Cyber Defence, Cybercrime and Digital Criminal Law

Criminal defence of companies, their executives and individuals, whether victims or under investigation, in cybercrime matters: data breach, ransomware, crypto-asset fraud and online abuse.

Our approach

The firm acts at both stages of digital risk: preparation, before an incident occurs, and defence, once proceedings have been opened. What is decided and written in the first hours of a crisis determines what can be held against the company months later.

A personal data breach must be notified to the CNIL, the French data protection authority, within 72 hours of its discovery. That notification is a self-report: the company itself declares its own failure to an authority that holds the power to impose sanctions.

One feature governs these cases: the company is often both the victim and the party under investigation in the same proceedings. As a victim of the attack, it has an interest in filing a criminal complaint. As the party under investigation for failing to secure the data, it answers to the CNIL and, where applicable, to the criminal courts. Both positions are built at the same time.

Matters are handled in French and in English.

Areas of practice

In the event of a cyberattack on the company

Preparing for the crisis before it happens

Preparing for a cyber crisis is usually approached as a technical and regulatory exercise. It is also, and first of all, an exercise in building evidence.

The 72-hour framework. That notification is provided for by Article 33 GDPR. What is written in it may be examined by the CNIL and by the judicial authorities alike, and may engage the liability of the company or of its executives. The time limit runs from discovery, not from the attack.

Three decisions are taken in those hours, and they are prepared in advance. Who drafts the notification, on what template and with what reservations. Whether the individuals concerned must be informed individually (Article 34), which conditions the flow of complaints to come. And whether the company files a criminal complaint as a victim, unauthorised access to a system being an offence under Articles 323-1 et seq. of the French Criminal Code.

The composition of the crisis cell. A cell bringing together a chief information officer, a data protection officer and a communications director produces technical and regulatory documents without anyone assessing their criminal-law implications. The Article 33 notification is not a form: it is a legal act, and each of its formulations shapes what follows.

The scope of legal professional privilege. Article 66-5 of the Act of 31 December 1971 protects, in all matters and in advisory work as much as in litigation, a lawyer’s opinions, the correspondence exchanged with the client and the documents in the case file. The report of an incident-response provider does not benefit from it. Article 56-1-2 of the French Code of Criminal Procedure sets privilege aside for advisory work in relation to a limited list of offences, which covers tax fraud, corruption and terrorist financing, and which includes neither offences against automated data processing systems nor failure to secure personal data.

The crisis exercise. A simulation whose deliverable concerns not the responsiveness of the teams but the documents they produced, and what a criminal case file would make of them, reveals vulnerabilities that no compliance audit brings to light.

What the company and its executives face

Digital criminal law does not form a self-contained body of law: it draws on scattered offences whose combination determines jurisdiction, the investigative techniques available and the penalties incurred.

Offences against automated data processing systems. Fraudulent access to, or continued presence in, a system is punishable by three years’ imprisonment and a fine of 100,000 euros (Article 323-1 of the French Criminal Code). The penalty rises to five years and 150,000 euros where it results in the deletion or alteration of data, or in impairment of the operation of the system. It is raised to seven years and 300,000 euros where the system processes personal data and is operated by the State, since the Act of 24 January 2023.

Failure to secure personal data. Article 226-17 of the French Criminal Code punishes by five years’ imprisonment and a fine of 300,000 euros the processing of personal data without implementing the measures required by Articles 24, 25, 30 and 32 GDPR. The offence may target the legal entity, whose fine is multiplied by five under Article 131-38, that is 1,500,000 euros, as well as the individuals who committed the same acts.

The ransom. A demand for payment under threat of disclosure or of blocking falls within extortion (Article 312-1 of the French Criminal Code), concurrently with the offences against the system.

Fraud and identity theft. CEO fraud, fraudulent payment orders and phishing campaigns fall within fraud (Article 313-1 of the French Criminal Code), often aggravated by the organised-gang element. Identity theft, including on an online public communication network, is punishable by one year’s imprisonment and a fine of 15,000 euros (Article 226-4-1 of the French Criminal Code).

Crypto-assets. Misappropriation, laundering and seizure of digital tokens apply the ordinary law of offences against property and the special seizure regime, which this field tests more than it renews.

Read the analysis on the criminal liability of company directors.

The risk of criminal proceedings being opened

The investigation. Filing a complaint opens a preliminary investigation, most often conducted with the assistance of specialised services. It involves computer searches, seizures of media and of data, requisitions addressed to operators and hosting providers and, in organised crime cases, special investigative techniques.

The interview of the executive. The executive, the chief information officer or the head of security may be interviewed in two capacities: as representatives of the company that is the victim of the attack, and as persons who may have failed in the obligation to secure the data. The framework of the interview, whether as a witness, under free-status questioning or in police custody, determines the rights available, and the shift from one framework to another may occur in the course of the same proceedings.

The expert report. Classification depends on technical findings: point of entry, chronology of the intrusion, scope of the exfiltrated data, attribution. The court-appointed IT expert report becomes the central document in the file, and the discussion of its conclusions a defence issue in its own right.

The court seised. Depending on the scale and the organisation of the acts, the case remains with the territorial prosecution office, moves up to a specialised interregional court (JIRS), or falls to the national organised crime prosecutor (procureur de la Republique anti-criminalite organisee, in office since 5 January 2026) for organised cybercrime of very great complexity, which is the statutory criterion. The forum determines the resources deployed and the procedural regime that applies.

The interaction of the two sets of proceedings. The CNIL sanction procedure and the criminal proceedings run in parallel, on the same facts and often on the same documents. What is conceded before one resurfaces before the other.

Recent cases

Firm insights

Criminal law emergencies

Guaranteed call-back within one hour during business hours.

Switchboard: +33 1 55 27 93 93
Emergencies (mobile and WhatsApp): +33 6 42 29 81 44
Email: mehdy@kadri-avocat.com

Request an appointment