Section I
HIPCAR – Cybercrime/e-Crimes
2.
CARICOM/CARIFORUM COUNTRIES SHALL DEVELOP SUBSTANTIVE CRIMINAL LAW DEALING WITH
CYBERCRIME
•
There shall be provisions covering the most common and internationally widely accepted forms of
Cybercrime as well as those offences that are of specific interest for the region (such as for example
SPAM).
•
To ensure the ability to cooperate with law enforcement agencies from countries in the region as
well as outside the region the legislation shall be compatible to both international standards and
best practices as well as (up to the largest extent possible) to existing regional standards and best
practices.
•
There shall be a provision criminalizing the intentional and illegal access to a computer system as
well as illegally remaining in a computer system. An aggravation of penalty in cases where protection
measures were circumvented to intercept the transmission could be taken into consideration.
•
There shall be a provision criminalizing the intentional and illegal interception of non-public data
transmission (illegal interception). This provision should not hinder a lawful interception by
competent authorities. An aggravation of penalty in cases where protection measures were
circumvented to intercept the transmission could be taken into consideration.
•
There shall be a provision criminalizing intentional and illegal interference with computer data. It
should be ensured that the application of procedural instrument necessary for investigations is not
hindered in cases where the offender commits several offences and each only leads to limited
damage.
•
There shall be a provision criminalizing intentional and illegal interference with computer systems
(such as denial of service attacks). An aggravation of penalty in cases where critical infrastructure is
affected could be taken into consideration.
•
There shall be a provision criminalizing intentional and illegal production, sale and related acts of
tools that are primarily designed to commit computer crimes. It should be ensured that such
legislation does not criminalize the legitimate use of such software tools.
•
There shall be a provision criminalizing intentional and illegal computer-related forgery. It should be
ensured that such legislation especially covers acts of sending out phishing emails. An aggravation of
penalty in cases where numerous emails are sent out should be taken into consideration.
•
There shall be a provision criminalizing intentional and illegal computer-related fraud.
•
It should be ensured that existing legislation criminalizing fraud is also applicable if offenders are
using means of electronic communication to communicate with the victim.
•
There should be a provision criminalizing the intentional and illegal production, sale and related acts
related to child pornography. Especially in this respect international standards should be taken into
consideration. The legislation should in addition cover the criminalization of the possession of child
pornography and gaining access to child pornography websites. An exemption that enables law
enforcement agencies to carry out investigations should be included.
•
There should be a provision criminalizing acts related to sending out SPAM if it affects the ability of
users to make use of Internet access.19
•
The legislation should reflect the challenges related to attribution.
•
There should be a provision criminalizing intentional and illegal acts of identity-related crime. The
different phases of identity theft (obtaining, transferring and using identity-related information)
should be taken into consideration
19
(There remains a concern about the proportionality of the remedy)
12
> Model Policy Guidelines & Legislative Text