Section 10(2) of the Cybercrime Code Act 2016 is the aggravated form of data espionage.
Section 10(2)
Where the offence under subsection (1) is committed against State secrets or Military secrets, or sensitive data, the offender is guilty of a crime.
Penalty: (a) in the case of a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 30 years, or both; and (b) in the case of a body corporate, a fine not exceeding K1,000,000.
| s 10(1) | s 10(2) | |
|---|---|---|
| Imprisonment | Up to 30 years — unchanged | |
| Fine — natural person | Up to K100,000 — unchanged | |
| Fine — body corporate | Up to K500,000 | Up to K1,000,000 |
| Extra element | — | State secrets, Military secrets, or sensitive data |
Everywhere else in the Act, an aggravated subsection raises the individual sentence. Section 6(2) triples it; section 7(2) raises 15 years to 25; section 9(2) raises 10 to 25; section 27(2) raises 15 to 25.
Section 10(2) does not. The individual penalty is identical to subsection (1), and only the corporate fine changes.
The explanation is that subsection (1) already carries the longest term of years in the Act. There was nowhere further to go short of life imprisonment, which the Act reserves for grooming a child under 16 and for bullying or harassment resulting in death.
For an individual, then, section 10(2) is significant not for the maximum but as an aggravating factor within a 30-year range — and for the label the conviction carries.
State secrets, Military secrets, or sensitive data
Any data or content, in any form, that is (a) potentially detrimental or damaging to the person who is its subject; (b) classified or intended for restricted use or specified persons only; or (c) data relating to the State, politics and the military, or corporate secrets, or otherwise not available to the public.
State secrets and Military secrets are not defined, and would carry their ordinary meanings. But the third alternative — sensitive data — is defined very widely.
Because paragraph (a) of that definition covers personal data potentially detrimental to its subject, and paragraph (c) covers corporate secrets and anything otherwise not available to the public, most espionage against protected data will engage subsection (2).
Stealing a company’s customer database, its pricing model, or its employees’ personnel files is espionage against sensitive data. So the aggravated offence is not confined to national security at all.
The same definition drives section 7(2), section 25 and section 24(2)(b).
The corporate dimension
Section 10(2) is aimed at organised, resourced espionage — the kind conducted by or for an entity rather than an individual acting alone. Doubling the corporate maximum to K1,000,000 puts it level with the most serious offences in the Act.
Remember that “body corporate” in section 2 means a company whether incorporated or unincorporated, and includes government or public bodies, as well as terrorist groups or organisations. A State agency that engages in data espionage against sensitive data is exposed to the K1,000,000 fine.
And note the words in subsection (1) carried into (2): whether for his own use or for the use of another person. A company that obtains protected data for a client, or an individual who obtains it for an employer, is within the offence.
Section 10(2) among the information offences
| Provision | The wrong | Individual / corporate maximum |
|---|---|---|
| s 7(2) | Intercepting a transmission of State, Military or sensitive data | 25 years, K100,000 / K1,000,000 |
| s 10(2) | Obtaining State or Military secrets or sensitive data | 30 years, K100,000 / K1,000,000 |
| s 25(1) | Disclosing confidential or classified communication or sensitive data | 15 years, K20,000 / K100,000 |
| s 25(2) | The same, by a person with lawful authority, custody, access or control | 25 years, K100,000 / K500,000 |
| s 24(2)(b) | Threatening to expose sensitive data to procure gain | 25 years, K100,000 / K1,000,000 |
An operation that intercepts a transmission, obtains protected data from it, then threatens to publish unless paid, and finally publishes, commits offences under sections 7(2), 10(2), 24(2)(b) and 25 — besides section 6 for the access and, if malicious software was used, section 27.
Note that section 25(3) provides a defence to unlawful disclosure — that the disclosure was for the benefit of the public — and section 25(4) makes that a question of fact. There is no equivalent defence in section 10. Obtaining the data is an offence whatever the motive for obtaining it.
Neither subsection of section 10 is listed in Schedule 2, so neither can be dealt with summarily.
Sources
- Cybercrime Code Act 2016 — ss 2, 6, 7, 9, 10, 24, 25, 27, 48; Schedule 2
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.