Section 6 of the Cybercrime Code Act 2016 is the first offence in the Act and the foundation of the others.
Section 6(1) — the basic offence
A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, accesses or gains entry without authorisation, to the whole or any part of a protected or non-public electronic system or device, or data, is guilty of a misdemeanour.
Penalty: imprisonment for a term not exceeding five years or a fine not exceeding K7,000.00, or both.
The elements
| Element | What it requires |
|---|---|
| Intentionally | The access must be deliberate. Accidental access — a mistyped address, a misdirected connection — is not within the section |
| Without lawful excuse or justification, or in excess of one | See the article on this formula. Note the third limb: exceeding a permission you do have is as culpable as having none |
| Accesses or gains entry | Two verbs. Nothing need be taken, read, copied or damaged — entry alone completes the offence |
| Without authorisation | A separate requirement from lawful excuse. The system’s owner or controller must not have permitted the access |
| To the whole or any part | Accessing one folder, one account or one page of a system is enough |
| Of a protected or non-public electronic system or device, or data | The target must be protected or non-public. A publicly accessible website is neither |
The Act does not define either word here, but the pairing matters. Protected suggests a technical barrier — a password, an access code, encryption, a firewall. Non-public is wider: a system or data not made available to the public, whether or not it is technically secured.
So an unsecured internal server that was never intended for public access is non-public even without a password. But visiting a page that anyone can reach on the open internet is not accessing something protected or non-public, however unwelcome the visit.
Note that the object may be a system, a device, or data. Accessing a protected file counts, even if the machine holding it was open.
The defined meaning of “hacking”
“Hacking” means the act of exploring programs or determining the limitations of a computer, electronic system or device or network, for the purposes of gaining unauthorised access to it.
The definition captures the reconnaissance phase — scanning, probing, testing what a system will allow — but only where done for the purposes of gaining unauthorised access.
The same technical activity done with authority, to find weaknesses so they can be fixed, is not hacking within the definition. And section 16(2) provides a defence in relation to illegal devices where the activity is for authorised testing or protection of an electronic system or device, or for law enforcement purposes — a defence expressed to apply to that section, but reflecting the same distinction.
Note that the heading of section 6 is “Unauthorised access or hacking”, while the body of subsection (1) speaks only of accessing or gaining entry. The definition of hacking colours the section, but the offence is committed by the access itself.
What falls inside and outside
| Conduct | Within section 6(1)? |
|---|---|
| Guessing or using someone else’s password to open their email | Yes — intentional, unauthorised, protected |
| Logging into a work system you have no permission to use | Yes |
| An employee opening a colleague’s restricted files using their own valid login | Yes — in excess of a lawful excuse |
| Using a friend’s phone with their permission | No — authorised |
| Browsing a public website | No — not protected or non-public |
| Scanning a network to find open ports, intending to break in | Hacking within s 2; the offence is complete once access is obtained |
| Penetration testing with the owner’s written authority | No — authorised; and see s 16(2) |
| Continuing to use an account after your access was revoked | Consider section 11 — illegally remaining |
Why this offence is a misdemeanour
Section 6(1) and section 11 are misdemeanours; every other offence in Division 1 — and section 6(2) — is a crime. The distinction matters for classification and, through section 3, for the Criminal Code procedure that applies. See the article on the distinction.
The K7,000 maximum fine is also the lowest of any offence in the Act apart from spam. The reason is that section 6(1) punishes bare access. Where the access produces consequences, other provisions take over:
- Section 6(2) — where the access results in damage or loss: a crime, 15 years or K25,000.
- Section 10 — where protected data is obtained: a crime, up to 30 years.
- Section 8 — where data is damaged, deleted or altered.
- Section 9 — where the system’s functioning is hindered.
Section 6(1) is listed in Schedule 2, so it may be dealt with summarily by a District Court constituted by a Principal Magistrate. Section 6(2) is not.
Sources
- Cybercrime Code Act 2016 — ss 2, 3, 6, 8–11, 16, 48; Schedule 2
- Criminal Code Act (Chapter 262)
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.