Budapest Convention28. 2.26 This judgment is in line with the support for the Budapest Convention from bodies such as the European Union in its Stockholm Programme29, and the Financial Action Task Force (FATF)30. In 2011, following the meeting of Commonwealth Law Ministers, the ‘Quintet’ of Attorneys-General from Canada, the United States, the United Kingdom, New Zealand and Australia met in Sydney to develop an action plan to address the significant and growing issue of cybercrime. In their Action Plan to Fight Cyber Crime (2011) they concluded that all Quintet countries should ‘take steps to become parties to the Convention; consider how the Convention can assist Quintet countries to share information and help to solve practical issues, and promote the Convention as the key international instrument for dealing with cybercrime and use the Convention as a basis for delivering capacity building and awareness raising activities’. Other international instruments 2.27 The Group is aware of a number of other instruments, proposed or already in existence, which address issues similar to those in the Commonwealth Model Law and the Budapest Convention. Some have, for geographical reasons, no relevance to Commonwealth member states. They include the Agreement on Co-operation in Combating Offences related to Computer Information drawn up in 2001 by the Commonwealth of Independent States (made up of states formerly within the Soviet Union); the Arab Convention on Combating Information Technology Offences of 2010; and the Shanghai Cooperation Organisation Agreement on Co-operation in the Field of International Information Security (2009). The European Union has been active in related areas, both in producing legislation31 and in the establishment in 2013 of the European Cybercrime Centre in The Hague, but there are only three Commonwealth member countries (Cyprus, Malta and the UK) within the Union. Recent developments: the Caribbean, the Pacific and Africa 2.28 Of much greater relevance to Commonwealth member countries are developments in the Caribbean, the Pacific and Africa. 2.29 In the Caribbean, with support from the ITU and the European Commission, the HIPCAR project developed a Model Policy Guidelines and a Model Legislative Text32 on 28 In view of the continuing work of the open-ended expert group on cybercrime established by the General Assembly, UNODC cannot endorse this recommendation. 29 Section 4.4.4. 30 FATF Recommendation 36 encourages States to ratify and implement other relevant international conventions, such as the Council of Europe Convention on Cybercrime, 2001. 31 Directive 2000/31/EC of the European Parliament and of the Council on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market; Council Framework Decision 2001/413/JHA combating fraud and counterfeiting of non-cash means of payment; Directive 2002/58/EC of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector; Council Framework Decision 2005/222/JHA on attacks against information systems (with a proposal for a replacement Directive in 2010); and Directive 2006/24/EC of the European Parliament and of the Council on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks. 32 See http://www.itu.int/en/ITU-D/Cybersecurity/Documents/HIPCAR%20Assessment%20Cybercrimes.pdf and http://www.itu.int/en/ITU-D/Cybersecurity/Documents/HIPCAR%20Model%20Law%20Cybercrimes.pdf 31

Select target paragraph3