Cybersecurity guide for developing countries – – the absence of appropriate categories, in some jurisdictions; the inadequate definition and transient nature of most IT-related evidence. For all of these reasons, the legal system remains ineffective in the context of the internet. Furthermore, just as there are tax shelters, so there are legal safe havens. The proliferation of computer-related crime is not necessarily a sign that there are not enough laws. Existing laws already cover many of the activities of IT criminals and hackers. What’s illegal offline, is also illegal online New legislation, born of the need to define a suitable legal framework adapted to the use of new technologies, is needed to complement many of the existing laws, which, of course, also apply in cyberspace. It is not enough to strengthen legislation, if the means to apply it are not there. A law is of little use if law enforcement is not up to the task of gathering and analysing evidence and identifying and prosecuting the perpetrators of criminal acts. If hackers are confident that they will escape punishment, that is proof that the law is ineffective. I.2.9.3 Combating cybercrime while respecting digital privacy: a tricky compromise The means needed to combat the growing international scourge of cybercrime require a legal framework that has been harmonized at the international level and can be applied effectively, along with the means for true international cooperation at the level of the police and justice authorities. National governments have important responsibilities in ensuring cybersecurity. This is particularly true for the definition of the suitable legal framework, i.e. one that is uniform and applicable, for the promotion of a security culture that will respect individuals’ right to digital privacy while strengthening efforts to combat cybercrime. The struggle against cybercrime must have as its principal objective the protection of individuals, organizations and countries, bearing in mind the fundamental principles of democracy. The tools used to combat cybercrime are potentially inimical to human rights, and may undermine the privacy of personal information. Security requires surveillance, verification and profiling. Checks and balances are essential if abuses of power and of position are to be prevented, the temptation of totalitarian methods resisted, and respect of basic rights guaranteed, including the right to cyberprivacy and the protection of confidential personal information. In addition to the European directive of 1995, other laws for the protection of personal information have been on the books in various countries for a number of years: Germany: Law of 21 January 1977 Argentina: Law on the protection of personal information, 1996 Austria: Law of 18 October 1978 Australia: Law on privacy, 1978 Belgium: Law of 8 December 1992 Canada: Law on the protection of private information, 1982 Denmark: Law of 8 June 1978 Spain: Law of 29 October 1992 United States: Law on the protection individual freedoms, 1974; Law on databases of private information, 1988 Finland: Law of 30 April 1987 France: Law on information technology and liberty of 6 January 1978, amended in 2004 Greece: Law of 26 March 1997 Hungary: Law on the protection of personal information and the communication of public information, 1992 18 Cybersecurity

Select target paragraph3