9/3/2014 cyber.police.ir - Iran Chapter 2- Collecting Digital Evidence Title 1- preservation of traffic data Art 32- Access service providers are obligated to preserv the traffic data at least until 6 month after the creation thereof and the users’ information at least 6 months form termination of the subscription. Note 1: The term “Traffic Data” refers to any data that computer systems generates in computer and chain of telecommunication chain make their trace from origin to destination possible. These data include information such as origin, path, date, time, duration, and volume [mass/ size] of communications and the type of the relevant services. Note 2: The term “User Information” refers to any information related to user of access services including the type of services, technical facilities used, duration, identity, geographical or postal address or internet protocol (IP), telephone number, and other individual characteristics of the user. Art 33- Domestic host service providers are obligated to retain their users’ information at least until 6 months, and the stored content and traffic data resulted from the occurred changes at least until 15 days from termination of subscription. Title 2- Expedited preservation of the Stored Computer Data Art 34- Whenever preservation of stored computer data is necessary for doing investigations or judgments, the judicial authority is empowered to issue the preservation order addressed to any persons who, anyhow, have them under their control or possession. In urgent cases, including [such as] danger of damage, alteration, or destruction of data, judicial officers are empowered to, on their own initiative directly issue the preservation order, and then inform the judicial authority of the actions carried out within 24 hours. In the event that any of the governmental staffs, judicial officers, or other persons refuse to execute the order, disclose the preserved data, or inform the persons to whom the aforesaid data is related to the provisions of the issued order, governmental staffs and judicial officers shall be punished by refusal of executing the judicial authority’s order, and other persons shall be punished by a term of 91 days to 6 months imprisonment, or by a fine of 5,000,000 to 10,000,000 Rials, or by both the imprisonment and fine. Note 1: Data preservation is not equal to presentation or disclosure thereof, and demands necessitates observance of the relevant laws and regulations. Note 2: the data protection duration is not to exceed 3 months, and in case of necessity, is extendable by means of the judicial authority’s order. Title 3- Data Presentation Art 35- The judicial authority is empowered to issue the order of presentation of data mentioned in articles (32), (33), and (34) above addressed to aforesaid persons to put (the data) at the disposal of the officers. Refusal of executing the order shall be punished by the punishment provided in article (34) of the present act. Title 4- Data and Computer and Telecommunication Systems’ Search and Seizure Art 36- Data or computer and telecommunications systems’ search and seizure shall be performed by virtues of the judicial order, in cases there is a strong suspicion concerning discovering the crime, or identifying the criminal or crime evidences. Art 37- Data or computer and telecommunications systems’ search and seizure shall be performed at the presence of the legal possessors or persons, anyhow, have them under their control, including system operators. Otherwise, the judge shall issue the order of search and seizure without the presence of the mentioned persons. Art 38- the search and seizure order must contain the information which aids the accurate execution thereof, including order execution in/out of the location, the qualifications and scopes [limits] of search and seizure, type and extent of the considered data, type and number of the hardware and software, the method of accessing the encrypted or deleted data, and the approximate time needed for accomplishment of search and seizure. Art 39- Data or computer and telecommunication systems’ search and seizure includes the following measures: A) B) C) Gaining access to computer and telecommunication systems, in whole or in part; Gaining access to data carriers including diskettes, compact discs, or memory discs; Gaining access to encrypted or deleted data. Art 40- In data seizure, proportionately considering the type, importance, and role of data in committing crime, methods including data printing, copying or imaging data -in whole or in part, making data inaccessible by means of techniques including changing passwords, encryption, and confiscation seizure of data carriers are practiced. Art 41- in any of the following cases, the computer or telecommunication systems shall be seized: A) B) The stored data is not conveniently accessible, or is in large volume Search and analysis of data is not possible without having access to hardware system; C) The legal possessor of data has given his/her consent; D) Copying data is not technically possible; E) In-place search causes damage to data. Art 42- Seizure of the computer or telecommunication systems is performed proportionately considering their type, importance, and role in committing crime, and by means of methods including changing passwords to cause lack of access to the system, in-place plumping, and seizure of the system. Art 43- in case of necessity of seizure of the data relevant to the committed crime existing in other computer or telecommunication systems which are)under control or possession of the accused, during seizure process, the officers –by the order of the judicial authority- shall expand the width of search and seizure to the mentioned systems, and take actions to search or seize the considered data. Art 44- Seizure of the data, or computer or telecommunication systems, in the event of causing physical injury or severe economic damages to individuals, or disruption to public services provision, is forbidden. Art 45- In cases that the original data is seized, the beneficiary is entitled to, after paying the cost, make a copy of them; provided that the presentation of the seized data is not concerned criminal or contrary to confidentiality of the investigations, and does not affect the procedure thereof. Art 46- in cases that the original data or computer or telecommunication system are seized, the judge is obligated to, considering the type and volume of data, type and number of the considered hardware and software, and their role in committed action , make decisions about them within a reasonable period of time. Art 47- The affected person is entitled to deliver his/her objection in writing with regard to the actions and measures taken by officers in search and seizure of data and computer and telecommunication systems, along with the reasons of the objection, to the judicial authority issuing the order. The mentioned objection shall be examined out of turn, and the decision shall be appealable. Title 3- Interception the Content data Art 48- intercepting the content of non-public communications in transit between computer or telecommunication systems shall be pursuant to the laws and regulations respecting interception of telephone conversations. Note: Gaining access to the content of stored non-public communications, including e-mail or short message sevice, is tantamount to intercepting, and necessitates http://cyber.police.ir/?siteid=46&pageid=632 4/5

Select target paragraph3