Section 7(2) of the Cybercrime Code Act 2016 is the aggravated form of illegal interception.
Section 7(2)
Where the offence under subsection (1) is committed against State or Military transmissions, or transmissions of other sensitive data, the offender is guilty of a crime.
Penalty: (a) in the case of a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 25 years, or both; and (b) in the case of a body corporate, a fine not exceeding K1,000,000.
| s 7(1) | s 7(2) | |
|---|---|---|
| Imprisonment | Up to 15 years | Up to 25 years |
| Fine — natural person | Up to K50,000 | Up to K100,000 |
| Fine — body corporate | Up to K500,000 | Up to K1,000,000 |
| Extra element | — | State or Military transmission, or other sensitive data |
The definition that does the work
Any data or content, whether in writing, images, audio, visual, audiovisual or in any other form —
(a) that is potentially detrimental or damaging to the person who is the subject of such information or personal data; or
(b) data that is classified or intended for restricted use or specified persons only; or
(c) data relating to the State, politics and the military, or corporate secrets, or data that is otherwise not available to the public.
Paragraph (a) covers personal data potentially detrimental or damaging to its subject — medical records, financial details, information about a person’s relationships or conduct. That is ordinary personal information, not government material.
Paragraph (b) covers anything intended for restricted use or specified persons only — internal company documents, confidential correspondence, restricted-circulation reports.
Paragraph (c) covers corporate secrets and, in its closing words, data otherwise not available to the public — which on its face reaches almost any non-public data.
The practical consequence is that most interception will engage section 7(2) rather than section 7(1), because most non-public communications carry data that falls within one of the three paragraphs.
Section 10(2) aggravates data espionage where the offence is committed against State secrets or Military secrets, or sensitive data — but the maximum imprisonment there is 30 years for both the basic and the aggravated form, and only the corporate fine rises, from K500,000 to K1,000,000.
So the drafting pattern differs between the two sections. In section 7 the aggravation raises the individual sentence; in section 10 it does not.
“State or Military transmissions”
The subsection names State or Military transmissions before adding transmissions of other sensitive data. The word “other” indicates that State and Military transmissions are themselves treated as sensitive.
So a prosecution has two routes: prove the transmission was a State or Military one, or prove it carried sensitive data within the section 2 definition. The first requires no enquiry into content.
Note that “body corporate” in section 2 includes government or public bodies. A public body that intercepts State transmissions without lawful excuse is exposed to the K1,000,000 corporate fine.
Where section 7(2) sits
| Provision | Trigger | Maximum for a natural person |
|---|---|---|
| s 7(2) | Interception of State, Military or sensitive data transmissions | 25 years / K100,000 |
| s 10(2) | Espionage against State or Military secrets, or sensitive data | 30 years / K100,000 |
| s 25(1) | Disclosing confidential or classified communication, or sensitive data | 15 years / K20,000 |
| s 25(2) | The same, by a person with lawful authority, custody, access or control | 25 years / K100,000 |
| s 24(2)(b) | Threatening to expose sensitive data to procure gain | 25 years / K100,000 |
| s 9(2) | System interference with critical infrastructure | 25 years / K100,000, plus K25,000 per day |
| s 27(2) | Cyber attack on critical infrastructure | 25 years / K100,000, plus ICT prohibition |
For investigators and prosecutors. Establishing that the intercepted transmission carried sensitive data is usually straightforward given the width of the definition — but the content of the transmission must be proved, which may itself require lawful access under Part IV.
For anyone conducting monitoring. Because paragraph (a) covers personal data potentially detrimental to its subject, unauthorised interception of ordinary employee or customer communications is capable of being the aggravated offence, not the basic one. That is a 25-year maximum for an individual and a K1,000,000 fine for the company.
The safe course is a court order under section 39, or a clear lawful basis and consent — kept strictly within its terms, since acting in excess of a lawful excuse is expressly within the offence.
Sources
- Cybercrime Code Act 2016 — ss 2, 7, 9, 10, 24, 25, 27, 39
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.