Papua New Guinea Cybercrime Policy 2014 6.   Liability  of  ICT  Service  Providers     The   Government   recognises   that   cybercrime   cannot   be   committed   without   the   use   of   services  and  networks  provided  by  ICT  service  providers  who  receive,  store  or  transmit   large  volumes  of  content  on  behalf  of  their  subscribers.    Accordingly,  it  is  necessary  to   impose  some  degree  of  responsibility  and  or  liability  on  ICT  service  providers.     However,  the  Government  acknowledges  that  it  is  practically  impossible  for  ICT  service   providers  to  monitor  the  content  in  order  to  be  held  responsible  and  or  liable  for  merely   receiving,   storing   or   transmitting   illegal   data,   unless   they   knowingly   aid   or   abet   the   offender,   or   are   criminally   negligent   in   their   performance   or   discharge   of   any   duty   or   obligation.     ICT  service  providers  play  an  important  role  in  making  the  Internet  accessible  to  users.    It   is   important   to   establish   a   reliable   legal   and   regulatory   framework   defining   the   obligations   of   ICT   Service   Providers   in   the   country,   whereby   the   responsibility   and   or   liability   for   crimes   committed   by   users   of   their   services   should   be   restricted   where   necessary.     In   this   context,   it   is   essential   to   distinguish   between   the   different   types   of   service  providers.     In  cases  where  responsibility  and  or  liability  exists,  legislation  should  limit  the  criminal   responsibility  and  or  liability  of  Internet  Service  Providers  (ISPs)  and  or  Access  Providers   on  offences  committed  by  users  of  their  service,  if  the  ICT  provider  –       • did  not  initiate  the  transmission;     • did  not  select  the  receiver;  and       • did  not  modify  the  information  contained  in  the  transmission.       The   criminal   responsibility   of   Caching   Providers   should   likewise   be   limited,   if   liability   exists,  for  the  automatic,  intermediate  and  temporary  storage  of  information.         Similarly,   responsibility   and   or   liability   for   Hosting   Providers   should   be   limited   by   the   framework,  in  cases  where  the  provider  has  no  actual  knowledge  about  the  existence  of   illegal  data  or  immediately  removes  them  upon  acquiring  such  knowledge.     Legislation   should   also   specify   the   responsibility   and   or   liability   of   Search   Engine   Providers  and  Hyperlink  Providers.         As   part   of   the   terms   and   conditions   of   their   license,   ICT   service   providers   shall   have   interception   capabilities   and   to   bear   the   costs   of   assisting   in   investigations   in   using   such   capabilities.     Given  the  qualified  degree  of  responsibility  for  ICT  service  providers,  legislation  should   prescribe  if  and  for  what  period  of  time,  ICT  service  providers  need  to  preserve  data  and   or  content.    Further,  the  Government  considers  it  necessary  that  ICT  service  providers  be   obligated   to   report   suspicious   behaviour   and   to   require   a   registration   prior   to   making   their  services  available.         P | 21

Select target paragraph3