Section 10 of the Cybercrime Code Act 2016 carries the longest term of years of any offence in the Act.
Section 10(1) — the offence
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, whether for his own use or for the use of another person, accesses or obtains protected data which is not meant for him, and which is protected against unauthorised access, is guilty of a crime.
Penalty: (a) in the case of a natural person, a fine not exceeding K100,000 or imprisonment not exceeding 30 years, or both; and (b) in the case of a body corporate, a fine not exceeding K500,000.
The elements
| Element | What it requires |
|---|---|
| Intentionally, without lawful excuse or in excess of one | No recklessness limb — unlike sections 8 and 9. The conduct must be deliberate |
| Whether for his own use or for the use of another | Obtaining data for someone else is expressly covered — the insider passing information out, the contractor collecting for a client |
| Accesses or obtains | Two verbs, as in section 6. Access alone is enough; nothing need be copied or removed |
| Protected data | The data must be protected — and see the second condition below |
| Which is not meant for him | The person must not be an intended recipient |
| And which is protected against unauthorised access | A second, separate requirement: there must be some protection against unauthorised access |
The section says the data must be protected data and protected against unauthorised access. The repetition is deliberate and it narrows the offence.
Data left open, with no access control at all, is not within section 10 — whatever its sensitivity. That is a real limit, and it distinguishes section 10 from section 6, which applies to a protected or non-public system, device or data. Section 6 covers material that is simply not public; section 10 requires actual protection.
The practical lesson for anyone holding valuable data is that access controls are what bring section 10 into play. Passwords, permissions and encryption are not only security measures but the condition of the strongest protection the Act offers.
Why the sentence is so high
Thirty years exceeds the maximum for electronic fraud (25), cyber attack (15, or 25 against critical infrastructure), illegal interception (15, or 25 aggravated), and child pornography (25). Only the life sentences in sections 19(2), 22(3) and 23(3) are higher.
The reason lies in what the offence protects. Espionage — commercial, governmental or personal — can cause harm out of all proportion to the act itself, and the harm is often irreversible: once data is obtained it cannot be un-obtained.
Note the contrast with the corporate fine, which at K500,000 is half the K1,000,000 imposed for the most serious offences elsewhere in the Act.
Section 10 and its neighbours
| Offence | Requires | Max (individual) |
|---|---|---|
| s 6(1) unauthorised access | Access to a protected or non-public system, device or data | 5 years / K7,000 |
| s 10(1) data espionage | Accessing or obtaining protected data, protected against unauthorised access, not meant for the person | 30 years / K100,000 |
| s 7 illegal interception | Tapping a communication during transmission | 15 years, or 25 aggravated |
| s 25 unlawful disclosure | Disclosing confidential or classified communication or sensitive data | 15 years, or 25 for an insider |
| s 15 identity theft | Accessing, manipulating, possessing, using or transferring a means of identification of another | 10 years / K15,000 |
An intrusion that ends in stolen data will usually engage several sections in turn: section 6 for the access; section 10 for obtaining the protected data; section 8 if data was altered or deleted along the way; section 25 if the data was then disclosed; and section 24(2)(b) if the disclosure was threatened in order to procure a gain.
Where the data taken is State or Military secrets, or sensitive data, the aggravated offence in section 10(2) applies.
Insiders and “in excess of a lawful excuse”
Section 10 does not require breaking in. It requires accessing or obtaining protected data not meant for you, without lawful excuse or in excess of one.
An employee with a valid login who opens records outside their role is acting in excess of their lawful excuse. So is a contractor who takes a copy of client data beyond what the engagement permits, and an administrator who reads material they have technical access to but no business reason to see.
The words “whether for his own use or for the use of another person” close the obvious argument that an employee who gained nothing personally is outside the section.
For employers, the practical protections are the same ones that establish the offence: define roles precisely, restrict access to what each role needs, log access, and make the boundaries explicit in writing. For employees, the rule is simple — having access is not the same as having permission.
Section 10 is not listed in Schedule 2, so it cannot be dealt with summarily. It is tried on indictment.
Sources
- Cybercrime Code Act 2016 — ss 2, 6–10, 15, 24, 25, 48; Schedule 2
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.