
Mon–Fri 09:00–19:00

The conflict in the case law which the Joint Divisions resolved, by the judgment of 27 October 2011, concerned the notion of "abuse" in the offence under Article 615-ter, first paragraph, of the Criminal Code, which punishes access…
The conflict in the case law which the Joint Divisions resolved, by the judgment of 27 October 2011, concerned the notion of "abuse" in the offence under Article 615-ter, first paragraph, of the Criminal Code, which punishes unlawful access to a computer or telematic system.
In the case a non-commissioned officer of the Carabinieri who was entitled to access a computer system supplied to the police and containing confidential investigation data had obtained information concerning the private sphere and the judicial affairs of various persons, although he had no reason to carry out those checks, and had subsequently disclosed the information so obtained to one of the persons concerned and to a third party. The Fifth Criminal Division referred the question to the Joint Divisions, given the persistence of the conflict as to the objective element of the offence in question.
The Joint Divisions, having noted that the conflict was still current, reviewed the various lines of authority in the case law of the ordinary divisions.
It should first be made clear that the conduct punished by Article 615-ter, first paragraph, of the Criminal Code consists in:
a) unlawfully introducing oneself into a computer or telematic system protected by security measures (to be understood as access to knowledge of data or information contained in the system, effected either remotely or in person);
b) remaining in the system against the will, express or tacit, of the person who has the right of exclusion (to be understood as the fact of a person who persists in an introduction which has already occurred, initially authorised or accidental, continuing to access knowledge of the data despite the prohibition, even tacit, of the holder of the system).
On one line of authority, the offence of unlawful access to a computer system would not be made out where a person who is entitled to access the system uses it for purposes extraneous to those of his office, without prejudice to his liability for the different offences that may be made out where those purposes are then actually pursued.
On the opposite line of authority, for the offence in question to be made out it is enough that a person who, although authorised to access the computer or telematic system, introduces himself into it with the service password in order to collect protected data for purposes extraneous to the reasons of the institution and to the purposes inherent in the protection of the computer archive, using the system for objectives other than those permitted. That line of authority is based on the point that the rule punishes not only unlawful introduction into the system (to be excluded where the person holds a title to access), but also unlawful remaining in it against the will of the person who has the ius excludendi, which is presumed to be contrary where an unlawful purpose incompatible with the reasons for which authorisation to access was granted is pursued.
Faced with that conflicting interpretive picture, the Joint Divisions held that the question should not be looked at from the point of view of the purposes pursued by the person who accesses or remains in the system, because the will of the holder of the right to exclude is connected only to the objective fact of the agent's remaining in it: which means that the contrary will of the person entitled must be verified only by reference to the immediate result of the conduct, and not to subsequent facts. Consequently, what matters is only the objective profile of access to and remaining in the computer system by a person who cannot be regarded as authorised to access it and to remain in it, both when he breaches the limits resulting from the body of instructions given by the holder of the system (instructions contained in internal organisational provisions, in company practice or in clauses of individual employment contracts), and when he carries out operations of a kind different from those with which he is charged and in relation to which access is permitted to him. The assessment of the existence of the dominus's dissent cannot therefore be formulated on the basis of the purposive direction of the conduct, but must take as its parameter the existence of an objective breach, by the agent, of the instructions given by the dominus himself as to use of the system. It follows that, where the agent carries out on the system an operation fully covered by the authorisation received and acts within its limits, the offence under Article 615-ter of the Criminal Code is not made out, regardless of any purpose pursued; so that, where the authorised activity also consists in the acquisition of computer data and the operator carries it out within the limits and in the forms permitted by the holder of the right of exclusion, the offence in question does not arise, even if he later uses those same data for unlawful purposes. Any subsequent facts must therefore be regarded as irrelevant: they may, if appropriate, be brought under another offence.