Section 44(1)(e) of the Cybercrime Code Act 2016 is unique. Every other offence in the Act requires intention, knowledge or recklessness. This one requires only negligence.
Section 44(1)(e)
An ICT Service Provider which negligently allows an employee to commit an offence under Paragraph (a), (b), (c) or (d) is guilty of a crime.
Penalty: natural person — a fine up to K100,000 or imprisonment up to 25 years, or both; body corporate — a fine up to K1,000,000.
The mental element is the lowest in the Act, and the penalty is among the highest. That combination has no parallel in the legislation.
Compare the opening words of every other offence: “intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, or recklessly”. Recklessness requires conscious advertence to a risk. Negligence does not.
What has to be proved
| Element | What it requires |
|---|---|
| An ICT service provider | Within one of the seven Schedule 1 categories |
| An employee | The offence must be committed by an employee — not a contractor, agent or customer |
| Who commits an offence under (a) to (d) | Monitoring or facilitation, or obstruction or non-compliance |
| Negligently allowed | A failure to take reasonable care to prevent it |
The verb implies a failure to prevent something the provider had the capacity to prevent. It contemplates a provider that had control — over systems, access, supervision, training — and did not exercise it with reasonable care.
It does not extend to conduct the provider could not have prevented. An employee who deliberately circumvents proper controls presents a very different case from one who was never given any.
Which employee offences count
Section 44(1)(e) is confined to offences under the earlier paragraphs of section 44(1). So the employee conduct that exposes the provider is:
- (a) monitoring users’ information, or actively seeking evidence of their illegal activity;
- (b) initiating or aiding in facilitating an action resulting in an offence under this Act or a contravention of any other law;
- (c) concealing, preventing or frustrating an investigation or proceeding;
- (d) failing to comply with a court order to assist law enforcement, or to terminate or prevent an action.
An employee who commits some other offence under the Act — hacking, unlawful disclosure, interception — does not engage paragraph (e). The provider’s exposure in that case is under the general principles of corporate criminal liability.
The paragraph (a) problem
Paragraph (e) covers negligently allowing an employee to commit the paragraph (a) offence — monitoring the information the provider transmits or stores on behalf of users, or actively seeking evidence of illegal activity.
That is a striking obligation. It means a provider must take reasonable care to ensure its own staff do not look at customer data.
The practical measures follow directly:
- Access controls limiting who can view customer content and traffic;
- Logging of staff access to customer data;
- A written policy stating what staff may and may not inspect, and on what authority;
- Training that explains section 44 and its penalties;
- Supervision and periodic review of access logs.
An organisation that has those measures, applies them, and can produce records of them, has the answer to a negligence allegation. One that permits unrestricted staff access to customer communications does not.
Answering a charge
- Show the system. Documented policies, access controls, training records and audit logs are the evidence of reasonable care.
- Show it operated. A policy nobody follows is not reasonable care. Records of monitoring compliance — access reviews, disciplinary action taken — matter.
- Show the employee circumvented it. Where the conduct required deliberate evasion of proper controls, the provider did not allow it.
- Address the specific paragraph. The charge must identify which of (a) to (d) the employee committed.
- Note the employee remains liable. The penalty structure provides separately for a natural person and a body corporate. Both may be charged.
See also what a business should do about cybercrime risk and section 45.
Sources
- Cybercrime Code Act 2016 — ss 2, 3, 6, 7, 25, 44, 45; Schedule 1
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.