Whether an organisation or person is an ICT service provider determines whether Part V of the Cybercrime Code Act 2016 applies — and with it, exposure to section 44 and section 45, both carrying 25 years.
Schedule 1 — the seven descriptions
| Category | Description |
|---|---|
| Telecommunications Service Provider | Provides mobile or fixed line telephony services |
| Internet Service Provider | Provides a service to connect users to the internet and allow them to remain online — by fixed lines, cable TV lines, fibre optic cables or satellite, among other means |
| Access Provider | Provides an electronic communication transmission service by transmitting information provided by or to a user in a communication network, or providing access to a communication network |
| Caching Provider | Provides a dedicated network server or service that saves web pages or other internet content locally by placing previously requested information in temporary storage |
| Hyperlink Provider | Provides a link from a hypertext document to another location |
| Web Hosting Provider | Provides an applications service — shared, dedicated or virtual private server hosting — including hosting files, images, games, webmail or similar content |
| Website Master or Administrator | A person responsible for maintaining one or many websites — also referred to as web architect, web developer, site author, website co-ordinator or website publisher |
Two categories that reach very widely
The description is “an ICT Service Provider providing a link from a hypertext document to another location”.
On its face that describes anyone who publishes a link. A news site linking to a source, a blog linking to a report, a forum post containing a URL — each is providing a link from a hypertext document to another location.
Read at its widest, the category would place a very large number of ordinary publishers within Part V. A narrower reading — confining it to services whose function is to provide linking, such as a directory, an index or an aggregator — is more consistent with the commercial character of the other six descriptions, each of which describes a service being provided to others.
The point has not been decided in Papua New Guinea.
This category is expressly a person — not a business. And the list of synonyms is broad: web architect, web developer, site author, website co-ordinator, website publisher.
So an individual who maintains a website — for an employer, for a community organisation, for a church, for a small business, or for themselves — is an ICT service provider for the purposes of Part V.
That individual is therefore subject to:
- Section 44(1)(a) — the prohibition on monitoring users’ information;
- Section 44(1)(c) and (d) — obstruction, and non-compliance with a court order;
- Section 45 — the non-disclosure obligation.
The penalty in each case is up to 25 years and K100,000 for a natural person.
What Schedule 1 does and does not settle
Schedule 1 is headed “Description of ICT Service Providers” and is referenced to section 1. It describes categories by function, not by naming particular companies or licence classes.
The consequence is that the question is always what a person or organisation does, not what it calls itself. An organisation may fall into several categories at once — a telecommunications operator that also hosts content and runs websites is within at least three.
Equally, an organisation that merely uses internet services, without providing any of the seven functions to others, is not an ICT service provider. An ordinary business with a corporate network for its own staff is not, by that fact alone, within Part V — though the person who maintains its website is.
Working out whether Part V applies
- Do you carry other people’s traffic? Telecommunications, internet or access provider.
- Do you cache content for others? Caching provider.
- Do you host files, images, games, webmail or similar content for others? Web hosting provider.
- Do you provide links from documents to other locations as a service? Hyperlink provider — subject to the interpretation question above.
- Does anyone in your organisation maintain a website? That person is a website master or administrator.
Where the answer to any of these is yes, the organisation or person should have a process for receiving and acting on preservation notices and court orders, controls limiting staff access to user data, and training on the confidentiality obligation in section 45.
See also what a business should do about cybercrime risk.
Sources
- Cybercrime Code Act 2016 — ss 1, 2, 35, 36, 44, 45; Schedule 1
Before relying on anything here, read the current text of the Cybercrime Code Act 2016 and check for later amendments. If a decision matters to you, get advice — start with the Office of the Public Solicitor, or find a firm in the law firms directory.