Section III
HIPCAR – Cybercrime/e-Crimes
targeted computer system no longer becomes available for potential lawful users as well as the owner of
the computer system. However a more specific provision (Section 9) was included to ensure the
criminalisation of such acts.
The suppression of computer data denotes an action that affects the availability of data to the person
with access to the medium, where the information is stored in a negative way.
Section 6 requires that the offender carries out the offences intentionally and without lawful excuse or
justification. The right to alter data was discussed, especially in the context of “remailers” that are used to
modify certain data for the purpose of facilitating anonymous communications. The intentional use of
such services is considered an authorisation for the necessary alterations.
Section 8: Data Espionage
The Convention on Cybercrime as well as the Commonwealth Model Law and the Stanford Draft
Convention provide legal solutions for illegal interception, but not for illegally obtaining data. It is
questionable whether Article 3 of the Convention on Cybercrime applies to other cases than those where
offences are carried out by intercepting data transfer processes.
Section 8 protects the secrecy of stored and protected computer data. Unlike other approaches this
section not only covers economic secrets, but also stored computer data in general. In terms of its objects
of protection, this approach is broad in nature, but the application of the provision is limited as obtaining
data is only criminalised where data are specially protected against unauthorised access. The special
protection requires that the hoster of the information has implemented protection measures that
significantly increase the difficulty of obtaining access to the data without authorisation. Examples are
password protection and encryption. It is necessary that the protection measures go beyond standard
protection measures that apply to data as well as other property, for example access restrictions to
certain parts of government buildings. On the other hand it is not necessary that the measures are
computer technology related. Even physical measures like locks enable the application of the provision.
The act of obtaining covers any activity undertaken by the offender to obtain possession of the relevant
data. This can for example be done by removing a storage device or copying files from the original source
to the offender’s storage device.
Section 9: System Interference
In order to protect access of operators and users to ICTs a provision was included that criminalizes the
intentional hindering of the lawful use of a computer system. This provision therefore aims to protect the
integrity of computer systems. The application of the provision requires that the offender hinders or
interferes the functioning of a computer system.
“Hindering” means any act that interferes with the proper functioning of a computer system. The term is
further defined in Section 3. The working group discussed whether the problem of spam e-mail could be
addressed under Section 5, since spam can overload computer systems. Due to the fact that the
application of a similar provision in the Convention on Cybercrime in relation to SPAM evinced challenges
the drafters decided to include a specific provision that addressed SPAM in Section 15. Section 9 requires
that the offender carries out the offences intentionally and without lawful excuse or justification. It
therefore stands to follow that authorised computer test shall not be criminalised.
Subparagraph 2 contains a regulation pertaining to an aggravated penalty if the offences affects critical
infrastructure. The functioning of computer system has become essential for the control of critical
infrastructure such as health care, transportation and energy supply. Subparagraph 2 therefore takes this
threat into consideration by providing the possibility to refer to higher penalties.
> Model Policy Guidelines & Legislative Text
35