Section 25(2) of the Cybercrime Code Act 2016 is the insider provision. It applies where the person who made the unlawful disclosure was entitled to have the material in the first place.
Section 25(2)
Where the offence is committed by a person with lawful authority, custody, access or control, in respect of such confidential or classified communication or sensitive data, the offender is guilty of a crime.
Penalty:
(a) natural person — a fine up to K100,000 or imprisonment up to 25 years, or both;
(b) body corporate — a fine up to K500,000.
| s 25(1) | s 25(2) | |
|---|---|---|
| Who | Any person | A person with lawful authority, custody, access or control |
| Imprisonment | Up to 15 years | Up to 25 years |
| Fine (natural person) | Up to K20,000 | Up to K100,000 |
| Fine (body corporate) | Up to K100,000 | Up to K500,000 |
| Public benefit defence | Available — s 25(3) applies to “an offence under this section” | |
| Triable summarily | Yes — s 25(1) is in Schedule 2 | No |
Four descriptions of an insider
The four words are cumulative in reach, not in requirement — any one of them is enough.
Lawful authority — the person is entitled to deal with the material. A manager, a records officer, an authorised signatory.
Custody — the person holds it. An IT administrator, a courier of physical media, a records clerk.
Access — the widest. Anyone with a login that reaches the material. An employee who can open the file has access to it.
Control — the person determines what is done with it. A system owner, a department head.
Taken together the four words reach almost every employee, contractor and officer who handles the information in the ordinary course of their work.
Why the penalty is heavier
An outsider who obtains confidential material must first commit some other offence to get it — hacking under section 6, interception under section 7, or data espionage under section 10.
An insider needs to commit none of those. The access was given to them. The organisation’s protection lies entirely in the trust placed in the person — and section 25(2) responds by increasing the maximum sentence by ten years and the fine fivefold.
The same logic runs through the Act. Section 11 covers the person who was lawfully in a system and stayed on; “in excess of a lawful excuse or justification” appears in the opening words of almost every offence, directed at the person who had permission and went beyond it.
The public benefit defence still applies
It is a defence to a charge for an offence under this section to prove that it was for the benefit of the public that the confidential or classified communication or sensitive data was disclosed. Whether it was is a question of fact — section 25(4).
A person who exposes wrongdoing from inside an organisation will, by definition, be a person with lawful authority, custody, access or control. So the charge will be under subsection (2), with its 25-year maximum — and the public benefit defence is the only answer the Act provides.
The burden of proof lies on the accused. That is a significant matter. The disclosure will already have been made, the employment relationship will already have ended, and the person must then establish public benefit on the balance of probabilities in a criminal trial.
Note that the defence is directed to whether the disclosure was for the benefit of the public — not to whether the underlying conduct disclosed was wrongful. Evidence of the wrongdoing will be central, but the question is about the disclosure.
For organisations
- Define what is confidential. The offence turns on the character of the material. A classification scheme and a written policy establish it, and equally establish what an employee may lawfully do with it.
- Grant access on need. Every person with access is a person within subsection (2).
- Record authorisations. The countervailing element is “without lawful excuse or justification”. A documented authorisation is the answer to a charge.
- Have an internal reporting channel. An organisation that provides a genuine route for raising wrongdoing internally reduces the likelihood of an external disclosure, and gives the employee an alternative to relying on section 25(3).
- Remember the corporate exposure. A body corporate faces up to K500,000. See corporate liability.
Related offences
An insider disclosure may engage several provisions at once. Section 10(1) covers obtaining protected data; section 10(2) deals with state secrets; section 24(2) applies where the disclosure or threatened disclosure is for gain; and section 8 covers alteration or deletion of the material. On charging practice generally, see how the Act fits with the Criminal Code.
Unlike subsection (1), section 25(2) is not listed in Schedule 2, so it must proceed on indictment. See summary trial.
Sources
- Cybercrime Code Act 2016 — ss 2, 6, 7, 8, 9, 11, 24, 25, 48; Schedule 2
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.