Almost every offence in the Cybercrime Code Act 2016 is built from defined terms. Reading the offence without the definitions gives a misleadingly narrow impression of its reach.
The technology definitions
“Computer” — an electronic, magnetic, optical, electrochemical, or other data processing device, or a group of such interconnected or related devices, performing logical, arithmetic, storage and display functions, and including any data storage or communications facility directly related to it — but not an automated typewriter or typesetter, or a non-programmable hand-held calculator or similar device with no data storage.
“Electronic system” — a system of hardware or software, or a group of interconnected or related systems or devices, one or more of which, under a program, performs automatic processing, generating, sending, receiving or storing of data — and includes electronic devices, the internet, and input, output and storage facilities.
“Device” — includes but is not limited to components (a computer, graphic card, mobile phone, memory chip), storage components (hard drive, memory card, compact disk, tape), input tools (keyboard, mouse, track pad, scanner, digital camera) and output tools (printer, monitor, screen).
“Network” — the interconnection, wired, wireless or both, of two or more electronic systems or data processing devices.
It appears in nearly every offence, and between the two definitions it captures a mobile phone, a laptop, a server, a router, a smart television, a memory card, a printer, a digital camera — and the internet itself.
Note the explicit inclusion of the internet in the definition of electronic system. That is what allows the content offences in sections 17 to 26 to operate on posts, messages and websites rather than only on machines.
“Data” — any representation of facts, concepts, information (text, audio, video, audiovisual or images), machine readable code or instructions, in a form suitable for processing in an electronic system or device, including a program.
“Content” — information in any combination or form, including speech, music or other sounds, data, text, writing, signs, signals or images.
“Communication” — any communication of content, between persons, things, or persons and things, in any form.
“Data traffic” — electronic data relating to a communication, generated by a system in the chain, indicating the communication’s origin, destination, route, time, date, size, duration, or type of underlying service.
“Electronic output” — a statement or representation produced by, displayed on the screen of, or accurately translated from a computer or other electronic device.
The conduct definitions
“Interference” — tampering with the integrity of information content, electronic data or systems, and includes damaging, deletion, deterioration, alteration, suppression, modification (additions, omissions and substitutions), or hindering.
“Hinder” — any act interfering with the proper functioning of an electronic system or device, including cutting or disrupting the electricity supply to it.
“Interception” — tapping into an electronic communication not directed to the one who is tapping, for the purpose of acquiring, viewing or capturing it, by any means, during transmission, through a technical device.
“Hacking” — exploring programs or determining the limitations of a computer, system, device or network, for the purposes of gaining unauthorised access.
“Malicious software” — malware or software intended to damage or disable an electronic system or device.
“Hinder” expressly covers cutting the electricity supply. Physically pulling the power to a server room is system interference under section 9, not merely a property offence.
“Interception” is limited to communications during transmission and not directed to the interceptor. Reading a stored message already received is not interception — though it may be unauthorised access under section 6 or data espionage under section 10.
“Hacking” is defined by purpose — exploring or probing for the purposes of gaining unauthorised access. Probing a system to test it, with authority, is not hacking; and see the section 16(2) defence for authorised testing.
Sensitive data and critical infrastructure
“Sensitive data” — any data or content, in any form, that is (a) potentially detrimental or damaging to the person who is its subject; (b) classified or intended for restricted use or specified persons only; or (c) data relating to the State, politics and the military, or corporate secrets, or otherwise not available to the public.
“Critical infrastructure” — the basic facilities, services and installations needed for the functioning of a community, society or government, including but not limited to transportation, communication systems, water supply, electricity supply, banking services, and public institutions including health facilities, post offices and education facilities.
Both are aggravating definitions. Interception of sensitive data raises the maximum under section 7(2) from 15 to 25 years. System interference with critical infrastructure raises it under section 9(2) from 10 to 25 years, plus K25,000 for each subsequent day the infrastructure remains inoperable. And a cyber attack on critical infrastructure raises section 27 from 15 to 25 years.
Note how wide “critical infrastructure” is. It includes banking services, schools and post offices — so an attack on a bank’s systems, or a school’s, engages the aggravated provisions.
People, places and possession
“Person” — a natural person or body corporate. “Body corporate” — a company whether incorporated or unincorporated, and includes government or public bodies, as well as terrorist groups or organisations.
“Child” — a person under the age of 18 years.
“Criminally responsible”, “offence”, “possession” and “property” take their meanings from the Criminal Code Act (Chapter 262) — but “possession” is extended to include having under control in or on any website, whether or not another person has actual custody, and whether or not the thing is visible.
“Premises” — land, buildings, movable structures and any conveyance by land, water or air, or web hosting servers or websites.
“Private place” — a place other than a public place, including a house, building, vessel, craft or vehicle. “Public place” — a place to which the public have access as of right, whether or not on payment.
Possession includes control of material on a website. A person who controls content stored on a remote server possesses it for the purposes of the Act — even if they cannot see it and someone else has custody of the machine.
Premises include web hosting servers and websites. That feeds directly into section 32, which allows a warrant to search a private place — and into the search powers in section 33, which permit access to data not held at the private place.
The remaining definitions — ICT service, ICT service provider, network service, applications service, content service and their providers — are dealt with in the article on ICT service providers. The investigation terms — seize, remote forensic tool, utilise, thing and storage device — are dealt with with the Part IV powers. And pornography, spam and multiple electronic message are dealt with in the offences that use them.
Sources
- Cybercrime Code Act 2016 — ss 2, 6–11, 16, 27, 32, 33
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.