A. International Cooperation As cybercrime defies traditional notions of geography and mobility, traditional definitions of jurisdiction have become insufficient. As discussed further on, various efforts have been undertaken to mitigate harder, limiting notions of jurisdiction (see sections 2 E and 3 A, below). Certain international legal instruments have been influential in harmonizing legislation.70 European instruments have been particularly impactful on national legislations, especially the CoE Convention on Cybercrime (commonly known as the “Budapest Convention”),71 which has had an impact on legislation even in those states that have not ratified it; the European Council Framework Decision 2005/222/JHA on attacks against information systems72; and European Council Framework Decision 2004/68/JHA on the sexual exploitation of children and child pornography.73 The EU Data Retention Directive 2006/24/CE74 has also had a great impact; however, on 8 April 2014, the Court of Justice of the European Union (CJEU) declared the Directive invalid in response to a case brought against Irish authorities.75 In general, there has been a remarkable degree of convergence of various multilateral instruments on cybercrime in criminalizing acts against the confidentiality, integrity and availability of computer data and systems. In addition to the aforementioned European measures, multilateral instruments connected with the African Union (AU), the League of Arab States(Arab League), the Economic Community of West African States (ECOWAS), the Common Market for Eastern and Southern Africa (COMESA), the Commonwealth Secretariat (COMSEC) and the International Telecommunications Union (ITU) all criminalize illegal access to: a computer system, illegal interception, illegal computer data and system interference and the misuse of devices.76 On the other hand, other offences, such as illegally remaining in a computer system to date, have received considerably less support. Remarkably, identity theft has not been universally condemned in multilateral instruments, nor have extortion, spam, harassment, stalking or bullying.77 Other areas receiving little demand to be classified as crimes in international treaties include: ƒƒ Violation of data protection measures for personal information; ƒƒ Breach of confidentiality; ƒƒ Use of forged or fraudulently obtained data; ƒƒ Illicit use of electronic payment tools; ƒƒ Acts against privacy; disclosure of details of an investigation; and ƒƒ Failure to permit assistance. 78 When it comes to computer-related acts, two categories—forgery and fraud—are widely criminalized, although neither the CIS nor the COMSEC have criminalized such actions. Computer solicitation or grooming of children has been included only in the CoE Convention on Protection of Children against Sexual Exploitation and Sexual Abuse (the “Lanzarote Convention”),79 the first Page 37 | Chapter 1 | § C. Challenges to Fighting Cybercrime Table of Contents

Select target paragraph3