14.8.2013
EN
Official Journal of the European Union
and security of information systems by legal persons, for
example in connection with the provision of publicly
available electronic communications services in
accordance with existing Union legislation on privacy
and electronic communication and data protection,
forms an essential part of a comprehensive approach to
effectively counteracting cybercrime. Appropriate levels
of protection should be provided against reasonably iden
tifiable threats and vulnerabilities in accordance with the
state of the art for specific sectors and the specific data
processing situations. The cost and burden of such
protection should be proportionate to the likely
damage a cyber attack would cause to those affected.
Member States are encouraged to provide for relevant
measures incurring liabilities in the context of their
national law in cases where a legal person has clearly
not provided an appropriate level of protection against
cyber attacks.
(27)
(28)
(29)
Significant gaps and differences in Member States’ laws
and criminal procedures in the area of attacks against
information systems may hamper the fight against
organised crime and terrorism, and may complicate
effective police and judicial cooperation in this area.
The transnational and borderless nature of modern
information systems means that attacks against such
systems have a cross-border dimension, thus underlining
the urgent need for further action to approximate
criminal law in this area. In addition, the coordination
of prosecution of cases of attacks against information
systems should be facilitated by the adequate implemen
tation and application of Council Framework Decision
2009/948/JHA of 30 November 2009 on prevention
and settlement of conflict of jurisdiction in criminal
proceedings (1). Member States, in cooperation with the
Union, should also seek to improve international
cooperation relating to the security of information
systems, computer networks and computer data. Proper
consideration of the security of data transfer and storage
should be given in any international agreement involving
data exchange.
Improved cooperation between the competent law
enforcement bodies and judicial authorities across the
Union is essential in an effective fight against cybercrime.
In this context, stepping up the efforts to provide
adequate training to the relevant authorities in order to
raise the understanding of cybercrime and its impact, and
to foster cooperation and the exchange of best practices,
for example via the competent specialised Union agencies
and bodies, should be encouraged. Such training should,
inter alia, aim at raising awareness about the different
national legal systems, the possible legal and technical
challenges of criminal investigations, and the distribution
of competences between the relevant national authorities.
This Directive respects human rights and fundamental
freedoms and observes the principles recognised in
particular by the Charter of Fundamental Rights of the
European Union and the European Convention for the
(1) OJ L 328, 15.12.2009, p. 42.
L 218/11
Protection of Human Rights and Fundamental Freedoms,
including the protection of personal data, the right to
privacy, freedom of expression and information, the
right to a fair trial, the presumption of innocence and
the rights of the defence, as well as the principles of
legality and proportionality of criminal offences and
penalties. In particular, this Directive seeks to ensure
full respect for those rights and principles and must be
implemented accordingly.
(30)
The protection of personal data is a fundamental right in
accordance with Article 16(1) TFEU and Article 8 of the
Charter on Fundamental Rights of the European Union.
Therefore, any processing of personal data in the context
of the implementation of this Directive should fully
comply with the relevant Union law on data protection.
(31)
In accordance with Article 3 of the Protocol on the
position of the United Kingdom and Ireland in respect
of the Area of Freedom, Security and Justice, annexed to
the Treaty on European Union and to the Treaty on the
Functioning of the European Union, those Member States
have notified their wish to take part in the adoption and
application of this Directive.
(32)
In accordance with Articles 1 and 2 of the Protocol on
the position of Denmark annexed to the Treaty on
European Union and to the Treaty on the Functioning
of the European Union, Denmark is not taking part in
the adoption of this Directive and is not bound by it or
subject to its application.
(33)
Since the objectives of this Directive, namely to subject
attacks against information systems in all Member States
to effective, proportionate and dissuasive criminal
penalties and to improve and encourage cooperation
between judicial and other competent authorities,
cannot be sufficiently achieved by the Member States,
and can therefore, by reason of their scale or effects,
be better achieved at Union level, the Union may
adopt measures in accordance with the principle of
subsidiarity as set out in Article 5 of the Treaty on
European Union. In accordance with the principle of
proportionality, as set out in that Article, this Directive
does not go beyond what is necessary in order to achieve
those objectives.
(34)
This Directive aims to amend and expand the provisions
of Council Framework Decision 2005/222/JHA of
24 February 2005 on attacks against information
systems (2). Since the amendments to be made are of
substantial number and nature, Framework Decision
2005/222/JHA should, in the interests of clarity, be
replaced in its entirety in relation to Member States
participating in the adoption of this Directive,
(2) OJ L 69, 16.3.2005, p. 67.