

Sentencing range. Imprisonment of six months to two years for unlawful access to an information system, and imprisonment of three months to two years or a fine of three to twelve months for the interception of non public transmissions of computer data.

Elements of the offence

  1. In paragraph 1, access to the whole or a part of an information system, the facilitation of that access to another, or remaining within the system against the will of the person entitled to exclude the intruder.
  2. The circumvention of the security measures established to prevent that access. Where no such measure exists, the objective element is not satisfied.
  3. The absence of due authorisation, assessed by reference to the access actually granted and not to the purpose pursued.
  4. In paragraph 2, the use of technical devices or instruments to intercept non public transmissions of computer data, including the electromagnetic emissions of the system.

Defence strategy

Existence and circumvention of security measures. Paragraph 1 requires that security measures established to prevent access be circumvented. Access to a system without a password, with credentials voluntarily handed over or through a publicly exposed interface does not satisfy that element.

Scope of the authorisation held. An employee or a service provider holding credentials of their own does not commit the offence by using them, even where that use exceeds internal policy. The dividing line is the authorisation granted and not the purpose for which it was used, and the internal documentation on access profiles is decisive.

Attribution of the access. The correlation between an internet protocol address, a session and a natural person requires technical evidence. Shared credentials, the absence of two factor authentication and the lack of a forensic examination of the terminal are habitual grounds of challenge.

Concurrence with Articles 197 and 264. Unlawful access is frequently charged together with the disclosure of secrets and with computer damage. Delimiting each provision avoids a double assessment of the same intrusion and habitually reduces the resulting penalty.

Are you under investigation or facing charges in Spain? Société Juridique acts for foreign nationals throughout Spain, with offices in Alicante and Madrid and a 24-hour custody line. +34 669 30 21 13 or enquire online.

This entry is provided for information only and does not constitute legal advice. The application of any provision depends on the circumstances of the individual case and requires examination of the case file by a qualified lawyer.

Logotipos-abogacia-scje
Paseo De La Castellana 216 8º 28046 Madrid
Alicante – Playa de San Juan Av. Ansaldo 31, local 16, 03540 Alicante
Londres: 20 Wenlock Road, N1 7GU, Reino Unido
París: 72 Faubourg St Honoré, 75008, Francia
info@societejuridique.com

Société de Conseil Juridique et Expert es un despacho de abogados con sedes en Madrid, Alicante, Londres y París, especializado en defensa y acusación penal, delitos económicos y corporativos y derecho tecnológico. Trabajamos con orientación estratégica en procedimientos penales complejos, propiedad intelectual y análisis forense avanzado, y prestamos consultoría jurídica, compliance y escudos de protección a particulares y empresas. Atendemos desde Alicante y Madrid, con consulta online en toda España y asistencia al detenido 24 horas. Resuelva sus dudas en las preguntas frecuentes o solicite una primera consulta.

Copyright © 2026 Société de Conseil Juridique et Expert S.L.

EspanolEnglishFrancaisРусскийItalianoDeutsch
WhatsApp · Urgencias 24h