Budapest Convention28.
2.26 This judgment is in line with the support for the Budapest Convention from bodies such
as the European Union in its Stockholm Programme29, and the Financial Action Task Force
(FATF)30. In 2011, following the meeting of Commonwealth Law Ministers, the ‘Quintet’ of
Attorneys-General from Canada, the United States, the United Kingdom, New Zealand and
Australia met in Sydney to develop an action plan to address the significant and growing
issue of cybercrime. In their Action Plan to Fight Cyber Crime (2011) they concluded that all
Quintet countries should
‘take steps to become parties to the Convention; consider how the Convention can
assist Quintet countries to share information and help to solve practical issues, and
promote the Convention as the key international instrument for dealing with cybercrime
and use the Convention as a basis for delivering capacity building and awareness
raising activities’.
Other international instruments
2.27 The Group is aware of a number of other instruments, proposed or already in
existence, which address issues similar to those in the Commonwealth Model Law and the
Budapest Convention. Some have, for geographical reasons, no relevance to
Commonwealth member states. They include the Agreement on Co-operation in Combating
Offences related to Computer Information drawn up in 2001 by the Commonwealth of
Independent States (made up of states formerly within the Soviet Union); the Arab
Convention on Combating Information Technology Offences of 2010; and the Shanghai Cooperation Organisation Agreement on Co-operation in the Field of International Information
Security (2009). The European Union has been active in related areas, both in producing
legislation31 and in the establishment in 2013 of the European Cybercrime Centre in The
Hague, but there are only three Commonwealth member countries (Cyprus, Malta and the
UK) within the Union.
Recent developments: the Caribbean, the Pacific and Africa
2.28 Of much greater relevance to Commonwealth member countries are developments in
the Caribbean, the Pacific and Africa.
2.29 In the Caribbean, with support from the ITU and the European Commission, the
HIPCAR project developed a Model Policy Guidelines and a Model Legislative Text32 on
28
In view of the continuing work of the open-ended expert group on cybercrime established by the General
Assembly, UNODC cannot endorse this recommendation.
29 Section 4.4.4.
30
FATF Recommendation 36 encourages States to ratify and implement other relevant international conventions,
such as the Council of Europe Convention on Cybercrime, 2001.
31 Directive 2000/31/EC of the European Parliament and of the Council on certain legal aspects of information
society services, in particular electronic commerce, in the Internal Market; Council Framework Decision
2001/413/JHA combating fraud and counterfeiting of non-cash means of payment; Directive 2002/58/EC of the
European Parliament and of the Council concerning the processing of personal data and the protection of privacy
in the electronic communications sector; Council Framework Decision 2005/222/JHA on attacks against
information systems (with a proposal for a replacement Directive in 2010); and Directive 2006/24/EC of the
European Parliament and of the Council on the retention of data generated or processed in connection with the
provision of publicly available electronic communications services or of public communications networks.
32 See http://www.itu.int/en/ITU-D/Cybersecurity/Documents/HIPCAR%20Assessment%20Cybercrimes.pdf and
http://www.itu.int/en/ITU-D/Cybersecurity/Documents/HIPCAR%20Model%20Law%20Cybercrimes.pdf
31