80. See, e.g., Additional Protocol to
the Council of Europe Convention
on Cybercrime Concerning the
Criminalization of Acts of a Racist and
Xenophobic Nature Committed through
Computer Systems, CoE (2003), at http://
conventions.coe.int/Treaty/en/Treaties/
Html/189.htm.
81. International Narcotics Control Board,
“Globalization and New Technologies:
Challenges to Drug Law Enforcement
in the Twenty-First Century,” (2001),
at https://www.incb.org/documents/
Publications/AnnualReports/AR2001/
AR_01_Chapter_I.pdf; ITU Understanding
Cybercrime, supra § 1 B, note 1, pp. 30–
40; Stefan Frederick Fafinski, “Computer
Use and Misuse: The Constellation of
Control,” Ph.D. Dissertation, University of
Leeds, School of Law, (2008), pp. 273–81.
82. See, e.g., “Europol Supports Huge
International Operation to Tackle
Organised Crime,” Europol, at https://
www.europol.europa.eu/content/europolsupports-huge-international-operationtackle-organised-crime.
83. Eric Neumayer, “Qualified Ratification:
Explaining Reservations to International
Human Rights Treaties,” Journal of Legal
Studies, Vol. 36 (2007), p. 397.
84. Budapest Convention, supra § 1 B, note
32, at Art. 42.
85. ITU Understanding Cybercrime, supra § 1
B, note 1, at 77–78.
86. For example, according to “Cybercrime
knows no borders” featured by
InfoSecurity Magazine in 2011, Invincea
founder Anup Ghosh notes that “Law
enforcement agencies don’t have
jurisdiction to prosecute outside their
borders, so they need bilateral or multilateral agreements to bring criminals to
justice. But often it is really just sharing
information with foreign law enforcement
agencies and hoping they will do
something about it.” For additional
information: Ibid.
87. See infra § 2 E.
88. Anthony J. Colangelo, “A Unified
Approach to Extraterritoriality,” Virginia
Law Review, Vol. 97 (2011), p. 1019.
89. United States v. Aleksandr Andreevich
Panin, a/k/a Harderman, a/k/a
Gribodemon, and Hamza Bendelladj,
a/k/a Bx1, (26 Jun. 2013) N.D. Ga., No.
1:11-cr-00557-AT-AJB Document 35.
Page 61 | Chapter 1 | End Notes
90. Christopher Budd, “Why the SpyEye
Conviction is a Big Deal,” Trend Micro,
(3 Feb. 2014), at http://blog.trendmicro.
com/spyeye-conviction-big-deal/.
91. “SpyEye Botnet Kit Developer Sentenced
to Long Jail Term,” PC World, (20 Apr.
2016), at http://www.pcworld.com/
article/3059557/spyeye-botnet-kitdeveloper-sentenced-to-long-jail-term.
html.
92. US Attorney’s Office, N.D. Ga., “Cyber
Criminal Pleads Guilty to Developing and
Distributing Notorious SpyEye Malware,”
(28 Jan. 2014), at https://archives.fbi.gov/
archives/atlanta/press-releases/2014/
cyber-criminal-pleads-guilty-todeveloping-and-distributing-notoriousspyeye-malware/.
93. “Two Major International Hackers Who
Developed the ‘SpyEye’ Malware Get
Over 24 Years Combined in Federal
Prison,” US Dept. of Justice, (26 Apr.
2016), at https://www.justice.gov/usaondga/pr/two-major-international-hackerswho-developed-spyeye-malware-getover-24-years-combined.
94. Ibid.
95. Ibid. See also US Attorney’s Office, supra
note 92.
96. UNODC Cybercrime Study, supra § 1 C,
note 7, at 108.
97. See infra § 5 A.
98. Fernando Molina, “A Comparison
between Continental European and
Anglo-American Approaches to
Overcriminalization and Some Remarks
on How to Deal with It,” New Criminal
Law Review, Vol. 14 (2011), p. 123;
Kimberly Kessler Ferzan, “Prevention,
Wrongdoing, and the Harm Principle’s
Breaking Point,” Ohio State University
Journal of Criminal Law, Vol. 10 (2013), p.
685, at http://ailadc.org/form.php?form_
id=12; Joel Feinberg & Robert P. George,
“Crime and Punishment: Moralistic
Liberalism and Legal Moralism: Harmless
Wrongdoing: The Moral Limits of the
Criminal Law,” Michigan Law Review, Vol.
88 (1990), p. 1415.
99. US Dept. of Commerce, Internet Policy
Task Force, Copyright, Creativity and
Innovation in the Digital Economy, (Jul.
2013).
100. Nina Persak, Criminalizing Harmful
Conduct: The Harm Principle, Its Limits
and Continental Counterparts, Springer
Science & Business Media, 2007.
101. The “harm” principle is fundamental to
John Stuart Mill’s approach to justifying
or rejecting the intervention of the
state through criminal law to prohibit,
deter and punish certain behaviors. In
On Liberty, Mill argues for “one very
simple principle, as entitled to govern
absolutely the dealings of society with
the individual in the way of compulsion
and control.” That principle is that “The
only purpose for which power can be
rightfully exercised over any member of
a civilized community, against his will, is
to prevent harm to others. His own good,
either physical or moral, is not a sufficient
warrant,” John Gray & G.W. Smith (eds.),
J.S. Mill on Liberty, (New York: Routledge,
2003), p. 90.
102. The principle is captured by the Latin
dictum “actus reus non facit reum nisi
mens sit rea” (“the act is not culpable
unless the mind is guilty”). See, e.g.,
Oxford Reference.
103. See, e.g., “Cyberla Tracker,” UNCTAD,
at http://unctad.org/en/Pages/DTL/
STI_and_ICTs/ICT4D-Legislation/eComData-Protection-Laws.aspx.
104. For instance, while an early leader in the
field of data protection, the US Privacy Act
1974 (USC Title 5, § 552a) applies only to
the Federal Government, and subsequent
laws applies to specific sectors, but there
is no comprehensive law to date.
105. “What Is Data Protection?,” Privacy
International, at https://www.
privacyinternational.org/node/44.
106. UN General Assembly, Universal
Declaration of Human Rights, (10
Dec. 1948) 217 A (III) [hereafter,
“UDHR”], at http://www.refworld.org/
docid/3ae6b3712c.html.
107. UN General Assembly, International
Covenant on Civil and Political Rights,
(16 Dec. 1966) United Nations, Treaty
Series, Vol. 999, p. 171 [hereafter,
“ICCPR”], at http://www.refworld.org/
docid/3ae6b3aa0.html.
108. OAS, American Convention on Human
Rights, (22 Nov. 1969), at http://www.
refworld.org/docid/3ae6b36510.html.
109. UN General Assembly, Report of the
Special Rapporteur on the promotion
and protection of the right to freedom of
opinion and expression, (10 Aug. 2011)
A/66/290, para. 10, at http://www.ohchr.
org/Documents/Issues/Opinion/A.66.290.
pdf.
110. UNODC Cybercrime Study, supra § 1 C,
note 7 at 110.
Table of Contents