There is no Papua New Guinean equivalent of a general privacy or data protection Act. What exists is a constitutional right and a set of provisions in the Cybercrime Code Act 2016 that operate in the same space.
Section 49 of the Constitution
Section 49 of the Constitution guarantees every person a reasonable right to privacy in respect of their private and family life, their communications with others, and their personal papers and effects — except as provided by an Act of the Parliament made for a stated public purpose.
Section 44 separately protects freedom from arbitrary search and entry.
Section 1(2) lists the qualified rights the Act restricts — including privacy under section 49 and freedom from arbitrary search and entry under section 44 — and states that the restrictions are necessary and reasonably justifiable in a democratic society.
That declaration is the Act’s compliance with section 38 of the Constitution, which requires a law restricting a qualified right to say so expressly and to state the public interest served.
Offences that protect personal data
| Provision | Protects against | Maximum |
|---|---|---|
| s 6 | Unauthorised access to systems and data | 5 years; 15 if damage or loss |
| s 7 | Interception of communications | 15 years; 25 for sensitive data |
| s 10 | Obtaining protected data not meant for you | 30 years — the highest determinate term in the Act |
| s 11 | Remaining logged in after authorisation ends | 7 years |
| s 15 | Use of another person’s identifying information | 10 years |
| s 25(1) | Disclosure of confidential communications or sensitive data | 15 years; 25 for an insider |
| s 24(2) | Exposing sensitive data for gain | 25 years |
| s 44(1)(a) | Providers monitoring their users | 25 years |
It makes it a crime, punishable by 25 years, for an ICT service provider to monitor the information it transmits or stores on behalf of its users, or to actively seek facts indicating illegal activity by them.
In a jurisdiction with no data protection statute, that provision does a great deal of work: it prevents carriers and hosts from building routine surveillance of their customers, subject to the lawful excuses discussed here.
Safeguards on the investigation powers
- Warrants. Section 32 requires a Magistrate’s warrant on information on oath, executed by day unless night execution is specifically authorised.
- Judicial authorisation for the intrusive powers. Section 35, 37, 38, 39, 40 and 41 all require a court order.
- Sworn evidence for the three most intrusive — sections 39, 40 and 41.
- Specificity. Orders attach to specified data or communications.
- Partial disclosure only. Section 37 is limited to sufficient traffic data to identify providers and path.
- Suspects cannot be compelled to assist. Section 34 applies only to a person who is not a suspect.
- Forensic tools are a last resort, capped at six months, with mandatory recording, protection of what is obtained, immediate removal on discharge, and revocation where police exceed the order.
What is missing
- No general data protection law. No principles on collection, use, retention, accuracy or security of personal data outside the criminal provisions.
- No breach notification. An organisation that loses customer data is under no statutory duty to tell anyone.
- No subject access rights. No right to know what data an organisation holds about you, or to correct it.
- No notification of surveillance. A person whose communications were intercepted or whose device was subject to forensic tools is never told.
- No independent oversight. No commissioner or supervisory body over the exercise of the Part IV powers.
- No destruction rule for material obtained where no charge follows. Section 32(4) allows a Magistrate to order destruction of seized material once it is no longer required, but there is no equivalent for material gathered under sections 39 to 41.
Several of these could be addressed under the rule-making powers in sections 49 and 50.
In practice
For individuals, the practical protections are the criminal offences above and section 57 of the Constitution, which allows application to the National Court for enforcement of guaranteed rights.
For organisations, the absence of a data protection statute does not mean the absence of obligation. Section 25(2) exposes an organisation whose staff disclose confidential material to a K500,000 fine, and the general law of confidence continues to apply. See managing cybercrime risk.
Sources
- Cybercrime Code Act 2016 — ss 1, 6, 7, 10, 11, 15, 24, 25, 32–45, 49, 50
- Constitution — ss 38, 44, 49, 57
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.