Unauthorized Access to Personal Data and Criminal Liability
In the modern world the overwhelming majority of personal data is stored in computer systems — databases, corporate servers, cloud services and other online environments. That is why entering such a system without authorization is treated as a crime under the Criminal Code of Georgia, namely Article 284. If this charge has been brought against you, or if your organization's system has become the object of such conduct, it is important to assess the exact legal boundaries of what happened. Below we set out in detail what the article covers, which penalties attach to each of its parts, and on which circumstances the outcome of the case depends.
What the Elements of the Offense Include
The first part of the article prohibits unauthorized access to a computer system. This formula is strictly interpreted through the notes to the corresponding chapter of the Code, and it is those definitions that determine which conduct attracts liability:
- the concept of a computer system is broad: it is any device or mechanism, or a group of interconnected devices or mechanisms, which automatically processes data by means of a program; under the law this concept covers a personal computer, any device with a microprocessor, and even a mobile telephone;
- computer data is information in any form convenient for processing in the system — including a program that ensures the system's functioning; inventories of personal data typically fall squarely within this category;
- unauthorized means unlawful, and also the situation where the holder of the right has not transferred the right to the person committing the act, directly or indirectly.
From these definitions it follows that one of the central questions of any case is whether the particular person had the right to enter the system. Where such a right existed — whether granted directly or indirectly — this element does not characterize the conduct as criminal. For a lawyer, one of the first tasks is therefore to reconstruct the history of access rights and to support it with documentary evidence.
Penalties Under the Parts of the Article
The law regulates liability at three levels. For the basic composition — the first part — the penalty is a fine, or corrective labor for a term of up to two years, or imprisonment for a term of up to two years. The second part addresses the aggravated composition: the same act committed by a group with prior conspiracy, through use of an official position, more than once, or causing significant damage, is punished by a fine or corrective labor for a term of up to two years, or imprisonment for a term of two to five years. The third part punishes acts provided for by the first and, or, the second part when committed against a subject of a critical information system, and this part contemplates imprisonment only — for a term of three to six years. Each level must be read and assessed separately, because the differences between them are substantial and reflect directly on the fate of the case.
Significant Damage and the Definition of Repetition
In this chapter, significant damage means damage exceeding 2000 GEL, except for a case provided for by another norm of the Code. Second, a crime provided for by this chapter is considered committed more than once if it was preceded by the commission of any crime under the same chapter. Both definitions are frequently contested in court practice: calculating the amount of damage requires establishing what is included in the damage and what is not, while repetition requires a precise legal assessment of prior conduct. The prosecution establishes and substantiates both circumstances, and the defense has the right to verify them in full.
Critical Information System Subjects and Legal Entities
The concept of a subject of a critical information system is defined by the Georgian Law on Information Security. Where the conduct is committed against such a subject, the third part applies and the penalty rises sharply — the case separately requires establishing that the particular organization falls within the circle of subjects defined by that law. In addition, under the note to the article, a legal entity is punished for this conduct by a fine, by deprivation of the right to carry out activity, or by liquidation and a fine — a circumstance that creates additional risk for companies and requires information-security matters to be planned meticulously in advance.
What a Lawyer Can Do in Cases of This Category
A lawyer's work in these cases develops along three directions. The first is the examination of the elements: a precise analysis of the element of lack of authorization, of the concepts of a system and data, and of the amount of damage often changes the qualification of the charges. The second is evidence: the lawfulness of how technical data was obtained and processed is a separate subject of review. The third is sentencing: separate establishment of each aggravating feature — and, where necessary, its refutation — substantially reduces the penalty. The procedural rules and deadlines of the case are governed by criminal procedure legislation. Contact us — we will review your situation in confidence and assess the realistic prospects.
