Computer misuse
Cyber Security and Crime Act, 2021, unauthorised access
Cyber Security and Crime Act, 2021 (Act No. 7 of 2021), s. 33 (Unauthorised Access)official gazetted Act text, Supplement to the Sierra Leone Gazette No. 71 of 25 November 2021, reproduced by SierraLII (Laws.Africa)
In force since 15 November 2021. Binds public and private bodies.
What this law does
Section 33(1) prohibits intentionally and without authorisation causing a computer system to perform a function with intent to secure access to the whole or a part of a computer system or to enable such access to be secured.
Section 33(3) defines unauthorised, for the purposes of this section, by reference to a person who has been authorised to access specific data and, without lawful excuse, causes the system to perform a function other than what was authorised, and section 33(4) confirms that the absence of authority includes a case where general authority exists but a specific type, nature, or method of access does not.
The Act's general interpretation section separately defines unauthorised access as access by a person who is either not entitled to access the computer system, program, or data at all, or who does not have or exceeds the level of authorisation consented to by the person entitled to grant it. Neither definition requires infringing a technical security measure to gain access, though both turn on there being a scope of consented access to exceed.
On conviction, an individual faces a fine of not less than Le 100,000,000 and not more than Le 250,000,000, or imprisonment of not less than 2 years and not exceeding 5 years, or both, and a corporation, partnership, or association faces a fine of not less than Le 500,000,000 and not exceeding Le 1,000,000,000.
What it requires