HomeCybercrimeService providers

Can a Provider Be Liable for an Employee?

Yes. Section 44(1)(e) makes it a crime for an ICT service provider to negligently allow an employee to commit an offence under paragraphs (a), (b), (c) or (d). It is the only negligence-based offence in the whole Act, and it carries the same 25-year maximum.

The cybercrime series, no. 87 · ICT service providers and co-operation · 5 min read

Section 44(1)(e) of the Cybercrime Code Act 2016 is unique. Every other offence in the Act requires intention, knowledge or recklessness. This one requires only negligence.

Section 44(1)(e)

Section 44(1)(e)

An ICT Service Provider which negligently allows an employee to commit an offence under Paragraph (a), (b), (c) or (d) is guilty of a crime.

Penalty: natural person — a fine up to K100,000 or imprisonment up to 25 years, or both; body corporate — a fine up to K1,000,000.

Negligence, at 25 years

The mental element is the lowest in the Act, and the penalty is among the highest. That combination has no parallel in the legislation.

Compare the opening words of every other offence: “intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, or recklessly”. Recklessness requires conscious advertence to a risk. Negligence does not.

What has to be proved

The elements of section 44(1)(e)
ElementWhat it requires
An ICT service providerWithin one of the seven Schedule 1 categories
An employeeThe offence must be committed by an employee — not a contractor, agent or customer
Who commits an offence under (a) to (d)Monitoring or facilitation, or obstruction or non-compliance
Negligently allowedA failure to take reasonable care to prevent it
“Allows”

The verb implies a failure to prevent something the provider had the capacity to prevent. It contemplates a provider that had control — over systems, access, supervision, training — and did not exercise it with reasonable care.

It does not extend to conduct the provider could not have prevented. An employee who deliberately circumvents proper controls presents a very different case from one who was never given any.

Which employee offences count

Only paragraphs (a) to (d)

Section 44(1)(e) is confined to offences under the earlier paragraphs of section 44(1). So the employee conduct that exposes the provider is:

  • (a) monitoring users’ information, or actively seeking evidence of their illegal activity;
  • (b) initiating or aiding in facilitating an action resulting in an offence under this Act or a contravention of any other law;
  • (c) concealing, preventing or frustrating an investigation or proceeding;
  • (d) failing to comply with a court order to assist law enforcement, or to terminate or prevent an action.

An employee who commits some other offence under the Act — hacking, unlawful disclosure, interception — does not engage paragraph (e). The provider’s exposure in that case is under the general principles of corporate criminal liability.

The paragraph (a) problem

Negligently allowing an employee to monitor

Paragraph (e) covers negligently allowing an employee to commit the paragraph (a) offence — monitoring the information the provider transmits or stores on behalf of users, or actively seeking evidence of illegal activity.

That is a striking obligation. It means a provider must take reasonable care to ensure its own staff do not look at customer data.

The practical measures follow directly:

  • Access controls limiting who can view customer content and traffic;
  • Logging of staff access to customer data;
  • A written policy stating what staff may and may not inspect, and on what authority;
  • Training that explains section 44 and its penalties;
  • Supervision and periodic review of access logs.

An organisation that has those measures, applies them, and can produce records of them, has the answer to a negligence allegation. One that permits unrestricted staff access to customer communications does not.

Answering a charge

  1. Show the system. Documented policies, access controls, training records and audit logs are the evidence of reasonable care.
  2. Show it operated. A policy nobody follows is not reasonable care. Records of monitoring compliance — access reviews, disciplinary action taken — matter.
  3. Show the employee circumvented it. Where the conduct required deliberate evasion of proper controls, the provider did not allow it.
  4. Address the specific paragraph. The charge must identify which of (a) to (d) the employee committed.
  5. Note the employee remains liable. The penalty structure provides separately for a natural person and a body corporate. Both may be charged.

See also what a business should do about cybercrime risk and section 45.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.