HomeCybercrimeData and system offences

What if Interception Targets State or Sensitive Data?

The maximum rises from 15 years to 25, the individual fine from K50,000 to K100,000, and the corporate fine from K500,000 to K1,000,000. The trigger is that the transmission is a State or Military one, or carries other sensitive data.

The cybercrime series, no. 12 · Attacks on data and systems · 5 min read

Section 7(2) of the Cybercrime Code Act 2016 is the aggravated form of illegal interception.

Section 7(2)

Section 7(2)

Where the offence under subsection (1) is committed against State or Military transmissions, or transmissions of other sensitive data, the offender is guilty of a crime.

Penalty: (a) in the case of a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 25 years, or both; and (b) in the case of a body corporate, a fine not exceeding K1,000,000.

Section 7(1) compared with section 7(2)
s 7(1)s 7(2)
ImprisonmentUp to 15 yearsUp to 25 years
Fine — natural personUp to K50,000Up to K100,000
Fine — body corporateUp to K500,000Up to K1,000,000
Extra elementState or Military transmission, or other sensitive data

The definition that does the work

Section 2 — “sensitive data”

Any data or content, whether in writing, images, audio, visual, audiovisual or in any other form

(a) that is potentially detrimental or damaging to the person who is the subject of such information or personal data; or

(b) data that is classified or intended for restricted use or specified persons only; or

(c) data relating to the State, politics and the military, or corporate secrets, or data that is otherwise not available to the public.

This definition is far wider than “State secrets”

Paragraph (a) covers personal data potentially detrimental or damaging to its subject — medical records, financial details, information about a person’s relationships or conduct. That is ordinary personal information, not government material.

Paragraph (b) covers anything intended for restricted use or specified persons only — internal company documents, confidential correspondence, restricted-circulation reports.

Paragraph (c) covers corporate secrets and, in its closing words, data otherwise not available to the public — which on its face reaches almost any non-public data.

The practical consequence is that most interception will engage section 7(2) rather than section 7(1), because most non-public communications carry data that falls within one of the three paragraphs.

Compare the parallel aggravating provision

Section 10(2) aggravates data espionage where the offence is committed against State secrets or Military secrets, or sensitive data — but the maximum imprisonment there is 30 years for both the basic and the aggravated form, and only the corporate fine rises, from K500,000 to K1,000,000.

So the drafting pattern differs between the two sections. In section 7 the aggravation raises the individual sentence; in section 10 it does not.

“State or Military transmissions”

A separate limb

The subsection names State or Military transmissions before adding transmissions of other sensitive data. The word “other” indicates that State and Military transmissions are themselves treated as sensitive.

So a prosecution has two routes: prove the transmission was a State or Military one, or prove it carried sensitive data within the section 2 definition. The first requires no enquiry into content.

Note that “body corporate” in section 2 includes government or public bodies. A public body that intercepts State transmissions without lawful excuse is exposed to the K1,000,000 corporate fine.

Where section 7(2) sits

Offences involving sensitive data or critical infrastructure
ProvisionTriggerMaximum for a natural person
s 7(2)Interception of State, Military or sensitive data transmissions25 years / K100,000
s 10(2)Espionage against State or Military secrets, or sensitive data30 years / K100,000
s 25(1)Disclosing confidential or classified communication, or sensitive data15 years / K20,000
s 25(2)The same, by a person with lawful authority, custody, access or control25 years / K100,000
s 24(2)(b)Threatening to expose sensitive data to procure gain25 years / K100,000
s 9(2)System interference with critical infrastructure25 years / K100,000, plus K25,000 per day
s 27(2)Cyber attack on critical infrastructure25 years / K100,000, plus ICT prohibition
Two practical points

For investigators and prosecutors. Establishing that the intercepted transmission carried sensitive data is usually straightforward given the width of the definition — but the content of the transmission must be proved, which may itself require lawful access under Part IV.

For anyone conducting monitoring. Because paragraph (a) covers personal data potentially detrimental to its subject, unauthorised interception of ordinary employee or customer communications is capable of being the aggravated offence, not the basic one. That is a 25-year maximum for an individual and a K1,000,000 fine for the company.

The safe course is a court order under section 39, or a clear lawful basis and consent — kept strictly within its terms, since acting in excess of a lawful excuse is expressly within the offence.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.