In the modern digital era, cybercrime is a transnational phenomenon that requires not only national but also coordinated international efforts to curb it. While the European Union strives for harmonization through instruments such as the Directive on Attacks against Information Systems (2013/40/EU) and the Budapest Convention on Cybercrime, national legislation remains the key framework for concrete measures against computer crimes. This article presents a comparative analysis of three leading European jurisdictions — Spain, Germany, and France — regarding their criminal law regulation of cybercrime.
The Spanish Criminal Code does not contain a separate chapter explicitly dedicated to computer crimes, yet it includes several provisions criminalizing them in various contexts. Article 248 addresses the crime of fraud and explicitly covers cases of computer manipulation that result in the unintended transfer of assets — a typical example of “computer fraud.”
In addition, Article 197 provides for criminal liability for persons who, with the intent to violate privacy or to disclose secrets, access or intercept electronic communications, intercept data, or use technical means to access third-party telecommunications signals. The penalty is more severe if the affected data contain sensitive information (health, race, religion, sexuality) or if the victim is a minor or legally incapacitated.
Spanish law also shows a clear tendency to aggravate penalties when there is intent for personal gain, abuse of trust, or harm to critical personal or public information. Special attention is given to the disclosure and dissemination of confidential information and violations of privacy through recording or tracking devices.
The German Criminal Code (StGB) contains provisions that directly address different forms of cybercrime and is distinguished by its exceptional precision. These are grouped into several paragraphs, with §202a criminalizing unauthorized access to data not intended for the offender and protected by special security measures. This covers actions involving the circumvention of protections like passwords, encryption, or physical barriers.
§202b complements this by criminalizing data interception — such as eavesdropping on traffic within a computer network. §202c is of particular interest as it penalizes not only the commission but also the preparation of computer crimes, making the creation, acquisition, or distribution of hacking tools (passwords, codes, programs) a criminal act even without a subsequent offense.
Germany was among the first in Europe to introduce provisions on “computer sabotage” — §303a and §303b — providing severe penalties for damaging data or computer systems, especially when this affects critical public or state infrastructures. There are also aggravating circumstances related to organized crime or harm to essential services.
The French Criminal Code includes a special Chapter III titled “Offences Against Automated Data Processing Systems” (Articles 323-1 to 323-7). This chapter presents a clear escalation of liability based on the severity of the offense.
Unauthorized system access is punished under Article 323-1, with increased penalties when data are deleted or altered. Further aggravation is provided when the affected system processes personal data on behalf of the state. Article 323-2 criminalizes actions that hinder the functioning of a system, while Article 323-3 addresses the unauthorized input or modification of data.
France also establishes liability for distributing tools to commit such crimes (Article 323-3-1), participating in organized groups with such a purpose (Article 323-4), and imposes sanctions on both natural and legal persons (Articles 323-5 and 323-6), including confiscation, bans on holding positions, and public announcement of convictions. Article 323-7 explicitly makes attempts punishable.
The French system shows a high degree of structure and includes protective mechanisms against technology misuse through additional provisions in the electronic communications and data protection legislation.
The comparative analysis of the criminal law frameworks of Spain, Germany, and France shows that despite differences in structure and terminology, there is a common trend towards expanding and deepening criminal liability for cybercrimes. While Spain uses more general provisions applied in a cyber context, Germany and France offer detailed and technically precise regulation focusing on preparation, dissemination of tools, damage to systems, and personal data protection. All three countries recognize the dynamics of digital threats and adapt their legal frameworks to technological developments, highlighting the growing need for a coordinated European strategy for cybersecurity and criminal law protection.