Read any offence in Part III of the Cybercrime Code Act 2016 and the same words appear first. They repay attention.
The formula
“A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification [or recklessly] ...”
| Limb | What it covers |
|---|---|
| 1. Intentionally and without lawful excuse or justification | The straightforward case — deliberate conduct with no legal basis |
| 2. In excess of a lawful excuse or justification | The person has a legal basis, but goes beyond it |
| 3. Or recklessly (where included) | Conscious disregard of a substantial risk, without intending the result |
The second limb — exceeding an excuse
Most people who commit offences against data are not strangers breaking in. They are employees, contractors, administrators and officials who already have access and use it for something they were not permitted to do.
Without the second limb, such a person could say they had a lawful excuse — their job, their contract, their warrant — and that would be the end of it. The words “or in excess of a lawful excuse or justification” remove that answer.
Concrete examples:
- An employee with a valid login who opens records outside their role — section 6 and section 10.
- An administrator authorised to maintain one system who alters another — section 8.
- A person carrying out authorised maintenance who takes a service down outside the approved window — section 9.
- An officer acting beyond the terms of a court order — section 39 interception, or section 41 forensic tools, where section 41(9) allows the Court to revoke an order if police acted in excess of its terms.
- An ICT service provider going beyond what an order permits — section 44.
The practical lesson: having access is not the same as having permission, and permission has boundaries.
What counts as a lawful excuse or justification
There is no definition in section 2, so the phrase carries its ordinary meaning: some recognised legal basis for the conduct. In practice the sources are:
A court order. Part IV provides for orders authorising search, production, preservation, partial disclosure, restraint, interception, traffic data collection and remote forensic tools.
Statutory authority. Powers conferred by this or another Act — including the Search Act (Chapter 341), which section 33 supplements.
Consent or authorisation from the person entitled to give it. The system owner, the account holder, the data subject, an employer.
Contract or employment. The authority under which ordinary IT work is done.
Note that section 3(1) applies the general provisions of the Criminal Code Act (Chapter 262) on criminal responsibility to this Act, so the Code’s general defences also operate.
Which offences add recklessness
| Intention required | Recklessness suffices |
|---|---|
| s 6 unauthorised access | s 8 data interference |
| s 7 illegal interception | s 9 system interference |
| s 10 data espionage | s 11 illegally remaining |
| s 12 electronic fraud | s 20 animal pornography |
| s 13 electronic forgery | s 21 defamatory publication |
| s 15 identity theft | s 22 cyber bullying |
| s 16 illegal devices | s 23 cyber harassment |
| s 17 pornography | s 25 unlawful disclosure |
| s 18 child pornography | s 26 spam |
| s 19 child online grooming | ss 28–31 IP and advertising offences |
| s 24 cyber extortion; s 27 cyber attack | s 45 disclosure by a provider |
The offences requiring intention are those where the wrong lies in a deliberate purpose — deceiving, forging, obtaining secrets, exploiting a child, extorting, attacking.
The offences that include recklessness are those where serious harm can be caused without any purpose to cause it — damaging data, taking a system down, publishing defamatory material, harassing, disclosing confidential information, sending spam.
For anyone working with systems and data, the second column is the one to watch. It means that a genuine belief that no harm would result is not necessarily an answer: what matters is whether the risk was obvious and was consciously disregarded.
Other mental elements used in the Act
- “Knowingly” — section 14(2) (a gaming operator who knowingly or recklessly makes gaming available to a child); section 19(3) (knowingly receiving a benefit from grooming); section 21(3) (knowledge that the material is false); sections 28 to 30 (knowingly and repeatedly, or knowingly or repeatedly).
- “For the purpose of” — section 12 (deceiving or depriving another of property); section 13 (creating inauthentic data); section 16 (committing another Part III offence); sections 22 and 23 (bullying, harassing, causing emotional distress); section 24 (procuring a benefit).
- “Negligently” — section 44(1)(e), where a provider negligently allows an employee to commit one of the listed acts. This is the only use of negligence in the Act, and it is the lowest mental threshold in it.
Where a defence is expressly provided — section 17(2), section 18(3), section 21(5), section 16(2) and section 25(3) — the Act generally makes the underlying question a question of fact, and in one case, section 21(7), expressly shifts the burden of proof.
Sources
- Cybercrime Code Act 2016 — ss 2, 3, 6–31, 39, 41, 44, 45
- Criminal Code Act (Chapter 262)
The Search Act (Chapter 341) is cited without a link as it is not currently available on PacLII.
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.