Article 286 – Infringement of Computer Data and/or a Computer System
Article 286 of the Criminal Code of Georgia protects the sphere of information security. Under this article the unauthorized damaging, deletion, alteration or suppression of computer data is punished, as well as the unauthorized insertion or transmission of computer data that has caused a deliberate significant disruption of the functioning of a computer system. In the conditions of a digital economy this norm finds wide practical application – from corporate data to personal accounts.
The article unites two kinds of object: computer data and the functioning of a computer system. The first part concerns actions directly related to data – damaging, deleting, altering or suppressing them; the second adds the unauthorized insertion or transmission of data and the deliberate significant disruption of the system's functioning. The fourth part separately protects subjects of critical information systems.
What the Prosecution Must Prove and Where the Defense Begins
The prosecution must prove the fact of the act – the damaging, deletion, alteration, suppression, insertion or transmission of data; the absence of authorization – that the act was performed without the consent or legal basis of the person holding the corresponding right over the data or the system; and the result – in the case of part 2, a deliberate significant disruption of the system's functioning, and in one of the forms of part 3, significant damage.
The defense position is built mainly on the absence of authorization: it is often contested whether the person had a lawful right of access – for instance, within the scope of an official authority. The scale of the result is also contested: what counts as a significant disruption or significant damage, and whether it is confirmed by evidence. These evaluative categories depend on concrete factual circumstances, and it is precisely there that the defense's opportunities unfold.
Sanctions – Every Part of the Article Separately
Article 286 provides for the following penalties, each part standing on its own:
- part 1 – unauthorized damaging, deletion, alteration or suppression of computer data – a fine, or corrective labor for a term of up to two years, and/or imprisonment for the same term;
- part 2 – the act provided for by part 1, and also the unauthorized insertion or transmission of computer data that has caused a deliberate significant disruption of the functioning of a computer system – a fine, or corrective labor for a term of up to two years, and/or imprisonment for a term of up to three years;
- part 3 – an act provided for by part 1 or 2, committed by a group with prior conspiracy, by using an official position, more than once, or having caused significant damage – a fine, or corrective labor for a term of up to two years, or imprisonment for a term of three to five years;
- part 4 – an act provided for by this article, committed against a subject of a critical information system – imprisonment for a term of four to seven years.
Under the note to the article, a legal person is punished for these acts by a fine, by deprivation of the right to conduct activity, or by liquidation and a fine. The rules on individualization of punishment are defined by other norms of the Code.
Aggravating Forms
Part 3 names four aggravating circumstances: commission by a group with prior conspiracy, the use of an official position, commission more than once, and the causing of significant damage. Part 4 names as a separate aggravating condition the commission against a subject of a critical information system – in that case the penalty consists of imprisonment alone, from four to seven years.
In practice the moment of the use of an official position is often contested: an action of an IT employee or administrator that appeared to remain within official functions may be assessed by the prosecution precisely as this aggravating form. Establishing whether the act exceeded the scope of the powers transferred to the person is decisive here.
Critical Information Systems
The application of part 4 is connected with who the injured party is – a subject of a critical information system. This category is subject to separate regulation, and which organizations belong to it depends on the corresponding normative acts. In analyzing a case a lawyer verifies this question separately, because it determines whether the case proceeds under the lighter or the graver part.
How a Defense Lawyer Assists in Computer Crime Cases
Such cases rest on technical evidence – logs, access histories, expert conclusions. A lawyer will assess the correctness of the qualification, the substantiation of the absence of authorization, the provability of the result, and the compliance of the evidence with the rules of lawfulness. If the accused's action remained within the scope of his office, this changes the qualification directly.
The lawyers of Legal.ge work on digital crime cases and will help you form an accurate assessment of your situation – under which part the case proceeds and what consequences each procedural step entails.
