Section 15 of the Cybercrime Code Act 2016 protects a person’s identity as such.
Section 15 — the offence
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, uses an electronic system or device —
(a) to access; or (b) to manipulate; or (c) to possess; or (d) to use; or (e) to transfer,
a means of identification of another person without the authorisation of that other person, is guilty of a crime.
Penalty: (a) for a natural person, a fine not exceeding K15,000 or imprisonment not exceeding 10 years, or both; and (b) for a body corporate, a fine not exceeding K100,000.
The five prohibited acts
| Verb | What it covers |
|---|---|
| (a) Access | Reaching the identification data — opening a file of credentials, viewing a record |
| (b) Manipulate | Altering it — changing details on an account, editing an identity record |
| (c) Possess | Holding it. And note the extended definition of “possession” in section 2 — it includes having under control in or on any website, whether or not another person has actual custody and whether or not the thing is visible |
| (d) Use | Employing it — logging in as someone else, opening an account in their name |
| (e) Transfer | Passing it on — selling a credential list, sending details to another person |
Paragraph (c) is the widest limb. A person who holds another’s identification data without authorisation commits the offence — without using it, without gaining anything, and without anyone suffering loss.
Combined with the extended meaning of possession, that reaches a person who controls a file of credentials stored on a remote server, even if they cannot see it and someone else holds the machine.
The practical consequence is significant for anyone who comes into possession of leaked or stolen credential data: retaining it is capable of being the offence.
“A means of identification”
Section 2 does not define “means of identification”, so the phrase takes its ordinary meaning: anything by which a person is identified.
That naturally covers:
- Names and personal particulars — date of birth, address, parents’ names;
- Numbers — passport, licence, tax file, employee, student or account numbers;
- Credentials — usernames, passwords, PINs, security answers, authentication tokens;
- Payment identifiers — card numbers, expiry dates, security codes;
- Biometric data — fingerprints, facial data, voice patterns;
- Digital identity — email addresses, phone numbers, social media accounts, digital signatures.
Note that the identification must be of another person. Using a wholly fictitious identity is not section 15 — though it may be electronic forgery under section 13 if inauthentic data is created to be acted on as authentic.
No loss, gain or deception required
Section 12 requires a purpose of deceiving or depriving another of property. Section 13 requires a purpose of creating inauthentic data to be acted on as authentic.
Section 15 requires no purpose at all beyond doing the act intentionally and without authorisation. The offence is complete on access, manipulation, possession, use or transfer.
That makes section 15 the natural charge where identity data has been taken but its intended use cannot be proved — a very common position in the early stages of an investigation.
The trade-off is the penalty. At 10 years and K15,000, section 15 is one of the lower maxima in Division 2, reflecting that it punishes the handling of identity rather than the harm done with it.
Where identity theft sits in a scheme
| Stage | Offence |
|---|---|
| Breaking into the system holding the data | s 6; s 6(2) if damage or loss resulted |
| Obtaining the protected data | s 10 — up to 30 years |
| Intercepting credentials in transit | s 7 |
| Holding or transferring the identification data | s 15 |
| Making or supplying the tools, passwords or access codes | s 16 |
| Sending deceptive messages to collect credentials | s 26; s 13 for spoofed content |
| Using the identity to take money | s 12 — up to 25 years |
| Publishing the data | s 25; s 24(2)(b) if used to extort |
Practical points
- Sharing credentials is capable of being an offence. Giving someone else your colleague’s login, or using a shared account belonging to a named individual without their authorisation, engages paragraphs (d) and (e). Organisations should issue individual credentials and prohibit sharing.
- Authorisation is the defence. The offence requires the act to be done without the authorisation of that other person. Consent from the person whose identity it is — not merely from an employer — is what takes conduct outside the section.
- “In excess of a lawful excuse” catches insiders. A staff member entitled to see customer identity data for one purpose who accesses it for another is within the section. See the article on the mental element.
- Delete what you should not hold. Because possession is enough, retaining old credential files, exported identity data or copies of documents beyond need creates exposure.
- Summary trial. Section 15 is listed in Schedule 2, so it may be dealt with summarily by a District Court constituted by a Principal Magistrate.
Sources
- Cybercrime Code Act 2016 — ss 2, 6, 7, 10, 12, 13, 15, 16, 24–26, 48; Schedule 2
- Criminal Code Act (Chapter 262) — s 1, definition of “have in possession”
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.