Section I HIPCAR – Cybercrime/e-Crimes 2. CARICOM/CARIFORUM COUNTRIES SHALL DEVELOP SUBSTANTIVE CRIMINAL LAW DEALING WITH CYBERCRIME • There shall be provisions covering the most common and internationally widely accepted forms of Cybercrime as well as those offences that are of specific interest for the region (such as for example SPAM). • To ensure the ability to cooperate with law enforcement agencies from countries in the region as well as outside the region the legislation shall be compatible to both international standards and best practices as well as (up to the largest extent possible) to existing regional standards and best practices. • There shall be a provision criminalizing the intentional and illegal access to a computer system as well as illegally remaining in a computer system. An aggravation of penalty in cases where protection measures were circumvented to intercept the transmission could be taken into consideration. • There shall be a provision criminalizing the intentional and illegal interception of non-public data transmission (illegal interception). This provision should not hinder a lawful interception by competent authorities. An aggravation of penalty in cases where protection measures were circumvented to intercept the transmission could be taken into consideration. • There shall be a provision criminalizing intentional and illegal interference with computer data. It should be ensured that the application of procedural instrument necessary for investigations is not hindered in cases where the offender commits several offences and each only leads to limited damage. • There shall be a provision criminalizing intentional and illegal interference with computer systems (such as denial of service attacks). An aggravation of penalty in cases where critical infrastructure is affected could be taken into consideration. • There shall be a provision criminalizing intentional and illegal production, sale and related acts of tools that are primarily designed to commit computer crimes. It should be ensured that such legislation does not criminalize the legitimate use of such software tools. • There shall be a provision criminalizing intentional and illegal computer-related forgery. It should be ensured that such legislation especially covers acts of sending out phishing emails. An aggravation of penalty in cases where numerous emails are sent out should be taken into consideration. • There shall be a provision criminalizing intentional and illegal computer-related fraud. • It should be ensured that existing legislation criminalizing fraud is also applicable if offenders are using means of electronic communication to communicate with the victim. • There should be a provision criminalizing the intentional and illegal production, sale and related acts related to child pornography. Especially in this respect international standards should be taken into consideration. The legislation should in addition cover the criminalization of the possession of child pornography and gaining access to child pornography websites. An exemption that enables law enforcement agencies to carry out investigations should be included. • There should be a provision criminalizing acts related to sending out SPAM if it affects the ability of users to make use of Internet access.19 • The legislation should reflect the challenges related to attribution. • There should be a provision criminalizing intentional and illegal acts of identity-related crime. The different phases of identity theft (obtaining, transferring and using identity-related information) should be taken into consideration 19 (There remains a concern about the proportionality of the remedy) 12 > Model Policy Guidelines & Legislative Text

Select target paragraph3