Papua New Guinea Cybercrime Policy 2014 efficient   conduct   of   investigations   while   maintaining   the   protection   of   an   individual’s   fundamental  human  rights.         • The   legislation   should   enable   competent   authorities   to   order   the   expedited   preservation   of   electronic   data,   as   well   as   the   partial   disclosure   of   preserved   electronic   data.     It   should   also   enable   competent   authorities   to   order   the   production  of  electronic  data.     • The   legislation   should   enable   competent   authorities   to   use   specific   search   and   seizure   instruments   related   to   electronic   evidence   and   technology.     It   should   regulate   search   and   seizure   proceedings   in   such   a   way   that   the   collection   of   evidence  and  treatment  of  the  surrounding  environment  from  which  the  evidence   is  extracted,  is  in  full  compliance  with  lawful  processes.     • Competent   authorities   should   be   enabled   to   order   the   lawful   collection   of   traffic   data  and  the  lawful  interception  of  content  data.         • In   cases   where   no   other   instrument   is   applicable,   competent   authorities   should   also   be   enabled   to   utilize   sophisticated   investigation   techniques   such   as   key-­‐ loggers  and  remote  forensic  software,  to  obtain  passwords,  data  used  by  a  suspect,   or  to  identify  the  connection  used  by  a  suspect.     d)   Jurisdiction     In   relation   to   the   difficulties   associated   with   the   application   of   traditional   principles   of   state  sovereignty  and  jurisdiction  to  the  elements  of  Cybercrime,  the  legislation  should   contain   the   requisite   provisions   dealing   with   jurisdiction   that   is   in   line   with   international   and  regional  best  practices.       2.     Harmonization     Harmonization   of   the   Cybercrime   legislation   with   those   of   other   countries   within   the   region   and   internationally   is   imperative.     Since   2000,   the   Commonwealth,   Common   Market   for   Eastern   and   Southern   Africa   (COMESA),   European   Union   (EU),   Council   of   Europe   (EC)   and   other   regional   organizations   have   introduced   legal   frameworks   and   model  laws  that  aim  to  harmonize  Cybercrime  legislation.     The  harmonization  of  legislation  is  widely  recognized  as  critical  in  the  global  endeavour   to   combat   Cybercrime.   The   reason   for   a   harmonization   of   legislation   is   mainly   that   a   number  of  countries  base  their  mutual  legal  assistance  regime  on  the  principle  of  dual   criminality.     Therefore,   if   a   country   develops   standards   that   fundamentally  differ   from   international   best   practices   this   can   effectively   preclude   such   country’s   ability   to   cooperate   on   an   international   level.     Further,   the   absence   of   applicable   and   enforceable   laws  in  a  country  can  lead  to  the  creation  of  safe  havens13.    The  existence  of  safe  havens   creates   the   threat   that   offenders   will   use   legislative   loop   holes   to   hamper   investigations   and  prosecution  of  offences.    One  well  known  example  of  such  occurrence  is  the  “Love                                                                                                                           13  This  issue  was  addressed  by  a  number  of  international  organizations.  The  UN  General  Assembly  Resolution  55/63  points  out:   “States  should  ensure  that  their  laws  and  practice  eliminate  safe  havens  for  those  who  criminally  misuse  information  technologies”.  The   full  text  of  the  Resolution  is  available  at:  http://www.unodc.org/pdf/crime/a_res_55/res5563e.pdf.  The  G8  10  Point  Action  plan  highlights:   “There  must  be  no  safe  havens  for  those  who  abuse  information  technologies”.  See  below:  Understanding  Cybercrime:  A  Guide  for   Developing  Countries,  ITU  2009,  Chapter  5.2.       P | 17

Select target paragraph3