The Cybercrime Code Act 2016 plainly contemplates corporate offenders. The mechanism by which a company commits an offence, however, has to be found elsewhere.
Where the Act says so
“Penalty: (a) In the case of a natural person … ; and (b) In the case of a body corporate, a fine not exceeding K…”
This appears in almost every offence provision in Part III. The exceptions are section 6, section 22, and sections 23(1) to (3). See corporate fines for the full table.
How a company commits an offence
Nothing in the Cybercrime Code Act says when the acts of a director, officer or employee are to be treated as the acts of the company. There is no provision deeming an officer liable, and no due diligence defence.
The gap is filled by section 3(1), which applies the Criminal Code Act (Chapter 262) provisions on criminal practice and procedure, jurisdiction and punishments to this Act — and by the general law.
At common law, a company is criminally liable for an offence requiring a mental element where the person who committed the act was the directing mind and will of the company in the relevant respect — typically the board, a managing director, or a person to whom the relevant function has been delegated.
Applied to the Act, that means asking:
- Who did the act? The conduct element — the deployment, the disclosure, the publication.
- Were they the company’s directing mind in that respect? A junior employee acting on their own account is usually not.
- Was the required mental element present in that person? Intention or recklessness, and the absence of lawful excuse.
A company will therefore most often be exposed where the conduct was authorised, directed or knowingly permitted at a senior level — the decision to run unlicensed software, to send deceptive bulk messages, to publish material, to disclose confidential data.
Other routes to corporate exposure
| Route | Basis | Where it bites |
|---|---|---|
| Principal offender | Identification principle | Conduct authorised or directed at a senior level |
| Party to the offence | Criminal Code provisions on parties, applied by s 3(1) | Aiding, enabling or counselling another’s offence |
| “Authorise, facilitate or enable” | Express words of the offence | s 23(4), s 28 |
| Provider liability | s 44 | An ICT service provider with knowledge and control, or ignoring an order |
| Operator duties | s 14 | A gaming or lottery operator permitting a child to participate |
An ICT service provider — and Schedule 1 defines that widely — is dealt with by section 44, which sets out the circumstances in which a provider is criminally liable for what passes through its service, and by implication when it is not.
A business that hosts content, carries traffic, or provides access should work from section 44 rather than from the general law, and should read it with Schedule 1.
The individuals remain liable
Where a company is convicted, the individuals who did the acts remain personally liable for the same offence — and it is they, not the company, who face imprisonment and an ICT prohibition.
The penalty structure makes this plain: paragraph (a) provides for a natural person, paragraph (b) for a body corporate. Both may be charged for the same conduct.
Directors should also keep in mind their duties under the Companies Act 1997 — in particular the duties directors owe and the standard of care required of them. Permitting the company to run a system that commits offences engages both.
Reducing the exposure
- Written authorisations. Almost every offence turns on acting “without lawful excuse or justification, or in excess of” one. Documented authority for what staff may access, send and publish is the practical defence.
- Access control. Limits who can commit an insider disclosure under section 25(2).
- Licence records. Answers a charge under section 28.
- Moderation. Addresses section 23(4) and section 21 exposure on company pages.
- An incident procedure. Preserving evidence, reporting, and responding to production orders and preservation notices is itself a legal obligation once one is served.
See also what a business should do about cybercrime risk.
Sources
- Cybercrime Code Act 2016 — ss 3, 6–31, 35, 36, 44; Schedule 1
- Criminal Code Act (Chapter 262); Companies Act 1997
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.