Section III
HIPCAR – Cybercrime/e-Crimes
(2) different approaches: Based on Section 25(1), any person in control of traffic data can be ordered to
either collect or record such data or permit and assist a police officer to collect or record such data.
Section 25(2) contains a warrant that authorises a police officer to undertake the collection of traffic data.
As the collection of traffic data was as controversially discussed as the interception of content data the
drafters decided to highlight that countries may in the exercise of their discretion decide not to
implement Section 25.
Section 26: Interception of Content Data
In some cases the collection of traffic data is not sufficient in order to secure the successful conviction of
the suspect. This is especially relevant in those cases where investigators already know the
communication partner and the services used but have no information about the information exchanged.
The drafters decided to include a provision enabling the interception of data communication. To ensure a
harmonised approach the provision was drafted in accordance with the model legislative text on
interception of communication.
Section 26 contains two (2) different approaches. Based on Section 26(a) an ISP can be ordered to record
or collect content data. Sec. 26(b) enables law enforcement authorities to carry out the interception. As
the provision was controversially discussed within the working group, the drafters decided that countries
may decide not to implement Section 26.
Section 27: Forensic Software
During the discussion within the working group the drafters analysed sophisticated investigation methods.
After intensive discussion the drafters decided to include a provision authorising investigators to utilize
remote forensic software to collect relevant evidence. The drafters recognised that the process is very
intrusive and could potentially interfere with fundamental rights of the suspect the drafters decided to
include a number of restrictions. Firstly, the use of such software requires that evidence can not be
collected by applying other processes. Secondly, an order by a judge or magistrate is required. Thirdly the
application needs to contain four key information (Section 27(1)(a)-(d). In addition the authorised acts are
limited by both paragraph 1 and 2. The drafters decided to enable countries to implement further
restrictions by limiting the application of the instrument to crimes contained in a list Section 27(7) or not
implement this provision (Section 27(8)).
PART V
Section 28: No Monitoring Obligation
Internet providers up to a certain degree have the theoretical technical possibility to monitor activities
related to their services. Without a clear regulation there is an uncertainty if there is an obligation to
monitor activities and if the providers could be prosecuted based on a violation of the obligation to
monitor users activities. Apart from possible conflicts with the data protection regulations and the secrecy
of telecommunication, such obligation would especially cause difficulties for hosting providers that store
thousands of websites. To avoid these conflicts Sec. 28 excludes a general obligation to monitor the
transmitted or stored information. The provision solely limits the liability of providers with regard to
criminal liability.
44
> Model Policy Guidelines & Legislative Text