C.2. Computer Crimes
The Computer Crimes Act No. 24 of 2007 provides for the identification of computer
crimes and stipulates the procedure for the investigation and enforcement of such crimes.
The Bill was presented in Parliament and debated on 23rd August 2005 and thereafter
extensively revised by the Parliamentary Standing Committee “B”. It was enacted as
legislation in May 2007 and certified by the Speaker of Parliament on 9th July 2007.
The basis of the Computer Crimes Act No. 24 of 2007 is to criminalise attempts at
unauthorised access to a computer, computer programme, data or information. It also
contains a provision to deal with unauthorised use of computers regardless of whether the
offender had authority to access the computer.
The Act creates offences for unauthorised modification, alteration or deletion of
information and denial of access, which makes it an offence for any person to program the
computer in such a manner so as to prevent authorised persons from obtaining access.
Other offences sought to be created under the proposed Act include causing damage or
harm to the computer by the introduction of viruses and logic bombs etc, unauthorised
copying of information, unauthorised use of computer service and interception of a
computer programme, data or information while it is been transmitted from one computer
to another.
The Act introduces a new regime for the investigation of offences. Provisions have been
made in the Act to designate a panel of ‘Experts’ to assist the Police in the investigation of
computer crime offences.
C.3. Data Protection
Data protection rules have become an increasingly important legal regime in an
information age where personal data has become a significant asset of many companies,
especially those operating over the Internet. However, in a connected global economy,
national data protection rules can be easily circumvented and protections granted to the
citizens lost as data is transferred out of the jurisdiction. In an attempt to prevent such
circumvention, the EU data protection regime contains provisions controlling the transfer of
personal data to non-EU countries, such as Sri Lanka.
At present the Government is pursuing a policy based on the adoption of a Data
Protection Code of Practice, encompassing the private sector, with the possibility of the
code being placed on a statutory footing through regulations issued under the Information
and Communication Technology Act of 2003. As such, this approach can be seen as self- or
co-regulatory approach. (Refer section 0103)
C.4. Intellectual Property Rights (IPR)
As regards the protection of intellectual property rights (IPR), the Intellectual Property
Act no. 36 of 2003 replaced the Code of Intellectual Property Act no. 52 of 1979. The IP Act
of 2003 contains several new features in relation to the protection of software, trade secrets
and integrated circuits. (Refer Sections 0204 and 0205 of this document for detail)
5