Article 264 of the Spanish Criminal Code punishes the unauthorised deletion, damage, deterioration, alteration, suppression or rendering inaccessible of another person’s computer data, programs or electronic documents, where both the conduct and the result are serious. It is the provision under which ransomware, the sabotage of a former employer’s systems and the destruction of company records are prosecuted, and it carries two to five years where the damage is of special gravity, affects a large number of systems or affects critical infrastructure. The requirement that both the conduct and the result be serious is what confines it, and it is where the defence begins.
1. A person who by any means, without authorisation and in a serious manner, deletes, damages, deteriorates, alters, suppresses or renders inaccessible another person’s computer data, computer programs or electronic documents, where the result produced is serious, shall be punished with imprisonment of six months to three years.
2. Imprisonment of two to five years and a fine of one to ten times the loss caused shall be imposed where any of the following circumstances is present in the conduct described:
1.ª It has been committed within the framework of a criminal organisation.
2.ª It has caused damage of special gravity or has affected a large number of computer systems.
3.ª The act has seriously harmed the operation of essential public services or the supply of goods of primary necessity.
4.ª The acts have affected the computer system of a critical infrastructure, or a situation of serious danger to the security of the State, of the European Union or of a Member State of the European Union has been created. For these purposes, critical infrastructure means an element, system or part of one which is essential for the maintenance of vital functions of society, health, safety, security and the economic and social well-being of the population, whose disruption or destruction would have a significant impact through the inability to maintain those functions.
5.ª The offence has been committed using one of the means referred to in article 264 ter.
If the acts have been of extreme gravity, the penalty one degree higher may be imposed.
3. The penalties provided for in the preceding paragraphs shall be imposed, in their respective cases, in their upper half where the acts have been committed through the unlawful use of another person’s personal data in order to facilitate access to the computer system or to gain the confidence of a third party.
Working translation prepared by Société Juridique from the consolidated Spanish text published by the Official State Gazette. It has no official status: the only authoritative version is the Spanish original, available at the Official State Gazette and reproduced verbatim in our Spanish-language entry for this provision. Source: Organic Law 10/1995 of 23 November, the Spanish Criminal Code.
Authorisation and the scope of access. In the great majority of cases the accused is a former employee, a partner or an external provider who held credentials. The question is not whether he had access but whether the specific act was authorised. The defence produces the contract, the internal policies, the access log and the evidence of what the accused was expected to do, since deletion of files the accused was responsible for, or the removal of his own work product, is frequently within his authority.
The seriousness of conduct and of result. The article requires both. Where the data were recoverable from backups, where the interruption lasted hours, or where the loss is asserted without a technical report, the threshold is not met and the matter is contractual. The defence commissions an independent examination of the system and of the backup regime, because the complainant’s valuation habitually includes the cost of improvements made afterwards rather than the loss caused.
Attribution to the accused. Attribution rests on logs, network addresses and device evidence. The defence tests whether the credentials were shared, whether the address was dynamic or belonged to a shared network, whether the timestamps are consistent across systems, and whether the material was obtained with the judicial authorisation required for access to traffic data. Where the log evidence has been collected by the complainant itself, its integrity and chain of custody are examined.
Excluding the aggravated circumstances. The circumstances in the second paragraph raise the sentence beyond the threshold for suspension. Damage of special gravity, a large number of systems and critical infrastructure are pleaded far more readily than they are proved: the definition of critical infrastructure in the article is demanding, and a company system is not one merely because the company is large. Each circumstance is contested with the technical evidence rather than accepted as a characterisation.
Are you under investigation or facing charges in Spain? Société Juridique acts for foreign nationals throughout Spain, with offices in Alicante and Madrid and a 24-hour custody line. +34 669 30 21 13 or enquire online.
This entry is provided for information only and does not constitute legal advice. The application of any provision depends on the circumstances of the individual case and requires examination of the case file by a qualified lawyer.