
Misuse of other people’s data through computer systems in Bolivia: context, legislation and a proposal for reform
Cybercrime has risen significantly in Bolivia in recent years, reflecting a global trend in which cybercrime grows alongside digitalisation. According to the United Nations, more than three quarters of cybercrime worldwide is reportedly linked to organised crime.
Bolivia is experiencing an increase in offences such as digital identity impersonation and the unauthorised use of personal data across electronic platforms. This growth is taking place against a backdrop of structural weaknesses: Bolivia ranks 79th worldwide, and last in Latin America, in preparedness for cybersecurity threats, highlighting the country’s vulnerability to these emerging offences.
The proliferation of digital scams, online banking fraud, unauthorised access to personal accounts and other cybercrimes in Bolivia has caused financial losses, infringements of privacy and risks to public safety. Widespread internet and social media use, combined with limited public awareness of basic cybersecurity precautions, has created opportunities for criminals to exploit technology. Underreporting compounds this problem. Experts identify victims’ embarrassment, distrust of the justice system and lack of digital security awareness as three principal reasons why many cybercrimes go unreported in Bolivia. These factors have allowed numerous incidents to go unpunished, encouraging repeat offending.
Against this background, it is essential to place the growth of cybercrime in Bolivia in context and critically examine the legal response. This article presents recent national statistics, analyses Bolivian legislation—including the unsuccessful criminal law reform of 2017—compares neighbouring countries’ legal frameworks and considers expert views on existing shortcomings. It then proposes a specific criminal offence addressing the misuse of other people’s data through computer systems, as one element of a broader programme of legal reform.
Recent cybercrime statistics in Bolivia
The scale of the problem is reflected in statistics compiled up to 2025. In 2023, the Observatorio de Delitos Informáticos de Bolivia (ODIB) recorded 3,768 cybercrime cases nationwide. The figures indicate a substantial increase over previous years: digital scams reportedly rose by 43% in the first half of 2023 compared with the same period in 2022. Common offences include computer-related fraud, online threats and grooming (online sexual harassment). La Paz, Santa Cruz and Cochabamba account for the highest incidence, consistent with their greater economic activity and use of technology.
Particular concerns include identity impersonation and the misuse of personal or financial data. Police have investigated messaging account takeovers, including WhatsApp accounts, in which offenders impersonate victims and use convincing pretexts to ask their contacts to transfer money to bank accounts. This form of WhatsApp fraud has become recurrent and is difficult to prosecute under traditional criminal offences. Increasing numbers of fake Facebook, TikTok and Instagram profiles are also reported, created to defame, defraud or damage the reputations of public figures and private individuals. These acts involve the unlawful use of another person’s name, photographs or personal information to commit offences ranging from financial fraud to infringements of reputation or privacy.
Official data and independent studies present a concerning picture. Women account for 54.7% of cybercrime victims in Bolivia and are particularly vulnerable to online fraud and personal extortion. People aged 16 to 35 are the most affected age group, reflecting their greater use of social media and digital platforms. High-profile incidents have also exposed weaknesses in data protection. In 2024, for example, reports of the alleged sale on underground forums of a database containing personal information about 12.5 million Bolivians raised concerns about information held by public and private entities.
Overall, statistics up to 2025 show a growing wave of cybercrime in Bolivia, with digital identity impersonation and unauthorised use of personal data among the most prominent forms. This development has outpaced the existing legal framework, creating a gap between criminal activity and the legal tools available to address it. The following sections examine how Bolivian legislation has sought—and at times failed—to respond.
Bolivia’s current legal framework on cybercrime
The Criminal Code and its scope
Bolivia does not have a dedicated cybercrime statute. Instead, its Criminal Code, originally enacted in 1972 and subsequently amended, contains only two offences specifically addressing this subject. Law No. 1768 of 1997 introduced Chapter XI, “Computer-related offences”, which provides for:
Article 363 bis: computer manipulation. This provision penalises anyone who, intending to obtain an improper benefit, manipulates the processing or transfer of computer data, producing an incorrect result that harms a third party and leads to an undue transfer of assets. In essence, it criminalises computer-related fraud through the alteration of data or software: an offence analogous to traditional fraud but committed digitally. The prescribed penalty is one to five years’ imprisonment and a fine.
Article 363 ter: alteration, access and misuse of computer data. This provision penalises the unauthorised acquisition, access, use, modification, deletion or rendering unusable of data stored on a computer or computer medium, where this harms the information holder. It covers unlawful access to systems or databases and unauthorised use of another person’s digital information. The penalty is considerably lighter than under Article 363 bis: up to one year of community service or a fine of up to 200 day-fines. This suggests that, in 1997, the legislature regarded such conduct as less serious, involving harm to computer-related assets without a direct financial transfer.
Other Bolivian legislation touches on related matters. Telecommunications Law No. 164 of 2011 regulates aspects of digital signatures, electronic commerce and data communications, while Law No. 3325 of 2006 addressed child pornography in digital environments. Neither, however, creates new offences specifically directed at computer-related conduct beyond adapting traditional offences to the internet, as in the case of child pornography.
Bolivia’s criminal law framework therefore remains highly limited in its response to cybercrime. Articles 363 bis and 363 ter, adopted more than two decades ago, have been criticised as overly traditional and insufficiently adapted to the country’s social and technological realities. Their wording is regarded as general and unclear. For example, Article 363 ter addresses unauthorised use of another person’s data causing harm, but does not expressly establish whether this includes social media impersonation or the takeover of digital profiles. Such ambiguity raises concerns under the requirements of legal certainty and precise definition of criminal conduct.
In recent Bolivian judicial practice, digital identity impersonation has often had to be fitted into traditional offences, with unsatisfactory results. When an offender takes over a Facebook or WhatsApp account and deceives the victim’s contacts into sending money, prosecutors seek to charge ordinary fraud. Yet the manipulation of the account and the impersonation used to commit the fraud do not always correspond neatly to that offence’s constituent elements. Similarly, fake profiles used to defame someone may lead to proceedings for offences against reputation or a constitutional action for protection of privacy. These mechanisms do not, however, address the distinctive features of anonymous dissemination on digital platforms. Gaps in the law thus hinder the precise classification of new unlawful conduct and can leave it unpunished. This situation prompted the reform efforts discussed below.
An unsuccessful reform: the Criminal Justice System Code (Law No. 1005) and its repeal
Recognising the need to modernise the legislation, Bolivia enacted Law No. 1005, the Criminal Justice System Code, on 15 December 2017, intended to replace the 1972 Criminal Code in full. The new code, due to take effect after an 18-month vacatio legis, included a dedicated title on cybercrime and adapted numerous offences to the digital age. It never entered into force. Strong opposition from the public and sectors including doctors, transport operators and the press led the Government to promote its repeal. Law No. 1027 of 25 January 2018 repealed it in its entirety before its entry into force, leaving the earlier Criminal Code and its brief Articles 363 bis and 363 ter in place.
Law No. 1005 represented a missed opportunity to modernise the definition of digital offences. Section IV, addressing computer-related offences, included violations of personal data, electronic fraud and computer-related forgery, among other conduct, bringing the framework closer to international approaches to criminal harm. Although it was never applied, it demonstrated the legislature’s intention to update criminal law. Its abrupt repeal left Bolivia with an outdated framework lacking specific offences for phenomena such as digital identity impersonation, phishing and non-consensual disclosure of private data.
Bolivian criminal legislation is consequently widely regarded as insufficient to address cybercrime. In 2019, Bolivia’s delegation to the United Nations itself acknowledged a legal gap arising from the inability of existing laws to address new technology-enabled offences, underscoring the need for review and reform. This contrasts with developments elsewhere in Latin America, where specific cybercrime laws have been adopted. The experiences of Peru, Colombia and Argentina are particularly instructive.
Comparison with the legal frameworks of Peru, Colombia and Argentina
Legal responses to digital identity impersonation and unlawful data use vary across the region. While Bolivia still lacks an express offence covering these forms of conduct, neighbouring countries have amended their criminal codes or enacted special legislation to address them more directly.
Peru. Law No. 30096, the Cybercrime Law, adopted in 2013, defines a range of offences in detail. Of particular relevance is digital identity impersonation under Article 9, which penalises impersonation of a natural or legal person through digital technology where harm results. The prescribed sentence is three to five years’ imprisonment, increasing to six to nine years where the victim is a minor. Peru expressly treats online impersonation as an offence separate from traditional fraud, facilitating prosecution of fake social media profiles, fraudulent emails and similar conduct. Its legislation also addresses unlawful system access, data tampering and trafficking in personal information, with penalties reflecting the seriousness of the conduct and resulting harm. These reforms place Peru at the forefront of regional criminal law protection against digital identity impersonation.
Colombia. Law No. 1273 of 2009 amended the Criminal Code to introduce a chapter on computer-related offences. Although Colombia does not define an identity impersonation offence in precisely the same terms as Peru, several provisions address equivalent conduct. Article 269F penalises obtaining, supplying, using or modifying personal data held in databases without authorisation and for profit or a third party’s benefit. Article 269I addresses theft by computer-related means, expressly covering the circumvention of security measures or impersonation of a user to take another person’s assets. This encompasses cases involving misuse of someone else’s credentials to commit theft and, in practice, many instances of fraud through digital impersonation. Colombia also penalises unauthorised system access (Article 269A), interception of data (269B), computer-related damage (269D), the introduction of malware (269E) and the creation of fraudulent websites or phishing (269G). The framework protects data confidentiality and digital identity while addressing common attack methods, with penalties generally ranging from four to eight years’ imprisonment. Colombia, like Peru, supplements its legislation with an active cybersecurity policy and has acceded to the Budapest Convention on Cybercrime, facilitating international cooperation.
Argentina. Law No. 26.388 of 2008 amended the Criminal Code to incorporate computer-related offences in line with the Budapest Convention. The reform criminalised unauthorised access to computer systems through Article 153 bis, computer-related damage or sabotage under Article 183(6), interception of electronic communications and various forms of computer fraud. It also penalised unauthorised acquisition and disclosure of confidential data and the impersonation of websites to capture information, conduct comparable to phishing. Although Argentina does not expressly define a “digital identity” offence, its framework allows online impersonation to be pursued through offences involving false representations in documents, computer-enabled fraud or use of another person’s digital document. The traditional civil identity offence under Article 138, concerning the assumption of a false civil status or identity, could apply to certain instances of digital identity theft, alongside the newer computer-related offences. Argentina has also increased penalties where computer-related offences affect public services or involve minors, including severe penalties for online distribution of child pornography. Nevertheless, Argentine lawyers identify continuing gaps as new attacks emerge, prompting proposals to update the Criminal Code and increase some penalties. Argentina therefore has a more robust framework than Bolivia, but one that continues to evolve.
This comparison shows that Bolivia lags behind in defining cybercrime offences. Peru directly criminalises digital identity impersonation, while Colombia and Argentina have legal mechanisms to address misuse of data and cyberfraud. Bolivia relies on general offences with limited scope. Specialists have also noted that Bolivia is not a party to the Budapest Convention on Cybercrime (2001), unlike Peru, limiting opportunities for international cooperation in investigating cross-border offences. International experts have highlighted shortcomings in Bolivia’s definition and regulation of cybercrime and called for legislation that responds to technological change, social needs and legal certainty.
The following section considers the views of Bolivian and international legal experts on the weaknesses of the existing framework and possible improvements, providing a basis for the proposed reform.
Weaknesses in Bolivia’s criminal law framework and expert proposals for improvement
Legal experts identify serious shortcomings in Bolivia’s response to cybercrime. National specialists emphasise the outdated nature and narrow scope of existing offences, while international experts highlight the gap between Bolivia’s framework and global standards. Key concerns include:
Insufficient coverage and the absence of expressly defined offences. Bolivia has only two computer-related offences in its Criminal Code, Articles 363 bis and 363 ter. In a 2021 assessment, Fundación Construir noted that many unlawful digital acts fall outside defined criminal offences, preventing their individual legal classification and contributing to a high level of unreported and unpunished crime. Conduct not expressly criminalised cannot be punished without breaching the principle of legality: nullum crimen, nulla poena sine lege. This creates practical obstacles to prosecuting phishing, hacking, social media profile takeovers, electronic extortion and other conduct beyond the scope of traditional offences.
Evidential and enforcement difficulties. Bolivian legal practitioners, including the firm Rigoberto Paredes & Asociados, point to underreporting and difficulties identifying offenders, in addition to gaps in the definition of offences. Victims often do not report incidents because of fear or lack of awareness. Cases reaching court may be dismissed for insufficient evidence or because the perpetrators cannot be identified, given the anonymity available online and the frequent location of servers abroad. A lack of robust digital investigation protocols within the police and prosecution service compounds these challenges. Peruvian lawyer Erick Iriarte has stressed Bolivia’s need to modernise its technical capabilities and join international agreements: cross-border cooperation is essential to locating digital evidence and identifying offenders.
Outdated legislation and the requirement of precise criminal definitions. Criminal law scholarship stresses that legislation must keep pace with social and technological developments. In Bolivia, the gap is evident. Professor V. C. Arequipa Rejas argues that Bolivia’s computer-related offences are so broadly worded that they fail to meet criminal law’s requirement of precision, creating legal uncertainty. She highlights the need for criminal provisions to satisfy the principles of specificity, certainty and statutory authority. International experts share these concerns. The Organization of American States (OAS) has urged countries with outdated frameworks to follow Budapest Convention guidelines and clearly define offences such as unlawful access, computer sabotage, digital fraud and misuse of personal data. Bolivia has not implemented those recommendations to date.
Recent legislative initiatives and criticism. Isolated bills have sought to address aspects of digital crime, sometimes controversially. In 2023, legislators proposed Bill No. 304 to regulate and penalise misuse of social media. It contemplated new offences such as falsification of digital data and trafficking in personal data, with sentences of five to seven years for creating false identities or hacking social media accounts in a way that damaged another person’s image or reputation. Civil society and the press strongly criticised the proposal as a threat to freedom of expression rather than an effective response to cybercrime. Consideration of the bill was ultimately suspended. The episode illustrates the absence of consensus and a comprehensive technical approach: proposals tend to emerge reactively, sometimes with political undertones, rather than as part of a coherent cybersecurity and data protection policy.
Experts therefore agree that Bolivia urgently needs comprehensive cybercrime law reform. It should close gaps by clearly defining currently unpunished digital offences, equip justice officials with better procedural tools for obtaining electronic evidence, and align domestic law with international standards, including through accession to the Budapest Convention and participation in regional cybersecurity initiatives.
The following proposal addresses one particularly significant gap: misuse of other people’s data through computer systems, encompassing digital identity impersonation and other unlawful exploitation of third parties’ personal data on electronic platforms.
Proposed criminal offence: misuse of other people’s data through computer systems
In light of the preceding analysis, this article proposes adding a clearly defined offence to Bolivia’s Criminal Code. Drawing on identified needs and comparative legislation, the suggested wording is:
Misuse of Other People’s Data through Computer Systems. Any person who, without authorisation and with the intention of obtaining an improper benefit or harming the victim’s image or dignity, uses another party’s confidential data or information—whether personal, institutional or financial—stored on computer or electronic media, or impersonates another person through digital means, thereby causing harm to the information holder or a third party, shall be liable to imprisonment for two (2) to four (4) years, together with monetary compensation for the harm caused. Where the victim is a child or adolescent, the penalty shall increase to three (3) to six (6) years’ imprisonment, together with monetary compensation.
The proposed offence addresses two common purposes observed in Bolivian criminal practice: obtaining unlawful financial benefits through impersonation—for example, securing transfers, loans, goods or access rights—and harming a person’s reputation, honour or personality rights through false identities or profiles, such as disseminating false or intimate material while impersonating them. By expressly covering both unauthorised use of confidential data and digital identity impersonation, the provision addresses common scenarios that do not currently fit precisely within an existing offence.
The proposed penalty of two to four years, rising to three to six years where the victim is a minor, is intended to be proportionate. It is more severe than the current penalty for simple unauthorised access under Article 363 ter, which provides only for community service or a fine, without exceeding the seriousness of major property offences. Mandatory monetary compensation would also redress material and non-material harm suffered by victims, complementing the criminal penalty.
The wording draws on elements of foreign legislation that have proved effective. The requirement of harm to the victim is taken from Peruvian law, focusing criminal liability on conduct that actually injures protected interests, whether property, privacy or reputation. The express reference to impersonation through electronic or digital means covers both account theft and fictitious profiles, similarly to Colombia’s concept of impersonating a user. The higher penalty where the victim is a minor reflects children’s and adolescents’ particular vulnerability online and the comparative trend towards stronger protection, exemplified by Peru.
A clearer and more detailed offence would allow conduct that currently goes unpunished, or is forced into ill-suited categories, to be classified appropriately and prosecuted more effectively. The WhatsApp fraud described above, for example, would fall within the use of another person’s data for financial gain through digital impersonation, satisfying the proposed offence’s elements. Likewise, creating a false profile to humiliate someone would fall within harming the victim’s dignity through digital impersonation, addressing reputational harm that traditional offences do not adequately cover.
The proposal would fill a critical gap in Bolivia’s Criminal Code, providing a suitable means to investigate and punish identity-based digital fraud as well as impersonation that causes non-financial harm. It is, however, only one part of the necessary reform. Effective implementation would also require specialised digital investigation training for prosecutors and police, public cybersecurity awareness campaigns and international cooperation to pursue offenders operating abroad.
Conclusions: the urgent need for comprehensive legal reform in Bolivia
The preceding analysis demonstrates the urgent need to reform Bolivia’s criminal law framework to address misuse of other people’s data through computer systems and cybercrime more broadly. Bolivia lags behind both the sophistication of everyday criminal activity and legislative advances in neighbouring countries. This gap undermines the protection of fundamental interests: property affected by electronic fraud; privacy compromised by data breaches and impersonation; and reputation and personal safety harmed by online defamation or harassment.
Recent statistics confirm an upward trend in cybercrime, exposing the population to growing risks without adequate legal safeguards. Legislation based on provisions drafted more than twenty years ago is poorly suited to offences involving emerging technologies. Reliance on computer manipulation and misuse of data under Articles 363 bis and 363 ter is insufficient and outdated. The resulting gaps raise concerns under the principles of legality and specificity, as conduct that does not fit existing offences may invite expansive interpretations with inadequate safeguards or remain unpunished. As Arequipa Rejas and other legal scholars emphasise, criminal law must adapt to social and technological changes to provide protection and resolve modern disputes.
The experiences of Peru, Colombia and Argentina demonstrate that updating criminal law to address specific cybercrimes through clear definitions and proportionate penalties is both possible and necessary. Bolivia can learn from these experiences while avoiding their shortcomings. Reform must not become a means of censorship or infringe fundamental rights, as critics feared in relation to the 2023 social media bill. It should protect people effectively from digital abuse while respecting freedoms such as freedom of expression. Technical expertise in legislative drafting and transparent public debate are essential.
The proposed offence is a concrete step towards closing one of the Criminal Code’s most notable gaps by expressly addressing digital identity impersonation and unlawful exploitation of personal data. A comprehensive reform should also review other computer-related offences, including unauthorised intrusion or access, cyberharassment, digital extortion and interference with critical computer systems. It should update procedural rules for obtaining electronic evidence and strengthen international investigative cooperation. Bolivia should seriously consider accession to the Budapest Convention, which would provide a framework for mutual legal assistance in cybercrime matters.
Rapid technological development and the proliferation of cybercrime present an unavoidable challenge to Bolivia’s criminal justice system. Continued legislative inaction leaves victims unprotected and signals impunity to potential offenders. A modern cybercrime framework would strengthen the rule of law in the digital sphere, safeguard fundamental rights online and support a safer, more reliable environment for the country’s economic and social development. As the Observatorio de Delitos Informáticos emphasises, only a comprehensive and collaborative approach combining updated legislation, technical capabilities and public awareness can mitigate these offences’ impact and uphold the rule of law in the digital age.
References
- Bolivian Criminal Code (Decree-Law No. 10426 of 1972, as amended by Law No. 1768/1997), Articles 363 bis and 363 ter.
- Law No. 1005 (2017), Bolivia’s Criminal Justice System Code, repealed by Law No. 1027/2018.
- Observatorio de Delitos Informáticos de Bolivia, Report on Cybercrime in Bolivia 2023.
- Arequipa Rejas, V. C. (2023). “La modificación del Código Penal boliviano en la incorporación de nuevos delitos informáticos”. Juris Studia, 1(2), 83–100.
- Rigoberto Paredes & Asociados (2022). “¿Qué son los delitos cibernéticos? ¿Existe legislación en Bolivia?”.
- Peru, Law No. 30096 (2013) on Cybercrime, Article 9 (digital identity impersonation).
- Colombia, Criminal Code, Articles 269F (violation of personal data) and 269I (theft by computer-related means through impersonation).
- El Diario (2 June 2024). “Tres causas por las que no se denuncian ciberdelitos”, interview with E. Iriarte.
- Bill No. 304/2023 on misuse of social media, proposed text; consideration suspended before approval.






















