Skip to content

Criminal Lawyers in Child Pornography Possession

Technical defence under Art. 189.5 CP. Demonstrating absence of intent and lack of storage will

Article 189.5 CP punishes mere possession of child pornography material for personal use with imprisonment of 3 months to 1 year, or a fine of 6 months to 2 years, penalties considerably lower than those for distribution (1 to 5 years) or the aggravated forms (5 to 9 years, Article 189.2 CP). The offence requires intent: knowledge and willingness to possess the file, an element that may be absent in automatic cache downloads or P2P network downloads. Accessing the content of a device requires a specific judicial warrant under Article 588 sexies a of the Spanish Criminal Procedure Act (LECrim). Our defence examines the digital forensic evidence on the download mechanism and the validity of the judicial authorisation for the search.

Child Pornography Possession: Art. 189.5 of the Criminal Code

The offence of possession of child pornography for personal use (Art. 189.5 CP) sanctions with 3 months to 1 year of prison or a fine of 6 months to 2 years those who acquire or possess pornographic material in whose elaboration minors or persons with disabilities have been used. The protected legal interest is the sexual indemnity of minors in its transversal dimension: the criminalization of mere demand for material seeks to close the chain of child sexual exploitation by reducing the economic incentive for its production. The provision, introduced by LO 15/2003 and reformed by LO 1/2015, complies with the Lanzarote Convention and Directive 2011/93/EU. Its elements are effective possession of the material, knowledge of its illicit nature and the will to possess it, which allows the defence to contest automatic downloads, browser cache files without deliberate conservation and files received involuntarily.

The commissive modalities and technical scenarios are diverse. Conscious and organised possession implies deliberate storage in personal folders, renaming files, organization by themes or labels; it constitutes the most clearly reproachable typical modality. Possession in cloud storage systems (Dropbox, Google Drive, OneDrive, MEGA) with automatic synchronization to personal devices equally integrates the type, but raises evidentiary questions about effective account ownership. Files in browser temporary cache (cookies, temporary files, thumbnails) raise jurisprudential debate: the defence argues that files found exclusively in cache, without organisation or deliberate storage, do not by themselves prove typical possession. Automatic unsolicited downloads through P2P programs, received in WhatsApp/Telegram groups, or introduced by third parties with device access, exclude intent when absence of knowledge is proven.

The penalties and accessory consequences, although less than in production or distribution modalities, are significant. The alternative principal penalty is 3 months to 1 year of prison or a fine of 6 months to 2 years. When the imposed sentence does not exceed 2 years and the accused has no prior records, Art. 80 CP allows sentence suspension avoiding actual imprisonment, although this does not exempt from accessory consequences. The mandatory registration in the Central Sex Offenders Registry (RD 1110/2015) for periods up to 30 years, the disqualification to work with minors in any sphere (education, pediatric healthcare, sports, entertainment, school transport), supervised release of 1 to 5 years where prison is imposed, which the court may waive for a single offence by a first-time offender (Art. 192.1 CP), and civil liability for moral damages are consequences to be anticipated. The forfeiture of electronic devices seized as instrument of the offence is ordered under Art. 127 CP.

Technical defence is built on four axes. First, the absence of intent in possession: the criminal type requires effective knowledge and will; when files come from automatic browser downloads, files stored in cache without deliberate conservation, unsolicited receipts in messaging groups, messages with automatic preview (WhatsApp, Telegram), or pop-ups during browsing, computer expert evidence can prove the absence of acquisition will. Second, the challenge of authorship attribution: in devices shared in households with multiple users, vulnerable or password-less wifi networks, unauthorized remote access, active malware that used the equipment without titular's knowledge, the in dubio pro reo principle operates when certain identification is not proven. Third, the challenge to the evidence due to chain of custody defects: absence of write blocker during initial cloning, discrepant hashes between original and copy, documentary defects in device traceability, undermine the reliability of the evidence and allow it to be challenged. Fourth, the nullity of home search or content examination: judicial authorization for home search does not automatically cover the examination of content of computers found (Art. 588 sexies a Criminal Procedure Act); content examination requires specific authorization.

In current forensic practice, possession investigations mostly arise from automatic provider alerts (Microsoft, Google, Meta, Apple) through technologies like PhotoDNA and Content Safety API, which are transmitted to NCMEC and Spanish national authorities (BIT-National Police, GDT-Civil Guard). International operations coordinated by Europol and Interpol generate massive proceedings with hundreds of simultaneous investigated persons. Organic Law 8/2021 on integral protection of childhood, the Budapest Convention on Cybercrime, Organic Law 1/2025 on Justice Service Efficiency and constitutional case-law on electronic evidence configure a demanding procedural scenario. At Alonso Sala, our criminal lawyers specialized in child pornography possession coordinate multidisciplinary teams with forensic computer experts performing exhaustive forensic audits, identifying cache files versus deliberately stored files, detecting active malware on download dates, examining user session attribution, and articulating technical defences that can determine acquittal, sentence suspension when Art. 80 CP circumstances concur, and minimization of impact on the defendant's professional trajectory and record.

Defence Strategies in Child Pornography Possession

Cache Files: Involuntary Download

Browser cache temporarily stores everything viewed online. If files were found exclusively in system temporary folders without deliberate organization, we defend the absence of voluntary storage act.

Automatic P2P Downloads

Programs like eMule or Torrent clients download fragmented files and share them automatically (seeding). The user may have searched for legal content and the program downloaded misleadingly named files. Forensic analysis demonstrating automatic downloads and default folders is the key defence evidence.

Vulnerable WiFi Network

If the router used WEP encryption (easily vulnerable), had no password, or had WPS enabled, anyone within range could have used the connection for illicit downloads. Network forensic analysis demonstrating vulnerability and absence of MAC records strengthens reasonable doubt.

Search Warrant Nullity

Entry and search requires a motivated judicial order. If the order doesn't specify devices, police exceeded authorization scope, or computer search was conducted without specific judicial authorization (different from home search warrant), the digital evidence obtained may be declared void (art. 11.1 LOPJ) and, without other independent incriminating evidence, acquittal follows.

KEY EVIDENCEDigital Evidence in Possession Cases

In possession crimes, digital evidence is everything. There are no witnesses, no victim testimony. Everything depends on what's found on the hard drive and how it was obtained.

HASH (SHA-256)

Police compare file hashes with international databases (ICSE/Interpol). A matching hash proves the file but not who downloaded it or when.

EXIF Metadata

Creation metadata (date, time, capture device) can indicate self-production or external origin. Absence of camera metadata points to download, not production.

System Logs

Windows Event Viewer logs, browser logs, and access history help reconstruct who was using the computer at the time of downloads.

Why Choose Us for Possession Defence?

Because the difference between conviction and acquittal isn't in the Criminal Code, but on the hard drive. Our team combines legal expertise with forensic computer experts who analyse every byte of seized evidence.

  • In-house computer experts with digital forensic analysis experience.
  • Defence strategy built from technical evidence, not just from law.
  • Systematic challenge of chain of custody in every proceeding.
  • Confidentiality and discreet case management.

Child Pornography in Spain: Complete Legal Defence Guide

Child pornography offences in Spain are governed by Art. 189 of the Criminal Code, with penalties ranging from 3 months (simple possession) to 9 years in prison (aggravated forms, Art. 189.2), or more with violence or intimidation (Art. 189.3). Online grooming is separately criminalized under Art. 183 CP. These crimes are investigated with specialized digital forensic tools and international cooperation through Europol, Interpol, and the ICSE database. Defence requires both deep legal knowledge and technical digital forensic expertise.

Penalty Table: Art. 189 CP & Related Offences

OffenceArticlePenalty
Production of child pornographic materialArt. 189.11 – 5 years
Distribution / disseminationArt. 189.1.b1 – 5 years
Aggravated (victim <16, organization, notorious importance)Art. 189.25 – 9 years
Facilitating minors' access to pornographyArt. 1866 months – 1 year or fine
Simple possession (personal use)Art. 189.53 months – 1 year or fine
Grooming (online contact with sexual purpose)Art. 1831 – 3 years or fine
Deceiving a minor into providing sexual materialArt. 183.26 months – 2 years

Critical Defence Strategies

Chain of Custody Challenge

If the seized device was handled without write blockers, stored without seal, or analysed without documented protocols, the entire digital evidence can be invalidated. This is the most powerful defence tool available.

Absence of Intent (Dolo)

Possession requires knowledge and will. Automatic P2P downloads, browser cache files, and malware infections can all store illicit material without user knowledge. Forensic analysis proving involuntary storage is essential.

IP ≠ Person Identification

An IP address identifies a connection, not a person. Vulnerable WiFi networks (WEP, no password, WPS enabled), shared routers, and VPN usage all prevent conclusive identification of the downloader.

Reclassification: Distribution → Possession

P2P programs share files automatically (seeding). If the user was unaware of this mechanism, distribution charges can be reclassified as simple possession, reducing the maximum penalty from 5 years to 1 year.

Key Defence Criteria

Defence argumentCache files do not prove intentional possession

Files found only in the browser cache, without being organised, renamed or deliberately stored in personal folders, may not prove the intentional possession required by Art. 189.5 CP: the prosecution must prove a voluntary act of storage.

Art. 588 sexies a LECrimSpecific judicial authorization for device search

Seizing a device during a home search does not by itself authorise access to its contents: the judicial decision must specifically justify that access, or it must be authorised afterwards (Art. 588 sexies a LECrim). Evidence obtained without that authorisation may be excluded (Art. 11.1 LOPJ).

Defence argumentP2P automatic sharing and distribution intent

Automatic seeding in P2P programs does not by itself prove the intent to distribute: if the accused was unaware of the sharing mechanism and has a low technical profile, the defence can argue for reclassification as possession.

The Digital Forensic Process

1

Seizure

Device sealed on-site with photographs and chain of custody document initiated.

2

Forensic Cloning

Bit-by-bit copy using write blocker. SHA-256 hash generated for original and clone comparison.

3

Hash Comparison

File hashes compared against ICSE (Interpol) and NCMEC databases to identify known illicit material.

4

Timeline Reconstruction

System logs, user sessions, and file metadata analysed to determine who, when, and how files arrived.

FAQ: Child Pornography Possession

Is possessing child pornography a crime even without sharing?
Yes. Art. 189.5 CP punishes mere possession of child pornographic material for personal use with 3 months to 1 year in prison, or a fine. Distribution is not required. However, the penalty is substantially lower than for distribution or production (1-5 years, and 5-9 with the aggravating factors of art. 189.2).
What if the files arrived on my device automatically?
The crime requires intent (knowledge and will). If files were automatically downloaded to the browser cache, arrived via WhatsApp group, or a P2P program downloaded them without your conscious intervention, defence can argue absence of intent. Forensic computer analysis proving involuntary download is the central evidence.
Does browser cache count as possession?
This is one of the most debated points. The defence argues that files found exclusively in browser cache, unorganised and without deliberate storage, do not by themselves prove intentional possession. However, if files were also found in organised folders or external storage devices, the cache argument weakens.
Do police need a warrant to search my computer?
Yes. Accessing device content requires a specific judicial order (Art. 588 sexies a LECrim). Authorization for home search does not automatically cover examining computer content. If police reviewed your computer without specific authorization, evidence may be void.
Can I avoid prison if I plead guilty?
If the sentence is 3 months to 1 year with no prior record, the sentence can be suspended. However, conviction still means Sex Offender Registry registration, disqualification from working with minors, and criminal records. If acquittal chances exist due to lack of intent, fighting the trial is preferable.
Can my partner be investigated for the same files?
Yes. When devices are seized in shared households, all inhabitants may be investigated. Key defence is determining who had access and habitual use of the specific device. User sessions, personal passwords, and creation metadata are decisive.
How long does such an investigation take?
Child pornography investigations tend to be very long. From provider alert to search can take 6-18 months. From device seizure to complete forensic analysis, another 6-12 months. Trial can take 2-4 years from initial report.
Can deleted files be recovered?
Yes. Police use specialized forensic tools (EnCase, FTK, Cellebrite) that can recover deleted files as long as they haven't been overwritten. Defence can question reliability of partial recoveries.
Could malware have downloaded files without my knowledge?
Yes. Trojans and malware exist that use infected computers to store and distribute illicit material without the user's knowledge. Forensic analysis can detect active malware present during download dates, strengthening the absence of intent defence.
Does using a VPN protect me from investigation?
Not necessarily. While VPN makes initial IP identification harder, once identified through other means, VPN usage can be interpreted as evidence of awareness of illegality. Many VPN providers also cooperate with authorities and hand over connection logs.
How is it determined whether the person in the material is a minor?
Age determination is done through forensic expert analysis (physical development, secondary sexual characteristics). If the victim cannot be identified, the forensic medical report on the image is the determining evidence. Defence can challenge the report if there are reasonable doubts about age.
Will my employer find out about the investigation?
Not necessarily. The pre-trial investigation is confidential (art. 301 LECrim) and the employer is not notified. However, if police search your office or seize professional devices, it may become known. Our firm manages procedural confidentiality as an absolute priority.
What are online 'sting' operations?
These are investigations where police infiltrate exchange platforms, identify IPs of users downloading material with known hashes, and request internet providers to identify the account holder. Defence verifies that judicial authorization covered the specific platform and that IP identification was correct.

Need urgent criminal defence?

Contact our specialist criminal defence lawyers. We evaluate your case confidentially.

This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.

Do you need specialised legal assistance?

The judicial system is complex. We have the criminal-law specialisation and technical resources required to take on the defence.