Section 44(1)(a) of the Cybercrime Code Act 2016 reverses what many people assume the law requires of a platform or a network.
Section 44(1)(a)
An ICT Service Provider which intentionally or knowingly, and without lawful excuse or justification or in excess of a lawful excuse or justification —
- monitors the information which they transmit or store on behalf of their users; or
- actively seeks facts or circumstances indicating illegal activity by their users,
is guilty of a crime. Penalty: natural person — K100,000 or 25 years, or both; body corporate — K1,000,000.
A provider that inspects everything it carries becomes the judge of what its users may say and do. The provision keeps carriers and hosts as conduits rather than censors, and protects the privacy of communications recognised by section 49 of the Constitution.
It also aligns with the structure of Part IV: access to user data is obtained through court orders, on stated grounds, for specified material — not by standing surveillance.
What makes monitoring lawful
Section 44(1)(a) applies only where the monitoring is done “without lawful excuse or justification or in excess of” one. Several sources of lawful excuse operate in ordinary practice:
- A court order. Section 39(a) orders a provider to collect or record specified communications; section 40 orders collection of traffic data; section 41(11) orders assistance with installation. Compliance is not merely excused — section 44(1)(d) makes non-compliance a crime.
- The user’s consent. Terms of service that clearly authorise particular processing supply a justification for that processing.
- Technical necessity. Network management, spam and malware filtering, capacity management and fault diagnosis all involve automated inspection. These are the ordinary and necessary operations of a service, and are justified as such.
- Regulatory obligation. Requirements imposed on a licensed operator by its own regulator.
Most providers will have some lawful excuse for some monitoring. The exposure lies in going beyond it.
Automated malware filtering is justified; a staff member reading a customer’s stored messages out of curiosity is not. Complying with a court order for specified communications is required; collecting more than the order specifies is in excess of the excuse.
Scope discipline — recorded, controlled and audited — is what keeps a provider on the right side of the line.
“Actively seeks facts or circumstances”
The first limb prohibits monitoring the information transmitted or stored. The second prohibits actively seeking facts or circumstances indicating illegal activity by users.
That reaches beyond content. Analysing usage patterns to identify probable wrongdoing, building detection systems aimed at user misconduct, or running investigations into customers all fall within the words.
The qualifier is “actively”. Information that comes to a provider without being sought — a complaint, an abuse report, a notice from a rights owner, an alert from an automated system operating for a legitimate technical purpose — is not actively sought.
That is the distinction on which a compliant abuse process rests: receive and act, do not go looking.
What to do once you know
| Stage | Position |
|---|---|
| Before notice | Do not monitor content; do not actively seek evidence of user wrongdoing — s 44(1)(a) |
| On notice | Record it. Do not destroy relevant material — s 44(1)(c) |
| On a preservation notice | Preserve the specified data — s 36; failure is an offence |
| On a court order | Comply within its terms — s 44(1)(d), 25 years for failure |
| Where confidentiality is stipulated | Do not tell the customer — s 45, 25 years |
The obligation extends to staff
Section 44(1)(e) makes it a crime for a provider to negligently allow an employee to commit the paragraph (a) offence. So a provider must take reasonable care that its own staff do not inspect customer data without authority — through access controls, logging, written policy, training and supervision.
That is the practical significance of section 44(1)(a) for most organisations: it is not primarily about corporate policy, but about who inside the organisation can see what, and whether anyone checks.
See also privacy protections in PNG cybercrime law and which businesses are ICT service providers.
Sources
- Cybercrime Code Act 2016 — ss 2, 35, 36, 39, 40, 41, 44, 45; Schedule 1
- Constitution — s 49
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.