HomeCybercrimeData and system offences

What Is Data Espionage?

Accessing or obtaining protected data that is not meant for you and is protected against unauthorised access — whether for your own use or someone else’s. It carries the highest maximum sentence in the Act: 30 years, or a fine of K100,000, or both.

The cybercrime series, no. 16 · Attacks on data and systems · 5 min read

Section 10 of the Cybercrime Code Act 2016 carries the longest term of years of any offence in the Act.

Section 10(1) — the offence

Section 10(1)

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, whether for his own use or for the use of another person, accesses or obtains protected data which is not meant for him, and which is protected against unauthorised access, is guilty of a crime.

Penalty: (a) in the case of a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 30 years, or both; and (b) in the case of a body corporate, a fine not exceeding K500,000.

The elements

Elements of section 10(1)
ElementWhat it requires
Intentionally, without lawful excuse or in excess of oneNo recklessness limb — unlike sections 8 and 9. The conduct must be deliberate
Whether for his own use or for the use of anotherObtaining data for someone else is expressly covered — the insider passing information out, the contractor collecting for a client
Accesses or obtainsTwo verbs, as in section 6. Access alone is enough; nothing need be copied or removed
Protected dataThe data must be protected — and see the second condition below
Which is not meant for himThe person must not be an intended recipient
And which is protected against unauthorised accessA second, separate requirement: there must be some protection against unauthorised access
The double protection requirement

The section says the data must be protected data and protected against unauthorised access. The repetition is deliberate and it narrows the offence.

Data left open, with no access control at all, is not within section 10 — whatever its sensitivity. That is a real limit, and it distinguishes section 10 from section 6, which applies to a protected or non-public system, device or data. Section 6 covers material that is simply not public; section 10 requires actual protection.

The practical lesson for anyone holding valuable data is that access controls are what bring section 10 into play. Passwords, permissions and encryption are not only security measures but the condition of the strongest protection the Act offers.

Why the sentence is so high

The highest term of years in the Act

Thirty years exceeds the maximum for electronic fraud (25), cyber attack (15, or 25 against critical infrastructure), illegal interception (15, or 25 aggravated), and child pornography (25). Only the life sentences in sections 19(2), 22(3) and 23(3) are higher.

The reason lies in what the offence protects. Espionage — commercial, governmental or personal — can cause harm out of all proportion to the act itself, and the harm is often irreversible: once data is obtained it cannot be un-obtained.

Note the contrast with the corporate fine, which at K500,000 is half the K1,000,000 imposed for the most serious offences elsewhere in the Act.

Section 10 and its neighbours

Section 10 compared with related offences
OffenceRequiresMax (individual)
s 6(1) unauthorised accessAccess to a protected or non-public system, device or data5 years / K7,000
s 10(1) data espionageAccessing or obtaining protected data, protected against unauthorised access, not meant for the person30 years / K100,000
s 7 illegal interceptionTapping a communication during transmission15 years, or 25 aggravated
s 25 unlawful disclosureDisclosing confidential or classified communication or sensitive data15 years, or 25 for an insider
s 15 identity theftAccessing, manipulating, possessing, using or transferring a means of identification of another10 years / K15,000
The sequence in a typical case

An intrusion that ends in stolen data will usually engage several sections in turn: section 6 for the access; section 10 for obtaining the protected data; section 8 if data was altered or deleted along the way; section 25 if the data was then disclosed; and section 24(2)(b) if the disclosure was threatened in order to procure a gain.

Where the data taken is State or Military secrets, or sensitive data, the aggravated offence in section 10(2) applies.

Insiders and “in excess of a lawful excuse”

The most common way section 10 is committed

Section 10 does not require breaking in. It requires accessing or obtaining protected data not meant for you, without lawful excuse or in excess of one.

An employee with a valid login who opens records outside their role is acting in excess of their lawful excuse. So is a contractor who takes a copy of client data beyond what the engagement permits, and an administrator who reads material they have technical access to but no business reason to see.

The words “whether for his own use or for the use of another person” close the obvious argument that an employee who gained nothing personally is outside the section.

For employers, the practical protections are the same ones that establish the offence: define roles precisely, restrict access to what each role needs, log access, and make the boundaries explicit in writing. For employees, the rule is simple — having access is not the same as having permission.

Section 10 is not listed in Schedule 2, so it cannot be dealt with summarily. It is tried on indictment.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.