Hacking and cybercrime in the Netherlands: what the law prohibits

A man working at a computer displaying a glowing digital brain
Cybercrime in the Netherlands is not a separate statute but a set of offences in the Dutch Criminal Code (Wetboek van Strafrecht, Sr). The hacking laws in the Netherlands centre on article 138ab Sr, which makes it an offence to enter an automated system intentionally and unlawfully, and are completed by article 138b Sr on obstructing systems, articles 139c to 139e Sr on interception, and articles 350a to 350d Sr on damaging data. Alongside this criminal framework sits the Dutch Cybersecurity Act (Cyberbeveiligingswet), in force since 15 August 2026, which imposes security and reporting duties on organisations rather than penalties on individuals.

Which offences the Criminal Code defines

Cybercrime and hacking law in the Netherlands

Computer trespass under article 138ab Sr

The central offence is computervredebreuk, computer trespass. Article 138ab Sr punishes anyone who intentionally and unlawfully enters an automated system, in whole or in part, where entry is gained by breaking through a security measure, by a technical intervention, by false signals or a false key, or by assuming a false identity. Two elements do the work in practice. The act must be intentional, and it must be unlawful, meaning without a right derived from consent, contract or statute. Damage is not required: the offence is complete on entry, and the maximum sentence at that level is two years of imprisonment.The penalty rises where more happens. If the intruder subsequently copies or records data held in the system, the maximum becomes four years. The same maximum applies where entry was gained through a public telecommunications network and the offender used the processing capacity of the system or moved on to a further system. Where the offence is committed for the benefit of a foreign power, the maximum is increased by a third.

Obstructing a system under article 138b Sr

Denial-of-service attacks are covered by article 138b Sr, which punishes the intentional and unlawful transmission of data to an automated system where that obstructs access to it or its use. The basic maximum is two years. It becomes three years where a substantial number of systems is involved or where the offender intended to obtain an unlawful advantage, and five years where the act causes serious damage or is directed at a system that serves vital infrastructure. Terrorist intent raises the maximum further.

Interception under articles 139c to 139e Sr

Article 139c Sr prohibits intercepting or recording, by technical means, data that is not intended for the person concerned and that is processed or transmitted through telecommunications or an automated system. The maximum is two years. The article contains express exceptions: reception of radio signals without special effort, interception by the lawful holder of the connection unless it is clearly abusive, and interception carried out for the operation of a network, for criminal investigation or under the Intelligence and Security Services Act 2017.Article 139d Sr addresses preparation. It covers placing recording equipment with the intention of enabling unlawful interception, and it also covers making, acquiring, distributing or holding a technical device that is primarily designed for committing an offence under articles 138ab, 138b or 139c Sr, or holding passwords and access codes with that same intention. The maximum is two years and rises to four where the preparation relates to the aggravated forms of computer trespass. Article 139e Sr then punishes handling the results: possessing a data carrier with unlawfully intercepted data, disclosing such data or passing it on, with a maximum of six months.

Damaging data under articles 350a to 350d Sr

Where the attack destroys rather than reads, Title XXVII applies. Article 350a Sr punishes intentionally and unlawfully altering, deleting or rendering inaccessible data, with a maximum of two years, and raises the maximum to four years for making available or distributing data intended to cause damage in an automated system, which is the provision used for malware and ransomware. The article contains an express exception for a person who acted in order to limit the damage such data would cause. Article 350b Sr is the negligent variant, with a much lower maximum, and applies where serious damage results from careless conduct. Article 350c Sr covers destroying, damaging or disabling an automated system or telecommunications equipment and thereby obstructing the storage, processing or transfer of data. Article 350d Sr mirrors article 139d Sr on the preparatory side: producing, obtaining, selling or holding tools or access codes intended to enable an offence under articles 350a or 350c Sr. Unauthorised entry is punishable in itself under article 138ab Sr, whether or not any data is copied and whether or not damage follows.

Where the line runs between security research and computer trespass

Dutch law on ethical hacking and responsible disclosure Dutch law contains no general exemption for ethical hackers. Testing someone else systems is lawful because it is authorised, not because it is well intended. The decisive question under article 138ab Sr is whether the access was unlawful, and consent removes that element only as far as the consent reaches. A penetration test therefore needs a written assignment that identifies the systems and addresses in scope, the period, the techniques that are permitted and excluded, what happens to data that is encountered, and who is to be informed. Where the systems are hosted by a third party, that provider has to agree as well, because the client cannot consent on its behalf.Outside a commissioned test, the framework is coordinated vulnerability disclosure. Many Dutch organisations publish a policy setting out how a vulnerability may be reported and what they undertake in return, and the national cybersecurity authority has published guidance on such policies. A policy of this kind does not create immunity: prosecution remains legally possible, and the Public Prosecution Service (Openbaar Ministerie) assesses whether prosecution is opportune. In that assessment the factors that carry weight are whether the finder acted in the public interest, whether the intrusion went no further than necessary to demonstrate the weakness, whether data was copied, published or retained, and whether the report was made promptly and directly to the organisation concerned. A researcher who goes beyond those limits, or who attaches conditions to the report, moves from disclosure into the offences described above.The same reasoning applies to employees and former employees. Access rights end when the role ends, and continuing to use an old account or a colleague password is entry by means of a false key within the meaning of article 138ab Sr, even where the system was once used lawfully every day.

Fraud committed by digital means

Online fraud under Dutch criminal law Most digital cases that reach the police are not pure hacking cases but fraud carried out with digital means, and they are prosecuted under the ordinary fraud provisions. Phishing, invoice fraud and false webshops fall under article 326 Sr, which punishes obtaining property, a service or a debt by means of a false name, a false capacity, cunning or a web of untruths. Where identifying personal data of another person is used to mislead, article 231b Sr adds a separate offence. Moving the proceeds through accounts or crypto-assets brings in the money laundering provisions of articles 420bis to 420quater Sr, which is why people who lend out a bank account are prosecuted as well as those who organised the scheme. Publishing another person personal data in order to intimidate is a distinct offence under article 285d Sr, introduced at the beginning of 2024.Proving these cases is largely a matter of digital evidence: headers, logs, IP data, payment traces and the timeline in which they sit. What that means in practice for a victim who wants to be believed is set out in our article on online fraud and phishing.

What the Cybersecurity Act requires of organisations

Dutch Cybersecurity Act obligations for organisations The Dutch Cybersecurity Act (Cyberbeveiligingswet) has applied since 15 August 2026 and implements the European NIS2 directive. It works differently from the Criminal Code: it does not punish attackers but places duties on the organisations that are attacked. Entities that fall within its scope must register with the national cyber security authority, take appropriate technical and organisational measures to manage the risks to their network and information systems, and report significant incidents, with a first notification within 24 hours and a fuller report within 72 hours. Responsibility for the measures rests with the management of the entity, which is also expected to keep its knowledge up to date. Which organisations are covered, and what the duty of care means concretely, is worked out in our article on NIS2 and the Dutch Cybersecurity Act.These duties run alongside, and not instead of, the obligations under the General Data Protection Regulation. A cyber incident that involves personal data is a personal data breach, which must be reported to the Dutch Data Protection Authority within 72 hours unless it is unlikely to pose a risk, and communicated to the individuals concerned where the risk to them is high. The two reporting regimes have different triggers, different addressees and different deadlines, and an incident can easily trigger both at once. The civil side, including who bears the loss when a supplier or a service provider is the weak link, is discussed in our article on liability after a data breach.

Investigation powers and how a case proceeds

Since the third Computer Crime Act came into force in 2019, the police have far-reaching digital investigative powers. Investigators may, in the case of serious offences, gain remote access to an automated system in use by a suspect and, once inside, record data or make it inaccessible. That power is exercised by the public prosecutor only after authorisation by the investigating judge (rechter-commissaris), and its use has to be recorded so that the defence and the court can review it afterwards. A suspect can also be ordered to give access to encrypted material in defined circumstances, and devices can be seized and examined.Because the conduct and the effect are often in different countries, jurisdiction and cooperation matter as much as the substantive offence. The Netherlands is party to the Council of Europe Budapest Convention on Cybercrime, uses the European investigation order for evidence within the European Union, and works through Europol and its European Cybercrime Centre and through Eurojust when proceedings run in several member states at once, alongside cooperation with INTERPOL beyond the European Union. For the person under investigation the practical consequences are familiar ones: the right to remain silent, the right to consult and be assisted by a lawyer before and during questioning, and a case file that consists largely of technical material which needs to be tested rather than accepted.

What a victim can do

Report the incident. A police report (aangifte) is the basis on which an investigation can be opened, and our guide to filing a police report explains how that is done. Preserve the evidence before anything is reinstalled: log files, the affected systems, e-mail headers, payment references and a timeline of what was noticed and when. Notify the bank immediately where payments were diverted, because a fast recall request is often the only chance of recovering money, and inform the Data Protection Authority if personal data was involved.Criminal proceedings and compensation are separate tracks that can be combined. A victim may join the criminal proceedings as an injured party and claim damages there, which is efficient but only works for claims that do not unduly burden the criminal case. Larger or contested claims are brought in the civil courts on the basis of an unlawful act under article 6:162 of the Civil Code, and interim relief proceedings are available where material has to be taken offline quickly. The steps that matter in the first days after an attack are set out in our article for victims of cyberattacks.

How Law and More can help

Law & More advises and represents clients on both sides of these cases: organisations that have been attacked and need to secure evidence, meet their reporting duties and recover their loss, and individuals or companies who are suspects in a criminal investigation into computer trespass, data damage or online fraud. We also review penetration testing assignments and vulnerability disclosure policies before the work starts, which is the point at which most of the legal risk can still be removed. Our cybercrime lawyers can be reached through the contact details on this site.

Cybercrime and hacking laws

What counts as cybercrime under Dutch law?

Cybercrime means any criminal activity carried out through computers, networks, or the internet, including breaking into computer systems, stealing data, launching DDoS attacks, deploying ransomware, and committing online fraud, all detailed in the Criminal Code.

What does Dutch hacking law actually prohibit?

Under Article 138ab of the Criminal Code, it is illegal to intentionally break into computer systems, whether by bypassing security measures, using fake credentials, or exploiting software glitches.

What are the business consequences of a data breach in the Netherlands?

Beyond immediate financial losses, businesses often face extra costs for fixing issues, notifying customers, and handling legal risks, along with reduced customer trust, potential reputational damage, and possible fines under laws like the GDPR.

Are cybercrime offences treated as minor issues under Dutch law?

No, these offences are taken very seriously and are treated as real criminal activity with serious legal consequences, not just minor technical violations.

Need Legal Assistance?

Contact Law & More for expert guidance on your legal matters. Our multilingual team is ready to help.

Related articles

An IT services agreement is the contract under which a provider delivers technology services to

Challenging a judge in the Netherlands is called wraking: a party asks for a judge

An ordered index of every guide we have written on Criminal law in the Netherlands.

For a foreign national in the Netherlands, a criminal case has two outcomes, not one:

Violating Russia sanctions is a criminal offence in the Netherlands. Breaches of the EU restrictive

Need to tell the police about theft, fraud, or a lost passport in the Netherlands?

Stay Updated on Dutch Law

Subscribe to our newsletter for the latest legal insights, regulatory updates, and practical advice.