Section 7 of the Cybercrime Code Act 2016 protects communications in transit.
Section 7(1) — the offence
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, intercepts by technical or other means —
(a) any non-public transmission to, from or within an electronic system or device; or
(b) electromagnetic emissions from an electronic system or device,
not intended for him, is guilty of a crime.
Penalty: (a) a fine not exceeding K50,000 or imprisonment not exceeding 15 years, or both; and (b) in the case of a body corporate, a fine not exceeding K500,000.
The defined meaning of interception
“Interception” means tapping into an electronic communication not directed to the one who is tapping into such communication, for the purpose of acquiring, viewing or capturing such communication — whether by earth bound (wired, cable), wireless, electronic, optical, magnetic or other means — during transmission, through the use of any technical device.
“During transmission”. Interception is about communications in transit. Reading a message that has already been delivered and stored is not interception — though it may be unauthorised access under section 6, or data espionage under section 10.
“Not directed to the one who is tapping” — and the offence itself repeats the point with “not intended for him”. A party to the communication does not intercept it. Recording your own call is not interception; recording someone else’s is.
Note also the breadth of “by technical or other means” in the offence, alongside the definition’s reference to any technical device. Wiretapping, packet capture, a rogue wireless access point, a hardware keylogger on a network cable, or a device reading signals off a cable all qualify.
The two things that may be intercepted
| Paragraph | What it covers | Examples |
|---|---|---|
| (a) Non-public transmission to, from or within an electronic system or device | The content of a communication in transit that is not public | Email in transit, a phone call, a message on a private network, traffic between a client and a server, data moving within a system |
| (b) Electromagnetic emissions from an electronic system or device | The incidental radiation a device gives off while operating | Reading a screen’s or cable’s emissions to reconstruct what is displayed or transmitted; capturing wireless keyboard signals |
Most interception offences address the communication. Paragraph (b) addresses emanations — the electromagnetic energy a device produces as a by-product, which can be captured and analysed without touching the device or the network at all.
Section 2 defines “electromagnetic” broadly: the interaction of electronic and magnetic fields producing energy propagated through free space or a material medium, such as radio waves, visible light, gamma rays, and the emission and transmission of such radiant energy.
Note that paragraph (b) does not require the emissions to be a communication at all. It is enough that they come from an electronic system or device and were not intended for the interceptor.
Only non-public transmissions are protected by paragraph (a). Listening to a public broadcast is not interception. But the great majority of network traffic — email, messaging, web requests, internal data — is non-public even though it travels over public infrastructure.
Where interception is lawful
Section 39 provides for authorised interception. On application by a member of the Police Force or the Public Prosecutor, and on sworn evidence that data or communication is reasonably required for an investigation or proceeding, the Court shall either order an ICT service provider to collect or record it, or assist police to do so — or authorise a member of the Police Force to collect or record it directly.
Related powers: section 40 on traffic data, and section 41 on remote forensic tools, which permits keystroke logging and remote access to a suspect’s device under strict conditions.
Outside a court order, a person seeking to rely on lawful excuse or justification would need some other legal authority. Note the third limb of the formula — in excess of a lawful excuse — which catches an officer or provider who goes beyond what an order permits. See the article on that phrase.
Monitoring staff communications, or a provider inspecting traffic, is capable of being interception. And for an ICT service provider there is a second and severe exposure: section 44(1)(a) makes it a crime, carrying up to 25 years or K1,000,000, for a provider to monitor the information which they transmit or store on behalf of their users without lawful excuse.
Any monitoring programme should therefore be grounded in a clear legal basis and in consent, and should be kept within its terms.
Where the interception is directed at State or Military transmissions, or transmissions of other sensitive data, the aggravated offence in section 7(2) applies, raising the maximum to 25 years or K100,000, and K1,000,000 for a body corporate.
Section 7 is not in Schedule 2, so it cannot be dealt with summarily.
Sources
- Cybercrime Code Act 2016 — ss 2, 6, 7, 10, 39–41, 44, 48; Schedule 2
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.