§ 202a StGB

Section 202a German Criminal Code — Data Espionage

§ 202a StGB — Ausspähen von Daten

Section 202a of the German Criminal Code criminalises the unauthorised obtaining of access to specially secured data — that is, overcoming an access protection to reach third-party data not intended for oneself. Even „cracking“ the protection is punishable, regardless of whether the data is subsequently used. The provision is a cornerstone of German computer criminal law.

History & facts. Section 202a presupposes that the data was specially secured against unauthorised access and that the perpetrator overcomes this protection; what is protected is the authorised party's interest in confidentiality. With the 41st Criminal Law Amendment Act (2007) the offence was extended: the mere obtaining of access — overcoming the protection — is already punishable, not only the actual reading of the data. The penalty range extends up to three years' imprisonment or a fine. Outlook & recommendation. Decisive is the element „unauthorised“: legitimate security work such as a commissioned penetration test takes place with the express consent of the authorised party and is thereby authorised. Those who test security should cleanly fix the assignment, the scope and the permission in writing before they begin — the legal basis is just as important here as the technical diligence. This is not legal advice; in case of doubt, professional legal counsel should be sought.
§ 202a StGB — Section 202a German Criminal Code — Data Espionage