Section III HIPCAR – Cybercrime/e-Crimes Section 14: Identity-Related Crimes This provision covers major phases of the typical identity-related crimes. Only the phase of obtaining identity-related information is not covered by this provision, such act is covered by other provisions contained in Part II of the Legislative Text. The term “transfer” covers data transmission processes from one computer to another computer system. This is relevant if databases with identity-related information that have been illegally obtained are transferred to crime groups which organize the sale of such information. “Possession” is the control a person intentionally exercises towards identity-related information. “Use” covers a wide range of practices such as submitting such information for purchase online. It is necessary that the offender intentionally carries out the act and in addition has special intent to commit, aid or abet an offence. Section 15: SPAM This provision addresses the issue of SPAM by criminalising three (3) of the main acts that most SPAM distributions have in common. In addition to limiting the criminalisation to three major acts, the offender can only be prosecuted if the act affects commerce. Variation a) covers initiating the transmission of multiple electronic mails. This criminalises the transfer of mass mailings without the permission of the recipient. The limitation of criminalization to acts carried out without lawful excuse or justification, plays an important role in distinguishing between legitimate mass mailings (like newsletters) and illegal SPAM. Variation b) criminalises the circumvention of anti-SPAM technology by abusing protected computer systems to relay or transmit electronic messages. It is necessary that the offender acts intentionally with regard to deceiving or misleading the recipient or the providers involved. Variation c) covers the circumvention of anti-SPAM technology by falsifying header information. Depending on the kind of manipulation such act can also be covered by Section 11 of the legislative text. Section15 requires that the offender carries out the offences intentionally and without lawful excuse or justification. Therefore authorized computer testing shall not be criminalized. Due to differing opinions about the necessity to criminalize the distribution of SPAM the drafters decided create the discretion for countries to opt to not criminalize such conduct in Section 15 (2)(a) provided that other effective remedies are available. Section 16: Disclosure of Details of and Investigation Confidentiality of investigations can be from great importance having regard to the aims and strategies employed in conducting such activities. This is particularly relevant if investigations have not yet been concluded and the relevant evidence in question could be modified. In this respect this measure accommodates the needs of law enforcement to ensure that the suspect of the investigation is not made aware of the investigation, as well as the right of individuals to privacy. The latter is included to protect the privacy of the data subject or other persons who may be mentioned or identified in that data. Section 17: Failure to provide assistance On many occasions law enforcement agencies are dependent upon the assistance of system administrators and other persons with specific knowledge in order to identify the storage location of relevant evidence or in order to obtain access to information stored. Section 20 establishes a coercive measure to facilitate the search and seizure of computer data. Section 17 establishes the consequences for the failure to comply with such obligation. “Failure” in this regard requires that the offender was objective and personally capable of following the order. > Model Policy Guidelines & Legislative Text 39

Select target paragraph3