Cybersecurity guide for developing countries Ireland: Iceland: Israel: Italy: Japan: Luxembourg: Norway: New Zealand: Netherlands: Poland: Portugal: Czech Republic: United Kingdom: Russia: Slovenia: Sweden: Switzerland: Taiwan: I.2.9.4 Law of 13 July 1988 Law on the recording of personal information, 1981 Law on the protection of privacy, 1981, 1985, 1996; Law on the protection of information in the administration, 1986 Law of 31 December 1996 Law on the protection of computerized personal information, 1988 Law of 31 March 1979 Law on personal data records, 1978 Law on official information, 1982 Law of 28 December 1988 Law on the protection of personal information, 1997 Law of 29 April 1991 Law on the protection of personal information in computerized systems, 1995 Law of 12 July 1988 Federal law on information, informatization and the protection of information Law on the protection of information, 1990 11 May 1973 Federal law on the protection of information, 1992 Law on the protection of information, 1995 International cybercrime legislation The first international convention set up to address the international character of cybercrime was the Council of Europe “Convention on Cybercrime”10 adopted in Brussels on 23 November 2001, which entered into force in July 2004 (following its ratification by five of the signatory countries, at least three of which had to be from the Council of Europe). The convention contains the following points. – Substantive criminal law: • offences against the confidentiality, integrity and availability of computer data and systems; • computer-related offences; • offences related to infringements of copyright and related rights. – Procedural law: • expedited preservation of computer and traffic data and rapid disclosure of the latter to the competent authorities; • preservation and maintenance of the integrity of computer data for a period of time as long as necessary to enable the competent authorities to seek its disclosure; • production order; • search and seizure of stored computer data; • real-time collection of computer data; • the adequate protection of human rights and liberties. – Each State has to adopt the necessary legislative and other measures to establish jurisdiction over the following offences, without prejudice to its domestic law: • when committed intentionally, the access to the whole or any part of a computer system without right; • when committed intentionally, the interception without right of non-public transmissions of data to, from or within a computer system; 10 www.conventions.coe.int/Treaty/FR/Treaties/Html/185.htm Cybersecurity 19

Select target paragraph3