Column 1 | Column 2 | Column 3 |
---|
Sections of Act creating contravention | Contravention | Administrative Penalty |
---|
36(4) | Owner of a registered critical information infrastructure failing to inform the Authority within seven days of the change in legal ownership of the registered critical information infrastructure. | Not less than five hundred penalty units and not more than ten thousand penalty units. |
39(2)(a) | Owner of a critical information infrastructure failing to report a cybersecurity incident. | Not less than two hundred and fifty penalty units and not more than ten thousand penalty units. |
39(2)(b) | Owner of a critical information infrastructure failing to cause an audit to be performed on the critical information infrastructure. | Not less than two hundred and fifty penalty units and not more than ten thousand penalty units. |
39(2)(c) | Owner of a critical information infrastructure failing to submit a copy of the audit report to the Authority. | Not less than two hundred and fifty penalty units and not more than ten thousand penalty units. |
44(6) | A Sectoral Computer Emergency Response Team failing to comply with the regulatory directives of the Authority. | Not less than five hundred penalty units and not more than five thousand penalty units. |
47(6) | The head of an institution failing to report a cybersecurity incident to the relevant Sectoral Computer Emergency Response Team or the National Computer Response Team. | Not less than two hundred and fifty penalty units and not more than five thousand penalty units. |
49(2) | Person providing a cybersecurity service without a licence. | Penalty equivalent to the cost of damage caused and value of the financial gain made. |
51(5) | A licensed service provider using a licence for a purpose other than the purpose for which the licence was granted. | Fifty thousand penalty units. |
59(4) | Person failing to comply with the cybersecurity standards. | Not less than two hundred and fifty penalty units and not more than twenty-five thousand penalty units. |
76(12) | Service provider who(a)fails to install an interception capability to enforce an interception warrant issued by a court of competent jurisdiction; or(b)fails to take the necessary steps to decrypt a telecommunication message pursuant to an inter ception warrant. | Ten thousand penalty units. |
77(5) | (a) Service provider who fails to retain(i)subscriber information for at least six years;(ii)traffic data for a period of twelve months; and(iii)relevant content data for a period of twelve months. | Not less than one thousand penalty units and not more than ten thousand penalty units. |
| (b) Person using data retained for a purpose other than what is stated in an interception warrant. | Not less than one thousand, five hundred penalty units and not more than ten thousand penalty units. |
86(2) | The owner or operator of a critical information infrastructure, a designated Sectoral Computer Emergency Response Team or a provider of a digital service failing to submit relevant information to the Authority for the purpose of ensuring the cybersecurity of the country. | Not less than two hundred and fifty penalty units and not more than ten thousand penalty units. |
86(3) | Daily default on the part of the owner of a critical information infrastructure, a designated Sectoral Computer Emergency Response Team or provider of a digital service to comply with a request to provide relevant information for the purpose of ensuring the cybersecurity of the country. | One hundred penalty units for each day that the contravention continues. |
87(3) | Service provider failing to comply with an authorisation to block, filter or take down any content which seeks to undermine the cybersecurity of the country. | Not less than one thousand penalty units and not more than twenty-five thousand penalty units. |
87(4) | Service provider failing on a daily basis, to comply with an authorisation to block, filter or take down any content which seeks to undermine the cybersecurity of the country. | One hundred penalty units for each day the contravention continues. |
92(2) | Owner of a critical information infrastructure, a cybersecurity service provider or a provider of a digital service failing to comply with a directive issued by the Authority. | Not less than two hundred and fifty penalty units and not more than ten thousand penalty units. |