HomeCybercrimeData and system offences

What Is the Offence of Illegally Remaining?

Staying logged in, or continuing to use a system or device, without authorisation or after your authorised use has expired. A misdemeanour carrying up to seven years or K10,000, and K50,000 for a company — and it can be committed recklessly.

The cybercrime series, no. 18 · Attacks on data and systems · 5 min read

Section 11 of the Cybercrime Code Act 2016 closes a gap left by the access offence.

Section 11 — the offence

Section 11

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification or recklessly, remains logged into or continues to use an electronic system or device, or part of an electronic system or device, without authorisation or after his authorised use of the electronic system or device has expired, is guilty of a misdemeanour.

Penalty: (a) in the case of a natural person, a fine not exceeding K10,000 or imprisonment not exceeding seven years, or both; and (b) in the case of a body corporate, a fine not exceeding K50,000.

Why the offence is needed

Section 6 punishes getting in; section 11 punishes staying

Section 6(1) is committed by accessing or gaining entry without authorisation. It is complete at the moment of entry.

That leaves two situations uncovered:

Access that was originally lawful. An employee logs in with a valid account, then leaves the company. Their authorisation has ended, but they never gained entry unlawfully.

Authorisation that expires during use. A person with time-limited or purpose-limited access continues after the limit.

Section 11 covers both by making it an offence to remain logged into or continue to use a system without authorisation, or after authorised use has expired.

The elements

Elements of section 11
ElementNote
Intentionally, in excess of a lawful excuse, or recklesslyRecklessness suffices — unlike section 6
Remains logged into or continues to useTwo alternatives. Passive presence in a session is enough; active use is not required
An electronic system or device, or part of oneRemaining in one module, folder or account of a larger system is enough
Without authorisationThe straightforward case
Or after his authorised use has expiredThe distinctive case — lawful access that has run out
“Remains logged into” is a low threshold

The section does not require the person to do anything. Simply remaining logged in after authorisation ends satisfies the conduct element.

Combined with the recklessness alternative, that produces real exposure. A departing employee whose session stays open on a home computer, or a contractor who does not log out when an engagement ends, may be reckless as to remaining logged in after authorisation expired.

In practice the mental element is what will matter. Recklessness requires awareness of a substantial risk and going ahead regardless; mere forgetfulness is unlikely to reach it. But the safe course is obvious: log out and confirm access is removed when a role, contract or permission ends.

A continuing offence

Two consequences of the offence being continuing

Timing. Under section 4, a person can only be punished for conduct that was an offence under the Act in force when it occurred. For a continuing offence, the relevant conduct is the continuation — so remaining logged in after the Act commenced is within it, whatever the position before.

Duration as an aggravating factor. The offence is committed as soon as the person remains without authorisation, but how long they remained will bear on sentence.

What this means for employers

Access management is now a criminal law question

Section 11 makes the boundaries of authorisation legally significant. Three practices follow:

Define when authorisation ends. Contracts, policies and system notices should state clearly that access is granted for a defined role, purpose and period, and ends with it.

Revoke promptly. Where accounts remain active after a person leaves, both sides are worse off: the organisation is exposed to the risk, and the former employee is exposed to section 11.

Tell people. Because the offence can be committed recklessly, a person who has been told plainly that their access has ended is in a very different position from one who was never told.

The same logic runs through the other Division 1 offences: section 10 catches access in excess of a lawful excuse, and section 8 catches interference done recklessly. Clear, documented access boundaries protect everyone.

Section 11 compared with related offences
OffenceConductMax (individual)
s 6(1)Getting in without authorisation5 years / K7,000
s 11Staying in without authorisation or after it expired7 years / K10,000
s 10Obtaining protected data while there30 years / K100,000
s 8Damaging or deleting data while there10 years / K20,000
s 9(1)Hindering the system10 years / K10,000
A higher maximum than the access offence

Section 11 carries seven years against section 6(1)’s five. That is a deliberate signal: persisting in unauthorised presence, particularly by a person who knows their authorisation has ended, is treated as more serious than a single unauthorised entry.

Both are misdemeanours and both are listed in Schedule 2, so both may be dealt with summarily by a District Court constituted by a Principal Magistrate.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.