What Article 284 of the Criminal Code Punishes
Article 284 of the Criminal Code of Georgia establishes criminal liability for unauthorized access to a computer system. In everyday speech this conduct is often called hacking, but the legal assessment does not depend on labels — it depends on the statutory definitions and on the concrete facts of the case. If a case has been initiated against you under this article, you need to understand exactly what the law requires, which circumstances make liability more severe, and where realistic defense arguments open up. This page explains the content of the article, every sanction it provides, and the questions on which a criminal defense lawyer's involvement is decisive.
Elements of the Offense Under the Law
Under the first part of the article, unauthorized access to a computer system is a crime. To assess the conduct correctly, the law explains several key concepts:
- a computer system is any device or mechanism, or a group of interconnected devices or mechanisms, that automatically processes data by means of a program; the law expressly states that this concept covers a personal computer, any device with a microprocessor, and a mobile telephone;
- computer data is any information represented in any form convenient for processing in a computer system, including a program that ensures the functioning of the computer system;
- unauthorized means unlawful, and also covers the situation where the holder of the right has not transferred the right to the person committing the act, either directly or indirectly.
These definitions show that the decisive question in a case is often the existence of a right: if the person had been granted the right of access by the holder of the system, directly or indirectly, the element of lack of authorization is absent. That is why a defense lawyer begins by establishing who granted or denied that right, when, and in what form, and then supports these facts with evidence.
Sanctions Under the First Part
For unauthorized access to a computer system, the first part of the article provides a fine, or corrective labor for a term of up to two years, or imprisonment for the same term — that is, up to two years. Cases under this part typically involve conduct committed without aggravating features. The specific penalty ultimately depends on how well the prosecution proves its case and how persuasively the defense position is presented.
Aggravating Circumstances Under the Second Part
The second part of the article provides for stricter liability when the same act is committed:
- by a group with prior conspiracy;
- through use of an official position;
- more than once;
- or where it caused significant damage.
In these cases the law provides a fine, or corrective labor for a term of up to two years, or imprisonment for a term of two to five years. Significant damage under this chapter means damage exceeding 2000 GEL, except for the case provided for by another norm of the Code. A crime is considered committed more than once if it was preceded by the commission of any crime provided for by this chapter. These definitions are frequently the central disputed point of a case: for example, the correct calculation and documentary substantiation of the amount of damage rests on the prosecution, and the defense is entitled to verify those calculations in full.
Critical Information System Subjects — the Third Part
The third part of the article addresses cases where an act provided for by the first and, or, the second part is committed against a subject of a critical information system. In such cases the law provides imprisonment for a term of three to six years. The concept of a subject of a critical information system is defined by the Georgian Law on Information Security, and the existence of that status in a given case must be established separately — the prosecution must present data confirming it.
Liability of Legal Entities
According to the note to the article, for this conduct a legal entity is punished by a fine, by deprivation of the right to carry out activity, or by liquidation and a fine. This means that the risk associated with unauthorized access to computer systems also extends to companies, and for private-sector organizations this circumstance reaches as far as the management of business processes.
How a Defense Lawyer Can Help You
A lawyer's involvement in such a case proceeds along several directions. The first concerns the elements of the offense: a precise legal assessment of lack of authorization, of the concept of a computer system, and of the amount of damage often changes the qualification of the charges or part of them. The second concerns the features of the second and third parts: prior conspiracy, use of an official position, repetition, and the status of a critical information system subject must each be substantiated separately. The third concerns the procedural dimension: in cases of this category technical evidence accumulates, and the lawfulness of how it was obtained is a separate subject of review. The rules on the allocation of punishments and on the liability of legal entities are set out in detail in other norms of the Code, and therefore must be assessed separately for each situation. If you would like us to review your situation, contact us — at a consultation we will discuss every circumstance of your case in confidence.
