50 CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA adopted in Malabo in June 2014.4 That treaty reflects a strong commitment by Member States of the African Union to establish a secure and trusted foundation for the information society. It covers a broad range of measures ranging from electronic transactions, to the protection of personal data, cyber security and also cyber crime. Given that this treaty is rather new and is yet to be tested in practice, and given its broad scope, the present report uses the Budapest Convention on Cyber Crime5 as reference. This Convention is more specifically focusing on cyber crime and electronic evidence, including international cooperation, and is increasingly being used in Africa. The Convention on Cyber Crime was opened for signature in Budapest, Hungary, in 2001. Elaborated by the Council of Europe with the participation of Canada, Japan, South Africa and the USA it is open for accession by any State prepared to implement it and to engage in international cooperation. By April 2016 it had 49 Parties and a further 17 States that had been invited to accede or have signed it. The Budapest Convention is backed up by the Cyber Crime Convention Committee representing the Parties to this treaty and capacity building programmes.6 It would seem that the African Union Convention on Cyber Security and Personal Data Protection and the Budapest Convention on Cyber Crime complement each other. Concepts and Definitions In terms of concepts and definitions, States should define “computer system” in a broad sense to encompass also devices such as smart phones, tablets or others while remaining technology neutral. Article 1.a of the Budapest Convention offers an example.7 Similarly, for criminal law purposes, “service providers” should comprise all types of service providers as proposed in Article 1.c Budapest Convention. While a general definition of “computer data” will be required (see Article 1.b), a specific definition of “traffic data” should be foreseen (see Article 1.d). In criminal investigations, the data most often needed is “subscriber information”. This type of information is less privacy-sensitive than traffic or content data. It will, therefore, be useful to define “subscriber information” separately so that a lighter regime for access to and sharing of subscriber information can be established while traffic and in particular content data require stricter safeguards. Article 18.3 Budapest Convention offers a definition of “subscriber information”. Substantive Criminal Law: Conduct to Be Defined as a Criminal Offence In terms of substantive law States should criminalise illegal access, illegal interception, data interference, system interference, misuse of devices, computer-related forgery, computer-related fraud, child pornography and offences related to infringements of copyright and related rights. Substantive criminal law under the Budapest Convention on Cyber Crime 4 5 6 7 Article 2 Illegal access to a computer system Article 3 Illegal interception of non-public transmissions to, from or within a computer system Article 4 Data interference Article 5 System interference Article 6 Misuse of devices https://ccdcoe.org/sites/default/files/documents/AU-270614-CSConvention.pdf http://conventions.coe.int/Treaty/Commun/QueVoulezVous.asp?NT=185&CM=8&DF=&CL=ENG In 2014, a dedicated Cyber Crime Programme Office of the Council of Europe became operational in Bucharest, Romania, and is responsible for capacity building programmes on cyber crime and electronic evidence worldwide. See also the Guidance Note on the notion of “computer system“ http://www.coe.int/en/web/cybercrime/guidance-notes

Select target paragraph3