Section 25 of the Cybercrime Code Act 2016 is the Act’s leaking provision. It has two levels and one defence.
Section 25(1)
any confidential or classified communication (whether content, data or electronic output) or sensitive data,
is guilty of a crime.
Penalty: natural person — a fine up to K20,000 or imprisonment up to 15 years, or both; body corporate — a fine up to K100,000.
What may not be disclosed
| Category | Covers |
|---|---|
| Confidential communication | Communication whose content, data or electronic output is confidential — not limited to government material |
| Classified communication | Material carrying a security classification |
| Sensitive data | As defined in section 2 — the same term used in s 10, s 7(2) and s 24(2) |
Section 2 defines sensitive data, but not confidential communication. The word carries its ordinary meaning, informed by the general law of confidence — information having the necessary quality of confidence, imparted in circumstances importing an obligation of confidence.
That reaches a very great deal: commercial information, employment records, medical records, legal advice, personal correspondence, internal company documents.
The parenthesis “(whether content, data or electronic output)” makes clear that it does not matter whether what is disclosed is the message itself, the underlying data, or a printout or export.
Recklessness is enough
Section 25(1) includes “or recklessly” — unlike section 24, which requires intention.
So a person who forwards material with conscious disregard of a substantial risk that it is confidential can commit the offence. Misdirected email, an over-wide distribution list, a document attached in error, a screenshot shared in a group chat — all are capable of falling within the words if the risk was adverted to and run.
The countervailing element is “without lawful excuse or justification, or in excess of” one. A disclosure authorised by the owner of the information, required by law, made under a court order, or made in the ordinary course of an employee’s duties is made with lawful excuse. See the article on that phrase.
The public benefit defence
(3) It is a defence to a charge under this section to prove that it was for the benefit of the public that the confidential or classified communication or sensitive data was disclosed.
(4) Whether the unlawful disclosure under this section is for the benefit of the public is a question of fact.
1. The burden is on the accused. The words are “to prove”. On ordinary principles that is a legal burden, discharged on the balance of probabilities — the same structure as the section 21(8) defamation defences.
2. It applies to the whole section. Section 25(3) says “an offence under this section”, so it is available to the aggravated section 25(2) offence as well.
3. It is a question of fact. Section 25(4) forecloses any argument that public benefit is a question of law for the judge. It is decided on the evidence, case by case.
Section 25 has no exception for journalists, for public servants reporting wrongdoing, or for a person disclosing evidence of an offence. The public benefit defence carries all of that weight.
Note also the related but separate protection in section 362E of the Criminal Code, which section 21(9) applies to defamatory publication — but which section 25 does not incorporate.
A person considering a disclosure in the public interest should understand that they carry the burden of establishing it, after the fact, in a criminal court.
For employers and employees
- Almost any workplace disclosure is capable of engaging the section. Forwarding an internal document to a personal address, sharing a client list, sending a colleague’s file to an outsider.
- Authorisation is the answer. A clear policy on what may be sent where, and to whom, establishes the lawful excuse.
- The aggravated form applies to those with access. Section 25(2) raises the maximum to 25 years and K100,000 where the person had lawful authority, custody, access or control — which describes most employees handling confidential material.
- Companies are exposed. A body corporate faces up to K100,000 under subsection (1) and K500,000 under subsection (2).
Section 25(1) is listed in Schedule 2 and may be dealt with summarily by a District Court constituted by a Principal Magistrate. See also privacy protections and managing cybercrime risk.
Sources
- Cybercrime Code Act 2016 — ss 2, 8, 11, 21, 24, 25, 48; Schedule 2
- Criminal Code Act (Chapter 262) — s 362E
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.