Unlawful Obtaining of Personal Data – How the Law Assesses This Conduct
Problems connected with personal data – often known as "data breaches" – are assessed under Article 157 of the Criminal Code of Georgia. The norm treats as a crime the unlawful obtaining, storage, use, dissemination or other making available of information on private life or personal data, where it has caused significant damage. Contacts extracted from databases, account details, personal files – all these situations fall within the scope of this norm.
The practical significance of the article lies in the fact that it covers nearly every form of dealing with data: from obtaining to making available. This means that the crime may consist both of extracting the data and of their subsequent dissemination – and each form is assessed separately.
What the Prosecution Must Prove – the Elements
The prosecution must prove: that the person performed one of the acts listed in the article on the data; that the act was unlawful – not based on a lawful ground; and that it caused significant damage. All three elements are required together – if any of them is absent, the qualification does not exist.
In data cases the element of unlawfulness is particularly important: often the person had lawful access to the data – by virtue of employment, contract or another ground – and the question is only whether he exceeded the scope of that access. Drawing this boundary is precisely where the defense position is built.
Sanctions – Every Part of the Article Separately
Article 157 provides for the following penalties, each part standing on its own:
- part 1 – unlawful obtaining, storage, use, dissemination or other making available of information on private life or personal data, having caused significant damage – a fine, or corrective labor for a term of up to two years, or imprisonment for a term of up to three years;
- part 2 – use and/or dissemination through the internet, including a social network, mass broadcasting or another public statement, having caused significant damage – a fine, or corrective labor for a term of up to two years, or imprisonment for a term of up to four years;
- part 3 – an act provided for by part 1 or 2, committed for mercenary reasons or more than once – a fine, or imprisonment for a term of up to five years;
- part 4 – an act committed by a person who was obliged to protect these data by virtue of official position, professional activity or another circumstance, or by using an official position – imprisonment for a term of four to seven years, with deprivation of the right to hold an office or conduct activity for a term of up to three years or without it.
Under the note to the article, a legal person is punished for these acts by a fine, deprivation of the right to conduct activity, or liquidation and a fine. The rules on individualization of punishment are defined by other norms of the Code.
The Note – the Possibility of Release
The note to the article defines a release for the forms of obtaining and storage: liability is not imposed on a person who handed the obtained or stored information over to the investigative bodies and thereby provided information about a committed or expected other criminal act. In other words, where the obtaining of data took place for the purpose of uncovering another crime and the information was transferred to the investigative bodies, liability for that form does not arise.
Aggravating Circumstances and Their Meaning
Part 3 names two aggravating circumstances: commission for mercenary reasons – with the aim of receiving benefit – and commission more than once. Part 4 separately aggravates liability for those who were precisely obliged to protect these data – for instance, an employee of an organization who had access to the data by virtue of official functions.
In data-case practice part 4 is often applied precisely against such persons: the employee who took out a client base, or the operator who lawfully saw the data and later disseminated them. In such cases the defense's task is to establish exactly within what scope the access was granted and where the unlawfulness began.
Challenges of the Digital Trail
In data cases it is often hard to establish exactly who acted and how: access to the same base may be held by several persons, and accounts may be shared. The prosecution's assumption that ownership of an account automatically means performance of the act must be challenged by the defense in every case – such reasoning remains fallacious until the authorship of the specific acts on which the charge rests is confirmed.
Practical Aspects of the Defense
The digital trail is the central evidence in such cases: logs, access histories, facts of transfer. The defense verifies their completeness and lawful obtaining – the procedure for collecting and using data is defined by other provisions. The significance of the damage is likewise central – the prosecution must confirm the existence of damage and its scale with evidence.
The lawyers of Legal.ge work on criminal cases connected with data protection: we assess the qualification, the boundaries of unlawfulness, the substantiation of damage and the real existence of aggravating circumstances, and help you build the correct strategy for the case.
