The 2026 cybercrime amendments broaden criminal exposure around unauthorized access and mishandled data. Even well-meaning businesses can find themselves on the wrong side of the line.
The key changes
The definition of unauthorized access now more clearly covers exceeding permitted use — for example, an employee pulling records they were never meant to touch.
Penalties escalate where sensitive personal data is involved, and organizations can face liability for failing to take reasonable security measures.
Reducing your exposure
Limit access to sensitive systems on a need-to-know basis and revoke it promptly when roles change or people leave.
Have an incident-response plan ready before you need it. How you respond in the first hours often shapes both liability and reputation.
Need legal support on this topic?
Every situation is different. Speak with an attorney about yours — your first consultation is free.