HomeCybercrimePolice powers

What Happens if I Ignore a Preservation Notice?

Section 36(4) makes failure to comply an offence — a fine of up to K10,000 or 12 months’ imprisonment, or both, for an individual, and up to K100,000 for a body corporate. It is one of only two offences in Part IV.

The cybercrime series, no. 76 · Search, evidence and investigation · 5 min read

Section 36(4) of the Cybercrime Code Act 2016 gives the preservation notice its force.

Section 36(4)

Section 36(4)

A person who fails to comply with a request under Subsection (1) is guilty of an offence.

Penalty:

(a) natural person — a fine not exceeding K10,000 or imprisonment for a term not exceeding 12 months, or both;

(b) body corporate — a fine not exceeding K100,000.

The lightest penalties in the Act, alongside spam

Twelve months and K10,000 matches section 26 for the custodial term, and section 36(4) is one of only two provisions in the Act carrying a 12-month maximum.

Like section 26, it says simply “is guilty of an offence” without classifying it as a crime or a misdemeanour. Unlike section 26, it is not listed in Schedule 2. See crimes and misdemeanours.

“A request under Subsection (1)”

The drafting

Subsection (1) speaks of a written notice that requires preservation. Subsection (4) calls it a request.

The inconsistency is immaterial. Subsection (4) identifies what it penalises by cross-reference — “under Subsection (1)” — and subsection (1) creates a requirement, not an invitation. A person served with a written notice under section 36(1) is obliged to comply.

Two conditions must nonetheless be satisfied before the obligation arises:

  • The notice must be in writing; and
  • It must specify the data to be preserved.

An oral request, or a notice that does not specify the data, does not engage subsection (4).

What compliance requires

What a preservation notice does and does not require
RequiredNot required
Keep the specified data intactHand it over — that needs a production order
Suspend automatic deletion and log rotation for itPreserve data outside the notice
Prevent alteration of itExamine or interpret it
Maintain it for the period specified, up to 14 daysPreserve it indefinitely
Continue if a Magistrate extends under s 36(2)Tell police what it contains
The practical risk is automation

Most failures to comply will not be deliberate. Systems delete data on schedule: message logs rotate, backups age out, deleted accounts are purged, CCTV overwrites.

An organisation that receives a notice must therefore act at the technical level — identify where the specified data lives, and suspend every process that would remove or alter it. A written instruction to staff is not enough if a scheduled job runs on day three.

The corollary is that an organisation should know, in advance, how to place a hold on its own data. That is a routine part of managing cybercrime risk.

Deliberate destruction is worse

Section 36(4) is not the only exposure

A person who deliberately destroys data after receiving a notice risks considerably more than 12 months:

  • Section 8 — data interference: damaging, deteriorating, deleting or altering data. Ten years or K20,000.
  • Section 44(1)(c) — for an ICT service provider, knowingly undertaking or omitting an act thereby concealing, preventing or frustrating criminal investigations or proceedings. Twenty-five years, or K1,000,000 for a body corporate.
  • The Criminal Code Act (Chapter 262) offences relating to interference with the course of justice.

A court may also make a restraining order under section 38 where it is satisfied that material is likely to be removed, destroyed, deleted or tampered with.

If compliance is impossible

  1. Say so immediately, in writing. Where the data was already deleted before the notice arrived, record when and why, and tell the officer.
  2. Preserve what does exist. Partial preservation is better than none, and demonstrates good faith.
  3. Preserve the evidence of deletion. Retention policy documents and system logs showing an automated process explain what happened.
  4. Ask for clarification if the notice is unclear. The obligation attaches to specified data; if the specification is ambiguous, ask.
  5. Watch the extension. The obligation may be extended once, by 14 days, on application made within the initial 14 days.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.