Part V of the Cybercrime Code Act 2016 imposes criminal liability on ICT service providers carrying up to 25 years’ imprisonment or a fine of K1,000,000. Knowing whether you are one matters.
Section 2 — the definition
“ICT service provider” means a person who provides content, applications or network services or a combination of such services, including but not limited to those identified in Schedule 1, and includes their employees, servants, agents or assignees.
“ICT service” has the same meaning as “ICT service” under section 4 of the National Information and Communications Technology Act 2009, and includes the services provided by an ICT service provider.
“Person” includes a body corporate — and under section 2, “body corporate” means a company whether incorporated or unincorporated, and includes government or public bodies. A State agency running a network is an ICT service provider.
“Including but not limited to those identified in Schedule 1” — the Schedule is illustrative. A business providing content, applications or network services is a provider whether or not it fits a listed description.
“And includes their employees, servants, agents or assignees” — this is unusual and important. An individual employee of a telecommunications company is themselves an ICT service provider for the purposes of the Act, and personally within the Part V offences. That is why section 44 states penalties for both a natural person and a body corporate.
The three kinds of service
“Network service” — a service for carrying communications by guided or unguided electromagnetic energy, supplied between distinct geographic points at least one of which is located in Papua New Guinea — but not services provided solely on the retail customer side of the network boundary.
“Applications service” — a service for facilitating communications, provided via one or more network services — again excluding services solely on the retail customer side of the network boundary.
“Content service” — (a) a broadcasting service; or (b) an applications service which also supplies content.
Each has its corresponding provider: network service provider, applications service provider, content service provider.
Both the network and applications service definitions exclude services provided solely on the retail customer side of the network boundary. That is the boundary between the operator’s network and the customer’s own equipment.
The practical effect is that an ordinary business running its own internal network, or a household with a home router, is not a network or applications service provider merely for doing so. The definitions target those who supply services across the boundary.
Note the geographic requirement in network service: the service must be supplied between distinct geographic points, at least one of which is in Papua New Guinea. A foreign carrier delivering traffic into the country is within it.
Schedule 1 — the seven categories
| Category | Description in Schedule 1 |
|---|---|
| Telecommunications service provider | Provides mobile or fixed line telephony services |
| Internet service provider | Provides a service to connect users to the internet and to allow users to remain online — by fixed lines, cable TV lines, fibre optic cables or by satellite |
| Access provider | Provides an electronic communication transmission service by transmitting information provided by or to a user in a communication network, or providing access to a communication network |
| Caching provider | Provides a dedicated network server or service acting as a server that saves web pages or other internet content locally by placing previously requested information in temporary storage or cache |
| Hyperlink provider | Provides a link from a hypertext document to another location |
| Web hosting provider | Provides an applications service — shared, dedicated or virtual private server hosting — including hosting files, images, games, webmail or similar content |
| Website master or administrator | A person responsible for maintaining one or many websites — also referred to as web architect, web developer, site author, website co-ordinator or website publisher |
Hyperlink provider. On the face of Schedule 1, a person who provides a link from a hypertext document to another location is an ICT service provider. Read literally, posting a link is enough. That is a very wide description, and it should be read with the section 2 definition, which requires a person to be providing content, applications or network services — a link on its own is unlikely to constitute a service.
Website master or administrator. This is not confined to businesses. Anyone responsible for maintaining one or many websites — including a site author or publisher — falls within it. A person who runs a community website, a church site or a small business page is on the face of the Schedule an ICT service provider, and within Part V.
That matters because of what section 44 makes criminal — including monitoring the information transmitted or stored on behalf of users, and negligently allowing an employee to commit one of the listed acts.
What follows from being a provider
- Section 44 liability. Six categories of conduct, from monitoring users to failing to comply with a court order, each carrying up to 25 years or K100,000 for an individual and K1,000,000 for a company.
- Section 45 confidentiality. Disclosing the existence of a court order, anything done under it, or data collected under it, is a crime.
- Production orders. Under section 35(b), a court may order a provider to produce information about persons who subscribe to or use its services.
- Interception assistance. Under section 39(a), a court shall order a provider whose service is available in the country to collect or record data, or to assist police in doing so.
- Forensic tool assistance. Under section 41(11), the court may order a provider to assist with the installation of remote forensic software or hardware.
- Spam. Under section 26(b), relaying multiple electronic messages to mislead any ICT service provider as to their origin is an offence.
Note finally that the Act does not contain a general safe harbour for intermediaries, and no notice-and-takedown scheme. The nearest thing to a protection is the structure of section 44 itself, which requires intention, knowledge, negligence or non-compliance with a court order before liability attaches.
Sources
- Cybercrime Code Act 2016 — ss 2, 26, 35, 39, 41, 44, 45; Schedule 1
- National Information and Communication Technology Act 2009 — s 4
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.