Almost every offence in Part III of the Cybercrime Code Act 2016 states a distinct penalty “in the case of a body corporate”. The amounts are substantial.
The corporate fines, section by section
| Provision | Offence | Maximum fine |
|---|---|---|
| s 11 | Illegally remaining | K50,000 |
| s 23(4) | Vulgar or obscene commentary | K50,000 |
| s 8 | Data interference | K100,000 |
| s 9(1) | System interference | K100,000 |
| s 15 | Identity theft | K100,000 |
| s 16 | Illegal devices | K100,000 |
| s 17 | Pornography | K100,000 |
| s 20 | Animal pornography | K100,000 |
| s 25(1) | Unlawful disclosure | K100,000 |
| s 26 | Spam | K100,000 |
| s 7(1) | Illegal interception | K500,000 |
| s 10(1) | Data espionage | K500,000 |
| s 19(1) | Child online grooming | K500,000 |
| s 21(1) | Defamatory publication | K500,000 |
| s 24(1) | Cyber extortion | K500,000 |
| s 25(2) | Insider unlawful disclosure | K500,000 |
| s 27(1) | Cyber attack | K500,000 |
| s 31 | Unlawful advertising | K500,000 |
| s 7(2) | Interception of state or sensitive data | K1,000,000 |
| s 10(2) | Data espionage — state secrets | K1,000,000 |
| s 12 | Electronic fraud | K1,000,000 |
| s 13 | Electronic forgery | K1,000,000 |
| s 14 | Electronic gambling — operator | K1,000,000 |
| s 18 | Child pornography | K1,000,000 |
| s 21 | Aggravated defamatory publication | K1,000,000 |
| s 24(2) | Online blackmail | K1,000,000 |
| s 27(2) | Cyber attack on critical infrastructure | K1,000,000 |
| s 28, s 29, s 30 | Online IP infringement | K1,000,000 |
| s 9(2) | System interference — critical infrastructure | K1,000,000 plus K25,000 per day |
The daily penalty under section 9(2)
Section 9(2) provides for a fine not exceeding K1,000,000 and K25,000 for each subsequent day the critical infrastructure remains inoperable.
Nothing else in the Act works this way. Every other penalty is a single maximum fixed at sentence.
The rationale is that the harm from disabling critical infrastructure is continuous: a power system, a payment system or a hospital network that stays down causes fresh loss every day. The daily component ties the penalty to the duration of the outage.
The exposure is open-ended. A month of inoperability adds K750,000 to the maximum; a year would add more than K9 million.
Offences with no corporate penalty
Section 6 (unauthorised access or hacking) states penalties of imprisonment or a fine, without a separate corporate provision.
Section 22 (cyber bullying) and section 23(1) to (3) (cyber harassment) state penalties for child offenders and adult offenders only. Only section 23(4) reaches a body corporate.
That does not necessarily mean a company cannot be convicted — see whether a company can be guilty of a cybercrime, and section 3, which applies the punishment provisions of the Criminal Code Act (Chapter 262). But the Act supplies no tailored penalty for those offences.
What this means for a business
- The exposure is real and large. Twelve provisions carry a maximum of K1,000,000, and one is open-ended.
- Employee conduct is the usual route. A company will most often be exposed through what its officers and employees do — unlicensed software (s 28), a mishandled disclosure (s 25), deceptive bulk messaging (s 26), or an unmoderated page (s 23(4)).
- Providers have a separate regime. An ICT service provider is dealt with by section 44, which turns on knowledge, control and compliance with orders.
- Policy is the defence. Almost every offence turns on acting “without lawful excuse or justification, or in excess of” one. Written authorisations, access controls and a moderation policy are what establish the excuse.
See also how cybercrime penalties are structured and managing cybercrime risk.
Sources
- Cybercrime Code Act 2016 — ss 3, 6–31, 44
- Criminal Code Act (Chapter 262) — ss 18, 19
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.