HomeCybercrimeIn practice

What Privacy Protections Exist in PNG Cybercrime Law?

Papua New Guinea has no general data protection statute. Privacy is protected by section 49 of the Constitution and, in the online context, by a set of offences and safeguards scattered through the Cybercrime Code Act 2016 — including the prohibition on providers monitoring their users.

The cybercrime series, no. 99 · Practical guidance · 5 min read

There is no Papua New Guinean equivalent of a general privacy or data protection Act. What exists is a constitutional right and a set of provisions in the Cybercrime Code Act 2016 that operate in the same space.

Section 49 of the Constitution

The right to privacy

Section 49 of the Constitution guarantees every person a reasonable right to privacy in respect of their private and family life, their communications with others, and their personal papers and effects — except as provided by an Act of the Parliament made for a stated public purpose.

Section 44 separately protects freedom from arbitrary search and entry.

The Act acknowledges the restriction

Section 1(2) lists the qualified rights the Act restricts — including privacy under section 49 and freedom from arbitrary search and entry under section 44 — and states that the restrictions are necessary and reasonably justifiable in a democratic society.

That declaration is the Act’s compliance with section 38 of the Constitution, which requires a law restricting a qualified right to say so expressly and to state the public interest served.

Offences that protect personal data

Offences with a privacy-protective function
ProvisionProtects againstMaximum
s 6Unauthorised access to systems and data5 years; 15 if damage or loss
s 7Interception of communications15 years; 25 for sensitive data
s 10Obtaining protected data not meant for you30 years — the highest determinate term in the Act
s 11Remaining logged in after authorisation ends7 years
s 15Use of another person’s identifying information10 years
s 25(1)Disclosure of confidential communications or sensitive data15 years; 25 for an insider
s 24(2)Exposing sensitive data for gain25 years
s 44(1)(a)Providers monitoring their users25 years
Section 44(1)(a) is the most privacy-protective provision in the Act

It makes it a crime, punishable by 25 years, for an ICT service provider to monitor the information it transmits or stores on behalf of its users, or to actively seek facts indicating illegal activity by them.

In a jurisdiction with no data protection statute, that provision does a great deal of work: it prevents carriers and hosts from building routine surveillance of their customers, subject to the lawful excuses discussed here.

Safeguards on the investigation powers

  1. Warrants. Section 32 requires a Magistrate’s warrant on information on oath, executed by day unless night execution is specifically authorised.
  2. Judicial authorisation for the intrusive powers. Section 35, 37, 38, 39, 40 and 41 all require a court order.
  3. Sworn evidence for the three most intrusive — sections 39, 40 and 41.
  4. Specificity. Orders attach to specified data or communications.
  5. Partial disclosure only. Section 37 is limited to sufficient traffic data to identify providers and path.
  6. Suspects cannot be compelled to assist. Section 34 applies only to a person who is not a suspect.
  7. Forensic tools are a last resort, capped at six months, with mandatory recording, protection of what is obtained, immediate removal on discharge, and revocation where police exceed the order.

What is missing

Six gaps
  • No general data protection law. No principles on collection, use, retention, accuracy or security of personal data outside the criminal provisions.
  • No breach notification. An organisation that loses customer data is under no statutory duty to tell anyone.
  • No subject access rights. No right to know what data an organisation holds about you, or to correct it.
  • No notification of surveillance. A person whose communications were intercepted or whose device was subject to forensic tools is never told.
  • No independent oversight. No commissioner or supervisory body over the exercise of the Part IV powers.
  • No destruction rule for material obtained where no charge follows. Section 32(4) allows a Magistrate to order destruction of seized material once it is no longer required, but there is no equivalent for material gathered under sections 39 to 41.

Several of these could be addressed under the rule-making powers in sections 49 and 50.

In practice

For individuals, the practical protections are the criminal offences above and section 57 of the Constitution, which allows application to the National Court for enforcement of guaranteed rights.

For organisations, the absence of a data protection statute does not mean the absence of obligation. Section 25(2) exposes an organisation whose staff disclose confidential material to a K500,000 fine, and the general law of confidence continues to apply. See managing cybercrime risk.

Sources

Check the section yourself

Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.

Disclaimer: This article provides general information about Papua New Guinea law and does not constitute legal advice. Laws may change, and their application depends on individual circumstances. You should obtain professional legal advice for your specific situation. Read the full disclaimer.