include the use of a certificate issued by a third party certification authority or service
provider, similar in nature to the services provided by notary publics in EAC member
states. Due to the critical role of such entities in the security of the process, the
legislation will often establish a regulatory framework governing the provision of
such services. This framework may include a licensing or accreditation scheme
designed to control market entry. In addition, a raft of criteria will be laid down
concerning the manner in which the service provider operates, including the
attribution of liability in the event of a failure to meet the criteria.
Experience of such regimes to date, however, suggests that they are very complex and
difficult to implement and operate. As such, they have often proven unable to
facilitate secure electronic transactions.
The Task Force recommends that Partner States give consideration to granting
delegated authority to a specified government ministry or department to adopt
relevant secondary regulations concerning digital signatures and the provision of
certification services (R.13).
The Task Force makes the following additional recommendations in respect of
electronic signatures:
2.3
•
That Partner States provide for a statutory definition for ‘signatures’ and
‘electronic signatures’
•
That Partner States should support the principle of technology neutrality
and promote interoperability in respect of ‘electronic signatures’
technologies
•
That Partner States should identify and recognise internationally
standards in relation to the use and operation of electronic signatures
•
That Partner States should consider the need for an institutional
framework to support the provision of certification and related services at
both a national and regional level (R.14).
Cybercrime
Generally legislative initiatives in the area of computer or cybercrime have two
distinct objectives. First, there is a need to amend or supplement existing criminal law
to reflect the use of ICTs to commit a range of traditional offences or to engage in
undesirable acts against ICTs and the data they process. Second, there is a need to
reform criminal procedure rules to facilitate the investigation and prosecution of those
that engage in criminal acts using or against ICTs by law enforcement agencies.
The Task Force recommends that Partner States should undertake reform of
their criminal laws to specifically provide for cybercrimes (R. 15).
2.3.1
Substantive offences
14