Section 8 of the Cybercrime Code Act 2016 protects the integrity and availability of data.
Section 8 — the offence
(a) damages or deteriorates data; or
(b) deletes data; or
(c) alters data; or
(d) renders data meaningless, useless or ineffective; or
(e) obstructs, interrupts or interferes with the lawful processing of data; or
(f) obstructs, interrupts or interferes with any person in their lawful use of data; or
(g) denies access to data to any person authorised to access it,
is guilty of a crime.
Penalty: (a) in the case of a natural person, a fine not exceeding K20,000 or imprisonment not exceeding 10 years, or both; and (b) in the case of a body corporate, a fine not exceeding K100,000.
The recklessness element
The opening formula is “intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification or recklessly”.
That third alternative matters. Section 6 and section 7 require the conduct to be intentional. Section 8 is satisfied by recklessness — acting with awareness of a substantial risk of the prohibited result, and going ahead anyway.
The practical exposure is real. A contractor who runs a script on a live database without checking, a technician who wipes the wrong volume, an employee who disables a process knowing others depend on it — each may be reckless as to damaging, deleting or denying access to data.
Sections 8, 9, 11, 20, 21, 22, 23, 25, 26 and 28 to 31 all include recklessness. See the article on the mental element.
What the seven limbs cover
| Limb | Typical conduct |
|---|---|
| (a) damages or deteriorates | Corrupting files; degrading a database; introducing errors |
| (b) deletes | Erasing files, records, logs or backups |
| (c) alters | Changing records, figures, entries or configurations |
| (d) renders meaningless, useless or ineffective | Encrypting data so the owner cannot read it; scrambling; stripping structure |
| (e) obstructs, interrupts or interferes with lawful processing | Stopping a batch job, a payment run, a backup or a reconciliation |
| (f) obstructs, interrupts or interferes with a person’s lawful use | Locking a colleague out of records they are entitled to work with |
| (g) denies access to a person authorised to access it | Changing passwords or permissions; removing an authorised user |
Encrypting a victim’s data is squarely within (d) — rendering data meaningless, useless or ineffective — and within (g), denying access to a person authorised to access it.
Where the encryption is done to procure a monetary or other benefit, the more serious offence is section 24(1) — cyber extortion, carrying 25 years and a corporate fine of K500,000. Where malicious software is deployed to cause harm, section 27 applies.
Limbs (e) and (f) are notable for protecting processes and use, not only the data itself. Data can be left intact and the offence still committed, if the lawful processing or use of it is obstructed.
“Data” and “interference”
“Data” — any representation of facts, concepts, information (text, audio, video, audiovisual or images), machine readable code or instructions, in a form suitable for processing in an electronic system or device, including a program.
“Interference” — tampering with the integrity of information content or electronic data, or systems, and includes damaging, deletion, deterioration, alteration, suppression, modification (additions, omissions and substitutions), or hindering.
Because the definition expressly includes a program, altering or deleting software is data interference. Disabling an application, removing a driver, or modifying code all fall within limbs (a) to (d).
Note also that “interference” as defined includes suppression and hindering, which supports the width of limbs (e) to (g).
Where lawful excuse comes in
System administrators delete, alter and overwrite data constantly. What makes that lawful is authority — the employment or contractual permission under which the work is done.
Two cautions follow from the wording of the section:
“In excess of a lawful excuse”. An administrator with authority over one system who interferes with another, or who exceeds the scope of a change authorisation, is within the offence.
Recklessness. Because intention is not required, an administrator who acts within their role but with conscious disregard of an obvious risk to data may still be caught.
Sound practice — change control, written authorisation, tested backups, restricted permissions — is therefore not only good administration but the practical foundation of a lawful excuse.
Charging and trial
Section 8 is a crime, but it is listed in Schedule 2, so it may be dealt with summarily by a District Court constituted by a Principal Magistrate under section 48.
A single incident will often support several charges. Breaking in and then deleting records engages section 6(2) as well as section 8; taking a service down engages section 9; obtaining the data engages section 10. Under section 3(2) the Act is in addition to the Criminal Code Act (Chapter 262), so Code offences may also be available.
Sources
- Cybercrime Code Act 2016 — ss 2, 3, 6–11, 24, 27, 48; Schedule 2
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.