Section 11 of the Cybercrime Code Act 2016 closes a gap left by the access offence.
Section 11 — the offence
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification or recklessly, remains logged into or continues to use an electronic system or device, or part of an electronic system or device, without authorisation or after his authorised use of the electronic system or device has expired, is guilty of a misdemeanour.
Penalty: (a) in the case of a natural person, a fine not exceeding K10,000 or imprisonment not exceeding seven years, or both; and (b) in the case of a body corporate, a fine not exceeding K50,000.
Why the offence is needed
Section 6(1) is committed by accessing or gaining entry without authorisation. It is complete at the moment of entry.
That leaves two situations uncovered:
Access that was originally lawful. An employee logs in with a valid account, then leaves the company. Their authorisation has ended, but they never gained entry unlawfully.
Authorisation that expires during use. A person with time-limited or purpose-limited access continues after the limit.
Section 11 covers both by making it an offence to remain logged into or continue to use a system without authorisation, or after authorised use has expired.
The elements
| Element | Note |
|---|---|
| Intentionally, in excess of a lawful excuse, or recklessly | Recklessness suffices — unlike section 6 |
| Remains logged into or continues to use | Two alternatives. Passive presence in a session is enough; active use is not required |
| An electronic system or device, or part of one | Remaining in one module, folder or account of a larger system is enough |
| Without authorisation | The straightforward case |
| Or after his authorised use has expired | The distinctive case — lawful access that has run out |
The section does not require the person to do anything. Simply remaining logged in after authorisation ends satisfies the conduct element.
Combined with the recklessness alternative, that produces real exposure. A departing employee whose session stays open on a home computer, or a contractor who does not log out when an engagement ends, may be reckless as to remaining logged in after authorisation expired.
In practice the mental element is what will matter. Recklessness requires awareness of a substantial risk and going ahead regardless; mere forgetfulness is unlikely to reach it. But the safe course is obvious: log out and confirm access is removed when a role, contract or permission ends.
A continuing offence
Timing. Under section 4, a person can only be punished for conduct that was an offence under the Act in force when it occurred. For a continuing offence, the relevant conduct is the continuation — so remaining logged in after the Act commenced is within it, whatever the position before.
Duration as an aggravating factor. The offence is committed as soon as the person remains without authorisation, but how long they remained will bear on sentence.
What this means for employers
Section 11 makes the boundaries of authorisation legally significant. Three practices follow:
Define when authorisation ends. Contracts, policies and system notices should state clearly that access is granted for a defined role, purpose and period, and ends with it.
Revoke promptly. Where accounts remain active after a person leaves, both sides are worse off: the organisation is exposed to the risk, and the former employee is exposed to section 11.
Tell people. Because the offence can be committed recklessly, a person who has been told plainly that their access has ended is in a very different position from one who was never told.
The same logic runs through the other Division 1 offences: section 10 catches access in excess of a lawful excuse, and section 8 catches interference done recklessly. Clear, documented access boundaries protect everyone.
Where section 11 sits
| Offence | Conduct | Max (individual) |
|---|---|---|
| s 6(1) | Getting in without authorisation | 5 years / K7,000 |
| s 11 | Staying in without authorisation or after it expired | 7 years / K10,000 |
| s 10 | Obtaining protected data while there | 30 years / K100,000 |
| s 8 | Damaging or deleting data while there | 10 years / K20,000 |
| s 9(1) | Hindering the system | 10 years / K10,000 |
Section 11 carries seven years against section 6(1)’s five. That is a deliberate signal: persisting in unauthorised presence, particularly by a person who knows their authorisation has ended, is treated as more serious than a single unauthorised entry.
Both are misdemeanours and both are listed in Schedule 2, so both may be dealt with summarily by a District Court constituted by a Principal Magistrate.
Sources
- Cybercrime Code Act 2016 — ss 2, 4, 6, 8–11, 48; Schedule 2
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.