Criminal defense for Data Espionage in Bonn

Legal Basis
§ 202a StGB
Sentencing Range
Imprisonment of up to three years or a fine
Summary
Unlawfully obtaining data that is not intended for the offender and is specially protected against unauthorised access

Data Espionage (Section 202a StGB)

Data espionage protects the formal right to control data that is specially secured against unauthorised access. In practice, this offence primarily concerns the unauthorised intrusion into other people’s computer systems — commonly known as “hacking.” With increasing digitalisation, this provision has gained considerable importance and is frequently applied in cybercrime investigations. Expats working in Germany’s tech sector or managing digital infrastructure should be aware of the broad scope of this offence.

Legal Basis

Section 202a of the German Criminal Code (StGB) provides:

“(1) Anyone who unlawfully obtains access to data that is not intended for them and is specially protected against unauthorised access, by overcoming the access protection, shall be punished with imprisonment of up to three years or a fine.
(2) Data within the meaning of subsection (1) means only data that is stored or transmitted electronically, magnetically, or otherwise in a form not directly perceptible.”

Elements of the Offence

Data: Only data that is stored or transmitted electronically, magnetically, or in a form not directly perceptible is covered. Paper documents do not fall within the scope of protection.

Not intended for the offender: The data must not be intended for the person accessing it. The decisive factor is the right of disposal of the person who stored the data. Even one’s own data on another person’s system can be “not intended” if the authorised person has restricted access.

Specially secured against unauthorised access: The data must be specially secured against unauthorised access. This includes password protection, encryption, firewalls, biometric security measures, and comparable technical measures. Merely organisational access restrictions (e.g., a locked door to a server room) are generally considered insufficient.

Overcoming the access protection: The offender must actually overcome the security measure. Simply exploiting an accidentally left-open access point (e.g., an unlocked computer) does not satisfy the offence. The overcoming can occur through technical means (brute-force attacks, exploits, keyloggers) or through social engineering (phishing).

Obtaining access for oneself or another: The offender must actually obtain access to the data. Merely acquiring the ability to access suffices; actual knowledge of the data content is not required.

Typical Methods of Commission

Common methods include cracking passwords through brute-force or dictionary attacks, exploiting software vulnerabilities, phishing attacks to obtain login credentials, deploying keyloggers or spyware, breaking into Wi-Fi networks by circumventing encryption, and accessing cloud accounts using stolen credentials.

Sentencing Range

Data espionage carries a penalty of up to three years’ imprisonment or a fine. In particularly serious cases, such as commercial-scale activity or where the data is subject to special confidentiality protection, a higher sentence within the sentencing range may be imposed. Where the offence coincides with other crimes (computer fraud, data alteration, computer sabotage), an aggregate sentence is formed.

Typical Defense Strategies

A central defense approach concerns whether special access protection actually existed and whether it was overcome. If the security was defective or access was open, the element of “overcoming” is absent. Furthermore, it is examined whether the data was truly “not intended for the offender” — in cases of authorised access (e.g., as an administrator or in the context of a penetration test), criminal liability is excluded. The reliable attribution of the act to the accused is also frequently problematic: IP addresses alone do not prove who actually acted. Finally, exclusionary rules may apply if law enforcement violated procedural rules when securing digital evidence.

How we defend against a charge of data espionage

The offence under Section 202a StGB is narrower than it first appears: only someone who obtains access to data not intended for them by overcoming a special access safeguard is liable. Our defence engages precisely with these requirements – on a sound technical footing.

Access safeguard and „specially secured“ data

Without overcoming a special access safeguard there is no offence. We examine whether an effective safeguard even existed and whether it was „overcome“ – for instance with openly accessible systems, shared passwords or inadequately protected interfaces.

Access rights and authorisation

Anyone who accesses data they are authorised to access does not spy on it. Particularly in employment relationships and with shared accounts, the scope of access authorisation is often unclear. We establish whether the access was covered by an existing authorisation.

Scrutinising log data and device forensics

The prosecution almost always relies on log files, timestamps and forensic device analysis. We question the attribution of access to a particular person: shared devices, open sessions, IP allocation and manipulable logs offer considerable room for defence.

Admissibility of privately obtained evidence

The evidence frequently comes from an employer or private party acting on their own initiative. We examine whether such evidence is admissible in criminal proceedings at all.

Summons or accusation of Data Espionage? What matters now

Make no statement to the police at first

As an accused person you are never obliged to comment on the allegation. Anything said to the police can be used against you. Provide statements only through your defense attorney and only after reviewing the case file.

File inspection comes first

A sound defense against the allegation of Data Espionage requires knowledge of the investigation file. Only once the available evidence is clear can we decide whether a statement is advisable or whether remaining silent is the better strategy.

Possible discontinuation of proceedings

Not every case ends in a trial. Depending on the evidence and any prior record, the proceedings may be discontinued for lack of sufficient suspicion (§ 170 II StPO), for triviality (§ 153 StPO) or subject to conditions (§ 153a StPO). Often a penalty order without a public trial can be achieved.

Victim-offender mediation and restitution

In many cases, victim-offender mediation or making good the damage (§ 46a StGB) can significantly reduce the sentence or enable a discontinuation. Whether this is advisable in your case is something we assess based on the file.

What we do after reviewing the file

We examine the evidence for reliability and admissibility, look for procedural errors, develop the defense strategy, seek a dismissal of the proceedings through discussions with the public prosecutor’s office and represent you, if necessary, at trial before the Bonn Local Court or Bonn Regional Court.

Available 24/7: +49 228 504 463 36

This information does not replace a review of the individual case. In criminal proceedings, the defense strategy depends substantially on the case file, the specific allegation and the evidence.

Why choose BAFTEH Criminal Defense?

  • Direct contact with your defense attorney – no intermediaries
  • Available around the clock, including nights and weekends
  • Fast file inspection and a clear defense strategy
  • Focused exclusively on criminal law
  • Defense in Bonn, Cologne and the entire region
Attorney Philip Bafteh

Written by attorney Philip Bafteh, criminal defense attorney in Bonn. Philip Bafteh publishes regularly on criminal and commercial law and defends accused persons in investigative and trial proceedings.

More about the attorney →

Last updated: July 2026

Free Initial Assessment

Have you received a summons or are you under investigation? Call us – the initial assessment by phone is free for up to 10 minutes.

+49 228 504 463 36