Article 3 of Saudi Anti-Cyber Crime Law addresses five categories of cyber offenses involving the protection of data, privacy, reputation, and websites. These include unlawful interception of transmitted data, unauthorized access connected with threats or blackmail, unlawful interference with websites, invasion of privacy, and defamation or harm caused through information technology.
However, not every online dispute automatically falls within Article 3. The legal classification depends on the conduct itself, the technology used, the purpose of the act, and the available evidence. Understanding the scope of the provision is therefore important before filing a report, particularly where there is an existing complaint, summons, investigation, or criminal case.
Quick Answer: What Does Article 3 of Saudi Anti-Cyber Crime Law Cover?
Article 3 criminalizes five specific forms of cyber conduct. The maximum penalty is imprisonment for up to one year and a fine of up to SAR 500,000, or either of those penalties.
These limits apply specifically to the offenses covered by Article 3. They are not a uniform penalty for every cybercrime committed in Saudi Arabia.
If you are dealing with an actual incident, the first question is not simply how severe the penalty may be. The key issue is whether the conduct in question falls within one of the five offenses covered by Article 3 of Saudi Anti-Cyber Crime Law.
If you are the affected party, preserve the incident details and available evidence before reporting it. If a complaint or summons has already been issued against you, first identify the alleged offense and the current procedural stage before responding.
BMS Legal’s cybercrime team can review a summary of the matter and identify the next legal step without requiring sensitive information during the initial contact.

What Does Article 3 of Saudi Anti-Cyber Crime Law Provide?
Article 3 covers five different offenses, each of which requires a particular element to be established before the applicable penalty can be considered. Interception relates to data transmitted through an information network or computer, while blackmail under this provision is linked to unauthorized access followed by a threat or coercive conduct.
The provision also addresses unauthorized interference with websites, including certain forms of alteration, damage, modification, or occupation of a website address. It further covers invasion of privacy through misuse of camera-equipped devices and defamation or harm caused through information technology.
| Offense | Key Element |
|---|---|
| Interception or capture of data | Accessing or intercepting transmitted data without lawful justification |
| Unauthorized access for threats or blackmail | Unauthorized access connected with threatening or blackmailing another person |
| Interference with websites | Unauthorized access, alteration, damage, modification, or occupation of a website address |
| Invasion of privacy | Misuse of recording or camera-equipped devices in a manner affecting privacy |
| Defamation and harm | Using information technology to defame or cause harm to others |
Cyber offenses in Saudi Arabia are not limited to these five categories. Understanding the broader types of cybercrime in Saudi Arabia helps distinguish Article 3 offenses from conduct regulated separately under other provisions of the law.
Which Offenses Fall Under Article 3?
The offenses covered by Article 3 range from interception and unauthorized access to threats, blackmail, privacy violations, and electronic defamation. Each category must be considered according to its own legal elements and the facts of the incident.
Interception, Capture, or Access to Transmitted Data
The first category concerns intercepting, capturing, or accessing data transmitted through an information network or computer without a valid legal justification.
When assessing such conduct, it is important to identify how access occurred, when it occurred, and which devices, accounts, or systems were involved. Merely viewing electronic content does not automatically establish this offense. The method of access, the person’s authority, any existing permission, and the surrounding circumstances all affect the legal classification.
Unauthorized Access for Threats or Blackmail
Article 3 also criminalizes unauthorized access when it is used to threaten or blackmail another person into performing an act or refraining from an act. The provision applies even where the requested act or omission would otherwise be lawful.
The relevant issue is therefore not limited to what the offender demanded. The manner in which access occurred, the nature of the threat, and the evidence establishing the conduct must also be examined. The applicable blackmail penalty in Saudi Arabia depends on the legal characterization of the incident and the conduct established by the evidence.
Unauthorized Access to a Website
Article 3 covers unauthorized access to a website and certain forms of access intended to alter its design, damage it, modify it, or occupy its address.
In these cases, access logs, permission records, hosting information, and evidence of changes made to the website may become particularly important. It is also necessary to distinguish unauthorized access from a commercial or employment dispute involving an employee, contractor, or service provider who originally possessed legitimate access rights.
Invasion of Privacy
The provision also addresses invasion of privacy through misuse of mobile phones equipped with cameras or comparable devices.
This does not mean that every photograph taken without consent automatically constitutes a completed Article 3 offense. The location, nature of the material, method of use, and extent to which the conduct interfered with a person’s private life must be assessed.
If the material is later used for threats, blackmail, or defamation, additional legal issues may arise depending on the facts.
Defamation and Causing Harm to Others
Article 3 includes defaming others and causing them harm through information technology.
Not every online disagreement, negative comment, or critical statement automatically amounts to criminal defamation. The content, context, manner of publication, audience, and resulting harm must be examined before determining the appropriate legal characterization.
The penalty for online defamation in Saudi Arabia should therefore be considered in light of the actual publication, its context, and the evidence of harm.
What Is the Penalty Under Article 3?
The maximum Article 3 cybercrime penalty in Saudi Arabia is imprisonment for up to one year and a fine of up to SAR 500,000, or either of these penalties.
The expression “up to” is important. One year of imprisonment and SAR 500,000 represent the statutory maximum limits rather than a fixed sentence automatically imposed in every case.
The criminal fine should also not be confused with a separate claim for compensation arising from damage suffered by an affected person. Criminal punishment and compensation are distinct legal matters, and each depends on the circumstances and procedural position of the case.
Where a report, summons, or investigation is already pending, focusing solely on the maximum penalty may give an incomplete picture. A cybercrime lawyer in Jeddah can review the legal characterization, available evidence, and current procedural stage before the available options are assessed.
What Is Unauthorized Access Under Saudi Cybercrime Law?
Unauthorized access means intentionally entering a computer, website, information system, or information network without permission to do so. This concept appears in more than one category of offense under Article 3 of Saudi Anti-Cyber Crime Law.
Using another person’s account does not produce the same legal result in every situation. There may have been prior authorization, limited permission, or a dispute over the scope of access.
The relevant questions include who granted access, what permission was given, whether that permission remained valid, and what the person did during or after entering the account or system.
Merely knowing another person’s password does not make access lawful. The central issue is whether valid permission existed and whether the person remained within its permitted scope.
How Can an Article 3 Cybercrime Be Proved?
Cybercrime evidence does not depend on screenshots alone. Where possible, preserve the content itself, its context, the URL, account name, timestamps, original conversations, login notifications, and related digital records.
System logs, hosting records, or technical examination may also become important where the dispute concerns attribution of an account or the manner in which unauthorized access occurred.
Useful steps include:
- preserving the URL, username, and timestamps;
- retaining original conversations and files;
- avoiding alteration of images, recordings, or digital files;
- avoiding unnecessary republication of harmful content;
- retaining the report number and subsequent official communications.
A screenshot can be useful, but its evidential value may be stronger when it can be connected to the relevant account, time, URL, and full context. Such evidence may continue through the stages of a criminal case in Saudi Arabia depending on the outcome of the investigation and subsequent proceedings.
What Should You Do After an Article 3 Cybercrime Incident?
Begin by documenting the incident before confronting the other party or deleting messages and online content. Preserve the available records and use the official reporting channel appropriate to the nature of the incident.
The reporting process can vary depending on whether the matter concerns blackmail, defamation, unauthorized access, or another cyber offense. The steps for reporting cybercrime in Saudi Arabia explain the available reporting channels and how to preserve the relevant information before filing.
If a complaint, summons, or investigation already exists, arrange the facts and evidence chronologically. Avoid deleting data or providing a rushed legal characterization before understanding the subject of the proceedings and the stage the matter has reached.
When Does Article 3 Not Apply?
Article 3 is not a general provision covering every offense committed through the internet, a mobile phone, or a computer.
Some conduct may fall under other provisions of the Saudi Anti-Cyber Crime Law or under separate Saudi laws depending on the nature of the act, its purpose, and its consequences.
Fraud, damage to data, or other unlawful uses of technology should therefore not automatically be treated as Article 3 offenses. Similar technology can be involved in two incidents while the applicable legal characterization remains different.
Frequently Asked Questions About Article 3 of Saudi Anti-Cyber Crime Law
What is Article 3 of Saudi Anti-Cyber Crime Law?
It criminalizes five categories involving data interception, certain forms of unauthorized access, privacy violations, and defamation.
What does Article 3 of Saudi Anti-Cyber Crime Law provide?
It defines five offenses and allows imprisonment for up to one year, a fine up to SAR 500,000, or either penalty.
Which offenses are covered by Article 3?
They include interception of data, unauthorized access for threats or blackmail, website interference, invasion of privacy, and defamation.
What is the penalty under Article 3 of Saudi Anti-Cyber Crime Law?
The maximum penalty is one year of imprisonment and a SAR 500,000 fine, or either of these penalties.
When is accessing another person’s account considered unauthorized?
It depends on whether valid permission existed, its scope, and what occurred during or after the access.
When does electronic blackmail fall under Article 3?
It may apply where unauthorized access is used to threaten or blackmail someone into acting or refraining from an act.
What is the legal position on threatening to publish private images?
It may fall under Article 3 depending on how the images were obtained, the threat, and the surrounding evidence.
When can photographing someone amount to an invasion of privacy?
It may apply where the use of a camera or similar device interferes with the person’s private life.
How is online defamation related to Article 3?
Article 3 covers defaming others and causing them harm through information technology.
What evidence is important in a cybercrime case?
Useful evidence includes original content, URLs, account details, timestamps, messages, login alerts, and related records.
Article 3 of Saudi Anti-Cyber Crime Law: 5 Offenses is more than a summary title. It reflects five distinct forms of prohibited conduct, each requiring the facts, method, and available evidence to be examined before the applicable penalty can be assessed.
The presence of blackmail, defamation, unauthorized access, or a privacy issue does not by itself determine the final legal outcome. The conduct itself, the way it occurred, and the evidence supporting it remain central to the legal assessment.
Where the matter requires broader legal review or representation in ongoing proceedings, a Jeddah law firm such as BMS Legal can review the file and explain the available legal options based on the circumstances of the case.
Sources: