in 2007, consideration by Senior Officials at their Meetings in 2007 and 2008, consultation
with governments with responses from 15 countries19, a further Working Group Meeting of
Senior Officials and Practitioners of Commonwealth countries meeting in January 2010 at
which representatives at a high policy-making level from 22 countries attended20. After
further work by a Drafting Committee and consideration by Senior Officials, the revised
Scheme was adopted by Law Ministers in 2011.
2.18 The revision of the Harare Scheme in 2011 introduced material on taking evidence or
statements from persons, including through live video link or other audiovisual means
(paras. 1(5)(b)) and 14), the preservation of computer data (para. 20), the interception of
telecommunications (paras. 22 and 23), the interception of transmission data (para. 24), the
disclosure of intercept material (para. 25), surveillance, including covert electronic
surveillance (para. 26), and the provision of subscriber information (para. 28). Although there
are differences of language, for example ‘transmission data’ rather than ‘traffic data’, the
provisions of the Harare Scheme correspond to article 27 to 34 of the Budapest Convention
which set out mutual assistance procedures to be applied in the absence of applicable
international agreements.
Recommendation concerning the Model Law and the Harare Scheme
2.19 The Group, having assessed the Model Law and the recently-revised Harare Scheme,
finds that they continue to provide Commonwealth countries with a sound basis for the core
provisions of their cybercrime legislation. There is no need at present for the revision of the
Model Law. However, the Group recognises that, given the rapid evolution of cybercrime,
some supplementation may in future be judged necessary. It would urge those
Commonwealth countries which have not already adopted legislation based on the Model
Law to consider doing so with a degree of urgency. The Group notes that an expert group
convened by the Commonwealth Secretariat is preparing a Model Law to give effect to the
revised Harare Scheme with a view to its adoption by Law Ministers in 2014.
2.20 Although the wide adoption of legislation inspired by the Model Law would be of great
value at the national level, the international dimension can only be legally secure if it is dealt
with in a binding international instrument.
The Budapest Convention
2.21 As noted above, the Commonwealth provisions, in the Model Law and the Harare
Scheme, are closely related to the Budapest Convention21. The Convention was drawn up
by the Council of Europe with the active participation of the United States, Canada, Japan,
and South Africa, and was adopted by the Committee of Ministers of the Council of Europe
in November 2001. It entered into force on 1 July 2004. The negotiation and adoption of the
Convention itself was based on more than a decade of discussions in the UN, G-8, OECD
and a range of other European and non-European fora which were also used in various
ways as Commonwealth resources22. To some extent the typology of crimes and inventory
19
Australia, Botswana, Cameroon, Canada, The Gambia, Ghana, Isle of Man, India, Jamaica, Malaysia,
Montserrat, New Zealand, Singapore, South Africa and the United Kingdom.
20 Australia, Bangladesh, Brunei Darussalam, Cameroon, Canada, The Gambia, Ghana, Jamaica, Kenya,
Malawi, Malaysia, Mauritius, Mozambique, Namibia, Nigeria, Singapore, South Africa, Sri Lanka, Trinidad and
Tobago, the United Kingdom, Tanzania and Zambia.
21 Council of Europe Convention on Cybercrime, C.E.T.S. No.185, in force 1 July 2004. Text available at
http://conventions.coe.int/Treaty/en/Treaties/Html/185.htm, See also (2002) 41 I.L.M. 282.
22 For a summary of multilateral efforts prior to the Budapest Convention, see M A Sussmann, “The critical
challenges from international high-tech and computer-related crime at the millennium”, (1999)9 Duke Journal of
Comparative and International Law, 451 at 476-88.
29