HomeCybercrimeService providers

Must a Provider Comply with a Court Order?

Yes. Section 44(1)(d) makes it a crime carrying 25 years for an ICT service provider not to comply with a court order requiring it to assist law enforcement or to terminate or prevent an action. Section 44(1)(c) separately criminalises concealing, preventing or frustrating an investigation.

The cybercrime series, no. 86 · ICT service providers and co-operation · 5 min read

Two of the five limbs of section 44(1) of the Cybercrime Code Act 2016 deal with a provider’s conduct once an investigation is under way.

Paragraph (c) — concealing or frustrating an investigation

Section 44(1)(c)

An ICT Service Provider which knowingly or upon knowledge of criminal investigations or proceedings, undertakes or omits to undertake an act, thereby concealing, preventing, or frustrating the criminal investigations or proceedings, is guilty of a crime.

Acts and omissions both

The words are “undertakes or omits to undertake an act”. Deleting logs is within the paragraph; so is failing to suspend an automatic deletion process that destroys them.

The trigger is knowledge of the investigation or proceeding. Before a provider knows, ordinary data retention practices carry no exposure under paragraph (c). Once it knows — through a preservation notice, a production order, or any other route — the position changes immediately.

Note the three verbs: concealing, preventing, frustrating. Frustration is the widest — conduct that makes the investigation harder, not only conduct that defeats it.

Paragraph (d) — non-compliance with a court order

Section 44(1)(d)

An ICT Service Provider which does not comply with an order by the Court requiring it to —

(i) assist law enforcement in the prevention, investigation or prosecution of an offence under this Act or any other law in force in Papua New Guinea; or

(ii) terminate or prevent a certain action which would result in the commission or continuation of an offence already committed under this Act or any other law,

is guilty of a crime.

Court orders that engage section 44(1)(d)
OrderWhat it requires of a provider
s 35(b)Produce information about subscribers or users
s 37Disclose traffic data identifying providers and path
s 38Refrain from removing, destroying or dealing with material
s 39(a)Collect or record, or permit or assist collection of, specified communications
s 40Collect or record traffic data, or assist police to do so
s 41(11)Assist with installation of forensic software or hardware
Twenty-five years for non-compliance

The penalty for section 44(1)(d) is the same as for every other limb: a natural person faces a fine up to K100,000 or imprisonment up to 25 years, or both; a body corporate faces a fine up to K1,000,000.

By comparison, ignoring a preservation notice under section 36(4) — a police notice, not a court order — carries 12 months and K10,000, or K100,000 for a body corporate.

The gap is deliberate. A court order carries the weight of the court behind it.

Sub-paragraph (ii) — termination and prevention

This is the takedown power

Sub-paragraph (ii) contemplates a court order requiring a provider to terminate or prevent an action — removing content, suspending an account, blocking a service — where continuing it would result in the commission or continuation of an offence.

It is the mechanism by which infringing material under section 28, counterfeit listings under section 29, defamatory publications, or child abuse material can be required to be taken down.

Note that the order must come from a Court. Section 44(1)(d) does not empower police or any agency to issue a takedown direction on their own authority; nor does it require a provider to act on a complainant’s demand. It attaches consequences to a court order.

Reconciling this with the monitoring offence

The knowledge point again

Section 44(1)(a) makes it an offence for a provider to monitor its users’ information or actively seek evidence of their illegal activity. Paragraphs (c) and (d) require the provider to act once an investigation exists.

The scheme is coherent: do not look on your own initiative; act decisively when told.

What that means operationally is that a provider should not build general surveillance, but must have a reliable process for receiving, escalating and acting on notices and orders — with records of what was received, when, and what was done.

Practical compliance

  1. Nominate a point of contact for law enforcement and keep it current.
  2. Log every notice and order on receipt, with the date and time.
  3. Place a hold immediately on the material identified, suspending automated deletion — this addresses paragraph (c).
  4. Comply within the terms of the order and record what was done — this addresses paragraph (d).
  5. Do not disclose the order where confidentiality is stipulated — section 45 makes that a separate crime carrying 25 years.
  6. Train and supervise staff. Section 44(1)(e) makes negligently allowing an employee to commit any of these offences a crime in itself.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.