HomeCybercrimeContent offences

What Is Unlawful Disclosure?

Using an electronic system or device to disclose confidential or classified communication — whether content, data or electronic output — or sensitive data. A crime carrying 15 years or a fine of K20,000, or both, with a public benefit defence.

The cybercrime series, no. 56 · Content related offences · 5 min read

Section 25 of the Cybercrime Code Act 2016 is the Act’s leaking provision. It has two levels and one defence.

Section 25(1)

A person who, intentionally and without lawful excuse or justification, or in excess of a lawful excuse or justification, or recklessly, uses an electronic system or device to disclose

any confidential or classified communication (whether content, data or electronic output) or sensitive data,

is guilty of a crime.

Penalty: natural person — a fine up to K20,000 or imprisonment up to 15 years, or both; body corporate — a fine up to K100,000.

What may not be disclosed

Categories of protected material under section 25(1)
CategoryCovers
Confidential communicationCommunication whose content, data or electronic output is confidential — not limited to government material
Classified communicationMaterial carrying a security classification
Sensitive dataAs defined in section 2 — the same term used in s 10, s 7(2) and s 24(2)
“Confidential” is not defined

Section 2 defines sensitive data, but not confidential communication. The word carries its ordinary meaning, informed by the general law of confidence — information having the necessary quality of confidence, imparted in circumstances importing an obligation of confidence.

That reaches a very great deal: commercial information, employment records, medical records, legal advice, personal correspondence, internal company documents.

The parenthesis “(whether content, data or electronic output)” makes clear that it does not matter whether what is disclosed is the message itself, the underlying data, or a printout or export.

Recklessness is enough

The wide mental element

Section 25(1) includes “or recklessly” — unlike section 24, which requires intention.

So a person who forwards material with conscious disregard of a substantial risk that it is confidential can commit the offence. Misdirected email, an over-wide distribution list, a document attached in error, a screenshot shared in a group chat — all are capable of falling within the words if the risk was adverted to and run.

The countervailing element is “without lawful excuse or justification, or in excess of” one. A disclosure authorised by the owner of the information, required by law, made under a court order, or made in the ordinary course of an employee’s duties is made with lawful excuse. See the article on that phrase.

The public benefit defence

Sections 25(3) and (4)

(3) It is a defence to a charge under this section to prove that it was for the benefit of the public that the confidential or classified communication or sensitive data was disclosed.

(4) Whether the unlawful disclosure under this section is for the benefit of the public is a question of fact.

Three points about the defence

1. The burden is on the accused. The words are “to prove”. On ordinary principles that is a legal burden, discharged on the balance of probabilities — the same structure as the section 21(8) defamation defences.

2. It applies to the whole section. Section 25(3) says “an offence under this section”, so it is available to the aggravated section 25(2) offence as well.

3. It is a question of fact. Section 25(4) forecloses any argument that public benefit is a question of law for the judge. It is decided on the evidence, case by case.

This is the Act’s whistleblower provision

Section 25 has no exception for journalists, for public servants reporting wrongdoing, or for a person disclosing evidence of an offence. The public benefit defence carries all of that weight.

Note also the related but separate protection in section 362E of the Criminal Code, which section 21(9) applies to defamatory publication — but which section 25 does not incorporate.

A person considering a disclosure in the public interest should understand that they carry the burden of establishing it, after the fact, in a criminal court.

For employers and employees

  1. Almost any workplace disclosure is capable of engaging the section. Forwarding an internal document to a personal address, sharing a client list, sending a colleague’s file to an outsider.
  2. Authorisation is the answer. A clear policy on what may be sent where, and to whom, establishes the lawful excuse.
  3. The aggravated form applies to those with access. Section 25(2) raises the maximum to 25 years and K100,000 where the person had lawful authority, custody, access or control — which describes most employees handling confidential material.
  4. Companies are exposed. A body corporate faces up to K100,000 under subsection (1) and K500,000 under subsection (2).

Section 25(1) is listed in Schedule 2 and may be dealt with summarily by a District Court constituted by a Principal Magistrate. See also privacy protections and managing cybercrime risk.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.